CIPA compliance

CIPA claims turn on what your site sends before visitors choose

CIPA compliance

CIPA claims turn on what your site sends before visitors choose

Our free guide covers new approaches to wiretapping litigation risk: how claims work, why CCPA compliance leaves a gap, and how server-side tagging changes your exposure.
Google-certified CMP · ISO/IEC 27001:2022 certified · 2,800+ clients in 55+ countries

the issue

How a CIPA claim usually starts

An analytics pixel collects visitor data, such as IP address, browser, screen size, cookie values and the page URL, and sends it to a third party. Plaintiff firms find this by inspecting a site's network traffic in an ordinary browser.

Claims began with chatbots, moved to session replay, then to pixels and tags. Mobile SDKs and AI chat features are now targets too. Courts have read "interception" under Section 631 broadly, and Section 632 is increasingly applied to chat widgets.

ccpa vs. cipa

Why CCPA compliance leaves a gap

CCPA: opt-out
Visitors can tell you to stop selling or sharing their data. A working opt-out meets that expectation.
CIPA: consent first
As courts have read it, tracking needs consent before it fires. A working CCPA opt-out can still face a CIPA claim.
"CCPA, which I call compliance, and CIPA, which is litigation."
Matthew Pearson
Partner, Frankfurt Kurnit Klein & Selz

cases

What four California enforcement cases got wrong

The operational program that reduces CIPA exposure, in a single platform.

Honda

Opting out took more steps than opting back in.

Healthline Media

The opt-out didn't disable tracking cookies.

PlayOn

The banner offered only "Agree", and the opt-out link didn't stop data sales.

Sling TV

Two inconsistent mechanisms confused cookie rejection with a CCPA opt-out.

checklist

The checklist that comes out of them

Consent and opt-out work together

Your banner, your opt-out link and Global Privacy Control switch off the same vendors.

Disclosures match actual data practices

On average, 67% of active vendors on a website aren't declared in its privacy notice (Didomi 2026 Data Privacy Benchmark).

Tracking waits until the visitor consents

Pixels, chat and session replay load only after the visitor decides.

Accepting and rejecting are equally easy

Same layer, same size, same number of clicks.

You test it regularly

Retest after every release and keep a dated record.

server-side tagging

Where server-side tagging fits

Client-side tags

The browser sends data directly to every third party at once. That's what plaintiff firms see when they inspect network traffic.

Server-side tagging

Data goes to a server your company owns first. That server decides what to forward, and to whom, based on consent signals.

The guide's risk matrix adds a second factor: sites where visitors expect more privacy, such as healthcare and financial services, carry more exposure. Server-side tagging gives you one place to enforce consent, and a log of every forwarding decision.

Consent and server-side tagging
‍
from one privacy company

Didomi's Consent Management Platform and Addingwell's server-side infrastructure connect each visitor's consent to what your tags actually do.

Consent before tags load

Configured with Didomi's CMP, third-party tags wait for the visitor's choice on websites, apps and connected TV.

Server-side, governed by consent

Addingwell by Didomi hosts your server-side Google Tag Manager with consent built into the data flow, so you control what each vendor receives.

Problems surfaced before a demand letter

Event Consent Monitoring logs, for every event, whether consent was given, which tags fired and what went to which partner, and flags misconfigurations automatically.

Questions legal teams ask

We comply with CCPA. Doesn't that cover us?

Does server-side tagging remove CIPA exposure?

Is the guide legal advice?

CCPA and CIPA are two different problems.
Get both right.