CIPA compliance

CIPA is rewriting the rules on tracking and recording.

CIPA compliance

CIPA is rewriting the rules on tracking and recording.

A 1967 wiretapping law is now one of the fastest-growing litigation risks for digital businesses collecting data from California users.

$5,000

Max penalty per violation

1967

Enacted, still in force

All-party

Consent required

Trusted by thousands of companies worldwide

What it is

A 1967 wiretapping law now targets modern tracking

CIPA (Cal. Penal Code § 630 et seq.) bans recording confidential communications without every party's consent. Written for landlines, it now covers cookies, pixels, session replay, and chat tools. Unlike federal law's one-party consent rule, California requires all-party consent, every participant in a confidential communication must agree to being recorded.

Request a demo

Where claims come from

Three recurring fact patterns in current CIPA litigation

Customer service call recording
Automated "this call may be recorded" disclosures are challenged as inadequate consent, especially when customers have no practical alternative but to continue the call.
Employee monitoring
Remote work and productivity tools raise claims that employees never consented to call recording, email monitoring, or activity tracking.
Third-party access via vendors
Search terms passed to trackers, chatbot vendors, and analytics platforms accessing communications without explicit consent from all parties.
"We're seeing a lot of CIPA litigation around search terms embedded in URLs, plaintiffs' attorneys are alleging that is a confidential communication under CIPA."
Matthew Pearson, Partner at Womble Bond Dickinson

Risk mitigation

One CMP for all six operational controls

The operational program that reduces CIPA exposure, in a single platform.

1. Consent & transparency

Notice before collection, not after. Store consent states, timestamps, and notice versions as evidence.

2. Minimize collection

Only what's needed, only when needed. Audit high-risk inputs and mask sensitive fields.

3. Vendor governance

Every tag inventoried and controlled, activated by consent state and matched to contracts.

4. Monitoring & change control

Catch drift before it becomes exposure. Govern new tags before launch and run regular audits.

5. Team training & escalation

Everyone knows what to flag, and to whom. Clear rules on what "do not deploy" means.

6. Defensible posture

Proof, on record, when a claim arrives. Consistent, documented, and reviewable without rebuilding.

How Didomi helps

A consent management platform
‍
built for exactly this kind of exposure

Consent, notice, and proof, without slowing your stack down

Didomi's CMP gives you the timing, notice, proof, and vendor governance a defensible CIPA program requires, in one place.

Didomi blocks tools until the right consent signal is collected, stores every consent state and notice version as evidence, and keeps a live inventory of every vendor tag activated by consent state, the exact record a defensible CIPA program requires.

Request a demo

Implementation

How to become CIPA compliant with Didomi

Assess

Scan your site, map vendors and purposes, import current consent.

Configure

Frameworks, regions, branding, and California-specific consent signals.

Integrate

Google Tag Manager, analytics, ads, block every tool until consent.

Prove and optimize

Analytics dashboard, audit-ready exports, and ongoing experiments.

Why teams choose Didomi

One platform. Every regulation. Every channel.

Built for teams who can't afford to choose between compliance and performance.

Multi-regulation coverage

CPRA/CCPA, LGPD, GDPR, DPA, etc., ready for other US state laws, so you don’t have to worry about what’s changing next.

Google Consent Mode v2

Seamless Google Consent Mode v2 integration (protect measurement while staying compliant). Keep your analytics alive as privacy evolves.

Built to scale globally

Multi-language, multi-brand, multi-region, multi-domain setup for fast global rollout. Because scaling shouldn’t mean starting over.

Customization

Fully customizable UX to lift opt-in rates (and trust).

Advanced Compliance Monitoring

Audit-ready reporting and consent proof exports for regulators and DPOs.

Partnership level support

Highly responsive, guided onboarding, technical setup support and continuously improving your consent performance.

Why choose Didomi for your Consent Management Platform?

A global leader in consent and data privacy, our CMP helps you comply with international data privacy regulations, regain your customers' trust, and generate revenue.

Why companies opt for betterconsent management with Didomi

+12 consent rate increase
"As a former consultant in the analytics field, I know Didomi very well. It’s a solution I consistently recommend for its robustness and its ability to continuously improve over time. I’ve seen a lot of evolution in recent years. For me, when it comes to CMPs, there’s no debate."
Hassen Hammeche
Lead tracking at Europcar
+10% consent rate increase
“The advantage with Didomi's CMP is that we can centralize consent management by screen: mobile, TV & App.”
Jean-Baptiste Viet
Web Analytics Project Manager
+12% traffic recovered
10%lower latency
"Didomi brings real improvement on key tracking metrics, with a simple and fast setup. Support is there when needed, and the product evolves regularly in the right direction, an efficient and reliable solution that I recommend."
Clément Trestard
Analytics & CRO Team Lead

See where your CIPA exposure sits today

Get a walkthrough of how Didomi's CMP maps to the six operational controls that reduce CIPA risk.

A 30-minute conversation to cover how Didomi privacy unblocks teams and supports revenue growth

A live demo of our products, personalized to your organization’s specific needs

All your questions answered, with no commitment

Fill out the form to talk to a Didomi expert and begin your journey.

Valid number

Frequently Asked Questions (FAQ)

What's the difference between CIPA and CCPA?

Does CIPA apply to businesses outside California?

What counts as a "confidential communication" under CIPA?

How does Didomi help with CIPA specifically?