CIPA compliance
CIPA claims turn on what your site sends before visitors choose
CIPA compliance
CIPA claims turn on what your site sends before visitors choose
.png)
the issue
How a CIPA claim usually starts
An analytics pixel collects visitor data, such as IP address, browser, screen size, cookie values and the page URL, and sends it to a third party. Plaintiff firms find this by inspecting a site's network traffic in an ordinary browser.
Claims began with chatbots, moved to session replay, then to pixels and tags. Mobile SDKs and AI chat features are now targets too. Courts have read "interception" under Section 631 broadly, and Section 632 is increasingly applied to chat widgets.

ccpa vs. cipa
Why CCPA compliance leaves a gap
cases
What four California enforcement cases got wrong
The operational program that reduces CIPA exposure, in a single platform.
Honda
Opting out took more steps than opting back in.
Healthline Media
The opt-out didn't disable tracking cookies.
PlayOn
The banner offered only "Agree", and the opt-out link didn't stop data sales.
Sling TV
Two inconsistent mechanisms confused cookie rejection with a CCPA opt-out.
checklist
The checklist that comes out of them
Your banner, your opt-out link and Global Privacy Control switch off the same vendors.
On average, 67% of active vendors on a website aren't declared in its privacy notice (Didomi 2026 Data Privacy Benchmark).
Pixels, chat and session replay load only after the visitor decides.
Same layer, same size, same number of clicks.
Retest after every release and keep a dated record.
server-side tagging
Where server-side tagging fits
Client-side tags
The browser sends data directly to every third party at once. That's what plaintiff firms see when they inspect network traffic.
Server-side tagging
Data goes to a server your company owns first. That server decides what to forward, and to whom, based on consent signals.
The guide's risk matrix adds a second factor: sites where visitors expect more privacy, such as healthcare and financial services, carry more exposure. Server-side tagging gives you one place to enforce consent, and a log of every forwarding decision.
Consent and server-side tagging
from one privacy company
Didomi's Consent Management Platform and Addingwell's server-side infrastructure connect each visitor's consent to what your tags actually do.
Consent before tags load
Configured with Didomi's CMP, third-party tags wait for the visitor's choice on websites, apps and connected TV.
Server-side, governed by consent
Addingwell by Didomi hosts your server-side Google Tag Manager with consent built into the data flow, so you control what each vendor receives.
Problems surfaced before a demand letter
Event Consent Monitoring logs, for every event, whether consent was given, which tags fired and what went to which partner, and flags misconfigurations automatically.
Questions legal teams ask
We comply with CCPA. Doesn't that cover us?
CCPA works on opt-out. CIPA claims ask whether tracking started before the visitor agreed to it, so the two need separate answers.
Does server-side tagging remove CIPA exposure?
It changes where data goes first and gives you control and a record of what each vendor receives. Consent still applies to what you forward.
Is the guide legal advice?
The guide explains how wiretapping claims under CIPA work. Your counsel decides how it applies to your business.
