Free scan
Demand letters · troubleshooting

What a CIPA demand letter is actually claiming

Almost every one of these letters makes the same argument in the same order: a third-party script on your website received the contents of a visitor's interaction while it was happening, the visitor never agreed to that, and California's wiretapping statute treats that as an interception. Everything else in the letter — the damages arithmetic, the deadline, the settlement figure — hangs off that one claim.

The short answer

Understanding the structure is useful for a practical reason: parts of the claim are legal questions you cannot answer, and parts are factual questions about your own website that you can settle in an afternoon. Separating them is the most productive thing you can do before you talk to a lawyer, because it turns "they say we wiretapped people" into a short list of verifiable statements about what your site loaded and when.

This page decodes the standard claims. It is not legal advice and it is not a response strategy — for the sequence of what to do after a letter arrives, see our walkthrough of what happens next, and talk to a qualified attorney about your specific letter.

Last reviewed: September 1, 2026Diagnostic + fix checklistGeneral information, not legal advice

The shape of the letter

The letters are near-identical because the theory is. A named individual says they visited your website. The letter identifies one or more third-party tools by name — a session recorder, a chat widget, an advertising pixel. It asserts that those tools captured what the visitor did and sent it to the vendor in real time, without consent. It then cites the statutory damages provision, multiplies it by an implied number of affected visits, and proposes a settlement below that number.

What it usually does not contain is evidence specific to you beyond a scan of your homepage — which is why the technical facts are worth establishing yourself.

The four claims, in the order they normally appear:
1. A third party received the communication ← the vendor, not you, is the alleged eavesdropper
2. It happened in transit, in real time ← not a later export — while the visitor was interacting
3. No consent from all parties ← California is an all-party-consent state
4. Statutory damages, per violation ← § 637.2 — up to $5,000, argued per session

Decode your own letter in five minutes

Work through the letter with a highlighter. You are sorting every assertion into one of two buckets: legal questions for your attorney, and factual questions about your website that you can answer today.

  1. Highlight every tool the letter names. Session recorder, chat widget, pixel, analytics. That named list is the letter's factual core — and it comes from an automated scan of your site, usually of the homepage only.
  2. Note the date the visit allegedly occurred. Then ask the question that decides a surprising number of these: was that tool even installed on that date? Letters do go to sites where the named tool was removed months earlier.
  3. Find the statutory citations. Almost always Penal Code § 631 (interception) and § 637.2 (the private right of action and damages). Some letters add § 632.7, which by its text addresses communications between cellular or cordless telephones, and some add § 638.51, the pen register and trap-and-trace provision. Which sections are cited tells you which theory the firm is running.
  4. Separate "what happened" from "what it means". "The Hotjar script transmitted data to hotjar.com before any consent interaction" is a fact you can verify. "This constitutes an unlawful interception" is a legal conclusion you cannot, and should not try to.
  5. Establish the facts on your side. Load your own site in a fresh incognito window with DevTools open and record which of the named tools actually contact their servers before consent. Save the evidence with the date. If you have monitoring or a prior dated report, pull the record for the alleged visit date too.
  6. Hand your attorney the sorted list, not the whole letter and a shrug. A one-page summary of what your site actually does, with dated evidence, is worth more than an hour of reconstruction.

What a healthy result looks like: You end with two lists: verified technical facts about your own site, and legal assertions for counsel. Do not respond to the sender yourself, and do not delete evidence in a way that looks like you are hiding what was running.

The four claims, decoded

1. "A third party intercepted the communication"

The core theory. Your visitor is communicating with your website; a script from another company — the recorder, the chat vendor, the pixel — receives that interaction at the same time. The letter argues that company is an uninvited party to the conversation. Note who is being described as the eavesdropper: not you, the vendor. The claim against you is generally framed as aiding that interception.

2. "While in transit"

§ 631 speaks to reading or learning the contents of a communication "while the same is in transit or passing over any wire, line, or cable". This is why real-time streaming tools — session replay, chat, live event pixels — anchor these letters, and why "we only look at aggregate reports later" is not the answer people expect it to be.

3. "Without the consent of all parties"

California is an all-party-consent state, so the letter argues that consent from you is not enough — the visitor had to agree too, before the transmission. This is the claim your consent banner is supposed to address, and it is the reason a banner that displays but does not block changes nothing about the argument.

4. "Up to $5,000 per violation"

§ 637.2 creates a private right of action with statutory damages of five thousand dollars per violation, or three times actual damages, whichever is greater. Plaintiffs argue each affected visit is a separate violation. That multiplication is where the intimidating headline number comes from; whether it survives contact with a court is a different question entirely.

What the statute actually says

The operative language of Penal Code § 631(a) covers any person who, "willfully and without the consent of all parties to the communication, or in any unauthorized manner, reads, or attempts to read, or to learn the contents or meaning of any message, report, or communication while the same is in transit or passing over any wire, line, or cable, or is being sent from, or received at any place within this state" — and, separately, anyone who "aids, agrees with, employs, or conspires with any person" to do so. That second clause is the one that reaches website operators.

The statute dates from 1967 and was written about telephone lines. Applying it to a script tag is a live legal argument, not a settled fact, and courts have not been uniform about it. Some letters also invoke § 638.51, which prohibits installing or using a pen register or trap and trace device without a court order — a theory built on the idea that tracking scripts capture identifying routing data. It is newer and less settled still.

The practical point stands regardless of how those arguments resolve: the letters are generated from automated scans that look for one specific, observable pattern. A site that does not exhibit the pattern is a much less attractive target than one that does.

The remediation that matters, whatever the letter's merits

What this is called

Terminology bridge

The umbrella term for this litigation is the website wiretapping or CIPA wave; the specific theory is the third-party eavesdropper theory, and the counter-argument you will hear from counsel is the party exception — the idea that a vendor acting purely as your tool is not a separate party at all. The newer theory built on § 638.51 is the pen register or trap and trace theory. What the plaintiff-side scanners are measuring, in our vocabulary, is a consent gap: a third-party transmission that happens before the visitor answers.

What a scan can and can't tell you

Be clear about what a scan is and is not. It establishes which third-party servers your site contacted, and when, relative to the consent interaction. It cannot tell you whether the party exception applies, whether the plaintiff has standing, whether the visit happened as alleged, or what any of it is worth. Those are legal judgments, and nothing on this page is legal advice — it is a description of a common document so you can read yours with less fog.

Sources

  1. California Penal Code § 631 — interception (leginfo)leginfo.legislature.ca.gov
  2. California Penal Code § 637.2 — private right of action and damagesleginfo.legislature.ca.gov
  3. California Penal Code § 632.7 — cellular and cordless telephone communicationsleginfo.legislature.ca.gov
  4. California Penal Code § 638.51 — pen register and trap and trace devicesleginfo.legislature.ca.gov
  5. California Attorney General: CCPA overviewoag.ca.gov

Check your own site

RegSentry loads your site in a real browser, records when each third-party tracker first contacts its server, and flags everything that fires before consent — with the fix for each one. Continuous monitoring re-runs it and emails you when something new appears.

Free real-browser scan

See every pre-consent tracker on your site — free, 30 seconds, no signup.

Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.

Common questions

What is a CIPA demand letter actually alleging?
That a third-party script on your website — typically a session recorder, chat widget, or advertising pixel — received the contents of a visitor's interaction in real time, without the visitor's consent, and that this is an interception under California Penal Code § 631. The letter then cites § 637.2, which allows statutory damages of up to $5,000 per violation, and argues each affected visit is a separate violation.
Why do some letters cite § 632.7 or § 638.51 as well?
They are alternative theories. Section 632.7 by its text addresses communications between cellular or cordless telephones. Section 638.51 prohibits installing or using a pen register or trap and trace device without a court order, and the argument is that tracking scripts capture identifying routing data. Both are less settled than the § 631 theory in the website context.
Can I check the letter's factual claims myself?
Partly, and it is worth doing. Whether the named tools actually contact their servers before consent on your site today is something you can verify in a browser in a few minutes, and whether they were installed on the alleged visit date is something your records or a dated report may answer. Whether any of it is a violation is a legal question for your attorney.

Keep reading

Guide: I got a CIPA demand letter — what happens nextGot a demand letter? Response guideCalifornia CIPA explainedSample scan reportCIPA exposure calculator