Pixel Tracking

Wiretapping Claims Against Website Tracking: How the Theories Work

Key Takeaways

  • The federal Wiretap Act permits interception where one party consents, so the volume of litigation sits in the all-party consent states rather than in federal court
  • California Penal Code section 637.2 awards the greater of $5,000 per violation or treble actual damages, and states expressly that actual damages are not a prerequisite to suit
  • The Third Circuit held in Popa v. Harriet Carter Gifts that Pennsylvania's wiretap act has no direct-party exception, and that interception occurs where a communication is captured, not only where a vendor's servers sit
  • The pen-register theory borrows sections 638.50 and 638.51 of the California Penal Code, which reach routing and addressing information rather than message contents
  • A federal court vacated the HHS bulletin treating an IP address plus a visit to a public health webpage as protected health information, in American Hospital Association v. Becerra

Statutes Older Than the Web

The claims brought against analytics pixels, session recording scripts and embedded chat widgets are, with few exceptions, not privacy claims. They are eavesdropping claims, pleaded under criminal surveillance statutes enacted before the technology existed and carrying civil remedies attached to them years later.

California's Invasion of Privacy Act opens with a legislative declaration from 1967 that “advances in science and technology have led to the development of new devices and techniques for the purpose of eavesdropping upon private communications,” and that the resulting invasion of privacy “cannot be tolerated in a free and civilized society.” The federal Wiretap Act followed in 1968. Neither was drafted with an HTTP request in mind, and the entire body of law discussed here consists of courts deciding how far that vocabulary stretches.

Two features explain why the theory is attractive to plaintiffs rather than merely available. The remedies are set per violation and do not require proof of loss. And because the statutes are criminal in origin, they attach to conduct rather than to a regulated category of business, so they reach any operator of a website regardless of sector, revenue or data volume.

Why the Federal Statute Is Rarely the Vehicle

The federal Wiretap Act defines “intercept” as the aural or other acquisition of the contents of a wire, electronic or oral communication through an electronic, mechanical or other device. “Contents” is separately defined to include any information concerning the substance, purport or meaning of the communication. Both definitions matter: information about a communication that is not its substance falls outside the term.

The provision that governs most private disputes is 18 U.S.C. 2511(2)(d). It makes interception lawful for a person not acting under colour of law “where such person is a party to the communication or where one of the parties to the communication has given prior consent,” unless the interception is made “for the purpose of committing any criminal or tortious act in violation of the Constitution or laws of the United States or of any State.”

One-party consent disposes of the ordinary case: a website operator is a party to the exchange with its own visitor. The residual federal question is therefore the crime-tort proviso, which asks about the purpose of the interception rather than about its consequences — and which, on its terms, requires an unlawful purpose separate from the interception itself.

The remedies in 18 U.S.C. 2520 are nonetheless substantial where the claim survives: statutory damages of the greater of $100 per day of violation or $10,000, or alternatively actual damages plus the violator's profits, together with punitive damages and fees. Subsection (d) supplies a good-faith reliance defence.

The All-Party Consent States Carry the Docket

Because the federal one-party rule is a floor rather than a ceiling, states that require every party's consent are where the litigation concentrates. Section 631(a) of the California Penal Code is the most heavily pleaded provision in the country on this subject, and it is really four prohibitions in one sentence:

  1. Making an unauthorised connection with any telegraph or telephone wire, line, cable or instrument.
  2. Willfully and without the consent of all parties reading, or attempting to read or learn, the contents or meaning of any message while it is in transit or passing over any wire, line or cable.
  3. Using, or attempting to use, in any manner or for any purpose, any information so obtained.
  4. Aiding, agreeing with, employing or conspiring with any person to do any of the above.

The third and fourth clauses do a great deal of work in tracking cases, because they reach a party who did not itself perform the acquisition. The first clause, by contrast, is textually tied to telegraph and telephone infrastructure, which is why arguments about section 631 tend to be fought over the second and third clauses rather than the first.

The civil remedy sits separately at section 637.2. It permits any person injured by a violation of the chapter to recover the greater of $5,000 per violation or three times actual damages, and to seek an injunction. Subdivision (c) states expressly that it “is not a necessary prerequisite to an action pursuant to this section that the plaintiff has suffered, or be threatened with, actual damages.”

Why 'of this chapter' matters

Chapter 1.5 of the California Penal Code runs from section 630 through section 638.55. Because section 637.2 attaches its civil remedy to a violation of the whole chapter rather than to any single section, every prohibition inside that range — including the pen-register provisions added in 2015 — carries the same $5,000 per-violation figure.

Section 632.7, sometimes pleaded alongside, is narrower by its own terms. It reaches communications transmitted between two cellular radio telephones, a cellular and a landline telephone, two cordless telephones, or combinations of those — and the statute defines cellular and cordless telephones by reference to the frequency bandwidths the Federal Communications Commission has reserved for them. A browser session is not obviously any of those devices.

The Party Exception and What the Third Circuit Did to It

The defence that decides most of these cases is that the recipient of the data was itself a party to the communication, so nothing was intercepted at all. The Third Circuit rejected that construction of Pennsylvania law in Popa v. Harriet Carter Gifts, Inc., No. 21-2203, decided August 16, 2022.

The facts are the ordinary pattern. In 2018 Ashley Popa browsed the Harriet Carter Gifts website on an iPhone, gave an email address to a pop-up, searched for pet stairs, added a set to her cart and abandoned checkout. Her browser was simultaneously communicating with the retailer and with NaviStone, a third-party marketing service she did not know was there. The district court granted summary judgment on the basis that NaviStone was a party to the exchange and so could not have intercepted anything.

Writing for the panel, Judge Ambro vacated. Pennsylvania's Wiretapping and Electronic Surveillance Control Act, 18 Pa. C.S. 5701 et seq., defines interception simply as acquisition of the contents of a communication through a device, and the court declined to read an unwritten direct-party exception into it. The reasoning was structural: section 5704(4) already exempts an interception “where all parties to the communication have given prior consent,” and a general direct-party exception would make that all-party requirement disappear.

Under Pennsylvania law, then, there is no direct-party exception to liability under the WESCA (save for law enforcement under specific conditions).

Popa v. Harriet Carter Gifts, Inc., No. 21-2203 (3d Cir. Aug. 16, 2022)

The panel resolved a second question with wider practical reach: where does an interception happen? The district court had located it at NaviStone's servers in Virginia, outside the Commonwealth. The Third Circuit held instead that the interception occurs where the communication is captured or redirected, aligning with federal decisions reading the identical definitional language — United States v. Rodriguez, 968 F.2d 130, 136 (2d Cir. 1992), United States v. Denman, 100 F.3d 399, 403 (5th Cir. 1996), and United States v. Luong, 471 F.3d 1107, 1109 (9th Cir. 2006). The opinion observed that the contrary rule would let a company “capture the data of people in other states as long as they parked their servers in a state with weak privacy protections.”

That situs holding is why the choice of a two-party consent state by the plaintiff, rather than by the defendant's place of business, tends to govern which statute applies.

Consent Is Where These Cases Are Actually Decided

Having removed the party exception, Popa remanded on consent — and the standard it identified is the one most of this litigation turns on. Quoting Commonwealth v. Byrd, 235 A.3d 311, 319 (Pa. 2020), the panel noted that prior consent under section 5704(4) does not require actual knowledge, and that implied consent “can be demonstrated when the person being recorded knew or should have known[] that the conversation was being recorded.”

The unresolved question on remand was whether the retailer's privacy policy said enough, and whether it existed in that form at the relevant time. The opinion records that a senior employee attested the policy was posted during the period but later could not produce the 2018 version at deposition. That evidentiary gap, rather than any doctrinal dispute, is what the case was sent back to resolve.

The general shape of the inquiry is therefore factual and record-bound: what a visitor was shown, when, in what prominence, and whether the disclosure described the transmission that actually occurred. Descriptions of the technology that do not match what the site did are the recurring point of failure in the reported decisions.

The Pen Register Theory

A newer line of pleading avoids the contents requirement altogether. Sections 638.50 and 638.51 of the California Penal Code, added by Stats. 2015, ch. 204 (AB 929) and effective January 1, 2016, transplant the federal pen-register framework into state law.

Section 638.50(b) defines a pen register as “a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, but not the contents of a communication.” Subdivision (c) defines a trap and trace device as one capturing incoming impulses identifying the source of a communication, again excluding contents. Section 638.51(a) then provides that “a person may not install or use a pen register or a trap and trace device without first obtaining a court order.”

Three features of that text explain the theory's appeal to plaintiffs. The prohibition runs to any person, not to law enforcement alone. The phrase “device or process” is broad enough to be argued to cover software. And because the definition excludes contents, the defence that a tracker captured only metadata — which defeats a section 631 claim — does not answer this one.

The statute's own exceptions are correspondingly narrow. Section 638.51(b) permits use by “a provider of electronic or wire communication service” for five listed purposes: operating, maintaining and testing the service; protecting the provider's rights or property; protecting users from abuse or unlawful use; recording that a communication was initiated or completed to guard against fraudulent, unlawful or abusive use; and where “the consent of the user of that service has been obtained.” Subdivision (d) makes good-faith reliance on a court order a complete defence.

The federal analogue at 18 U.S.C. 3127 uses near-identical definitional language but sits in a chapter without a private civil remedy, which is why the theory is a state-law one.

Healthcare Pixels and the Vacated Bulletin

Tracking on hospital and health-system websites drew a separate federal response, which a court then set aside. In December 2022 the HHS Office for Civil Rights issued guidance on online tracking technologies, revised on March 18, 2024. The revised bulletin treated a combination of a visitor's IP address with a visit to an unauthenticated public webpage addressing specific health conditions or providers as individually identifiable health information under HIPAA.

Two hospital associations and a regional health system challenged that position. In American Hospital Association v. Becerra, No. 4:23-cv-01110-P (N.D. Tex. June 20, 2024), the court granted declaratory judgment, holding what it called the “Proscribed Combination” unlawful “as it was promulgated in clear excess of HHS's authority under HIPAA.” Measuring the guidance against the statutory definition at 42 U.S.C. 1320d(6), the court found that the closest the combination came to identifiable health information was “a speculative inference extrapolated from (but unsubstantiated by) collected metadata.”

On remedy the court denied a permanent injunction but granted vacatur, and added a footnote limiting the scope of what it had done: the vacatur “is not intended to, and should not be construed as, limiting the legal operability of other guidance in the germane HHS document.” The remainder of the bulletin stands; the specific IP-address-plus-page-visit rule does not.

The decision removes one federal theory from health-sector pixel disputes. It does not touch the state eavesdropping claims described above, which do not depend on whether the data is health information at all.

Where the Record Is Incomplete

Two limits on this guide are worth stating rather than papering over. First, the great majority of session-replay and chat-widget rulings are unpublished district-court orders on motions to dismiss, decided on the particular script and the particular disclosure in front of the court. This guide sets out the statutory elements those orders apply; it does not chart the orders themselves, and no count of how they have divided is offered here.

Second, at least one state supreme court has addressed whether a state eavesdropping statute reaches ordinary website browsing at all. That decision is not cited here because the official and mirrored copies of the opinion could not be retrieved, and a holding this consequential is not worth reporting from a summary of it.

Background

For the underlying law rather than this development: California privacy law, Pennsylvania privacy law, Retail & E-Commerce privacy law, Healthcare privacy law.

Frequently Asked Questions

Why are these claims brought under state law rather than the federal Wiretap Act?
Because 18 U.S.C. 2511(2)(d) makes interception lawful where one party consents, and a website operator is a party to the exchange with its own visitor. States that require the consent of all parties, such as California and Pennsylvania, do not have that off-ramp.
What are statutory damages under the California Invasion of Privacy Act?
Penal Code section 637.2 permits recovery of the greater of $5,000 per violation or three times actual damages, plus injunctive relief. Subdivision (c) states that suffering actual damages is not a prerequisite to bringing the action.
What is the pen register theory in website tracking cases?
It relies on Penal Code sections 638.50 and 638.51, which bar installing or using a pen register or trap and trace device without a court order. Those definitions cover routing, addressing and signaling information and expressly exclude the contents of a communication, so a defence that only metadata was captured does not answer the claim.
Does a privacy policy establish consent to tracking?
Popa v. Harriet Carter Gifts remanded that question rather than answering it. The Pennsylvania standard the panel applied asks whether the person knew or should have known, which makes it a fact question about what was disclosed, how prominently, and whether the disclosure matched what the site actually transmitted.
Did the court in American Hospital Association v. Becerra strike down all of the HHS tracking guidance?
No. It vacated only the rule treating an IP address combined with a visit to an unauthenticated public webpage about specific health conditions as individually identifiable health information. A footnote states the vacatur was not intended to limit the legal operability of other guidance in the same document.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.