Websites and Wiretap Laws: Emerging Trends in Privacy Class Action Litigation Risks
As an onslaught of recent class actions allege, companies may be liable for eavesdropping and wiretapping based on the use of common analytics software on their platforms.
For instance, in California, plaintiffs have filed hundreds of lawsuits against a broad range of businesses, alleging that using common online software or technologies like chatbots and cookies on their websites without express consumer consent constitutes unlawful eavesdropping or wiretapping under the California Invasion of Privacy Act (“CIPA”), Cal. Penal Code §§ 630, et seq. This 1967 law, enacted in the era of rotary telephones, is now being used to challenge the use of common third-party software that aids businesses in analyzing consumer activity and engagement with their websites. Because CIPA provides for statutory damages of $5,000 per violation, companies run the risk of significant exposure if CIPA claims are ultimately successful.
California courts have diverged in their approach to these CIPA cases: Courts following Graham v. Noom, 533 F. Supp. 3d 823 (N.D. Cal. 2021) and its progeny have required plaintiffs to plausibly allege that the third-party software (e.g., chatbot) provider uses purportedly intercepted information for its own purpose to support claims that the third-party provider is an unlawful eavesdropper. By contrast, courts relying on Javier v. Assurance IQ, LLC, 649 F. Supp. 3d 891 (N.D. Cal. 2023) and related cases merely require plaintiffs to claim that the software provider has the capability for such use. The California Supreme Court has yet to decide the issue.
Across the country, the Massachusetts Supreme Court is poised to rule on whether the use of analytics software to collect website browsing activity constitutes eavesdropping under the Massachusetts Wiretap Act. The court recently heard oral argument in Vita v. New England Baptist Hospital, et al., Case No. SJC-13542, in which the plaintiff alleged that multiple companies unlawfully eavesdropped on her communications when she browsed the websites of several hospitals that used such software without obtaining consumer consent. Like California courts, the Massachusetts justices appeared particularly concerned that the hospitals could “sell” purportedly intercepted information to advertisers or otherwise profit from such information without the consent of the website visitors. A decision from the court is forthcoming.
Ultimately, state legislatures may need to weigh in on whether decades-old wiretap laws apply to modern communications technology. Until then, companies would be wise to provide explicit disclosures and obtain express consent when utilizing analytics software on their consumer-facing platforms.
This article is available in the Jenner & Block Japan Newsletter. / この記事はJenner & Blockニュースレターに掲載されています。
Related Lawyers
Related Articles
Related Capabilities
© 2026 Jenner & Block LLP. Attorney Advertising. Jenner & Block LLP is an Illinois Limited Liability Partnership including professional corporations. This publication, presentation, or event is not intended to provide legal advice but to provide information on legal matters and/or firm news of interest to our clients and colleagues. Readers or attendees should seek specific legal advice before taking any action with respect to matters mentioned in this publication or at this event. The attorney responsible for this communication is Brent E. Kidwell, Jenner & Block LLP, 353 N. Clark Street, Chicago, IL 60654-3456. Prior results do not guarantee a similar outcome. Jenner & Block London LLP, an affiliate of Jenner & Block LLP, is a limited liability partnership established under the laws of the State of Delaware, USA and is authorised and regulated by the Solicitors Regulation Authority with SRA number 615729. Information regarding the data we collect and the rights you have over your data can be found in our Privacy Notice. For further inquiries, please contact dataprotection@jenner.com.
As an onslaught of recent class actions allege, companies may be liable for eavesdropping and wiretapping based on the use of common analytics software on their platforms.
For instance, in California, plaintiffs have filed hundreds of lawsuits against a broad range of businesses, alleging that using common online software or technologies like chatbots and cookies on their websites without express consumer consent constitutes unlawful eavesdropping or wiretapping under the California Invasion of Privacy Act (“CIPA”), Cal. Penal Code §§ 630, et seq. This 1967 law, enacted in the era of rotary telephones, is now being used to challenge the use of common third-party software that aids businesses in analyzing consumer activity and engagement with their websites. Because CIPA provides for statutory damages of $5,000 per violation, companies run the risk of significant exposure if CIPA claims are ultimately successful.
California courts have diverged in their approach to these CIPA cases: Courts following Graham v. Noom, 533 F. Supp. 3d 823 (N.D. Cal. 2021) and its progeny have required plaintiffs to plausibly allege that the third-party software (e.g., chatbot) provider uses purportedly intercepted information for its own purpose to support claims that the third-party provider is an unlawful eavesdropper. By contrast, courts relying on Javier v. Assurance IQ, LLC, 649 F. Supp. 3d 891 (N.D. Cal. 2023) and related cases merely require plaintiffs to claim that the software provider has the capability for such use. The California Supreme Court has yet to decide the issue.
Across the country, the Massachusetts Supreme Court is poised to rule on whether the use of analytics software to collect website browsing activity constitutes eavesdropping under the Massachusetts Wiretap Act. The court recently heard oral argument in Vita v. New England Baptist Hospital, et al., Case No. SJC-13542, in which the plaintiff alleged that multiple companies unlawfully eavesdropped on her communications when she browsed the websites of several hospitals that used such software without obtaining consumer consent. Like California courts, the Massachusetts justices appeared particularly concerned that the hospitals could “sell” purportedly intercepted information to advertisers or otherwise profit from such information without the consent of the website visitors. A decision from the court is forthcoming.
Ultimately, state legislatures may need to weigh in on whether decades-old wiretap laws apply to modern communications technology. Until then, companies would be wise to provide explicit disclosures and obtain express consent when utilizing analytics software on their consumer-facing platforms.
This article is available in the Jenner & Block Japan Newsletter. / この記事はJenner & Blockニュースレターに掲載されています。
Related Lawyers
Related Articles
Related Capabilities
© 2026 Jenner & Block LLP. Attorney Advertising. Jenner & Block LLP is an Illinois Limited Liability Partnership including professional corporations. This publication, presentation, or event is not intended to provide legal advice but to provide information on legal matters and/or firm news of interest to our clients and colleagues. Readers or attendees should seek specific legal advice before taking any action with respect to matters mentioned in this publication or at this event. The attorney responsible for this communication is Brent E. Kidwell, Jenner & Block LLP, 353 N. Clark Street, Chicago, IL 60654-3456. Prior results do not guarantee a similar outcome. Jenner & Block London LLP, an affiliate of Jenner & Block LLP, is a limited liability partnership established under the laws of the State of Delaware, USA and is authorised and regulated by the Solicitors Regulation Authority with SRA number 615729. Information regarding the data we collect and the rights you have over your data can be found in our Privacy Notice. For further inquiries, please contact dataprotection@jenner.com.
News and Insights
Event
Partner John Storino to Speak at Sandpiper Partners' “AI and Outside Counsel Guidelines Roundtable”
On October 8, Partner John Storino will serve as a panelist at the “AI and Outside Counsel Guidelines Roundtable,” hosted by Sandpiper Partners in Chicago.
October 8, 2026
Event
Partner Meghan Greenfield to Speak on Supreme Court Climate Case at Edison Electric Institute's Fall Legal Conference
On Wednesday, October 7, Partner Meghan Greenfield will speak on a panel titled "Boulder County v. Suncor Energy: What the Supreme Court's Climate Case Means for the Energy Industry" at the Edison Electric Institute's Fall Legal Conference in Salt Lake City, Utah.
October 7, 2026
Publications
The Form Rules Everything: A Seventh Circuit Ruling on ERISA's Substantial Compliance Doctrine
Partner Joseph Torres and Special Counsel Jennifer Beach authored an article for Employee Relations Law Journal examining the Seventh Circuit's decision in Packaging Corp. of America Thrift Plan for Hourly Employees v. Langdon, a ruling that addresses both the standard of review in ERISA interpleader actions and the continued viability of the substantial compliance doctrine for changing plan beneficiaries.
October 5, 2026
Recognition
Jenner & Block Rises in American Lawyer Rankings for Summer Associate Experience
Jenner & Block ranked 14th nationally in The American Lawyer’s 2026 Summer Associate Satisfaction Survey, jumping 10 spots from last year. The annual survey measures summer associate satisfaction at US law firms based on ratings provided directly by summer associates across key firm qualities.
October 2, 2026
Publications
Partner Ashley Callen Discusses Potential Congressional Investigations in Reuters
Partner Ashley Callen was quoted in a Reuters article examining how Democrats could ramp up congressional investigations into Trump family business dealings if they win control of the House or Senate in the 2026 midterm elections this November.
September 30, 2026
Event
Associate Steven Arango Addresses North Korean IT Worker Threat in Talks to Business Executives for National Security Members in Texas
On September 29 and 30, Associate Steven Arango led luncheon discussions titled "North Korea's IT Worker Threat: Corporate Risk and Response" for Business Executives for National Security (BENS) members in Dallas and Austin, Texas, speaking to an audience of CEOs, CISOs, and other senior leaders from the national security, finance, and healthcare sectors.
September 2026