CIPA / ECPA / VPPA / WESCA / FSCA

got pixels?

CIPA lawsuit evidence

Preserve Section 631 facts. Keep each CIPA theory distinct.

For defense counsel reviewing a California Invasion of Privacy Act claim, preserve the consent path, request timing, contents, recipients, and browser steps. Separate Section 631 from Sections 632 and 638.51.

Try it yourself. Open the app.

byPapaya Privacy Co.General product and technical information. Not legal advice.
Matter-specific evidence question

What left the browser after a California visitor rejected tracking?

JurisdictionCalifornia
ConsentReject all
CommunicationSearch + form
RecipientThird-party endpoint
EvidenceTiming + payload

The short answer

CIPA evidence to preserve

For a CIPA pixel lawsuit, preserve the California user context, consent interface and choice, communication or user action, request timing, script initiator, recipient, payload contents, identifiers, screenshots, and reproduction steps. Tie each transmission to the browser state that produced it.

CIPA contains distinct provisions. Section 631 addresses tapping, unauthorized connections, and learning the contents or meaning of a communication in transit. Section 632 addresses eavesdropping upon or recording a confidential communication without all-party consent. Section 638.51 addresses pen registers and trap-and-trace devices, subject to statutory exceptions.

The browser record does not decide whether a tracker satisfies a statutory definition, whether the communication was confidential, whether a participant or service-provider defense applies, or whether consent was legally sufficient. Counsel applies those questions to the preserved facts and current authority.

Authority map

Match law to evidence

These authorities frame different elements, exceptions, and defenses. The browser record should stay factual enough for counsel to apply the current law.

Cal. Penal Code § 631

Was there an unauthorized connection or an attempt to learn the contents or meaning of a communication while it was in transit?

Communication, user action, script initiator, request timing, payload contents, recipient, party roles, and consent state.

Cal. Penal Code § 632

Was a confidential communication intentionally eavesdropped upon or recorded without all-party consent?

The communication or interaction, surrounding page context, recording or capture mechanism, consent interface, recipients, and user expectations available for review.

Cal. Penal Code § 638.51

Did the technology function as the alleged pen register or trap-and-trace device, and does an exception apply?

Addressing or signaling data, request destination, initiator, user consent, provider role, and facts relevant to the statute's listed exceptions.

Evidence ledger

CIPA evidence checklist

The test should isolate the provision-specific facts instead of applying one CIPA label to every request.

California context

The tested user location, browser state, page, and journey relevant to the asserted California theory.

Consent record

Banner text, no-choice, accept, reject, and GPC paths, plus the moment the visitor's choice changed.

Communication

Search, chat, form, checkout, page view, or other interaction that allegedly produced the disputed request.

Timing and initiator

Sequence between the user action, script execution, and network request, including which code initiated it.

Contents and signals

URLs, event names, search or form values, payload fields, identifiers, and addressing or signaling data.

Recipient and repeatability

Third-party destination, request chain, screenshots, agent steps, and a workflow that can be rerun.

Controlled browser workflow

Compare CIPA consent paths

A provision-specific audit compares what the site does before and after consent choices while preserving the same user action.

01

Define the CIPA theory

Name the provision, communication, tracker, California user context, consent path, and journey the run is meant to test.

02

Capture the baseline

Record initial scripts, requests, cookies, banner state, and page conditions before the visitor makes a choice.

03

Reproduce the interaction

Make the specified choice, complete the search, chat, form, checkout, or page journey, and preserve every outgoing request.

04

Compare and qualify

Repeat accept, reject, no-choice, and applicable GPC paths. Separate observed facts, inconsistent results, defenses, and open legal questions.

Limits and defenses

CIPA test limitations

A technical record can confirm or contradict factual assumptions. It cannot decide every CIPA element or defense.

01

The same request may present different questions under Sections 631, 632, and 638.51. One result should not be generalized across all three.

02

Request timing can support an in-transit analysis, but the report does not determine the legal meaning of interception under current authority.

03

A captured search, chat, or form value does not by itself establish confidentiality, contents, intent, party status, or lack of consent.

04

Section 638.51 includes statutory exceptions, including specified service-provider uses and user consent. The test should preserve facts relevant to them.

05

A present-day run does not establish the site's historical behavior, every California visitor state, or the result in another browser or account condition.

Questions counsel ask

CIPA evidence FAQ

Direct answers about the evidence record. Legal conclusions still depend on the statute, jurisdiction, parties, exceptions, defenses, and current authority.

What evidence matters in a CIPA pixel lawsuit?

The evidence depends on the provision and theory. A useful record can preserve the California user context, consent state, communication or interaction, request timing, initiator, recipient, payload contents, identifiers, screenshots, and the steps needed to reproduce the transmission.

What evidence matters under CIPA Section 631?

Preserve the communication or user action, request timing, script initiator, recipient, payload contents, party roles, and consent state. Those facts help counsel evaluate the asserted Section 631 theory, including whether a third party learned contents or meaning while a communication was in transit. The browser record does not establish a violation or resolve statutory exceptions and defenses.

How is a Section 632 theory different from Section 631?

Section 632 addresses intentional eavesdropping upon or recording a confidential communication without all-party consent. Section 631 contains separate language concerning tapping, unauthorized connections, and learning the contents or meaning of a communication in transit. The browser test should match the specific theory.

Does CIPA Section 638.51 apply to every tracking pixel?

The statute restricts installing or using a pen register or trap-and-trace device without a court order, subject to listed exceptions that include user consent for certain service-provider uses. Whether a website tool fits those definitions is a legal question; the browser record preserves addressing, signaling, consent, and request facts for that analysis.

See the software in action

Watch Got Pixels test a browser journey relevant to your work.

Book a demo

Got Pixels

Build and rerun journey tests.

Set the user path once, inspect what fires along the way, and reuse the workflow when the site changes. Start in the app.

  • Set a site, jurisdiction, consent choice, and journey
  • Reuse the journey across consent states and site changes
  • Inspect requests, payloads, and screenshots
  • Share the report for legal review
Open the app

Product findings support legal analysis. The software does not determine liability or compliance.

Product demo

See a CIPA workflow in the software.

Book a demo and bring a CIPA provision, California user context, consent path, or tracker relevant to your work. We'll show how Got Pixels configures the browser test and presents the resulting requests and evidence.

  • A product walkthrough using the tracker or legal theory you choose
  • How to set the consent state and browser journey in Composer
  • Where the resulting requests, authority, defenses, and limitations appear