CIPA / ECPA / VPPA / WESCA / FSCA

got pixels?

Pixel litigation statutes and the browser evidence each theory needs

A practical guide to CIPA, ECPA, VPPA, WESCA, FSCA, and related health-data laws.

Map the legal theory to the browser facts Got Pixels can reproduce, preserve, and analyze against jurisdiction-specific authority.

View sample report
byPapaya Privacy Co.General product and technical information. Not legal advice.
Assessment structure

Which pixel-litigation theory fits the reproduced browser facts?

JurisdictionState + federal law
JourneySearch, video, chat, form
AssessmentResult + risk level
AuthorityStatutes + case law
LimitsDefenses + open questions

The short answer

Pixel litigation is not one claim under one law.

The theory may depend on whether a communication was acquired in transit, whether video-viewing information was disclosed with an identifier, whether a tracker captured the contents of a substantive interaction, or whether health information reached a third party without the required permission.

Got Pixels runs defined browser journeys and turns the factual record into a jurisdiction-specific assessment. Each tested theory can include a result, risk level, technical evidence, supporting authority, defenses, limitations, and open questions.

The assessment supports counsel's analysis. It does not determine liability or replace legal judgment.

CIPA

Cal. Penal Code §§ 631, 632, 638.51

Interception, confidential communications, and pen-register theories

Consent state, timing, request initiator, third-party role, contents, addressing or signaling data

ECPA

18 U.S.C. §§ 2511, 2520

Intentional interception, use, or disclosure, subject to statutory exceptions

Contemporaneous acquisition, contents, recipient, party roles, consent, service-provider facts

VPPA

18 U.S.C. § 2710

Knowing disclosure of identifiable video-viewing information concerning a consumer

Video title or URL, watch event, account or device identifier, recipient, consent record

WESCA

18 Pa.C.S. § 5703

Interception, disclosure, or use of electronic communications

Pennsylvania user context, timing, contents, consent, tracker and website roles

FSCA

Fla. Stat. §§ 934.03, 934.10

Interception, use, or disclosure of substantive electronic communications

Search terms, health details, form fields, chat text, consent state, third-party requests

Health data

HIPAA, FTC/HBNR, RCW 19.373

Collection, sharing, authorization, or disclosure of sensitive health information

Health-related journeys, inputs, custom events, identifiers, recipients, authorization, privacy notices

Inside a report

Evidence, risk analysis, and authority in one record.

A public sample report tested a Pennsylvania article-search journey after the user selected “Reject optional cookies.” Got Pixels captured pre-consent, post-rejection, and post-journey checkpoints, then organized the findings into WESCA, ECPA, and VPPA matrices.

View the sample report

Pennsylvania assessment

Sample risk matrix

Nature.com · rejected consent

WESCA contents interception

Elevated

High

After rejection, Google ad requests carried the searched phrase, article URL, DOI, and subject fields. The report separated these contents facts from evidence the run did not establish.

ECPA party defense

Limited

Medium

The browser sent requests directly to Google's servers. The report treated intended-recipient and party arguments as a material defense rather than ignoring the competing theory.

VPPA consumer relationship

Limited

Low

The tested visitor was not logged in or subscribed, and the journey did not play video. The report identified the missing consumer, video, and person-linked identifier facts.

The report also preserved screenshots, request counts, tracker domains, cookies, timestamps, browser steps, cited authority, defenses, and factual limitations.

Statute families

Start with the theory. Then test the facts it requires.

California

California Invasion of Privacy Act

CIPA website cases can involve distinct provisions. Section 631 addresses wiretapping and unauthorized interception or learning of a communication's contents or meaning. Section 632 addresses recording or eavesdropping on confidential communications. Section 638.51 restricts pen registers and trap-and-trace devices, subject to statutory exceptions that include user consent.

The browser test must match the theory. A chatbot exchange presents different facts from a page view. A search term or form value differs from routing or device data. Timing may matter when counsel evaluates whether a third party acquired a communication in transit.

  • Test before consent, after accept, after reject, and with GPC where relevant.
  • Preserve the sequence between the user action and the outgoing request.
  • Identify the request initiator, recipient, third-party role, contents, identifiers, and addressing signals.

Federal

Electronic Communications Privacy Act

Title 18 U.S.C. section 2511 prohibits intentional interception, use, or disclosure of wire, oral, or electronic communications, subject to statutory exceptions. Section 2520 authorizes civil recovery for a person whose communication was intercepted, disclosed, or intentionally used in violation of the chapter.

Website disputes can turn on contemporaneous acquisition, contents, party or service-provider exceptions, purpose, and consent. A browser audit cannot resolve those questions by itself, but it can show exactly when the request occurred, what it carried, and which party received it.

  • Tie the request timestamp to the user action and script execution.
  • Separate substantive contents from routing, device, and ad-delivery metadata.
  • Preserve the recipient, request initiator, consent state, and facts relevant to party or provider arguments.

Video

Video Privacy Protection Act

The VPPA restricts knowing disclosure by a video tape service provider of personally identifiable information concerning a consumer, subject to statutory exceptions. A pixel allegation can therefore raise separate provider, consumer, video-information, identification, disclosure, and consent questions.

The browser record should connect a viewing action to a transmission without assuming the legal result. Courts have not treated every video event and identifier combination alike, so the assessment must show what was present and what was missing.

  • Preserve the video title or URL and the specific watch or playback event.
  • Identify account, advertising, device, or other person-linked identifiers sent with the event.
  • Record the recipient, consent interface, account state, and evidence of any subscriber relationship.

Pennsylvania and Florida

WESCA and FSCA

Pennsylvania WESCA prohibits intentional interception, disclosure, or use of covered communications, subject to statutory exceptions. Florida FSCA addresses intentional interception, use, or disclosure and can turn on whether the transmitted data contained the substance of a communication rather than generic navigation.

Preserve the user location, consent state, communication contents, timing, tracker role, searches, form fields, chat text, health details, and third-party requests.

Health information

HIPAA, FTC, HBNR, and state health-data laws

Health-related tracking can raise regulatory and state-law questions that are not interchangeable with a private wiretap claim. HHS states that the HIPAA Rules apply when covered entities or business associates use tracking technologies that collect or disclose protected health information.

Capture the health-related page or journey, search or form input, event name, identifier, third-party recipient, authorization or consent state, privacy notice, and full payload.

Other state laws

Website tracking allegations also appear under statutes in Maryland, Washington, Illinois, Massachusetts, and other states. Definitions, consent rules, exceptions, remedies, and judicial interpretations differ. Capture the jurisdictional inputs instead of applying one universal label. Massachusetts is one example of why qualification matters. The state's highest court narrowed the application of its wiretap statute to ordinary web browsing in Vita v. New England Baptist Hospital, while other theories remained outside that specific holding.

Browser evidence checklist

The record counsel should ask for.

A legal theory is only as useful as the facts tied to it. Preserve the inputs, action, transmission, recipient, and limits in one repeatable browser record.

01

Jurisdiction

Relevant user location and the website journey tested

02

Consent

Before consent, after accept, after reject, and applicable opt-out signals

03

Communication

Page view, video watch, search, chat, form submission, or checkout interaction

04

Timing

Sequence between the user action, script execution, and network request

05

Contents

URLs, event names, payload fields, form values, searches, video data, and cookies

06

Identifiers

Account, device, advertising, session, and other identifiers sent with the event

07

Recipient

Each third party that received the request and the initiator that sent it

08

Repeatability

The same journey rerun under controlled consent and user states

09

Evidence

Request details, screenshots, page state, timestamps, and reproduction steps

Ready to test the theory?

Reproduce the browser facts before you commit to the assessment.

Book a matter review

Matter review meeting

Book a meeting to review the statute and browser journey.

Walk through the jurisdiction, website, consent state, and user journey at issue. We can discuss how Got Pixels would reproduce the record and organize the findings into evidence, authority, risk levels, defenses, and stated limitations.

  • The statute, jurisdiction, and legal theory you are evaluating
  • The website, tracker, consent state, and user journey at issue
  • The browser evidence and report structure that would help your review

Got Pixels Pro

Build the statute-specific audit yourself.

Composer turns the legal question into a browser audit suite. Change the jurisdiction, consent state, journey, or tracker, then compare the resulting report matrices.

  • Jurisdiction-specific result and risk matrices
  • Linked statutes and matching case law
  • Full search, video, chat, checkout, and form journeys
  • Technical evidence, defenses, limitations, and open questions
Open Pro

Product results require legal interpretation and do not determine liability or compliance.