This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
Skip to Main Content

The Pulse

| 2 minute read

What the Vivek Shah Ruling Means for CIPA Claims

Over the past several years, the California Invasion of Privacy Act ("CIPA"), enacted in 1967 to combat unauthorized wiretapping of telephone communications, has been repurposed into one of the most active vehicles for privacy litigation against website operators. Plaintiffs' firms have increasingly invoked CIPA's wiretapping provision (Section 631) and its pen register/trap-and-trace provision (Section 638.51) to challenge common website technologies, including live chat widgets, session replay software, marketing pixels, and third-party analytics tools. The core theory in these suits is that such tools allow a third-party vendor to "intercept" or "eavesdrop" on a visitor's communications with a website, or to capture identifying information analogous to a pen register, without the visitor's prior consent.

This wave of litigation accelerated sharply beginning in 2022 and has continued through 2026, fueled by a cottage industry of plaintiffs' counsel filing hundreds of nearly identical complaints in California state and federal courts. Defendants have ranged from small e-commerce sites to major national brands, and the claims have expanded well beyond their original telephone-wiretapping context to reach nearly any business that embeds third-party code on its website. Courts have reached inconsistent results on threshold issues such as whether a chatbot or analytics vendor qualifies as an unauthorized "third party" to the communication, whether the "party exception" applies, and whether website visitors have been adequately put on notice through privacy policies or consent banners. This patchwork of rulings has left website operators facing significant uncertainty and exposure, particularly given CIPA's statutory damages provision, which allows for penalties of up to $5,000 per violation.

One very active plaintiff who has pursued CIPA claims is Vivek Shah. But in an order issued July 20, 2026, by Judge Klausner, the US District Court for the Central District of California declared Mr. Shah a “Vexatious Litigant”, and imposed a pre-filing order requiring Mr. Shah to obtain permission from the court before filing any new civil action or pleading in the US District Court for the Central District of California that asserts claims under CIPA or related consumer digital privacy statutes. In the order, the Court cited 29 separate lawsuits filed by Mr. Shah, and mentioned his use of “template versions of Plaintiff's own CIPA complaints or copy-and-paste versions of pending class action matters” that were nearly identical, his record of seeking out CIPA violations and submitting enough search queries in an attempt to establish the amount in controversy, and then his failure to try any claims on the merits, in support of the decision. While this doesn't change or narrow CIPA risk generally, it shines a light on the more aggressive forms of this business model which were less about protecting consumers than attempting to leverage quick settlements.  
 

 

Tags

cipa, digital privacy