Blog/AI
AI

AI Chatbot Wiretapping Lawsuits: What CIPA Requires

Website chatbots have drawn 49 tracked CIPA lawsuits and $153M in settlements. Here is what actually triggers one, and what a pending bill changes.

BY SUVYSOFT TEAM
A wooden gavel resting on a desk next to an open laptop displaying a chat conversation

Yes. A website chatbot that routes visitor messages to a third-party vendor without upfront consent can trigger a California wiretapping lawsuit under Penal Code Section 631, and businesses have already paid over $153 million in disclosed CIPA settlements. A bill on the governor's desk narrows one related claim, but leaves the wiretapping claim that actually reaches chatbots untouched.

Most coverage of this topic falls into one of two traps. Vendor pages either skip the legal risk entirely and lean on a one-line "fully compliant" badge, or they treat a pending bill as though it makes the whole problem go away. Neither is accurate, and the gap between them is exactly where a small business chatbot ends up exposed.

Can a chatbot really trigger a wiretapping lawsuit?

Yes, and it already has, repeatedly. California's Invasion of Privacy Act, or CIPA, was written in 1967 for phone taps, but its language covers any electronic communication read or recorded without the consent of every party. Plaintiffs' firms have applied that language to ordinary website chat widgets: the theory is that when a visitor types a message into a chatbot, and a third-party vendor's servers store or process that message for the vendor's own purposes, an undisclosed outsider has effectively listened in on a conversation the visitor believed was private.

As of September 2026, trackers following this litigation count 49 documented CIPA website lawsuits with more than $153 million in disclosed settlements, according to ConsentPixel's ongoing CIPA lawsuit tracker. Separate reporting puts the number of pre-suit demand letters and claims filed since 2022 at 50,000 to 100,000, most of which never reach a public docket because businesses settle quietly to avoid the cost of litigating a class action.

What does the actual statute say?

Two sections do the work. Penal Code Section 631 prohibits reading or learning the contents of a communication in transit without the consent of all parties to it. Penal Code Section 632 covers recording a confidential communication without consent. Neither section mentions chatbots, pixels, or software of any kind, because both were written decades before either existed; the litigation exists because courts have had to decide whether that 1967 language stretches to cover a 2026 chat widget.

The damages provision is what makes this worth a plaintiff's firm's time. Penal Code Section 637.2 sets statutory damages at $5,000 per violation, or three times actual damages, whichever is greater, and it explicitly does not require the plaintiff to prove they were actually harmed to bring the claim. Multiply $5,000 by every website visitor who used the chat widget during the class period, and a single small business's chat log can produce a seven-figure exposure number even with no evidence anyone was hurt.

Is my chat vendor a party to the conversation, or an eavesdropper?

This is the question that decides most of these cases, and courts have split on it. Every CIPA chatbot claim comes down to whether the third-party vendor running the chat widget counts as a party to the conversation, or as an outside eavesdropper listening in.

Defendants argue the extension theory: the vendor is functionally a tape recorder or an outsourced switchboard, acting entirely on the business's behalf with no independent use of the data. Under this view there is no third party at all, so Section 631 never applies. Plaintiffs argue the eavesdropper theory: the vendor is an independent business with its own access to the transcripts and its own uses for them, including product improvement, analytics, marketing, or training its own AI models. Courts have split on which allegation is enough to survive a motion to dismiss, with some asking only whether the vendor has the capability to use the data for itself and others requiring proof it actually did.

Old Navy and Hot Topic won CIPA chatbot claims against them on the extension theory. European Wax Center and Flixbus, by contrast, faced claims specifically built around third-party chat and messaging vendors with their own downstream data uses. The difference is not the chat widget itself, it is the vendor contract behind it and what that vendor is allowed to do with the transcripts.

Does the pending bill fix this?

No, and this is the detail most coverage gets wrong. The California legislature passed SB 690 on August 28, 2026, and it now sits on Governor Newsom's desk with a decision deadline of September 30, 2026. If signed, it takes effect January 1, 2027, and applies retroactively to claims filed within the two years before that date.

Here is the part that matters for a chatbot specifically: SB 690, as passed, amends only Penal Code Section 638.51, the pen-register and trap-and-trace provision, limiting future claims under that section to enforcement by the California Attorney General rather than private plaintiffs. An earlier draft of the bill would have gone much further, creating a broad "commercial business purpose" exemption covering the wiretapping and eavesdropping sections too. That broader version did not survive the legislative process. The version that passed leaves Sections 631 and 632, the exact provisions behind chatbot wiretapping claims, completely untouched. A business that reads headlines about SB 690 and assumes its chatbot risk just disappeared is reading the wrong section.

What does a claim actually cost to resolve?

Individual chatbot settlements are rarely disclosed at the same scale as the largest CIPA cases, which have involved healthcare and tracking-pixel defendants rather than chat widgets specifically. But the statutory framework applies the same way regardless of industry, and it explains why even a modest local business becomes a viable target: a chat widget that logged a few thousand California visitor sessions during a two-year lookback window, multiplied by the $5,000 statutory floor, produces a settlement demand well past what most small businesses would spend defending the claim on the merits, which is exactly the pressure a demand letter is built to apply.

Claim typeStatuteWho can sue after SB 690Statutory damages
Wiretapping (reading in transit)Penal Code 631Private plaintiffs, class actions$5,000/violation or 3x actual damages
Eavesdropping (confidential comms)Penal Code 632Private plaintiffs, class actions$5,000/violation or 3x actual damages
Pen register / trap-and-tracePenal Code 638.51Attorney General only (if signed)$2,500/violation, AG enforcement

What actually needs to change before you launch a chatbot?

Three things, none of which require dropping the chatbot entirely.

Disclose before the conversation starts, not after. Consent has to precede the recording it covers. A line reading "This chat may be recorded and shared with our support vendor" shown before the visitor types their first message is doing real legal work; the same line appearing in a linked privacy policy the visitor never opened is not, and a disclosure that loads after the first message has already been sent misses the point entirely.

Check what your chat vendor's contract actually permits. The extension-versus-eavesdropper question turns on whether the vendor can use transcript data for its own purposes, such as training its own models or building its own analytics products, separate from serving your business. A vendor agreement that grants the vendor broad rights to reuse chat data is the fact pattern plaintiffs plead around. Tightening that clause to a service-provider-only relationship, where the vendor processes data solely on your instructions and for no independent purpose, is the strongest practical defense available and does not require changing the software.

Know that this is not a California-only concern if you sell there. CIPA applies based on where the website visitor is located, not where the business is headquartered, the same way most state privacy statutes work. A Kansas business with California customers using its chatbot is exposed the same way a Los Angeles business is. Florida's Security of Communications Act and Pennsylvania's Wiretapping and Electronic Surveillance Control Act carry similar theories and are being pled in parallel litigation, so the practical fix, upfront disclosure plus a tightened vendor contract, is worth doing regardless of where your customers are, not just for California traffic.

Suvysoft builds consent timing and vendor-contract review into every website chatbot deployment, as part of the same AI setup engagement that covers scoping, tuning, and launch. For a chatbot that is part of a larger custom agent build, the same disclosure and data-handling review gets scoped in from day one instead of retrofitted after a demand letter arrives.

Frequently asked questions

Does SB 690 eliminate chatbot wiretapping lawsuits in California?

No. SB 690, as passed by the legislature on August 28, 2026, only narrows private lawsuits under Penal Code Section 638.51, the pen-register provision, to Attorney General enforcement. It does not touch Sections 631 or 632, the wiretapping and eavesdropping provisions that chatbot claims are actually built on. Those private-lawsuit rights remain fully in place whether or not the governor signs the bill by the September 30, 2026 deadline.

Do I need to worry about this if my business is not based in California?

Yes, if you have website visitors or customers there. CIPA's coverage turns on where the person using the chatbot is located, not where the business is incorporated or headquartered. A business anywhere in the country with California traffic on its site can face the same claim as a California-based company.

Does a visible "this chat is AI" disclosure fix the wiretapping risk?

Only partly. An AI disclosure addresses a different legal question, whether the bot is misleading the visitor about talking to a human, covered by separate statutes like California's SB 1001. The wiretapping claim is about consent to recording and to a third party accessing the data, so it needs its own disclosure covering that specific point, shown before the conversation starts.

Is my business too small to be a target?

No. Penal Code Section 637.2 does not require proof of actual harm to bring a claim, and the $5,000-per-violation statutory floor applies regardless of company size. Plaintiffs' firms have specifically targeted small and mid-size businesses using common third-party chat vendors, precisely because the statutory damages make even a modest visitor count worth pursuing.

What is the fastest fix if I already have a chatbot live?

Add a pre-conversation disclosure line naming the vendor and stating that the chat may be recorded and processed by that vendor, shown before the first message is typed, and request a copy of your chat vendor's data-use terms to confirm they process transcripts only on your instructions rather than for their own separate purposes. Both changes are configuration and contract work, not a chatbot rebuild.

Where can I check if my state has a similar law?

California, Florida, and Pennsylvania currently have the most active wiretapping-style litigation theories applied to website tools, through CIPA, the Florida Security of Communications Act, and the Pennsylvania Wiretapping and Electronic Surveillance Control Act respectively. If your business has meaningful traffic from any of those three states, the same upfront-disclosure and vendor-contract review is worth doing even without a filed claim against you yet.

Not sure whether your current chatbot setup creates this exposure? Talk to us and we will walk through your vendor contract and disclosure flow before a demand letter forces the question.

Want us to do this for you?

Free 20-minute call

Tell us your goal. We will come back with a one-page document of the smallest moves to make for your business.

Start the conversation