CIPA
Cal. Penal Code §§ 630–638.55California Invasion of Privacy Act
In force since January 1, 1967
Who it applies to
- Any party recording or eavesdropping on a confidential communication without the consent of all parties
- Increasingly applied to website session-replay, chat and tracking technologies
Consumer rights
- Access / know — not granted
- Correction — not granted
- Deletion / erasure — not granted
- Portability — not granted
- Opt out of sale / sharing — not granted
- Opt out of targeted advertising — not granted
- Opt out of profiling — not granted
- Limit sensitive data use — not granted
- Human review of automated decisions — not granted
- Non-discrimination — not granted
- Appeal a refusal — not granted
- Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.
Obligations
- Consent model
- Opt-in
- Universal opt-out signal
- Not required
- Risk assessments
- Not required
- Data protection officer
- Not required
- Records of processing
- Not required
- Processor contract
- Not required
- Right to cure
- None — enforcement may follow immediately
- Data broker registration
- Not required
Breach notification
- To individuals
- Not addressed by this Act
- To the regulator
- Not required by this law
- What triggers it
- Not addressed by this Act
Penalties
- Headline
- $5,000 per violation, or three times actual damages
- Private right of action
- Yes — individuals can sue directly
- Notes
- California is an all-party consent state. The statutory damages are per violation and require no proof of harm, which is why CIPA drives far more private litigation against web tracking than the CCPA does.
Sources
- PrimaryStatuteCal. Penal Code §§ 630 et seq. — Invasion of Privacy