CIPA

Cal. Penal Code §§ 630–638.55

California Invasion of Privacy Act

In force since January 1, 1967

Who it applies to

  • Any party recording or eavesdropping on a confidential communication without the consent of all parties
  • Increasingly applied to website session-replay, chat and tracking technologies

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.

Obligations

Consent model
Opt-in
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Not required
Processor contract
Not required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Not addressed by this Act
To the regulator
Not required by this law
What triggers it
Not addressed by this Act

Penalties

Headline
$5,000 per violation, or three times actual damages
Private right of action
Yes — individuals can sue directly
Notes
California is an all-party consent state. The statutory damages are per violation and require no proof of harm, which is why CIPA drives far more private litigation against web tracking than the CCPA does.

Sources