California
CIPA: California Invasion of Privacy Act Explained
Independently fact-checked against primary sources (last audited August 24, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 24, 2026. · 8 primary sources cited on this page. How we verify our legal content

The California Invasion of Privacy Act (CIPA), Cal. Penal Code § 630 et seq., is California state law, not a federal statute. It requires the consent of every party to a confidential communication before recording, and it is now the country's most litigated wiretap-adjacent statute, reaching AI notetakers and website chat tools.
Information last verified on 2026-07-08. This article has not yet been reviewed by a licensed lawyer.
Jurisdiction scope: This article addresses California state law under the California Invasion of Privacy Act, Cal. Penal Code § 630 et seq. It is included in this federal-recording-laws cluster because CIPA is the most actively litigated state statute layered on top of the federal Wiretap Act baseline, not because it is itself federal law. For the federal floor CIPA sits on top of, see Federal Wiretap Act and ECPA: The Complete Guide. For other states' consent rules, see two-party (all-party) consent states.
CIPA is a state law, not a federal one
It is worth stating plainly: CIPA is not part of the ECPA, the Wiretap Act, or any other federal statute. The California Legislature enacted it in 1967, a year before the federal Wiretap Act existed, declaring its purpose was to protect the right of privacy of the people of California against new eavesdropping devices and techniques (Cal. Penal Code § 630). It belongs in a federal-recording-laws cluster for a practical reason, not a jurisdictional one: CIPA is, by a wide margin, the most heavily litigated wiretap-adjacent statute in the country, and any business operating nationally needs to understand how it layers on top of the federal one-party consent floor described in Federal recording laws: the complete hub. Federal law permits a participant in a conversation to record it without telling the others. CIPA does not.
The all-party consent rule: Sections 631 and 632
CIPA regulates two distinct kinds of conduct under two separate sections. Section 631, the wiretapping provision, prohibits tapping a telephone or telegraph line, making an unauthorized connection to a communication system, or reading or attempting to learn the contents of a message while it is in transit, without the consent of all parties. Section 632, the eavesdropping and recording provision, is the one that comes up most often in ordinary recording disputes:
"A person who, intentionally and without the consent of all parties to a confidential communication, uses an electronic amplifying or recording device to eavesdrop upon or record the confidential communication ... shall be punished by a fine not exceeding two thousand five hundred dollars ($2,500), or imprisonment in the county jail not exceeding one year, or in the state prison, or by both that fine and imprisonment." Cal. Penal Code § 632
A "confidential communication" under Section 632(c) is one carried on in circumstances that reasonably indicate a party desires it to be confined to the parties to it, and the definition specifically excludes communications made at a public gathering or in any circumstance where the parties should reasonably expect the communication might be overheard or recorded. That carve-out is why CIPA does not reach every recording made in California; a conversation shouted across a crowded public event is not "confidential" in the statutory sense, while a private phone call or a one-on-one business conversation typically is.
Criminal and civil penalties
A first violation of Section 631 or 632 is punishable by a fine of up to $2,500, up to one year in county jail, or both; a subsequent violation raises the fine ceiling to $10,000. Beyond the criminal penalty, Section 637.2 gives any person injured by a CIPA violation a private civil right of action, and it does not require proof of actual damages to proceed. A prevailing plaintiff can recover $5,000 per violation, or three times actual damages, whichever is greater, plus injunctive relief. That statutory-damages floor, available without showing a dollar figure of actual harm, is the economic engine behind the wave of CIPA class actions described below: a company that records or transmits data from thousands of California visitors without proper consent faces exposure calculated per violation, not per lawsuit.
The pen register theory: how CIPA reached websites and apps
CIPA's pen register and trap-and-trace provisions, Cal. Penal Code §§ 638.50-638.51, were written to regulate physical telephone surveillance equipment: a pen register is a device or process that records dialing, routing, addressing, or signaling information without capturing content, and installing one without a court order is prohibited absent a specific exception. Around 2022, plaintiffs' firms began arguing that website tracking code, analytics scripts, and third-party SDKs are themselves a "device or process" that captures addressing information, namely IP addresses, and therefore requires a court order or consent. In Greenley v. Kochava, Inc., 684 F. Supp. 3d 1024 (S.D. Cal. 2023), the court became the first federal court to squarely confront that theory, denying a motion to dismiss and holding that software identifying users and correlating data through device fingerprinting can qualify as a pen register, reasoning that "pen registers [now] take the form of software." Other California courts have gone the other way, reasoning that the pen register provision's legislative history targeted telephone-tracking technology, not internet communications. The result is a genuine split, with dozens of website-tracking CIPA suits filed against businesses using chat widgets, session-replay tools, and analytics pixels; more than 800 CIPA claims were filed in 2025 alone. California's Senate Bill 690 would narrow this exposure, most recently by limiting private lawsuits over Section 638.51 website claims to enforcement by the state Attorney General, but as of this writing it remains pending, having been amended and advanced by an Assembly committee on July 1, 2026, and it has not yet been enacted.
AI notetakers and the Otter.ai litigation
The newest front in this litigation wave targets AI meeting-notetaker tools rather than websites. Beginning August 15, 2025, plaintiff Justin Brewer filed a putative class action against Otter.ai, Inc. in the US District Court for the Northern District of California, alleging that Otter's "Otter Notetaker" and "OtterPilot" tools join meetings on platforms like Zoom, Google Meet, and Microsoft Teams, transmit the audio to Otter's servers in real time, and transcribe what every participant says, including participants who are not Otter users and who were never asked for consent. Three related complaints followed, and the court consolidated all four into In re Otter.AI Privacy Litigation, No. 5:25-cv-06911 (N.D. Cal.), on October 22, 2025, before Judge Eumi K. Lee. The consolidated complaint asserts claims under the federal Wiretap Act, under CIPA's Sections 631 and 632 for recording without every participant's consent, under the Illinois Biometric Information Privacy Act, under the Computer Fraud and Abuse Act, and under several common-law theories. Otter moved to dismiss, and on August 13, 2026, Judge Lee granted the motion in part and denied it in part. The CIPA claims under Sections 631 and 632, the federal Wiretap Act claim, the Illinois BIPA claim, and the unjust enrichment and UCL claims survive; the CFAA, CDAFA, and Washington Privacy Act claims were dismissed, along with most plaintiffs' common-law privacy claims. The court held that Otter is a third-party eavesdropper under Section 631, not an invited participant, because Otter independently collects, retains, and uses the recordings for its own commercial purposes rather than simply returning a transcript to the meeting host. The ruling is the clearest example yet of CIPA's all-party consent rule being applied to an AI tool that a meeting host invites, rather than to the host's own recording decision.
The prior-consent rule: Javier v. Assurance IQ
A separate line of CIPA cases addresses timing rather than technology: when must consent be obtained. In Javier v. Assurance IQ, LLC, No. 21-16351, 2022 WL 1744107 (9th Cir. May 31, 2022), the Ninth Circuit considered a session-replay case in which a website visitor's interactions were recorded by third-party software before he reached a screen stating that clicking a button would constitute agreement to the site's privacy policy. The panel held that Section 631(a) requires the prior consent of all parties to a communication, so consent obtained only after the recording has already begun does not satisfy the statute; retroactive agreement through a privacy policy displayed later in the flow comes too late. The Ninth Circuit expressly did not decide the separate, and still unresolved, question of whether a third-party session-replay vendor counts as a party to the communication or as an outside eavesdropper for purposes of CIPA's party exception, leaving California federal courts split on that issue.
Practical compliance steps for businesses
The following are general compliance considerations, not legal advice, and following them does not guarantee compliance with CIPA in every circumstance. Businesses commonly reduce exposure by obtaining consent before a recording or tracking tool activates, rather than through a privacy policy displayed afterward, consistent with Javier's prior-consent holding. For phone calls, that typically means a clear notice, played or stated before recording begins, with a documented opportunity for the caller to decline. For websites serving California visitors, it typically means disclosing and obtaining consent before activating chat-recording, session-replay, or similar tracking tools, rather than relying on a general privacy policy alone. For AI notetakers joining meetings, it typically means notifying every participant, including participants outside the host's own organization, before the tool begins recording, and documenting that notice. Because the pen register theory and the AI-notetaker litigation wave are both still developing, with courts reaching different results, a business with meaningful California exposure should have counsel review its specific practices rather than rely on general guidance alone.
Disclaimer
This article provides general legal information about the California Invasion of Privacy Act, Cal. Penal Code § 630 et seq., as verified on 2026-07-08. It does not constitute legal advice and does not create an attorney-client relationship. CIPA is California state law, and its application depends on specific facts, including where the parties and any recording device were located and the nature of the communication. Readers should consult a lawyer licensed in California before recording a conversation or deploying website tracking, chat, or AI-notetaker tools that reach California users.
Related articles
- Federal recording laws: the complete hub
- Federal Wiretap Act and ECPA: The Complete Guide (2026)
- Stored Communications Act Explained
- Two-party (all-party) consent states: full list and rules
Last updated: 2026-07-08. Statutes cited reflect their in-force version as of 2026-07-08.
More California Laws
Frequently Asked Questions
Is CIPA a federal law?
No. The California Invasion of Privacy Act, Cal. Penal Code 630 et seq., is a California state statute enacted in 1967. It applies alongside the federal Wiretap Act and can require more consent, all-party rather than one-party, for recordings made in California.
What counts as a confidential communication under CIPA?
Cal. Penal Code 632(c) defines it as a communication carried on in circumstances reasonably indicating a party wants it confined to the parties involved. It excludes communications made at a public gathering or in any setting where the parties should reasonably expect to be overheard or recorded.
How much can I sue for under CIPA?
Cal. Penal Code 637.2 allows a private plaintiff to recover $5,000 per violation or three times actual damages, whichever is greater, plus injunctive relief, without needing to prove a specific dollar amount of actual harm.
Does CIPA apply to phone calls made from outside California?
Courts have generally looked at where the recording device is located or where the recorded party is situated, and California courts have sometimes applied CIPA to recordings involving California residents even when the other party or the recording equipment was elsewhere. This is a developing and fact-specific area; consult a lawyer for a specific call pattern.
Can website chat tools or trackers violate CIPA?
Plaintiffs have argued yes, under CIPA's pen register and trap-and-trace provisions, Cal. Penal Code 638.50-638.51, treating tracking software as a device that captures addressing information. Greenley v. Kochava, Inc., 684 F. Supp. 3d 1024 (S.D. Cal. 2023), allowed such a claim to proceed, though other courts have rejected the theory, and the law remains unsettled.
What is the Otter.ai CIPA lawsuit about?
In re Otter.AI Privacy Litigation, No. 5:25-cv-06911 (N.D. Cal.), consolidated October 22, 2025, alleges Otter's AI notetaker joins meetings and transcribes all participants' speech, including non-Otter users, without obtaining their consent, in violation of CIPA's all-party consent rule and the federal Wiretap Act. On August 13, 2026, the court granted Otter's motion to dismiss in part: the CIPA, federal Wiretap Act, and BIPA claims survive, while the CFAA, CDAFA, and Washington Privacy Act claims were dismissed. The court held Otter is a third-party eavesdropper under CIPA Section 631, not an invited participant, because it independently retains and uses the recordings for its own commercial purposes.
Does CIPA apply to businesses located outside California?
It can. CIPA is not limited to California-based businesses; the relevant question is generally whether the recorded or tracked party was in California, not where the business itself is headquartered. This is a fact-specific jurisdictional question that a business with California customers or website visitors should review with counsel.
Updates
Updated the Otter.ai CIPA lawsuit to report the August 13, 2026 ruling: the CIPA, federal Wiretap Act, and BIPA claims survive, the CFAA, CDAFA, and Washington Privacy Act claims were dismissed, and the court held Otter is a third-party eavesdropper under CIPA Section 631 because it independently retains and uses the recordings commercially.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
California Penal Code
§ 630In force
The Legislature hereby declares that advances in science and technology have led to the development of new devices and techniques for the purpose of eavesdropping upon private communications and that the invasion of privacy resulting from the continual and increasing use of such devices and techniques has created a serious threat to the free exercise of personal liberties and cannot be tolerated in a free and civilized society. The Legislature by this chapter intends to protect the right of privacy of the people of this state. The Legislature recognizes that law enforcement agencies have a legitimate need to employ modern listening devices and techniques in the investigation of criminal conduct and the apprehension of lawbreakers. Therefore, it is not the intent of the Legislature to place greater restraints on the use of listening devices and techniques by law enforcement agencies than existed prior to the effective date of this chapter.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 203 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Ribas v. Clark (California Supreme Court 1985, 38 Cal. 3d 355)“…s wife constituted a breach of the Invasion of Privacy Act (Pen. Code, §§ 630-637.2, hereafter Privacy Act), vesting…”
- North v. Superior Court (California Supreme Court 1972, 8 Cal. 3d 301)“…ions of privacy through eavesdropping and wiretapping. (See Pen. Code, § 630 et seq.) For example, section 632 forbi…”
- Warden v. Kahn (California Court of Appeal 1979, 99 Cal. App. 3d 805)“…hn under certain provisions of the Invasion of Privacy Act, Penal Code section 630 et seq., and should not have been dismi…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 631In forcecited in 9 of our articles
(a) Any person who, by means of any machine, instrument, or contrivance, or in any other manner, intentionally taps, or makes any unauthorized connection, whether physically, electrically, acoustically, inductively, or otherwise, with any telegraph or telephone wire, line, cable, or instrument, including the wire, line, cable, or instrument of any internal telephonic communication system, or who willfully and without the consent of all parties to the communication, or in any unauthorized manner, reads, or attempts to read, or to learn the contents or meaning of any message, report, or communication while the same is in transit or passing over any wire, line, or cable, or is being sent from, or received at any place within this state; or who uses, or attempts to use, in any manner, or for any purpose, or to communicate in any way, any information so obtained, or who aids, agrees with, employs, or conspires with any person or persons to unlawfully do, or permit, or cause to be done any of the acts or things mentioned above in this section, is punishable by a fine not exceeding two thousand five hundred dollars ($2,500), or by imprisonment in the county jail not exceeding one year,…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 202 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Ribas v. Clark (California Supreme Court 1985, 38 Cal. 3d 355)“…iminal statutes prohibiting various forms of eavesdropping (Pen. Code, §§ 631, subd. (a), and 637), as well as for in…”
- Warden v. Kahn (California Court of Appeal 1979, 99 Cal. App. 3d 805)“…not to be found elsewhere among the states of the nation. Penal Code section 631 provides: "Any person who, by means of…”
- Rogers v. Ulrich (California Court of Appeal 1975, 52 Cal. App. 3d 894)“…nowledge the incident amounted to wiretapping as defined by Penal Code section 631; a statutory penalty in the amount of $…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Serial CIPA Website-Wiretap Filer Declared a Vexatious Litigant, California Pixel-Wiretap Rulings Split the Same Week: Blue Shield Claim Dismissed, BlueChew Claims Advance, Otter.ai Faces Consolidated Wiretap Class Action Over Its AI Meeting Notetaker and All-Party Consent
§ 632In forcecited in 39 of our articles
(a) A person who, intentionally and without the consent of all parties to a confidential communication, uses an electronic amplifying or recording device to eavesdrop upon or record the confidential communication, whether the communication is carried on among the parties in the presence of one another or by means of a telegraph, telephone, or other device, except a radio, shall be punished by a fine not exceeding two thousand five hundred dollars ($2,500) per violation, or imprisonment in a county jail not exceeding one year, or in the state prison, or by both that fine and imprisonment. If the person has previously been convicted of a violation of this section or Section 631, 632.5, 632.6, 632.7, or 636, the person shall be punished by a fine not exceeding ten thousand dollars ($10,000) per violation, by imprisonment in a county jail not exceeding one year, or in the state prison, or by both that fine and imprisonment.
Official text (excerpt) · last checked 2026-08-31 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 267 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Kimmel v. Goland (1990) held the section 47(2) litigation privilege does not bar a damages claim under Section 632 for recording confidential conversations without consent. Lieberman v. KCOP Television, Inc. (2003) held a Section 632 violation is complete the moment the recording is made, whether or not it is disclosed.
Opinions citing this section in our collection:
- Rubin v. Green (California Supreme Court 1993, 4 Cal. 4th 1187)“…f telephone conversations with defendants, an offense under Penal Code section 632. We noted that defendants alleged that…”
- Kimmel v. Goland (California Supreme Court 1990, 51 Cal. 3d 202)✓Mobilehome owners secretly taped phone calls with park management in anticipation of suing; the court held the section 47(2) litigation privilege did not bar the cross-complaint for damages under Penal Code section 632, since the injury came from recording, not publication.
- Shulman v. Group W Productions, Inc. (California Supreme Court 1998, 74 Cal. Rptr. 2d 843)✓A TV producer put a wireless microphone on the flight nurse treating a crash victim. No section 632 claim was before the court, but it called section 632 and the intrusion tort laws of general applicability and said the press may not eavesdrop in violation of section 632.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Recording Laws (2026): All-Party Consent Rules, US Recording Laws by State (2026): All 50 States Explained, Can an Employer Record Conversations Without Consent? (2026)
§ 637.2In forcecited in 20 of our articles
(a) Any person who has been injured by a violation of this chapter may bring an action against the person who committed the violation for the greater of the following amounts: (1) Five thousand dollars ($5,000) per violation. (2) Three times the amount of actual damages, if any, sustained by the plaintiff. (b) Any person may, in accordance with Chapter 3 (commencing with Section 525) of Title 7 of Part 2 of the Code of Civil Procedure, bring an action to enjoin and restrain any violation of this chapter, and may in the same action seek damages as provided by subdivision (a). (c) It is not a necessary prerequisite to an action pursuant to this section that the plaintiff has suffered, or be threatened with, actual damages. (d) This section shall not be construed to affect Title 4 (commencing with Section 3425.1) of Part 1 of Division 4 of the Civil Code.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 103 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Ribas v. Clark (1985) held the section 637.2 award accrues at the moment of the Privacy Act violation, so the Civil Code section 47 litigation privilege does not bar it, though damages flowing solely from privileged testimony fail. Kimmel v. Goland (1990) applied that reasoning to recordings made in anticipation of litigation.
Opinions citing this section in our collection:
- Rubin v. Green (California Supreme Court 1993, 4 Cal. 4th 1187)“…asion of privacy and related torts as well as damages under Penal Code section 637.2, granting persons injured by eavesdropp…”
- Ribas v. Clark (California Supreme Court 1985, 38 Cal. 3d 355)✓A wife asked a third party to listen on an extension phone while she called her husband, and that listener later testified about it; the court held the judicial privilege barred damages from the testimony but not Section 637.2's fixed award, which accrues at the violation.
- Kimmel v. Goland (California Supreme Court 1990, 51 Cal. 3d 202)✓Mobilehome residents secretly taped calls with park management to gather evidence for a planned lawsuit; the court held the litigation privilege did not bar management's Section 637.2 claim, because the injury came from the recording itself and not from any publication.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Can I Sue Someone for Recording Me on Private or Public Property?, How to Detect and Block Listening Devices in Your Home (2026), Is It Illegal to Video Record Someone Without Their Consent? (2026)
§ 638.50In force
For purposes of this chapter, the following terms have the following meanings: (a) “Wire communication” and “electronic communication” have the meanings set forth in subdivision (a) of Section 629.51. (b) “Pen register” means a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, but not the contents of a communication. “Pen register” does not include a device or process used by a provider or customer of a wire or electronic communication service for billing, or recording as an incident to billing, for communications services provided by such provider, or a device or process used by a provider or customer of a wire communication service for cost accounting or other similar purposes in the ordinary course of its business.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 11 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Bradshaw (District Court, S.D. California 2025)“…nder the California Invasion of 17 Privacy Act (“CIPA”). California Penal Code § 638.50(b) defines a “pen register” as “a 18…”
- Fregosa v. Mashable Inc. (District Court, N.D. California 2025)“…rocess that captures incoming addressing 2 information. Cal. Penal Code § 638.50(c). 3…”
- Lesh v. Cable News Network, Inc. (CNN) (District Court, S.D. New York 2025)“…ed, but not the contents of the communication.” Cal. Penal Code § 638.50(b). Lesh…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 638.51In force
(a) Except as provided in subdivision (b), a person may not install or use a pen register or a trap and trace device without first obtaining a court order pursuant to Section 638.52 or 638.53. (b) A provider of electronic or wire communication service may use a pen register or a trap and trace device for any of the following purposes: (1) To operate, maintain, and test a wire or electronic communication service. (2) To protect the rights or property of the provider. (3) To protect users of the service from abuse of service or unlawful use of service. (4) To record the fact that a wire or electronic communication was initiated or completed to protect the provider, another provider furnishing service toward the completion of the wire communication, or a user of that service, from fraudulent, unlawful, or abusive use of service. (5) If the consent of the user of that service has been obtained. (c) A violation of this section is punishable by a fine not exceeding two thousand five hundred dollars ($2,500), or by imprisonment in the county jail not exceeding one year, or by imprisonment pursuant to subdivision (h) of Section 1170, or by both that fine and imprisonment.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 25 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Fregosa v. Mashable Inc. (District Court, N.D. California 2025)“…a court order as required by CIPA. Id. ¶¶ 49– 5 56; see Cal. Penal Code § 638.51(a) (“[A] person may not install or use…”
- Garon v. Keleops USA, Inc. (District Court, N.D. California 2025)“…he California Invasion of Privacy Act (“CIPA”), Cal. 16 Penal Code § 638.51(a). Keleops now moves to dismiss the F…”
- Gabrielli v. Haleon US Inc. (District Court, N.D. California 2025)“…631; (4) use of a pen register in violation of 25 CIPA, Cal. Pen. Code § 638.51; (5) common law fraud; (6) unjust enric…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Cal. Penal Code § 630: legislative declaration of purpose for the Invasion of Privacy Act(leginfo.legislature.ca.gov).gov
- Cal. Penal Code § 631: wiretapping prohibition(leginfo.legislature.ca.gov).gov
- Cal. Penal Code § 632: all-party consent for recording confidential communications; penalties(leginfo.legislature.ca.gov).gov
- Cal. Penal Code § 637.2: private civil action; $5,000 per violation or 3x actual damages(leginfo.legislature.ca.gov).gov
- Cal. Penal Code § 638.50: definitions of pen register and trap and trace device(leginfo.legislature.ca.gov).gov
- Cal. Penal Code § 638.51: prohibition on installing a pen register or trap and trace device without a court order(leginfo.legislature.ca.gov).gov
- Javier v. Assurance IQ, LLC, No. 21-16351 (9th Cir. May 31, 2022): official Ninth Circuit memorandum disposition on CIPA prior-consent requirement(cdn.ca9.uscourts.gov).gov
- Greenley v. Kochava, Inc., No. 3:22-cv-01327, 684 F. Supp. 3d 1024 (S.D. Cal. 2023): docket, pen register theory applied to tracking SDK(courtlistener.com)
- In re Otter.AI Privacy Litigation / Brewer v. Otter.ai, Inc., No. 5:25-cv-06911 (N.D. Cal.): docket(courtlistener.com)
- OneTrust, CIPA Litigation Is Accelerating: secondary commentary noting more than 800 CIPA claims filed in 2025(onetrust.com)
- California SB 690 (2025-2026 session): official bill text and status, Section 638.51 private-right-of-action amendment(leginfo.legislature.ca.gov).gov
- National Law Review, coverage of the August 13, 2026 order in In re Otter.AI Privacy Litigation granting Otter's motion to dismiss in part(natlawreview.com)