Skip to content
Patrick Webby

Insights

June 2, 2026

California CIPA Compliance for Small Business Websites

The California Invasion of Privacy Act (CIPA) is driving a wave of lawsuits over ordinary website tools. Here's what small business owners actually need to know.

California CIPA Compliance for Small Business Websites

If you run a small business website and haven’t heard of CIPA, you’re not alone — until recently, the California Invasion of Privacy Act was mostly known as an old wiretapping law. Over the past few years, plaintiffs’ firms have started applying it to website tools that log or record visitor activity without clear disclosure, and small businesses are getting named in lawsuits over tools they installed without a second thought.

What CIPA actually covers

CIPA predates the modern web, but its wiretapping language — originally written for phone calls — has been applied to website technologies that capture a visitor’s activity in real time. The tools that show up most often in these claims are:

  • Live chat widgets that route conversations through a third party
  • Session replay tools that record mouse movement, clicks, and form input
  • Some analytics and advertising pixels, depending on what they capture and how

The common thread isn’t that these tools are unusual — most websites run at least one of them — it’s that the visitor wasn’t clearly told their activity was being captured by a third party in real time.

Why small businesses are getting caught up in this

Bigger companies typically have legal teams reviewing every script added to a site. Small businesses usually don’t — a chat widget or analytics tool gets added because a plugin recommended it, and nobody revisits that decision. That gap between “installed once” and “reviewed since” is exactly where the exposure sits.

What to actually do about it

  1. Inventory what’s running. Most sites have more third-party scripts than the owner realizes — plugins, themes, and marketing tools all add their own.
  2. Understand what each tool captures, and whether it shares that data with a third party in a way that could be read as “recording” under CIPA.
  3. Review your disclosures. A generic privacy policy buried in the footer usually isn’t enough — the specific tools and their behavior need to be identified.
  4. Reconsider tools you don’t actually use. The easiest fix is often removing a tool nobody’s looked at the reports for in a year.

This isn’t a one-time fix — it’s closer to routine hygiene, the same way you’d review who has admin access to your site. We do this kind of tracking-tool audit as part of our privacy & compliance work, alongside GDPR review for businesses with EU visitors.

There are plenty of DIY tools, services, and plugins that can get a site compliant with a few hours of work — or you can contact us and let us do the heavy lifting for you. Either way, don't wait: another day out of compliance can end up costing a lot more than the fix itself.

Not legal advice. This post is general information, not legal advice — pair it with your attorney's review before making representations about your compliance status.