Over 20 states have active comprehensive data privacy laws, none of which give a broad private right of action, so why have companies been hit with approximately 4,000 privacy litigation filings since 2022? Two-party consent, and decades-old wiretapping laws.
The US has an ever-expanding state privacy law patchwork, but states have been able to agree on a few common requirements between their data privacy laws. Notably, all US privacy laws adhere to an opt-out standard of consent–meaning businesses are free to collect most types of personal information from consumers so long as they notify consumers of this practice and give them a chance to opt out. Even when there’s a violation, only regulators can enforce the law.
However, wiretapping laws in two-party consent states conflict with this arrangement.
The Context Behind the Surge in Wiretap Lawsuits
The wiretap lawsuit model is built on three things: per-violation statutory damages that don't require proof of harm, two-party-consent statutes, and non-essential trackers firing before a privacy preference is obtained. In effect, they create a shadow opt-in model amidst US states’ opt-out approach to data privacy regulation.
"Two-party consent" means that every participant involved in a private communication must give explicit permission before the conversation can be legally recorded or intercepted. But state wiretapping laws were written broadly enough that even interacting with a website with commonplace tracking technologies in place can constitute an interception. Thus, states with a two-party consent standard and wiretap law in place can expose businesses engaged in standard web tracking practices to wiretap lawsuits.
When most people talk about wiretap lawsuits, they’re talking about California Invasion of Privacy Act (CIPA) lawsuits. But the CIPA wave was never really about CIPA; it was about private law firms getting a payout from consumer data privacy violations, something that the state laws designed to regulate data privacy don't permit.
That's why we are seeing this dynamic shift to adjacent laws like the Florida Security of Communications Act (FSCA).
Are Legislators Fixing the Problem?
California recently enacted SB 690, which gave many businesses subject to CIPA hope that these wiretapping claims were on their way out. However, the legislative process ground away at this bill's teeth. As a result, only the private right of action for one type of CIPA lawsuit (those relying on pen register/trap-and-trace claims) was banned by SB 690, while the main approach to CIPA lawsuits (those relying on interception claims) remained available to private litigants.
Even if California was able to eliminate CIPA claims all together, many litigants would just easily copy and tweak their demand letters to change the law from CIPA to the FSCA. The FSCA has had pushback and dismissals in court, but the reward for plaintiffs lies in the pre-lawsuit settlement, not the court settlement. These plaintiffs rely on companies determining that it’s easier to hand them $10,000 to leave them alone than roll the dice in court.
Anatomy of a FSCA Demand Letter
Long before they’re giving your general counsel or C-suite a migraine, FSCA claims start with a user:
- Loading your website in Florida
- Capturing network traffic before interacting with the banner
- Documenting trackers that are sharing data with third parties
They then edit a templatized letter to account for these endpoints, along with your company’s name, and send the demand letter to your legal inbox.
In the context of wiretap litigation, demand letters are pre-suit documents that include:
- A legal citation
- A list of “offending” trackers
- A self-imposed deadline to respond
- A monetary “early resolution” figure
What Legal Provisions Are Commonly Alleged to Be Violated?
You’ll commonly see the following FSCA provisions cited in a demand letter:
934.03 Interception and disclosure of wire, oral, or electronic communications prohibited.
-
(1)(a): “Intentionally intercepts, endeavors to intercept, or procures any other person to intercept or endeavor to intercept any wire, oral, or electronic communication;”
-
(2)(d): "It is lawful under this section and ss. 934.04-934.09 for a person to intercept a wire, oral, or electronic communication when all of the parties to the communication have given prior consent to such interception."
934.10 Civil remedies.
-
(1)(b): Actual damages, but not less than liquidated damages computed at the rate of $100 a day for each day of violation or $1,000, whichever is higher;
934.31 General prohibition on pen register and trap and trace device use; exception.
Plaintiffs map these provisions back to common website technologies in the following ways:
- The pen register section targets cookies, ad pixels, analytics, and fingerprinting scripts. The theory claims logging IP addresses, device IDs, or routing data without a court order uses a "device or process" to capture addressing info.
- Interception rules target session-replay and chat tools. Plaintiffs argue recording typed inputs or page views in real time intercepts substantive content rather than collecting metadata. A federal court allowed a lawsuit over healthcare tracking pixels to move forward on this theory.
Because Florida requires all-party consent, these cases turn on whether scripts fire before a visitor opts in and whether privacy disclosures are detailed enough to count as informed consent.
What Are the Offending Trackers?
The FSCA was originally written for telephone communications, but it was expanded to include electronic communications in 1988, and it adopted the PATRIOT Act's pen register definitions. The core change was moving pen registers from a telephone-only concept to a technology-neutral one.
The statute never directly mentions trackers, pixels, scripts, cookies, or websites, but its terms also aren’t narrowly limited to telephone wiretapping. Litigants have leveraged this gray area to argue the following categories of technologies fall within this category:
- Session replay software
- Ad and social pixels
- Live chat tools
What Is the Self-Imposed Deadline, and Do You Need to Meet It?
This should be seen as a request and not a legally binding timeline. It is designed to manufacture urgency and scare you into settling. Small-claims summons or a court-set pretrial conference, however, are legally binding timelines, but these aren’t typically a feature of FSCA demand letters.
How you respond to an FSCA letter will be based on a number of factors specific to your organization, so take your legal counsel’s lead regarding response timing and posture.
How Much Is a Typical “Early Resolution” Sum?
These “early resolution” figures are estimated to range in the five figures, but actual settlement averages are unknown. Only FSCA cases that make it to court are associated with publicly disclosed settlement sums (and only some of the time). These resolution sums are “early” in the sense that they are pre-court settlements, and therefore are not publicly shared.
Where Else Is This Happening?
Federal wiretap laws create a baseline for these types of laws, but each state has their own take on wiretap legislation. The important feature to look for is whether a given state’s wiretap law adheres to a two-party (or all-party) consent standard or a one-party consent standard. Since your business is one of the parties involved in a communication, you generally don’t have to worry about one-party consent wiretap laws.
The following table shows the states with two-party consent wiretap laws and associated case filings. Note that the number of demand letters will exceed the number of filed cases.
|
State
|
Statutory Wiretap Law
|
2022–2026 Cases Filed (Source)1
|
|
California
|
California Invasion of Privacy Act
|
3,135
|
|
Florida
|
Florida Security of Communications Act
|
586
|
|
Illinois
|
Illinois Eavesdropping Act
|
95
|
|
Pennsylvania
|
Wiretapping and Electronic Surveillance Control Act
|
48
|
|
Massachusetts
|
Massachusetts Wiretap Act
|
36
|
|
Washington
|
Washington Wiretap Act
|
21
|
|
Nevada
|
Nev. Rev. Stat. § 200.620
|
11
|
|
New Hampshire
|
N.H. Rev. Stat. Ann. § 570-A:2
|
2
|
|
Maryland
|
Maryland Wiretap Act
|
1
|
1 The table includes all-party consent states only. Cases filed March 1, 2022 – March 1, 2026, per DarrowEverett's review of publicly available dockets. Filings also occur in one-party consent states under different legal theories.
How Can Companies Protect Themselves?
Effective protection requires a proactive stance rather than a reactive one. Simply deploying a consent management platform (CMP) on your site is insufficient: it must accurately classify trackers, reliably block or postpone data collection until permission is granted, and maintain clear documentation supporting why certain items are deemed essential.
CIPA and FSCA risk mitigation starts with understanding what non-essential trackers are firing prior to a user submitting a privacy preference. “Non-essential” trackers are just website technologies that can be blocked without interfering with your website’s functionality.
However, manually cataloging these different trackers is not advisable due to the dynamic nature of website tracking. You could spend a whole day documenting every non-essential tracker, but that list could go out of date days later once the marketing team adds something new to your website.
Continuous compliance monitoring is the best way to maintain a clear vision of your website. Osano’s Compliance Check tracks and documents pre-consent tracking technologies, enabling you to understand what technologies on your website may be attractive targets for an FSCA or CIPA litigant. Compliance Check can be set to run automatically on a daily, weekly, and monthly cadence, so you can stay informed on the state of your tracking practices even if other team members make changes to your website.
If you use a CMP like Osano to manage your website’s data privacy compliance, you’ll be able to define whether you want visitors from a given jurisdiction to have an opt-in or an opt-out data privacy experience. Defending against wiretap litigation requires an opt-in standard (meaning no tracking can occur until the visitor opts in to being tracked). Even though state privacy laws only require opt-out consent, you may choose to deploy opt-in consent in risky jurisdictions like Florida and California.
Once you know what trackers are on your website and have configured your website to present Florida and California visitors with an opt-in consent banner, you’ll have to make one of two decisions for each tracker on your website:
- Block it from firing until the visitor gives their opt-in consent.
- Permit it to fire because it’s essential to your site’s functionality. In this case, you’ll also want to document your rationale to defend against wiretap claims that reference it.
This approach will allow your team to have a consistent and clear defensive position if a professional plaintiff drifts into your legal inbox with a demand letter.
If you’re curious about what your website’s current risk profile looks like, try a free scan from Compliance Check. To be forewarned, after all, is to be forearmed.