TL;DR, Quick Answer
7 min readUS class actions call session replay an unlawful interception under California's CIPA section 631(a), Pennsylvania's WESCA, and the federal Wiretap Act. Courts have reached opposite results on whether the analytics vendor is a party to the communication and on whether recording clicks alone is a concrete injury. The Third Circuit dismissed one such case for lack of standing in 2025 and revived two of eight plaintiffs in another in 2026, and the difference was whether the visitor typed anything sensitive.
What is a session replay lawsuit wiretapping claim?
US class action plaintiffs bring a session replay lawsuit wiretapping claim when they allege that a website recorded their mouse movements, clicks and keystrokes and routed that recording to a third-party vendor without asking first, which they say is the unlawful interception of an electronic communication. The mechanism they point to is the script: it runs in the visitor's browser and copies interaction events to a server the visitor never chose to contact. Read the complaint before the commentary, because the allegation is about interception and routing, not about whether session replay works. Nothing here is legal advice.
Which statutes do these lawsuits actually use?
Three statutes carry almost all of this litigation: California Penal Code section 631(a), the Pennsylvania Wiretapping and Electronic Surveillance Control Act at 18 Pa. Cons. Stat. section 5701 and following, and the federal Wiretap Act at 18 U.S.C. section 2510 and following. They diverge on the question that decides most cases: how many parties have to consent. Check which statute a complaint pleads first, because a defense built on federal law does not transfer to California or Pennsylvania.
| Statute | Whose consent is required | Provision | Who may sue |
|---|---|---|---|
| California Invasion of Privacy Act | All parties to the communication | Cal. Penal Code 631(a) | Any injured person, Cal. Penal Code 637.2 |
| Pennsylvania WESCA | All parties, given in advance | 18 Pa. Cons. Stat. 5704(4) | Any intercepted person, 18 Pa. Cons. Stat. 5725(a) |
| Federal Wiretap Act | One party, unless the purpose is criminal or tortious | 18 U.S.C. 2511(2)(d) | Any intercepted person, 18 U.S.C. 2520 |
| CIPA pen register clause | Court order, or consent of the user | Cal. Penal Code 638.51 | Changing, see the SB 690 section below |

Why do so many of these cases end on standing instead of privacy?
Federal judges dismiss many of these suits before reaching the wiretap question, because Article III demands a concrete injury and a bare statutory violation does not supply one. In Cook v. GameStop, Inc. (3d Cir. 2025), the Third Circuit held that Amber Cook lacked standing after Microsoft Clarity recorded her mouse movements, clicks and search terms on GameStop's site, since she entered nothing sensitive, never identified herself, and the data reached a vendor and not the public. Nine months later the same court came out differently in In re BPS Direct, LLC (3d Cir. 2026): six of eight plaintiffs lost for Cook's reason, and two won reversal because they had entered payment and billing information, including a credit card number, into Bass Pro Shops and Cabela's checkout pages while the script ran. Read the fact section first, because what the visitor typed has decided more of these cases than any argument about statutory text.
- Amber Cook entered nothing sensitive
- Never identified herself
- Data reached a vendor, not the public
- Six of eight BPS plaintiffs lost for the same reason
- Two plaintiffs entered payment and billing information
- Including a credit card number
- Typed into Bass Pro Shops and Cabela's checkout pages while the script ran
- Reversal on those two claims
Is the analytics vendor a party to the communication or a third party?
Defendants argue the vendor is a direct party and therefore consents to its own receipt, and the Third Circuit rejected that reading of Pennsylvania law in Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022). The court held that NaviStone was not a direct party to Ashley Popa's communications with the retailer's website, and that an interception occurred when the JavaScript routed those signals to NaviStone's servers. That ruling vacated a district court decision holding the opposite on both points, the clearest example of the disagreement running through this area. Where a vendor sits in that argument tracks the line GDPR draws between a data controller and a data processor, so the contract and the real data flow both feed the analysis.
When does consent have to be collected?
The Ninth Circuit predicted in Javier v. Assurance IQ, LLC, No. 21-16351 (9th Cir. May 31, 2022), an unpublished memorandum, that the California Supreme Court would read section 631(a) to require the prior consent of all parties, and it reversed a district court that had accepted consent given after the recording. Florentino Javier answered demographic and medical questions on an insurance quote form while ActiveProspect's TrustedForm recorded him, and he clicked through the privacy policy only afterwards. The disposition is unpublished and binds nobody as precedent, and it still explains why complaints now plead the exact moment the notice appeared relative to the first keystroke. The timing of tracking consent is the fact a pleading will aim at.
What is the pen register theory, and what is California doing to it?
Plaintiffs added a second CIPA theory: that a tracking script is a pen register or trap and trace device installed without a court order, which California Penal Code section 638.51 prohibits. California's legislature answered with Senate Bill 690, which as enrolled amends Penal Code section 637.2 so that only the Attorney General may sue a private actor under section 638.51 over conduct on an internet website, online application or mobile application, and applies that limit retroactively to any claim pending in an action commenced within two years of the operative date. The California Legislative Information site records the bill as enrolled and presented to the Governor on September 4, 2026. It leaves section 631(a) alone, so the interception theory survives whatever happens to the pen register theory.

How large is the number on the complaint?
The demand in these cases is arithmetic, not damages evidence. California Penal Code section 637.2(a) sets recovery at the greater of $5,000 per violation or three times actual damages, and subsection (c) removes any need to prove actual damages.
Statutory demand = class members x $5,000 per violation
A class of 10,000 California visitors produces a $50,000,000 demand before anyone proves a dollar of harm. The federal figure is smaller: 18 U.S.C. section 2520(c)(2)(B) sets the greater of $100 per day of violation or $10,000. Both are the pressure a complaint applies at the pleading stage, and none of the decisions above awarded either.
What reduces exposure to one of these claims?
Three things reduce exposure, and none of them guarantees an outcome. Consent collected before the first recorded event addresses the sequencing problem Javier identified. Masking that runs in the browser, so sensitive values never reach a server, addresses the fact pattern that gave two BPS plaintiffs standing and left six without it, which is why session replay privacy masking belongs in the recorder configuration and not in the player. A vendor role documented in the contract and matched by the real data flow addresses the direct party question Popa turned on. California residents separately hold rights to know and to delete, and meeting CCPA consumer privacy rights is a distinct obligation from the wiretap question.
Where does Flowsery sit in this?
Flowsery records every user session, is cookie-free, is EU-hosted and is built GDPR by design. None of those facts answers a CIPA, WESCA or Wiretap Act question, because those statutes turn on interception and consent, not on cookies or hosting location. Review how AI session replay captures and stores sessions, then take the statutory question to your own counsel.
Frequently asked questions
Do these lawsuits establish that session replay is illegal?
They do not. Plaintiffs allege that recording without consent is an unlawful interception under a named statute, and courts have resolved standing, party status and consent timing case by case. Cook and BPS turned on what the individual visitor typed, not on a ruling about the software category.
Which statute is hardest for a defendant?
California and Pennsylvania both require every party to consent, which removes the one-party defense the federal Wiretap Act allows at 18 U.S.C. section 2511(2)(d). CIPA adds $5,000 per violation under Penal Code section 637.2(a) with no proof of damages required. Pennsylvania's WESCA requires that the consent be given in advance under 18 Pa. Cons. Stat. section 5704(4).
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Does a privacy policy linked in the footer count as consent?
None of the decisions above treated a footer link as settled consent. The Third Circuit in Cook noted the policy was buried at the bottom of the site, and the Ninth Circuit in Javier declined to credit consent given after the recording had already run. Complaints target the sequence, so the placement and timing of the notice are what get litigated.
Have the courts really split on this?
Yes, and the reversals show it. Popa vacated a district court that had held the vendor was a direct party and that interception happened only at the vendor's servers. Javier reversed a district court that had accepted retroactive consent. Inside the Third Circuit, Cook found no standing while BPS found standing for two of eight plaintiffs.
Does being cookie-free or EU-hosted resolve a wiretapping claim?
No. Section 631(a), WESCA and the federal Wiretap Act ask whether a communication was intercepted and who consented. The presence of cookies and the location of the server are not elements of any of those statutes, so neither fact disposes of the claim in either direction.
How does the pen register theory differ from the section 631 theory?
Section 631(a) covers reading the contents of a communication in transit without the consent of all parties. Section 638.51 covers installing a pen register or trap and trace device, which captures routing and addressing data instead of contents, without a court order. SB 690 as enrolled would hand the section 638.51 claim for website conduct to the Attorney General alone and would leave section 631(a) open to private plaintiffs.
Who can actually sue under CIPA, WESCA or the federal Wiretap Act?
California Penal Code section 637.2 lets any injured person bring a CIPA claim, Pennsylvania's WESCA lets any intercepted person sue under 18 Pa. Cons. Stat. section 5725(a), and the federal Wiretap Act gives the same right to any intercepted person under 18 U.S.C. section 2520. SB 690 narrows that list only for the pen register theory, since it hands section 638.51 claims about website conduct to the Attorney General alone. The section 631(a) interception theory keeps its private right of action untouched.
Does SB 690 erase session replay lawsuits that are already pending?
SB 690, as enrolled, applies its Attorney-General-only limit on section 638.51 pen register claims retroactively to any such claim pending in an action commenced within two years of the operative date. It leaves section 631(a) alone, so a pending interception claim survives even where the pen register theory in the same complaint does not. The bill was enrolled and presented to the Governor on September 4, 2026, according to the California Legislative Information site.
What made NaviStone a third party rather than a direct participant in Popa?
The Third Circuit found that NaviStone never became a direct party to Ashley Popa's communications with Harriet Carter Gifts' website, even though NaviStone supplied the tracking code. The interception happened the moment the JavaScript routed Popa's signals to NaviStone's own servers rather than keeping them between Popa and the retailer. That ruling vacated a district court decision that had reached the opposite conclusion on both the party question and where the interception occurred.
How large can the statutory damages figure get in a CIPA session replay class action?
Penal Code section 637.2(a) sets recovery at the greater of $5,000 per violation or three times actual damages, and subsection (c) removes any need to prove actual harm to collect it. Multiplied across a class, the arithmetic gets large fast: 10,000 California visitors produce a $50,000,000 demand before a single dollar of harm is proven. The federal Wiretap Act caps the same math much lower, at the greater of $100 per day of violation or $10,000 under 18 U.S.C. section 2520(c)(2)(B).
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Glossary Terms
What Server Side Tracking Fixes, and What It Leaves Untouched
Learn what server side tracking moves to your own server, which Safari cookie caps it escapes, how to deduplicate events, and why consent obligations stay.


How Much Does Session Replay Slow Down Website Speed?
The real answer to does session replay slow down website speed, with published rrweb and Sentry numbers for script size, main-thread CPU, and upload bandwidth.


What Digital Experience Analytics Covers That Web Analytics Misses
Unlike event counting, digital experience analytics reconstructs the visit itself, using session replay, heatmaps, friction detection and journey analysis.


Two Numbers Hide Behind One Drop-off Rate
Every funnel produces two drop-off rate numbers, one per step and one end to end, and teams quote them interchangeably. A worked table separates them.


Who Owns Dwell Time, the Search Engine or Your Analytics
Search engines own dwell time and your analytics cannot see it. Where the line falls against time on page and session duration, and what Google documents.


The Setup Choices Behind Every Funnel Analysis
Three setup choices decide what funnel analysis reports: step sequencing, the conversion window, and whether the funnel counts users or sessions.
Related Articles


What Autocapture Records Without Any Manual Instrumentation
In product analytics, autocapture records every click, page view and form submit automatically, without a single tracking call written by hand.


How Cookieless Analytics Counts Visitors Without an Identifier
A cookieless analytics tool counts visitors without storing an identifier in the browser. What that removes, what it costs, and why fingerprinting fails.


The Four Frustration Signals and What Each One Means
The four frustration signals are rage clicks, dead clicks, error clicks and thrashed cursors. Each one fires on a threshold your tool sets, not on a guess.

