budding planted 2026-02-18 · tended 2026-03-09 unverified — check

Placeholder note

Structure is real; the analysis is not written yet. [draft — Peter to write]

California’s Invasion of Privacy Act was written for telephone wiretapping. The interesting question is how a statute from that era ended up as the engine of a wave of website-tracking complaints — and where the theory gets thin.

The statutory move

The plaintiff’s theory reads the old “reading or attempting to read” and third-party “eavesdrop” language onto modern session-replay and chat-widget vendors. [draft — Peter to write] — set out the two clauses and the party/third-party distinction here.

see also

Compare the standing posture in the BIPA map — different statute, same concrete-harm pressure.

The defense usually contests whether the vendor is a “third party” at all, or merely a tool of the first party.1 That is the hinge the whole theory turns on.

Where it strains

[draft — Peter to write] — the party-exception argument, the consent theories, and the split in how district courts have handled the pen-register clause.

Footnotes

  1. The party/third-party line and the pen-register clause both need a pinned controlling case before this goes live. [unverified — check]