How server-side tagging can help American businesses with a 1967 wiretapping law

Michael Lanoie, Product Marketing Manager at Didomi, provides an overview of California's Invasion of Privacy Act (CIPA) and how server-side solutions can help businesses approach it.

Michael Lanoie
•
September 24, 2026
•
4
min read
Summary

California's Invasion of Privacy Act (CIPA) was passed in 1967 to address wiretapping on telephone lines. Today, it's the basis for a wave of class-action lawsuits against websites using chat tools, session replay software, and third-party tracking pixels.

Server-side tagging, known for its benefits of improved data collection and web performance, might just be a key technology for helping mitigate risk from this old law. This article explains how.

What exactly is CIPA

The California Invasion of Privacy Act (CIPA) is a California law originally written in the 1960s to stop illegal wiretapping (think secretly recording phone calls). The law was enacted to address growing concerns about invasions of privacy through emerging technologies, such as pen registers and trap-and-trace devices. It requires all parties to a communication to consent before it's recorded or intercepted.

The law covers all private individuals, businesses, employers, and technology providers that interact with or record communications involving people in California. The communications must be confidential, and made in circumstances that reasonably indicate the parties desire it to be confined to them. This includes telephone and cellular conversations (mobile and landline), electronic messages (email and text), and in-person conversations, all where participants reasonably expect confidentiality.

California takes privacy invasions seriously, with statutory civil damages being $5,000 per violation, while criminal fines can reach up to $10,000 per violation.

Why CIPA lawsuits are arguing over website technologies like cookies and tags

Over the past few years, California courts have been open to  lawsuits claiming that chat widgets, session-recording tools, analytics scripts, and ad pixels are violating rights granted through CIPA. Plaintiffs have argued that third-party tools (in the form of different types of scripts on a webpage) capture what a visitor does or types without their explicit knowledge or consent, and that those tools “wiretap” that webpage interaction.

CIPA was written with phone lines in mind, but some plaintiffs' attorneys have successfully argued that third-party JavaScript tags can fit that description, citing the evolving technology spirit of the original law. They argue that these tags are dropped directly into a user's browser, reading page content and user behavior, and transmitting it straight to an external server, turning the browser into a wiretap. The user never authorized the third party to listen in, they only interacted with the first-party site.

Courts have allowed these claims to proceed often enough that CIPA litigation has become a real operating risk for any site running client-side third-party scripts. The arguments often hinge on the fact that the tag runs in the user's browser and sends data directly to a third party, without the first-party site acting as an intermediary.

How Server-Side Tagging comes into play

With server-side tagging, those tags no longer live in the browser. Data collection happens through a contained, first-party server, and that server decides what data gets forwarded to which vendor, and when.

This shift matters for CIPA exposure in three concrete ways:

1. The third party isn't "listening in" on the browser anymore.
Data flows from the user's browser to the website's own server first. The website is a party to that communication, not an eavesdropping third party. As long as the company follows local regulations on the transmitting of that data, it can not be construed as aiding in the third party listening in.

2. Data leaving the server is filtered, not raw.
Client-side tags typically forward everything they can capture. A server-side setup lets a company strip identifiers, mask fields, or drop unnecessary data points before anything reaches a vendor. Less raw behavioral data reaching third parties means less surface area for a wiretap claim to attach to.

3. Consent enforcement happens at a single, auditable point.
When tag firing is server-side, consent status can gate data transmission at that one location, rather than depending on dozens of individually configured client-side scripts to each respect a consent signal correctly. This closes the pre-consent firing gap that's often the first thing a plaintiff's technical expert checks.

What Server-Side Tagging doesn't do on its own

Moving tags server-side reduces exposure, but it doesn't eliminate the need for consent. A server-side setup that forwards data to advertising or analytics vendors without a valid legal basis  is still processing personal information without authorization. CIPA risk mitigation works best paired with:

  • Clear, unbundled consent choices for tracking and analytics purposes.
  • Honoring the Global Privacy Control (GPC) signal, which several CIPA-adjacent state laws now treat as a binding opt-out.
  • Documentation showing which vendors receive which data, and under what consent basis.
  • Working with a qualified legal team that knows and understands your marketing and data collection practices.

Figuring it all out on your own can be intimidating, and this is where Addingwell and Didomi come in.

How Addingwell helps

There are many server-side tagging solutions out there that tackle the first issue: funneling all data collection to a controlled server. But that might not be enough in the face of a CIPA lawsuit.

Addingwell takes things a step further. You still get all the advantages of server-side tagging such as the improved page speed, better first-party data collection in the face of browser restrictions and ad blockers, and increased return on ad spend. But you also get the following:

1. Enterprise-grade performance with 99.99% uptime

Addingwell’s multi-zone infrastructure provides the reliability needed whether you have one domain of one hundred. The server container deploys across multiple regions effortlessly, ensuring optimal speed and redundancy no matter where your users are located. Pair all of that with dedicated, personalized support that ensures your tagging server is always working for you.

2. Visibility for every tag, cookie, and crumb of data

For every event passing through the server, the system logs which tags fired and what payload was sent to which partner. Meanwhile, our cookie and data monitoring tools provide details insights into what’s actually happening on your web pages, the information being collected, and the third parties you are sharing with. Get instant alerts if anything goes wrong, so you can ensure your tags fire correctly in real time rather than discovering issues through a demand letter or enforcement notice.

3. Traceable, certifiable consent with Event Consent Monitoring

With Didomi’s consent infrastructure, you can add an additional layer to your server-side tagging solution to create a defensible audit trail. With misconfiguration detection, your tags are checked for consent status in real time, ensuring that tags only fire with the correct consent signal attached. With over 25 privacy regulations covered out of the box, you get better privacy governance across your web properties while still driving better opt-in rates. Learn more about Event Consent Monitoring.

---

It’s important to call out that server-side tagging doesn’t completely absolve you of CIPA or any regulatory compliance risk. Addingwell’s server-side tagging solution can help you mitigate risk in combination with qualified legal counsel and a stiff privacy posture across all your data collection practices.

Interested in exploring further? Book a call with an expert to discuss your data challenges and learn more about CIPA compliance in our guide:

The author

Michael Lanoie
Product Marketing Manager at Didomi
Product Marketing Manager at Didomi. When I'm not writing about data privacy or technology, I'm reading, cooking, or driving some windy roads.
Resources

How server-side tagging can help American businesses with a 1967 wiretapping law

Thank You for Your Interest !
Your request has been successfully submitted. You can now download and explore the document.
Download
Download
Oops! Something went wrong while submitting the form.

Intuitive, Complete
and Powerful.

Addingwell’s interface is designed to save you time and streamline your server management and tag debugging processes.

No credit card required
addingwell interface