There is a new wave of lawsuits targeting online businesses, including adult websites. These suits involve the California Invasion of Privacy Act (CIPA), and they are becoming increasingly prevalent. In fact, three different clients of my law firm were recently served or threatened with CIPA lawsuits — all in the same week.
The problem is, plaintiffs and their lawyers seem to be going down lists of websites, so it’s hard to predict who will next be subject to this kind of lawsuit. The sensitivity of the information you handle could increase your exposure — for example, records of searches for particular sex acts — but in general, there is simply no way to know if you might become the next defendant.
Since plaintiff lawyers are asking for settlement sums ranging from $10,000 to $50,000 to settle these actions, it makes sense to try to avoid these types of lawsuits by taking whatever preventative steps you can. This article will explain what CIPA is, the current status of CIPA lawsuits, and what you can do to head off such lawsuits and protect your business.
First enacted in 1967 and codified in sections 630-638 of the California penal code, CIPA prohibits improper monitoring of someone’s communications without their consent or a court order, such as by wiretapping, or using trap-and-trace devices or “pen registers.”
The term “pen register” formerly referred mainly to a device that records the numbers of outgoing calls dialed by a specific phone. According to some plaintiffs’ lawyers, however, it also refers to monitoring of internet communications and activity. Other attorneys, including me, do not agree with this interpretation.
Each CIPA violation comes with a penalty of $5,000, or three times the actual damages. Importantly, the law doesn’t only impact businesses based in California. Anyone in California can sue you for an alleged violation as long as your business interacts with California residents.
The Current Status of CIPA Lawsuits
Attorneys representing the plaintiffs in these CIPA suits contend that the websites they are suing are violating CIPA by planting trackers and cookies, and sharing information about site users, before obtaining those users’ permission.
Defense lawyers argue that since internet technology did not exist and had not been contemplated when the law was enacted in 1967, CIPA should not be applied to websites at all. They point out that even when California has amended CIPA over the past 20 years, it still didn’t add websites specifically, and that most information collected and shared is not private, damaging or embarrassing.
As of this writing, the question of whether CIPA applies to websites remains up in the air. Some courts have ruled that CIPA does not apply, while others have ruled that the law may apply and allowed lawsuits to proceed, setting up a potentially expensive path for defendants. Until a high enough court sets a binding precedent, the issue remains unsettled, so your outcome in court may depend on factors like who your trial judge is and where the lawsuit is filed.
What Protective Measures Should Adult Websites Take?
Although there is no surefire way to guarantee that you won’t be sued or threatened with a lawsuit, taking the following precautions will make it harder for plaintiffs to attack your business.
If the above steps are too difficult or burdensome, consider blocking California visitors altogether.
You did everything right. Now you must make sure to follow through on your stated policies.
When someone declines or doesn’t opt in, be certain you don’t continue to obtain any information. Don’t forget that users — and lawsuit filers — have access to reports that show what the website has shared and when.
Thorough follow-up will require technical audits of every tracking tool, cookies, etc. Perform these audits after every tech or policy update. It can be tempting to keep adding new online services and trackers, but this can get you into trouble if you add new services that record or share information before the opt-in.
Be ready to show proof of whether a particular user consented or declined, and what information can or cannot therefore be tracked, shared or saved. Keep a time-stamped log of consent interactions. Be able to prove in court what you did and didn’t do based on a user’s actions.
It is also your duty to make sure third-party vendors aren’t tracking your users. Make sure to review your agreements with all third-party vendors, even those that provide trackers and analytics for free, like Google and Meta. Confirm with them — in writing, if possible — that they aren’t tracking your users without the users having opted in, and make sure their actions also comply with your terms of use and other policies. Include all third-party search functionality suppliers and other vendors.
Potential Changes to CIPA
I am not alone in believing that CIPA is being abused by plaintiff lawyers. A bill to update the law has been passed by California’s Senate and is currently winding its way through the committee process in the state Assembly. SB 690, as it stands now, would narrow the scope of the law, so that only the state attorney general would be able to sue for CIPA violations. It would even be partially retroactive, applying to some pending claims.
Many organizations are backing SB 690 in order to protect businesses, but plaintiff lawyers and some privacy rights activists are aggressively fighting against the proposed legislation. If you are in California, contact your Assembly member. Urge them to support SB 690.
As I cautioned earlier, there is no 100% certain way to prevent your site from being threatened with a CIPA lawsuit. However, taking the proper steps as described above can help you avoid such a scenario, and defend yourself if a lawsuit does happen.
This article is not intended as legal advice and should not be relied upon as such, but only to present information and analysis to help guide businesses. The facts of any individual case can and do vary widely.Nader “Nick” Zargarpour is a business lawyer with over 25 years of trial experience. His firm handles the writing, negotiating and enforcement of contracts, as well as partnership disputes and various other business litigation.
Stay informed of the latest developments. Subscribe to XBIZ newsletters.
Thank you, we have sent you an email to confirm your request.
Click here if you would like to subscribe an additional email address.
Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.
For years, artificial intelligence felt like the plot of a science-fiction movie. Pop culture gave us Skynet from “The Terminator,” the replicants of “Blade Runner” and countless visions of machines replacing human creativity altogether. AI was cast as either humanity's next great breakthrough or the beginning of a dystopian future.
Choosing a payment provider involves more than comparing features and pricing. It's also about trusting that your customers' payment information is being handled securely. Every August, Segpay is recertified as a Level 1 PCI-compliant service provider, a milestone the company has achieved for the past 20 years. Having helped write Segpay's original PCI policy documents more than two decades ago, I've seen firsthand how PCI compliance has evolved.
Savannah Sly is the first to admit she didn't always understand sex work. At 18, she was an art student in Boston, working part-time at a box office and, as she puts it, "broke as a joke." While looking for ways to make ends meet, she often found herself browsing Craigslist's adult ads, intrigued by the women advertising their services.
The adult industry has always been defined by its ability to evolve. It embraced online distribution before much of mainstream entertainment did, pioneered subscription-based business models, and continues to evolve in areas ranging from streaming to AI.
Long before joining the Jerkmate team as a marketing strategist, Lili L. was the kind of person who always felt like she needed a new challenge.
For business owners in the adult and specialty spaces, the rules have always been written in someone else’s office. The latest Mastercard changes are no exception, though there are practical ways merchants can begin preparing now.
Throughout 2025, age verification remained a major focus as merchants worked to meet the requirements of 26 U.S. states, country-specific regulations in France, the UK, and Italy, and evolving guidance from the European Commission.
For adult website operators, compliance can no longer live in a folder that only opens when a bank, regulator, attorney, or payment processor starts asking questions.
When Ricci Levy speaks about human rights, she does not use detached, academic language. She speaks with urgency, emotion and the kind of passion that immediately makes it clear just how deeply personal this work is for her.
After my first year of college, I needed a job. So I did what people did back then: I opened the newspaper and started scanning the classifieds. One listing stood out: “Image Librarian.” I had no idea what that meant, but I applied, and got the job.
Fuente: xbiz.com
