Glossary · Privacy

Electronic Communications Privacy Act (ECPA): The Federal Wiretap Law Behind Website-Tracking Lawsuits

By Steve Levine · Updated August 23, 2026 · 9 min read

Quick Answer

The Electronic Communications Privacy Act (ECPA) is the 1986 federal law that governs when electronic communications may be intercepted, accessed, or disclosed. It has three parts: the Wiretap Act (18 U.S.C. §§ 2510–2523) for communications in transit, the Stored Communications Act (§§ 2701–2713) for messages and records sitting on a provider's servers, and the pen register statute (§§ 3121–3127) for routing metadata. The Wiretap Act is the piece consumers meet in class actions: it creates a private right of action with statutory damages of $100 a day or $10,000, whichever is greater. But federal law needs only one party's consent, so a website that receives its own visitors' data is usually exempt — which is why web-tracking suits almost always plead a stricter state statute alongside it.

What the ECPA Is and Why It Exists

The Electronic Communications Privacy Act of 1986 is the federal government's core communications-privacy statute. It did not start from scratch. Congress built it on the 1968 federal wiretap law, which had been written for telephone taps and hidden microphones, and extended that framework to cover “electronic communications” — email, data transfers, and the digital traffic that was just becoming ordinary in the mid-1980s.

One naming quirk causes endless confusion. The 1968 wiretap law was Title III of a larger crime bill, so practitioners still call the federal Wiretap Act “Title III.” The ECPA also has its own Title III, which is the pen register statute. When a source refers to a “Title III claim,” it almost always means the Wiretap Act at 18 U.S.C. § 2511, not the ECPA's third title.

Like other statutes written before the commercial internet, the ECPA's broad language has been aimed at technology its drafters never contemplated. That is why a law about telephone wiretaps now turns up in class actions over marketing pixels, and why so much of the litigation is about definitions rather than about facts.

The Three Titles — Transit, Storage, Metadata

The ECPA is best understood as three separate statutes that divide the world by where a communication is and what part of it is being captured:

  1. Title I — the Wiretap Act (18 U.S.C. §§ 2510–2523). Covers wire, oral, and electronic communications in transit. § 2511 sets the prohibition; § 2510 supplies the definitions that decide most cases; § 2520 creates the civil remedy. This is the title pleaded in consumer class actions.
  2. Title II — the Stored Communications Act (18 U.S.C. §§ 2701–2713). Covers communications and subscriber records at rest on a provider's system. § 2701 bars unauthorized access to stored communications, § 2702 limits when a provider may voluntarily disclose them, and § 2707 creates a civil action with a $1,000 floor.
  3. Title III — pen register and trap and trace (18 U.S.C. §§ 3121–3127). Covers dialing, routing, addressing, and signaling information — the metadata about a communication rather than its substance. It restricts government use of these devices and, critically for consumers, gives no private right of action.
That last point drives a lot of pleading strategy. A consumer who believes a tracking tag captured routing data about their browsing has no federal claim to bring under the pen register statute, which is precisely why the metadata theory is litigated under California's equivalent instead. OCA covers that theory separately in the pen register and trap and trace guide.

What the Wiretap Act Prohibits — § 2511

Section 2511(1)(a) is the operative ban: it reaches anyone who intentionally intercepts, or tries to intercept, a wire, oral, or electronic communication. Related provisions bar disclosing or using the contents of a communication a person knows was obtained through an unlawful interception. Two defined terms decide most disputes.

“Intercept.” Defined in § 2510(4) as acquiring the contents of a communication through an electronic, mechanical, or other device. Courts have read the word to require acquisition contemporaneous with transmission — the rule the Ninth Circuit applied in Konop v. Hawaiian Airlines, Inc., 302 F.3d 868 (9th Cir. 2002). Grabbing a message out of storage after it lands is not an interception; that belongs under the Stored Communications Act.
“Contents.” Defined in § 2510(8) as information about the substance, purport, or meaning of a communication. The substance of a message is protected; the routing and addressing data describing it is not, which is the line the pen register statute sits on.

Those two definitions do more work in modern cases than the prohibition itself. A defendant arguing that a script pulled stored data rather than live traffic, or captured URLs rather than message content, is arguing that no interception of contents ever happened.

The most consequential feature of the federal statute is its consent rule. Under § 2511(2)(d), it is not unlawful for a person who is a party to a communication to intercept it, or for someone else to intercept it where one of the parties has given prior consent. Federal law, in other words, is a one-party consent regime.

This is why the same conduct can be lawful federally and unlawful under state law. California, Pennsylvania, and Florida use an all-party framework, so a claim that dies on the federal party exception can survive under California's Invasion of Privacy Act or Pennsylvania's Wiretap Act.

Section 2511(2)(d) carries one proviso, and it has become the center of gravity in current litigation: consent does not save an interception made for the purpose of committing any criminal or tortious act. This is the crime-tort exception. Plaintiffs use it to get around the party exception by alleging that the defendant's stated privacy practices were misleading, or that the transfer itself was an independent tort. Courts have not agreed on how demanding the word “purpose” is. Some read it to require that committing the crime or tort was the interceptor's actual objective, not a byproduct of an ordinary commercial motive; others let the allegation through at the pleading stage. Federal district courts have split on materially similar facts, and the question is unsettled.

The scope of the party exception itself is also contested. In In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589 (9th Cir. 2020), the Ninth Circuit held that Facebook was not exempt as a matter of law as a party to communications it received through plug-ins embedded on third-party websites, allowing Wiretap Act and CIPA claims to proceed. The court aligned itself with the First and Seventh Circuits and diverged from the Third Circuit's narrower reading — a split that still shapes where these cases get filed.

Damages and the Two-Year Clock — § 2520

Section 2520 gives a private right of action to anyone whose communication is intercepted, disclosed, or intentionally used in violation of the Wiretap Act. Under § 2520(c)(2), a court may assess whichever is greater of (A) the plaintiff's actual damages plus any profits the violator made, or (B) statutory damages of whichever is greater of $100 a day for each day of violation or $10,000. Section 2520(b) adds equitable relief, punitive damages in appropriate cases, and reasonable attorney's fees and litigation costs.

Two qualifications matter. First, the statute says a court may assess those amounts, and several courts have treated the award as discretionary rather than automatic — so a proven violation does not guarantee a $10,000 check. Second, § 2520(e) sets a two-year limitations period that runs from the date the claimant first has a reasonable opportunity to discover the violation, not from the date it occurred. In tracking cases, where the conduct is invisible to the visitor, when that clock started is frequently litigated.

A Stored Communications Act claim carries its own remedy: § 2707 allows actual damages plus the violator's profits, with a floor of $1,000, along with punitive damages for willful violations and fees. Courts disagree over whether a plaintiff must first prove some actual damages to reach that $1,000 floor.

Why the ECPA Shows Up in Website-Tracking Cases

A statute about phone taps became a consumer-litigation fixture because of how modern web pages are built. When a visitor loads a page, embedded third-party code — an advertising pixel, an analytics tag, session-replay software, a live-chat widget — can transmit a copy of what that visitor is doing to an outside company as it happens. Plaintiffs characterize that duplicate stream as an interception of the contents of a communication in transit, which is exactly what § 2511 prohibits.

The complaints typically pair a federal Wiretap Act count with a state wiretap count and sometimes a Video Privacy Protection Act claim where video content is involved. OCA is tracking a number of these, including the Otter.ai meeting-transcription lawsuit, the PNC Bank website-tracking lawsuit, and the Crocs website-tracking lawsuit.

Federal claims do sometimes clear the pleading stage. In Krzyzek v. OpenX Technologies, Inc., No. 3:25-cv-05588 (N.D. Cal. Jan. 27, 2026), the court allowed an ECPA § 2511 claim to proceed against an advertising-technology company alongside CIPA § 631(a) and § 638.51 claims. It is worth being precise about what that means: denying a motion to dismiss decides only that the allegations, taken as true, are enough to move forward. It is not a finding that anyone did anything wrong. At the complaint stage there is no settlement and no claim form — allegations must still be proven, a class must be certified, and any recovery is years away if a case advances at all.

Where ECPA Claims Fail — and Why Plaintiffs Reach for CIPA

Federal wiretap counts are dismissed more often than they survive, and usually for one of these reasons:

The party exception. The website received its own visitor's communication, so it was a party and § 2511(2)(d) applies. This is the single most common defense, and outside the Ninth Circuit's approach it often ends the federal claim outright.
No contemporaneous interception. The data was read from storage rather than captured in transit, so under Konop there was no “intercept” at all.
No “contents.” What moved was routing or addressing information, not the substance of a communication — and the pen register title carries no private right of action to fall back on.
Consent. A cookie banner, privacy policy, or terms-of-use agreement gave the one party's consent federal law requires.
Standing. Whether the plaintiff suffered a concrete injury sufficient to sue in federal court, an issue governed by evolving Article III standing law.

Set against that, the state statutes are simply better tools for a plaintiff. CIPA requires all-party consent, has no crime-tort predicate to satisfy, and sets damages at $5,000 per violation or three times actual damages under Cal. Penal Code § 637.2 — and its § 638.51 pen register provision reaches the metadata the federal statute leaves unremedied. Pennsylvania's WESCA offers $100 per day or $1,000, whichever is higher, plus punitive damages and fees. The federal count is often kept as a hedge and to anchor federal jurisdiction, while the state claim does the real work.

Even so, the appellate law here is moving. The Third Circuit's 2022 decision in Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121, opened Pennsylvania to website claims, while its November 2025 decision in Cole v. Quest Diagnostics Inc., No. 25-1449, affirmed dismissal of CIPA and medical-confidentiality claims on the ground that a pixel provider receiving a browser's direct transmission was itself a party to it. Outcomes continue to turn on the circuit, the specific technology, and how the receiving company is positioned in the data flow.

Frequently Asked Questions

What is the Electronic Communications Privacy Act?

The Electronic Communications Privacy Act (ECPA) is a 1986 federal law that governs when electronic communications may be intercepted, accessed, or disclosed. It works through three parts: the Wiretap Act (18 U.S.C. §§ 2510–2523), which covers communications while they are in transit; the Stored Communications Act (18 U.S.C. §§ 2701–2713), which covers messages and subscriber records held by a service provider; and the pen register and trap and trace statute (18 U.S.C. §§ 3121–3127), which covers routing and addressing metadata rather than content. The ECPA updated the 1968 federal wiretap law so it reached email and other data, not just telephone calls.

How much can you recover under the federal Wiretap Act?

Under 18 U.S.C. § 2520(c)(2), a court may assess whichever is greater of (A) the actual damages the plaintiff suffered plus any profits the violator made, or (B) statutory damages of whichever is greater of $100 a day for each day of violation or $10,000. Section 2520(b) also allows equitable relief, punitive damages in appropriate cases, and reasonable attorney's fees and litigation costs. Because the statute says a court may assess these amounts, several courts have treated the award as discretionary rather than automatic. A separate claim under the Stored Communications Act carries its own floor of $1,000 under 18 U.S.C. § 2707(c). None of this is a guaranteed payout; it is what a court may award if a violation is proven.

Does the ECPA require everyone's consent to record?

No. Federal law is a one-party consent rule. Under 18 U.S.C. § 2511(2)(d), it is not unlawful for a person who is a party to the communication to intercept it, or for someone to intercept it where one of the parties has given prior consent — unless the interception is made for the purpose of committing a criminal or tortious act. That last clause is known as the crime-tort exception. States are free to be stricter, and several are: California, Pennsylvania and Florida all use an all-party consent framework, which is why a single set of facts can violate a state wiretap statute while the federal claim fails.

Why do website-tracking lawsuits plead CIPA instead of just the ECPA?

Because the federal statute is harder to win on and pays less. The ECPA's party exception in 18 U.S.C. § 2511(2)(d) generally protects a website that receives its own visitors' data, so a plaintiff must either show the recipient was not a party or invoke the crime-tort exception, which courts have applied inconsistently. California's Invasion of Privacy Act requires all-party consent, has no equivalent crime-tort predicate, and sets damages at $5,000 per violation or three times actual damages under Cal. Penal Code § 637.2. The ECPA's Title III pen register provisions also give no private right of action, so metadata theories are pleaded under CIPA § 638.51 instead. Plaintiffs commonly plead both statutes and let the state claim carry the case.

What is the difference between the Wiretap Act and the Stored Communications Act?

Timing. The Wiretap Act covers a communication while it is moving, and courts have read the word intercept to require acquisition contemporaneous with transmission — the rule applied in Konop v. Hawaiian Airlines, Inc., 302 F.3d 868 (9th Cir. 2002). The Stored Communications Act covers a communication after it has come to rest on a provider's system, and it turns on unauthorized access rather than interception. The practical consequence is that data pulled out of storage is generally not an interception, so a claim aimed at stored records belongs under 18 U.S.C. § 2701 rather than § 2511.


About This Page

General legal-information about the federal Electronic Communications Privacy Act, not legal advice. OpenClassActions.com is a consumer news site and is not a law firm or a settlement administrator. Statutes and case law change, and how they apply depends on the facts of a particular situation. For the controlling text, see the ECPA itself (18 U.S.C. §§ 2510–2523, 2701–2713, and 3121–3127) and the court decisions interpreting it. If you think your rights were affected, consult a qualified attorney in your jurisdiction.


More on Wiretap & Website-Tracking Law