Glossary · Privacy

Pennsylvania Wiretap Act (WESCA): Website-Tracking & Wiretap Lawsuits Explained

By Steve Levine · Updated July 20, 2026 · 7 min read

Quick Answer

The Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa.C.S. §§ 5701–5775, is a state law that bars the intentional interception, disclosure, or use of wire, electronic, or oral communications without consent. Because Pennsylvania is an all-party (two-party) consent state, recording or intercepting a communication generally requires the consent of everyone involved. WESCA carries civil liquidated damages of $100 per day of violation or $1,000 (whichever is higher), plus punitive damages and attorney's fees. Written for the telephone era, it is now a driver of class actions against websites that use session-replay and third-party tracking tools — a theory the Third Circuit opened up in Popa v. Harriet Carter Gifts.

What WESCA Is and Why It Exists

The Pennsylvania Wiretapping and Electronic Surveillance Control Act — usually shortened to WESCA or simply the Pennsylvania Wiretap Act — is the Commonwealth's core communications-privacy statute. Enacted in 1978, it sits in the Pennsylvania Crimes Code at Chapter 57 of Title 18 (18 Pa.C.S. §§ 5701 through 5775). It was written to control government and private surveillance in an era of telephone wiretaps and hidden recorders, and it functions as Pennsylvania's counterpart to the federal Wiretap Act.

Like several older wiretap laws, WESCA's broad language has let plaintiffs argue it reaches modern internet tracking. That is why a statute written decades before the web now drives some of Pennsylvania's most active privacy litigation — much like California's Invasion of Privacy Act (CIPA) has been revived against website session-replay and chat tools.

What the Law Prohibits — § 5703

WESCA is a set of related prohibitions rather than a single rule. The provisions doing the most work in current litigation are:

  1. § 5703 — Interception, disclosure or use. The heart of the statute. It makes it a crime to intentionally intercept a wire, electronic, or oral communication, or to disclose or use the contents of a communication a person knows was unlawfully intercepted. A violation is generally a third-degree felony.
  2. § 5702 — Definitions. Defines the key terms — “intercept,” “electronic communication,” “contents,” and more. How broadly “intercept” and “contents” are read decides many website cases.
  3. § 5704 — Exceptions to prohibition. Lists when interception is lawful, including certain consent scenarios and law-enforcement activity. Defendants often argue a visitor consented or that an exception applies.
  4. § 5725 — Civil action. Creates a private right of action for anyone whose communication is intercepted, disclosed, or used in violation — the engine behind WESCA class actions.
A website complaint typically centers on § 5703 (the interception) and § 5725 (the money), reading the § 5702 definitions to cover data sent from a visitor's browser.

The feature that makes WESCA powerful is Pennsylvania's two-party (all-party) consent rule. In many states, one participant in a conversation can record it without telling anyone. Pennsylvania is different: intercepting or recording a communication generally requires the consent of everyone involved. If a company intercepts an interaction — or lets a third party do so — without that consent, it can face liability even when no one suffered a measurable financial loss.

Pennsylvania is not alone. California's CIPA and Florida's Security of Communications Act use the same all-party framework to power similar website-tracking suits. For WESCA cases, plaintiffs argue that a visitor never agreed to have a third-party vendor silently capture their clicks, keystrokes, or searches, and that a buried line in a general privacy policy is not the kind of consent the statute requires. Defendants respond that visitors did consent — often pointing to a cookie banner or a browsewrap agreement — that the vendor was acting as the company's own tool rather than an eavesdropping outsider, or that what was captured was not a “communication” at all.

Popa v. Harriet Carter Gifts — The Website-Tracking Door

The case that turned WESCA into a website-tracking tool is Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022). A shopper alleged that as she browsed the retailer's site, code on the page rerouted her activity — searches, clicks, and cart actions — to a third-party marketing vendor, NaviStone, without her consent.

The Third Circuit made two holdings that plaintiffs now rely on across Pennsylvania:

No blanket “direct party” exception. The court rejected the idea that a party to a communication is automatically exempt from WESCA, so a vendor that receives data directly can still be an unlawful interceptor. It left open a narrower question of whether any statutory exception might apply.
Interception happens at the browser. The court held the interception occurred where the signals originated — the visitor's browser in Pennsylvania — not at the vendor's out-of-state servers, keeping the conduct within Pennsylvania's reach.

After Popa, a stream of complaints has accused Pennsylvania websites of using session-replay code and marketing pixels to intercept visitor activity. OCA is tracking several, including the PNC Bank website-tracking lawsuit over the LinkedIn Insight Tag and the Dolce & Gabbana session-recording lawsuit, both pleaded under WESCA. As always, being named in a complaint is not a finding of wrongdoing: at the pleading stage there is no settlement and no claim form — allegations must be proven, a class must be certified, and any recovery is typically years away if a case advances at all.

Damages and Your Rights — § 5725

WESCA provides a private right of action in 18 Pa.C.S. § 5725. A person whose communication is intercepted, disclosed, or used in violation may recover actual damages, but not less than liquidated damages computed at $100 per day for each day of violation or $1,000, whichever is higher. The statute also allows punitive damages and reasonable attorney's fees and litigation costs.

The $100-per-day floor matters because it can grow quickly across a long class period and a large class, which is why even technical violations can translate into significant aggregate exposure. But these are amounts a court may award if a violation is proven — they are not guaranteed, and not money that exists simply because a case was filed. How the damages are counted, and whether the conduct is a WESCA violation at all, are contested in almost every case.

Common Defenses and Open Questions

WESCA website litigation is unsettled, and defendants raise several recurring arguments:

Consent. That the visitor agreed to the tracking through a privacy policy, cookie banner, or a browsewrap or clickwrap agreement — a defense some Pennsylvania courts have credited at the pleading stage.
The vendor-as-tool argument. That a service provider acting only as the website's tool is not an eavesdropping third party, and that any remaining exception under § 5704 applies.
No “contents.” That what was captured was routing or metadata, not the substance of a communication protected by the statute.
Standing and injury. Whether the plaintiff suffered a concrete injury sufficient to sue, an issue that turns on evolving Article III standing law in federal court.

Because these questions are still being worked out after Popa, outcomes vary by court and by the specific technology at issue. If you believe your communications were intercepted without consent, the controlling text is WESCA itself (18 Pa.C.S. §§ 5701–5775) and the Pennsylvania and Third Circuit decisions interpreting it.

Frequently Asked Questions

What is the Pennsylvania Wiretapping and Electronic Surveillance Control Act?

The Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa.C.S. §§ 5701–5775, is a state law that prohibits the intentional interception, disclosure, or use of wire, electronic, or oral communications without consent. Because Pennsylvania is an all-party (two-party) consent state, recording or intercepting a communication generally requires the consent of everyone involved. WESCA provides a private right of action with civil damages and is enforced criminally as well.

How much can you recover under Pennsylvania's Wiretap Act?

Under 18 Pa.C.S. § 5725, a person whose communication is intercepted, disclosed, or used in violation of WESCA may recover actual damages but not less than liquidated damages computed at $100 per day for each day of violation or $1,000, whichever is higher, plus punitive damages and reasonable attorney's fees and litigation costs. These are amounts a court may award if a violation is proven; they are not a guaranteed payout.

Why are websites being sued under Pennsylvania's Wiretap Act?

A wave of WESCA lawsuits targets website tracking technology. Plaintiffs allege that session-replay code and third-party marketing or analytics tools intercept visitors' clicks, keystrokes, and searches in real time and reroute them to an outside vendor without consent, in violation of 18 Pa.C.S. § 5703. The theory gained traction after the Third Circuit's 2022 decision in Popa v. Harriet Carter Gifts, which held there is no blanket "direct party" exception under WESCA and that an interception can occur at the visitor's browser in Pennsylvania. Whether a decades-old wiretap statute reaches modern web tracking remains contested and is decided case by case.

What did Popa v. Harriet Carter Gifts decide?

In Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022), the Third Circuit revived a WESCA claim over a marketing vendor (NaviStone) that allegedly received a shopper's browsing activity through code on the retailer's website. The court rejected the idea that a party to a communication is automatically exempt from WESCA and held that the interception occurred where the signals originated — the plaintiff's browser in Pennsylvania — not at the vendor's out-of-state servers. The ruling is widely cited as the basis for Pennsylvania website-tracking class actions.

How is WESCA different from California's CIPA?

Both are state two-party-consent wiretap statutes now used against website tracking, but they differ in structure and damages. Pennsylvania's WESCA sets liquidated damages at $100 per day or $1,000 (whichever is higher) plus punitive damages and fees under 18 Pa.C.S. § 5725, while California's CIPA sets $5,000 per violation or three times actual damages under Cal. Penal Code § 637.2. Their definitions, the "direct party" analysis, and the leading case law also differ, so a claim can survive under one statute and fail under the other.


About This Page

General legal-information about the Pennsylvania Wiretapping and Electronic Surveillance Control Act, not legal advice. OpenClassActions.com is a consumer news site and is not a law firm or a settlement administrator. Statutes and case law change, and how they apply depends on the facts of a particular situation. For the controlling text, see WESCA itself (18 Pa.C.S. §§ 5701–5775) and the relevant court decisions. If you think your rights were affected, consult a qualified attorney in your jurisdiction.


More on Wiretap & Website-Tracking Lawsuits