By Steve Levine · Updated July 20, 2026 · 7 min read
The Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa.C.S. §§ 5701–5775, is a state law that bars the intentional interception, disclosure, or use of wire, electronic, or oral communications without consent. Because Pennsylvania is an all-party (two-party) consent state, recording or intercepting a communication generally requires the consent of everyone involved. WESCA carries civil liquidated damages of $100 per day of violation or $1,000 (whichever is higher), plus punitive damages and attorney's fees. Written for the telephone era, it is now a driver of class actions against websites that use session-replay and third-party tracking tools — a theory the Third Circuit opened up in Popa v. Harriet Carter Gifts.
Free settlement alerts
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
The Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa.C.S. §§ 5701–5775, is a state law that prohibits the intentional interception, disclosure, or use of wire, electronic, or oral communications without consent. Because Pennsylvania is an all-party (two-party) consent state, recording or intercepting a communication generally requires the consent of everyone involved. WESCA provides a private right of action with civil damages and is enforced criminally as well.
Under 18 Pa.C.S. § 5725, a person whose communication is intercepted, disclosed, or used in violation of WESCA may recover actual damages but not less than liquidated damages computed at $100 per day for each day of violation or $1,000, whichever is higher, plus punitive damages and reasonable attorney's fees and litigation costs. These are amounts a court may award if a violation is proven; they are not a guaranteed payout.
A wave of WESCA lawsuits targets website tracking technology. Plaintiffs allege that session-replay code and third-party marketing or analytics tools intercept visitors' clicks, keystrokes, and searches in real time and reroute them to an outside vendor without consent, in violation of 18 Pa.C.S. § 5703. The theory gained traction after the Third Circuit's 2022 decision in Popa v. Harriet Carter Gifts, which held there is no blanket "direct party" exception under WESCA and that an interception can occur at the visitor's browser in Pennsylvania. Whether a decades-old wiretap statute reaches modern web tracking remains contested and is decided case by case.
In Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022), the Third Circuit revived a WESCA claim over a marketing vendor (NaviStone) that allegedly received a shopper's browsing activity through code on the retailer's website. The court rejected the idea that a party to a communication is automatically exempt from WESCA and held that the interception occurred where the signals originated — the plaintiff's browser in Pennsylvania — not at the vendor's out-of-state servers. The ruling is widely cited as the basis for Pennsylvania website-tracking class actions.
Both are state two-party-consent wiretap statutes now used against website tracking, but they differ in structure and damages. Pennsylvania's WESCA sets liquidated damages at $100 per day or $1,000 (whichever is higher) plus punitive damages and fees under 18 Pa.C.S. § 5725, while California's CIPA sets $5,000 per violation or three times actual damages under Cal. Penal Code § 637.2. Their definitions, the "direct party" analysis, and the leading case law also differ, so a claim can survive under one statute and fail under the other.
HOT
HOT