By Steve Levine · Updated July 20, 2026 · 7 min read
Quick Answer
The Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa.C.S. §§ 5701–5775, is a state law that bars the intentional interception, disclosure, or use of wire, electronic, or oral communications without consent. Because Pennsylvania is an all-party (two-party) consent state, recording or intercepting a communication generally requires the consent of everyone involved. WESCA carries civil liquidated damages of $100 per day of violation or $1,000 (whichever is higher), plus punitive damages and attorney's fees. Written for the telephone era, it is now a driver of class actions against websites that use session-replay and third-party tracking tools — a theory the Third Circuit opened up in Popa v. Harriet Carter Gifts.
What WESCA Is and Why It Exists
The Pennsylvania Wiretapping and Electronic Surveillance Control Act — usually
shortened to WESCA or simply the Pennsylvania Wiretap Act — is the
Commonwealth's core communications-privacy statute. Enacted in 1978, it sits in the
Pennsylvania Crimes Code at Chapter 57 of Title 18 (18 Pa.C.S.
§§ 5701 through 5775). It was written to control government and private
surveillance in an era of telephone wiretaps and hidden recorders, and it functions as
Pennsylvania's counterpart to the federal Wiretap Act.
Like several older wiretap laws, WESCA's broad language has let plaintiffs argue it reaches
modern internet tracking. That is why a statute written decades before the web now drives
some of Pennsylvania's most active privacy litigation — much like California's
Invasion
of Privacy Act (CIPA) has been revived against website session-replay and chat tools.
What the Law Prohibits — § 5703
WESCA is a set of related prohibitions rather than a single rule. The provisions doing the
most work in current litigation are:
§ 5703 — Interception, disclosure or use. The heart of the statute. It makes it a crime to intentionally intercept a wire, electronic, or oral communication, or to disclose or use the contents of a communication a person knows was unlawfully intercepted. A violation is generally a third-degree felony.
§ 5702 — Definitions. Defines the key terms — “intercept,” “electronic communication,” “contents,” and more. How broadly “intercept” and “contents” are read decides many website cases.
§ 5704 — Exceptions to prohibition. Lists when interception is lawful, including certain consent scenarios and law-enforcement activity. Defendants often argue a visitor consented or that an exception applies.
§ 5725 — Civil action. Creates a private right of action for anyone whose communication is intercepted, disclosed, or used in violation — the engine behind WESCA class actions.
A website complaint typically centers on § 5703 (the interception) and § 5725
(the money), reading the § 5702 definitions to cover data sent from a visitor's browser.
Two-Party Consent — What Makes Pennsylvania Different
The feature that makes WESCA powerful is Pennsylvania's two-party (all-party) consent
rule. In many states, one participant in a conversation can record it without telling anyone.
Pennsylvania is different: intercepting or recording a communication generally requires the
consent of everyone involved. If a company intercepts an interaction — or lets
a third party do so — without that consent, it can face liability even when no one
suffered a measurable financial loss.
Pennsylvania is not alone. California's CIPA
and Florida's Security of Communications Act use the same all-party framework to power
similar website-tracking suits. For WESCA cases, plaintiffs argue that a visitor never
agreed to have a third-party vendor silently capture their clicks, keystrokes, or searches,
and that a buried line in a general privacy policy is not the kind of consent the statute
requires. Defendants respond that visitors did consent — often pointing to a cookie
banner or a browsewrap agreement — that the vendor was acting as the company's own
tool rather than an eavesdropping outsider, or that what was captured was not a
“communication” at all.
Popa v. Harriet Carter Gifts — The Website-Tracking Door
The case that turned WESCA into a website-tracking tool is
Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022). A shopper alleged
that as she browsed the retailer's site, code on the page rerouted her activity —
searches, clicks, and cart actions — to a third-party marketing vendor, NaviStone,
without her consent.
The Third Circuit made two holdings that plaintiffs now rely on across Pennsylvania:
• No blanket “direct party” exception. The court rejected the idea
that a party to a communication is automatically exempt from WESCA, so a vendor that receives
data directly can still be an unlawful interceptor. It left open a narrower question of
whether any statutory exception might apply.
• Interception happens at the browser. The court held the interception occurred
where the signals originated — the visitor's browser in Pennsylvania — not at
the vendor's out-of-state servers, keeping the conduct within Pennsylvania's reach.
After Popa, a stream of complaints has accused Pennsylvania websites of using
session-replay code and marketing pixels to intercept visitor activity. OCA is tracking
several, including the
PNC
Bank website-tracking lawsuit over the LinkedIn Insight Tag and the
Dolce
& Gabbana session-recording lawsuit, both pleaded under WESCA. As always, being named
in a complaint is not a finding of wrongdoing: at the pleading stage there is no settlement
and no claim form — allegations must be proven, a class must be
certified, and
any recovery is typically years away if a case advances at all.
Damages and Your Rights — § 5725
WESCA provides a private right of action in 18 Pa.C.S. § 5725. A person whose
communication is intercepted, disclosed, or used in violation may recover actual
damages, but not less than liquidated damages computed at $100 per day for each
day of violation or $1,000, whichever is higher. The statute also allows
punitive damages and reasonable attorney's fees and litigation costs.
The $100-per-day floor matters because it can grow quickly across a long class period and a
large class, which is why even technical violations can translate into significant aggregate
exposure. But these are amounts a court may award if a violation is proven —
they are not guaranteed, and not money that exists simply because a case was filed. How the
damages are counted, and whether the conduct is a WESCA violation at all, are contested in
almost every case.
Common Defenses and Open Questions
WESCA website litigation is unsettled, and defendants raise several recurring arguments:
• Consent. That the visitor agreed to the tracking through a privacy policy,
cookie banner, or a browsewrap or clickwrap agreement — a defense some Pennsylvania
courts have credited at the pleading stage.
• The vendor-as-tool argument. That a service provider acting only as the
website's tool is not an eavesdropping third party, and that any remaining exception under
§ 5704 applies.
• No “contents.” That what was captured was routing or metadata, not
the substance of a communication protected by the statute.
• Standing and injury. Whether the plaintiff suffered a concrete injury
sufficient to sue, an issue that turns on evolving
Article III standing
law in federal court.
Because these questions are still being worked out after Popa, outcomes vary by court
and by the specific technology at issue. If you believe your communications were intercepted
without consent, the controlling text is WESCA itself (18 Pa.C.S. §§ 5701–5775)
and the Pennsylvania and Third Circuit decisions interpreting it.
Frequently Asked Questions
What is the Pennsylvania Wiretapping and Electronic Surveillance Control Act?
The Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), 18 Pa.C.S. §§ 5701–5775, is a state law that prohibits the intentional interception, disclosure, or use of wire, electronic, or oral communications without consent. Because Pennsylvania is an all-party (two-party) consent state, recording or intercepting a communication generally requires the consent of everyone involved. WESCA provides a private right of action with civil damages and is enforced criminally as well.
How much can you recover under Pennsylvania's Wiretap Act?
Under 18 Pa.C.S. § 5725, a person whose communication is intercepted, disclosed, or used in violation of WESCA may recover actual damages but not less than liquidated damages computed at $100 per day for each day of violation or $1,000, whichever is higher, plus punitive damages and reasonable attorney's fees and litigation costs. These are amounts a court may award if a violation is proven; they are not a guaranteed payout.
Why are websites being sued under Pennsylvania's Wiretap Act?
A wave of WESCA lawsuits targets website tracking technology. Plaintiffs allege that session-replay code and third-party marketing or analytics tools intercept visitors' clicks, keystrokes, and searches in real time and reroute them to an outside vendor without consent, in violation of 18 Pa.C.S. § 5703. The theory gained traction after the Third Circuit's 2022 decision in Popa v. Harriet Carter Gifts, which held there is no blanket "direct party" exception under WESCA and that an interception can occur at the visitor's browser in Pennsylvania. Whether a decades-old wiretap statute reaches modern web tracking remains contested and is decided case by case.
What did Popa v. Harriet Carter Gifts decide?
In Popa v. Harriet Carter Gifts, Inc., 52 F.4th 121 (3d Cir. 2022), the Third Circuit revived a WESCA claim over a marketing vendor (NaviStone) that allegedly received a shopper's browsing activity through code on the retailer's website. The court rejected the idea that a party to a communication is automatically exempt from WESCA and held that the interception occurred where the signals originated — the plaintiff's browser in Pennsylvania — not at the vendor's out-of-state servers. The ruling is widely cited as the basis for Pennsylvania website-tracking class actions.
How is WESCA different from California's CIPA?
Both are state two-party-consent wiretap statutes now used against website tracking, but they differ in structure and damages. Pennsylvania's WESCA sets liquidated damages at $100 per day or $1,000 (whichever is higher) plus punitive damages and fees under 18 Pa.C.S. § 5725, while California's CIPA sets $5,000 per violation or three times actual damages under Cal. Penal Code § 637.2. Their definitions, the "direct party" analysis, and the leading case law also differ, so a claim can survive under one statute and fail under the other.
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
About This Page
General legal-information about the Pennsylvania Wiretapping and Electronic Surveillance
Control Act, not legal advice. OpenClassActions.com is a consumer news site and is not a law
firm or a settlement administrator. Statutes and case law change, and how they apply depends
on the facts of a particular situation. For the controlling text, see WESCA itself (18
Pa.C.S. §§ 5701–5775) and the relevant court decisions. If you think your
rights were affected, consult a qualified attorney in your jurisdiction.
More on Wiretap & Website-Tracking Lawsuits
PNC Bank Website-Tracking Lawsuit: A WESCA class action over the LinkedIn Insight Tag on PNC's site — filed in Pennsylvania. See the case →
Dolce & Gabbana Session-Recording Lawsuit: A Pennsylvania Wiretap Act suit over the "INSIDE" script that allegedly recorded visitors. Read the case →
California Invasion of Privacy Act (CIPA): The California parallel — $5,000-per-violation two-party-consent wiretap statute. Read the guide →
Session Replay Software: How keystroke-and-click recording works — and why it draws wiretap claims. Learn more →
Pen Register & Trap and Trace: The metadata-interception theory aimed at tracking pixels and analytics tags. What it covers →