Skip to content

Electronic Communications Privacy Act (ECPA): An Overview

Electronic Communications Privacy Act
Resources / Blog / Electronic Communications Privacy Act (ECPA): An Overview
Summary
  • The Electronic Communications Privacy Act (ECPA) is a 1986 U.S. federal law that prohibits the unauthorized interception, access, and disclosure of electronic communications.
  • The ECPA comprises three titles: the Wiretap Act, the Stored Communications Act (SCA), and the Pen Register Act.
  • The ECPA is a one-party consent law at the federal level, though many states impose stricter all-party consent requirements.
  • Plaintiffs’ firms are filing ECPA claims alongside CIPA lawsuits against businesses over common website tracking technologies, including pixels, cookies, and session replay tools.
  • A landmark August 2025 ruling opened the door for ECPA claims based on misrepresentations in a company’s own privacy policy, extending risk well beyond healthcare.
  • ECPA violations can result in criminal fines of up to $250,000 per individual ($500,000 for organizations) and civil statutory damages of $10,000 or $100 per day of violation, whichever is greater.

The Electronic Communications Privacy Act (ECPA) was enacted by the U.S. Congress and signed into law in 1986 to extend federal wiretapping protections from traditional telephone calls to the then-emerging world of electronic communications. 

At the time, legislators were concerned that the existing Federal Wiretap Act of 1968 could not adequately address the privacy of computer transmissions, stored digital data, and the emerging practice of tracing electronic communications through metadata.

Decades later, the ECPA finds itself in a strikingly different role. The same broadly worded statute that was designed to restrain government surveillance is now the basis for a rapidly escalating wave of class action litigation against private businesses. These are frequently filed alongside California Invasion of Privacy Act (CIPA) lawsuits, specifically targeting businesses operating websites that use standard tracking technologies such as analytics pixels, third-party cookies, and session replay tools. 

Understanding what the ECPA covers, how courts are interpreting it in the modern tracking context, and what operational steps businesses can take to manage exposure has become a significant compliance priority for legal, marketing, and technology teams alike.

What the ECPA Covers

The ECPA, as amended, protects wire, oral, and electronic communications across three distinct phases: while communications are being made, while they are in transit, and while they are stored on computers. 

The Act applies to email, telephone conversations, and data stored electronically. It is codified in Title 18 of the U.S. Code and has been amended by several subsequent statutes, including the Communications Assistance for Law Enforcement Act (CALEA) of 1994, the USA PATRIOT Act (2001), and the FISA Amendments Act (2008).

The ECPA is structured around three separate but interrelated titles, each addressing a different aspect of communications privacy.

Title I: The Wiretap Act

Title I of the ECPA, often referred to simply as the Wiretap Act, prohibits the intentional interception, use, or disclosure of wire, oral, or electronic communications during transmission. The prohibition covers any person who intentionally intercepts or attempts to intercept a wire, oral, or electronic communication using an electronic, mechanical, or other device.

Violations of Title I can result in both criminal and civil penalties. Criminal penalties include imprisonment for up to five years and fines of up to USD 250,000 for individuals or USD 500,000 for organizations. 

Victims of a Wiretap Act violation may bring civil claims and recover statutory damages of USD 100 per day of violation or USD 10,000, whichever is greater, along with actual damages, attorneys’ fees, and punitive damages in some cases.

Title I includes several important exceptions:

  • Law enforcement access. Communications may be intercepted with appropriate judicial authorization.
  • One-party consent. Interception is permitted if at least one party to the communication has consented. In practice, a website operator that deploys tracking technology on its own site has historically been considered a party to visitors’ communications, providing a consent defense.
  • The crime-tort exception. The “one-party consent” defense does not apply if the interception is carried out for the purpose of committing an independent crime or tort. This exception has become the primary mechanism through which plaintiffs’ firms are pursuing ECPA claims against website operators.

Title II: The Stored Communications Act

Title II of the ECPA, the Stored Communications Act (SCA), protects electronic communications held in electronic storage by third-party service providers. This includes files stored on servers (such as emails), subscriber information such as names, billing records, and IP addresses, and other records held about individuals by service providers.

The SCA makes it unlawful to intentionally access a facility in which electronic communication services are provided and obtain, alter, or prevent authorized access to a stored wire or electronic communication. 

Importantly, the SCA makes exceptions for law enforcement access and for user consent. In practice, this means that employers generally cannot access an employee’s private emails stored on a work server without consent or a valid court order, and third parties cannot access stored communications without authorization.

Title III: The Pen Register Act

Title III of the ECPA, also known as the Pen Register Act, governs devices that record or decode dialing, routing, addressing, and signaling information transmitted by electronic communications. A pen register captures outgoing communication metadata; a trap-and-trace device captures incoming metadata. Neither captures the content of the communication itself.

The Pen Register Act prohibits the installation or use of pen registers or trap-and-trace devices without a court order, with exceptions for law enforcement and foreign intelligence investigations. 

While Title III was originally concerned with telephone call metadata, plaintiffs have increasingly argued that website tracking technologies function analogously to pen registers by capturing IP addresses, routing information, and other communication metadata.

ECPA and Website Tracking: The Litigation Landscape

The ECPA’s broad language was written in the rotary-phone era to address government wiretapping. But it has become the basis for a significant and accelerating wave of private litigation against businesses operating websites. 

Plaintiffs’ firms began systematically applying state and federal wiretap statutes to common website tracking technologies around 2022, and the pace of filings has increased sharply since.

Federal ECPA claims can be filed in any federal court nationwide, unlike state wiretapping claims such as the California Invasion of Privacy Act (CIPA), which is jurisdictionally limited. It’s an all-party consent law and also generally only applies to entities located or website visitors in California.

This nationwide reach, combined with statutory damages that can aggregate rapidly across a class of website visitors, has made the ECPA an increasingly attractive vehicle for plaintiffs’ attorneys. After a 235 percent increase in ECPA lawsuit filings in 2025, filings are on pace for approximately 460 new lawsuits in 2026, a further 60 percent increase year-over-year.

The Crime-Tort Exception

Businesses deploying tracking technologies on their own websites have historically relied on the one-party consent defense. As a party to the communication, the operator’s consent to the tracking would appear to immunize the conduct. 

Plaintiffs have developed a strategy to circumvent this defense, arguing that the interception was carried out for the purpose of committing an independent tort, such as intrusion upon seclusion, unjust enrichment, or a violation of a statute like HIPAA or the CCPA, thereby triggering the crime-tort exception.

Early applications of this theory focused primarily on healthcare companies whose tracking technologies potentially exposed protected health information (PHI) to third parties without appropriate authorization. Federal courts in Illinois and New York allowed these ECPA claims to survive past motions to dismiss in February and June 2025.

A landmark ruling in August 2025 was Smith v. Rack Room Shoes in the Northern District of California. It substantially broadened the theory’s reach. The court ruled that alleged inaccuracies or misrepresentations in a company’s own privacy policy could supply the predicate tort needed to state a Wiretap Act claim under the crime-tort exception.

In plain terms, if a company’s privacy policy states that certain data is not shared with third parties, but tracking technologies on that company’s website transmit visitor data to third parties, that alleged mismatch could form the basis of a federal ECPA claim. Dozens of complaints replicating this formula were filed in the months following the ruling.

A Developing Circuit Split

Courts across the country have issued conflicting decisions on whether ECPA claims based on website tracking can advance past motions to dismiss. The law is genuinely evolving. Several courts have dismissed claims on the grounds that a website operator is a party to the communication and that advertising use alone does not constitute the kind of tortious intent required by the crime-tort exception. 

Others have permitted claims to proceed where plaintiffs plausibly alleged a privacy policy misrepresentation or where the data included sensitive categories of information.

On April 6, 2026, the First Circuit heard argument in a case directly raising the question of whether website operators face wiretapping liability under the crime-tort exception to ECPA’s party consent rule. A decision is pending and is expected to be among the most significant rulings on online wiretap liability in recent years.

For businesses, this doctrinal uncertainty means that litigation risk is real even where a successful defense on the merits is possible. Litigation costs, discovery obligations, and settlement pressure all arise well before any judicial resolution.

Relationship to CIPA and Other State Wiretap Laws

The ECPA is frequently invoked alongside state wiretapping statutes, particularly CIPA, which is an all-party consent law. This means that all parties to a communication — including the visitor — must consent to interception. 

The one-party consent defense that partially insulates ECPA defendants is not available under CIPA. CIPA carries statutory damages of USD 5,000 per violation, which can aggregate rapidly across a class.

Plaintiffs’ firms are increasingly bundling ECPA claims with CIPA and, more recently, with claims under the California Comprehensive Computer Data Access and Fraud Act (CDAFA), creating a multi-statute litigation posture in a single complaint. 

Businesses receiving a demand letter alleging CIPA violations should assess the ECPA exposure that often accompanies it.

For more on demand letters and pre-litigation exposure, see our article on CIPA demand letters.

Who Is Exposed

The practical answer is any business that operates a website using third-party tracking technologies. This includes analytics platforms, advertising pixels (from Meta, Google, TikTok, LinkedIn, and others), chat widgets, session replay tools, and software development kits (SDKs).

Nearly every commercial website uses at least some of these tools, though risk is heightened in certain circumstances.

Healthcare and health-adjacent companies

Organizations subject to HIPAA that deploy tracking technologies disclosing protected health information to third parties without appropriate authorization have faced the highest volume of litigation and the largest settlements. High-profile healthcare tracking settlements exceeded USD 135 million between 2023 and March 2026.

Companies with inaccurate privacy policies

Following Smith v. Rack Room Shoes, any organization whose privacy policy does not accurately reflect actual data-sharing practices, including data flows to third-party analytics and advertising vendors, faces additional ECPA exposure under the crime-tort exception.

Website operators that do not obtain visitor consent before deploying tracking technologies lack the foundational consent record that supports both a consent defense and an accurate privacy disclosure.

Managing ECPA Exposure

While ECPA risk cannot be entirely eliminated through operational steps alone, a privacy by design approach to website tracking meaningfully reduces exposure and strengthens the factual record available in litigation.

The following measures are commonly recommended by legal practitioners active in this space.

Conduct a Tracking Technology Audit

Before any compliance posture can be established, businesses need an accurate inventory of the tracking technologies deployed on their websites and the third-party vendors receiving data. 

Tracking technologies often proliferate without centralized oversight. Pixels added by one team member may not be visible to the legal or compliance function. A consent management platform (CMP) can support this process by categorizing and controlling the technologies permitted to load on a given site.

The gap between what a privacy policy states and what tracking technologies actually do is frequently wider than businesses expect. LOKKER, a website data governance platform, reported that in approximately 90 percent or more of websites it scanned, actual data flows differed materially from what company policies described or what internal teams anticipated. 

While that figure comes from a commercial vendor with an interest in the result, it is consistent with the operational picture described by legal practitioners active in this litigation space, and with the complaint data showing that privacy policy misrepresentation is now the most common ECPA crime-tort predicate.

Align Privacy Policies with Actual Data Flows

The Smith v. Rack Room Shoes ruling has made privacy policy accuracy a direct litigation risk factor. If a privacy policy states that certain categories of data are not shared with third parties, but deployed technologies transmit that data to advertising or analytics vendors, the mismatch is the predicate for an ECPA claim. 

Privacy policies should accurately describe the categories of data collected, the technologies used to collect it, and the third parties receiving it.

Analysis of ECPA complaints filed between September 2025 and March 2026 identified six recurring categories of privacy disclosure that plaintiffs have used to support crime-tort claims:

“No PII” claims

The privacy policy states that cookies or tracking technologies do not collect personally identifiable information, while the complaint alleges that pixels, tags, and SDKs transmit unique identifiers, hashed emails, IP addresses, device fingerprints, and browsing history linked to user profiles.

“No third-party sharing” claims

The policy states that personal information will not be shared with or disclosed to third parties, while tracking technologies transmit visitor data to third parties for those parties’ own commercial purposes.

“Bait and switch” claims

The policy uses marketing language about respecting or valuing visitor privacy, while the complaint alleges the site deploys tracking pixels that funnel visitor data into identity graphs used for cross-site profiling and real-time bidding.

“Broken banner” claims

The consent banner represents that visitors can opt out of non-essential tracking, but the consent process does not function as described — due to tracker miscategorization, misconfiguration, timing issues, or failures of the consent management tool itself.

“Scope mismatch” claims

The policy accurately describes some data collection but omits the full scope — for example, acknowledging analytics cookies while failing to disclose that those cookies enable cross-site tracking or identity resolution through data brokers.

“Security promise” claims

The policy states that visitors’ personal information is secure or protected, and the complaint alleges that unauthorized disclosures occur when visitor consent is not obtained for the deployment of tracking technologies.

Create a clear, accurate privacy policy in minutes. Keep your business aligned with legal privacy requirements and inform users how their data is handled with Usercentrics Privacy Policy Generator.

Because the ECPA is a one-party consent law, a website operator’s own consent to deployed tracking tools provides a partial defense. State laws (including CIPA) do not offer the same latitude, and the crime-tort exception has narrowed the federal defense in certain courts. 

Obtaining informed visitor consent before tracking technologies are set provides a stronger factual foundation across both federal and state law, and is consistent with the opt-out framework that governs most U.S. state privacy laws.

A CMP manages this consent process, categorizing tracking technologies, presenting consent choices at the time of a visit, recording consent decisions, and blocking non-consented technologies from loading.

One growing — and particularly consequential — category of ECPA claim targets consent banners that do not function as represented.

Where a visitor opts out of non-essential tracking and tracking continues regardless, courts have taken notice. The causes are varied: misconfiguration, hardcoded scripts that load outside the CMP’s control, or race conditions on page load that fire trackers before consent preferences are applied.

In each scenario, courts have treated the prior opt-out as a “plus factor” when assessing offensiveness in intrusion upon seclusion claims.

In other words, a consent banner that does not work as described can itself create greater liability than no banner at all. Implementing a CMP is therefore only the first step. Verifying that consent signals are correctly received, enforced, and maintained across page loads, subdomains, and tag manager configurations is equally necessary.

Monitor Litigation and Regulatory Developments

The ECPA litigation landscape is developing rapidly, with new decisions being issued weekly. Legal and compliance teams should monitor the pending First Circuit ruling on the crime-tort exception, ongoing CIPA developments in California courts (including the pending California appellate court decision on whether CIPA’s pen register provision applies to websites), and state attorney general activity. 

The California Privacy Protection Agency (CPPA), known as CalPrivacy, has already signaled active enforcement attention to tracking technologies and opt-out compliance.

Penalties

Criminal penalties under the ECPA include:

  • Imprisonment of up to five years per violation
  • Fines of up to USD 250,000 for individuals; up to USD 500,000 for organizations

Civil damages include:

  • Statutory damages of USD 100 per day of violation, with a minimum of USD 10,000, or actual damages, whichever is greater
  • Punitive damages in appropriate cases
  • Attorneys’ fees and litigation costs

Approximately 70 percent of ECPA lawsuits filed through 2025 were filed as class actions, meaning that per-visitor statutory damages can accumulate into claims carrying aggregate exposure in the tens or hundreds of millions of dollars.

How Usercentrics Helps

Usercentrics consent management solutions support businesses in building the operational foundation needed to manage ECPA and related wiretap law exposure across 2.4 million websites and applications.

Specifically, Usercentrics helps businesses:

  • Inventory and categorize tracking technologies deployed on a website
  • Present informed consent choices to visitors before non-essential tracking technologies are set
  • Record and store consent decisions to create an auditable compliance record
  • Block tracking technologies from loading until the appropriate consent signal has been received
  • Align privacy disclosures with actual data processing practices

These capabilities directly address the consent, disclosure accuracy, and audit trail requirements that courts and regulators increasingly scrutinize in wiretap litigation and enforcement actions.

Is your website exposed to ECPA and CIPA lawsuits?

Pixels, cookies, and session replay tools are at the center of a growing wave of ECPA and CIPA wiretap litigation. Get control of what’s running on your site before a demand letter arrives. Start your 14-day trial now.

This article is for informational purposes only and does not constitute legal advice. ECPA and wiretap law compliance is a complex and developing area of law. Businesses should consult qualified legal counsel for guidance specific to their situation.

William Newmark
Senior Legal Counsel, Usercentrics
Stay in the loop

Join our growing community of data privacy enthusiasts now. Subscribe to the Usercentrics newsletter and get the latest updates right in your inbox.