From Judge Vince Chhabria's opinion Friday in Doe v. Eating Recovery Center LLC (N.D. Cal.):
The California Invasion of Privacy Act (CIPA) was enacted in 1967 to criminalize wiretapping and eavesdropping on confidential communications. Although it is a criminal statute, CIPA also authorizes victims to bring civil actions against those who violate the statute, allowing recovery of civil penalties of $5,000 per violation or three times the amount of actual damages—whichever is greater. See Cal. Penal Code § 637.2(a).
The language of CIPA is a total mess. It was a mess from the get-go, but the mess gets bigger and bigger as the world continues to change and as courts are called upon to apply CIPA's already-obtuse language to new technologies. Indeed, we have reached the point where it's often borderline impossible to determine whether a defendant's online conduct fits within the language of the statute.
This is such a case. The plaintiff seeks to impose CIPA liability on a website operator for using a third party to perform data analytics and targeted advertising. In particular, liability here turns on whether the third party "read" or "attempt[ed] to read" or attempted "to learn" the contents of an internet communication between the plaintiff and the website operator while that communication was "in transit." If so, the website operator could be liable to the plaintiff under CIPA for enabling the third party to engage in that conduct.