All-party consent is a legal rule requiring that every participant in a conversation agree before it is recorded or intercepted. It exists in the wiretap and eavesdropping statutes of roughly a dozen US states, written mostly in the late 1960s and 1970s to stop secret taping of telephone calls. The federal government and most other states take the opposite approach, allowing a recording if just one participant, often the person making it, consents. For advertisers, the distinction matters because plaintiffs' lawyers argue that a tracking pixel, a session replay script or a chatbot vendor is an uninvited third party listening to the conversation between a website and its visitor.

How the rule works

Most all-party statutes contain the same three building blocks: a communication that the law protects, an act of interception or recording, and a consent requirement covering every party. California's Invasion of Privacy Act (CIPA) is the most litigated example. Section 631 punishes anyone who reads or learns the contents of a communication in transit "without the consent of all parties to the communication." Section 632 covers the recording of a "confidential communication" without the consent of all parties. Section 637.2 gives any injured person a private right of action worth $5,000 per violation or three times actual damages, whichever is greater, with no requirement to prove harm.

Applied to a website, the theory runs as follows. A visitor's browser sends page loads, search terms, form entries and chat messages to a retailer's server. JavaScript on the page, such as the Meta Pixel, Google Analytics, a session replay tool or a chat widget, simultaneously sends some of that information to the vendor. The visitor and the website are the two parties; the vendor, plaintiffs argue, is a third who intercepted the exchange without consent, and the website aided it.

Defendants have several standard answers. The party exception holds that a participant cannot eavesdrop on its own conversation, and a vendor acting purely as the website's tool shares that status. Courts in California have split over whether a vendor is a mere "extension" of the site or a separate listener because it has the "capability" to use data for its own purposes. Defendants also contest whether URLs and clicks are "contents", whether a banner or privacy policy supplied consent, and whether visitors suffered a concrete injury.

Timing matters. In Javier v. Assurance IQ, decided in May 2022, the Ninth Circuit Court of Appeals held that Section 631 requires the prior consent of all parties and that consent given after a recording starts does not cure it. The case involved TrustedForm, a script that recorded a user's keystrokes on an insurance quote form before the privacy notice was accepted. Many consent banners still load vendor tags before any click, which is why the Ace Hardware complaint filed in March 2026 alleged that tracking began before the banner could be answered.

Which states require it

There is no official list. According to a 2008 guide by the Reporters Committee for Freedom of the Press, twelve states require the consent of all parties under most circumstances: California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania and Washington. A September 2026 analysis by the law firm Bass, Berry & Sims lists Delaware instead of Michigan. One Michigan court has read that state's statute to let a participant record, Delaware's wiretap and privacy laws conflict, and Nevada's one-party text has been read by its Supreme Court to require all-party consent for calls.

Illinois rewrote its eavesdropping act after its Supreme Court struck down the previous version in March 2014. The amended law, effective December 30, 2014, requires all-party consent for "private conversations" recorded surreptitiously, according to the law firm Littler. Pennsylvania's Wiretapping and Electronic Surveillance Control Act (WESCA) dates from 1978. Washington's Privacy Act (chapter 9.73 of the Revised Code of Washington) was enacted in 1967, the same year as CIPA, and a Washington appeals court called it "one of the most restrictive electronic surveillance laws in the nation."

Origin and evolution

The split dates to 1968. Title III of the Omnibus Crime Control and Safe Streets Act made it lawful for a private person to intercept a communication "where one of the parties to the communication has given prior consent," unless the purpose is to commit a crime or tort. That one-party rule, codified at 18 USC 2511(2)(d), carried into the Electronic Communications Privacy Act (ECPA) of 1986, which extended wiretap protection to electronic communications. States remained free to be stricter.

For four decades the rule mainly governed recorded customer-service calls. In April 2020 the Ninth Circuit ruled in In re Facebook Internet Tracking Litigation that Facebook was not automatically a party to communications it duplicated from users' browsers through its plug-ins. In August 2022 the Third Circuit held in Popa v. Harriet Carter Gifts that a 2012 amendment had narrowed WESCA's direct-party exception and that interception occurs at the user's browser in Pennsylvania.

Section 638.51, added to CIPA in 2015 to regulate pen registers, opened a second front in 2023 and 2024. Plaintiffs argued that any tag recording IP addresses or device data was an unlawful tracing device. Section 638.51 filings climbed from roughly 600 to nearly 4,000 after February 2025, most of them aimed at ordinary analytics.

Why it matters for marketers

Exposure comes from statutory damages multiplied across visitors, as Frasco v. Flo Health shows. In August 2025 a federal jury in San Francisco found that Meta had violated Section 632 by receiving health information from the Flo period-tracking app through a software development kit (SDK), without users' consent. Flo, Google and Flurry had settled for a combined $59.5 million, according to class counsel Labaton Keller Sucharow. In September 2026 the plaintiffs asked Judge James Donato to enter a partial judgment of about $1.1 billion for roughly 222,000 California class members, according to MLex. That figure is essentially 222,000 multiplied by $5,000. Meta opposed the request, citing "opaque calculating methods."

The same theory now reaches AI products. A May 2026 class action against OpenAI alleges that the Meta Pixel and Google Analytics received ChatGPT conversation titles under Sections 631 and 632. Perplexity faced a similar suit in March 2026, later voluntarily dismissed. The complaint against Granola, filed on July 30, 2026, returns to the statute's original purpose, alleging that an AI notetaker recorded meetings without the knowledge of participants.

In an amicus brief filed on April 10, 2026, the Interactive Advertising Bureau (IAB) told the Washington Supreme Court that reading the state's Privacy Act to cover routine web requests would threaten ad measurement across the ad-supported web.

Limitations and disputes

Courts are deeply divided, and outcomes often depend on the forum. The Massachusetts Supreme Judicial Court held in Vita v. New England Baptist Hospital on October 24, 2024 that browsing a public website is not a "communication" under the state's wiretap act, which it read as protecting person-to-person conversations. Justice Dalila Wendlandt dissented and urged the Legislature "to correct today's error." Federal standing has become another barrier. The Third Circuit dismissed a session replay suit against GameStop on August 7, 2025, and the Ninth Circuit followed in Popa v. Microsoft on August 26, 2025, noting that the plaintiff identified "no embarrassing, invasive, or otherwise private information" collected by Microsoft Clarity.

Critics describe much of the litigation as a settlement business; a federal court in Los Angeles declared one serial plaintiff a vexatious litigant on July 20, 2026, according to Bass, Berry & Sims. Others cite the Flo verdict as proof that the statutes catch real harms. The IAB argues in Washington that the statute should not reach ordinary web traffic, while a paper it distributed in October 2026 warns that California wiretap exposure persists. Applying 1960s telephone concepts such as "contents" and "in transit" to packets remains the core interpretive problem.

Not the same as

One-party consent is the federal standard and the rule in most states: a recording is lawful if any single participant agrees. All-party consent is stricter.

GDPR consent, under the General Data Protection Regulation, is one of six legal bases for processing personal data under European law, with conditions set in Article 7. It concerns data processing generally rather than interception, and regulators, not private damages suits, mainly enforce it.

Opt-in consent describes a consent mechanism, an affirmative action before collection, used in several US state privacy laws for sensitive data. An all-party statute does not prescribe a banner design; it asks whether every party consented before the interception.

Recent developments

Governor Gavin Newsom signed Senate Bill 690 (SB 690) on September 30, 2026. From January 1, 2027, private plaintiffs can no longer sue under Section 638.51 over conduct on websites and apps, and the change reaches pending claims filed since January 1, 2025. The original February 2025 bill would have exempted commercial purposes from Sections 631 and 632 too, but that exemption was removed in July 2026. All-party consent claims therefore survive intact, a point an IAB-distributed paper made the day after signing, arguing that websites still face wiretap exposure. Newsom's signing message said CIPA "contains other decades-old statutes that are also susceptible to abuse," according to the law firm WilmerHale.

Outside California, the Washington Supreme Court accepted review of Baker v. Seattle Children's Hospital on January 8, 2026, and as of October 2026 had not ruled. France's data protection authority opened a consultation on February 25, 2026 proposing prior consent for all session replay. Some vendors moved earlier: Microsoft Clarity began requiring calls to its Consent API before enabling recordings in December 2024.

Timeline

  • 1967 - California enacts the Invasion of Privacy Act; Washington enacts its Privacy Act, chapter 9.73 RCW.
  • 1968 - Title III of the Omnibus Crime Control and Safe Streets Act sets the federal one-party consent rule.
  • 1978 - Pennsylvania enacts the Wiretapping and Electronic Surveillance Control Act.
  • 1986 - The Electronic Communications Privacy Act extends federal wiretap protection to electronic communications.
  • 2012 - Pennsylvania amends WESCA's definition of "intercept", later read to narrow the direct-party exception.
  • March 2014 - The Illinois Supreme Court strikes down the state's eavesdropping statute.
  • December 30, 2014 - Illinois' amended all-party eavesdropping law takes effect.
  • 2015 - California adds pen register provisions, Sections 638.50 to 638.53, to CIPA.
  • April 9, 2020 - The Ninth Circuit decides In re Facebook Internet Tracking Litigation.
  • May 2022 - The Ninth Circuit holds in Javier v. Assurance IQ that Section 631 requires prior consent.
  • August 2022 - The Third Circuit decides Popa v. Harriet Carter Gifts under WESCA.
  • October 2023 - Parents file Baker v. Seattle Children's Hospital over the Meta Pixel.
  • October 24, 2024 - The Massachusetts Supreme Judicial Court decides Vita v. New England Baptist Hospital.
  • February 21, 2025 - Senator Anna Caballero introduces SB 690.
  • June 3, 2025 - The California Senate passes SB 690 by 35 votes to 0.
  • August 1, 2025 - A federal jury finds Meta violated CIPA in Frasco v. Flo Health, according to class counsel.
  • August 7, 2025 - The Third Circuit dismisses Cook v. GameStop for lack of standing.
  • August 26, 2025 - The Ninth Circuit dismisses Popa v. Microsoft for lack of standing.
  • January 8, 2026 - The Washington Supreme Court accepts review in Baker.
  • February 25, 2026 - France's CNIL opens a consultation on session replay.
  • April 10, 2026 - The IAB files an amicus brief in Baker.
  • May 13, 2026 - A class action is filed against OpenAI under CIPA Sections 631 and 632.
  • July 1, 2026 - An Assembly committee strips SB 690's commercial purpose exemption.
  • July 30, 2026 - Granola is sued over AI meeting recording.
  • August 28, 2026 - The California Assembly passes SB 690 by 66 votes to 0; the Senate concurs 40 to 0.
  • September 29, 2026 - Meta opposes a proposed $1.1 billion partial judgment in the Flo case.
  • September 30, 2026 - Governor Newsom signs SB 690.
  • January 1, 2027 - SB 690's limit on private pen register suits becomes operative.

Summary

Who. State legislatures wrote the rule, and roughly a dozen states, including California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania and Washington, apply it. Plaintiffs' firms invoke it against website operators and vendors such as Meta, Google, Microsoft and OpenAI, while courts, the California Attorney General and trade groups such as the IAB shape its reach.

What. A requirement that every participant in a conversation consent before it is recorded or intercepted, backed in California by statutory damages of $5,000 per violation. It contrasts with the federal one-party rule.

When. The statutes date mostly from 1967 to 1978. Their use against web tracking accelerated after 2020 appellate rulings, and SB 690, signed on September 30, 2026, removes only the pen register strand from January 1, 2027.

Where. In state and federal courts in all-party states, chiefly California, Pennsylvania, Washington, Florida and Massachusetts, wherever a visitor's browser sends data to a third-party script.

Why. It was designed to stop secret telephone taping. It matters to advertisers because pixels, session replay, chat widgets and AI notetakers can be cast as a third party listening without permission, and the liability scales with every visitor.