Plaintiffs have spent three years pointing a 1967 wiretapping statute at ordinary website analytics, and the arithmetic is why: $5,000 per violation, counted per visitor, with no proof of harm required. If you are searching for real estate website tracking lawsuits because you just read that your brokerage site could be next, here is the honest state of the record.
The defendants are portals, not brokerages. Realtor.com's operator is currently defending one of these claims and lost its motion to dismiss last October. Redfin was sued and got out. Zillow drew three suits in 2022. We looked for a case against a brokerage, an agent, an MLS, an IDX vendor or a real estate CRM, and did not find one.
And the California bill that every summary describes as ending this litigation is sitting on the Governor's desk as we publish. It does not end it. It kills one of the two theories, and not the one being used against Realtor.com.
Real estate website tracking lawsuits: who has actually been sued
Three real estate defendants, all of them portals.
Apaydin v. Move, Inc. (Realtor.com)
Mata v. Redfin
Zillow session replay suits
| Case | Court | Technology | Status |
|---|---|---|---|
| Apaydin v. Move, Inc. (Realtor.com) | C.D. Cal., No. 2:25-cv-07905 | Meta Pixel | Motion to dismiss denied 29 Oct 2025, live |
| Mata v. Redfin | S.D. Cal., No. 3:24-cv-01094 | video view tracking | Voluntarily dismissed with prejudice, 5 Feb 2025 |
| Zillow session replay suits | WA, IL, PA | Microsoft Clarity | Filed Sept 2022, outcomes not established |
The live one is Apaydin. Judge Percy Anderson held that the plaintiff had adequately pleaded that Move intercepted and disclosed the "contents" of her communications under the California Invasion of Privacy Act, and let the case proceed.
Note what all three have in common. They are national platforms with enormous visitor volumes, which is what makes a per-visitor damages theory worth a plaintiff firm's time. A brokerage with four hundred monthly visitors is a different arithmetic problem even if the legal theory is identical.
That is a fact about the current docket, not a rule of law. Nothing in these statutes exempts a small business, and the defense bar's client alerts describe retail, healthcare, hospitality and financial services defendants of every size. Treat the portal pattern as a description of where plaintiff firms have aimed so far.
The two theories, and why the difference decides everything
Almost every article on this topic treats CIPA as one thing. It is two, they work completely differently, and the difference is about to matter more than it ever has.
The wiretap theory, Penal Code 631. It reaches anyone who "reads, or attempts to read, or to learn the contents or meaning of any message, report, or communication while the same is in transit." The operative word is contents. A plaintiff has to show that something meaningful about what you said or viewed was disclosed, and that the site operator aided the third party in reading it.
The pen register theory, Penal Code 638.51. It bars installing or using a pen register or trap and trace device without a court order. And Penal Code 638.50 defines a pen register as a process that records "dialing, routing, addressing, or signaling information ... but not the contents of a communication."
Read that exclusion again, because plaintiffs read it as a gift. The pen register theory does not require contents. It requires only that something on your page captured an IP address or routing data, which is what essentially every analytics script does by existing. No contents, no harm, no difficulty. That is why the volume went where it went.
Damages are the same either way. Penal Code 637.2 gives the greater of actual damages or "Five thousand dollars ($5,000) per violation," plus injunctive relief with no actual damages required at all.
The law everyone says ends this only ends half of it
California SB 690 passed both houses on 28 August 2026, cleared the Senate concurrence vote 39 to 0, was enrolled on 31 August, and was "Enrolled and presented to the Governor at 2 p.m." on 4 September. As of publication its status on the Legislature's own page reads "Active Bill - Enrolled." No signature, no veto. The Governor's deadline is 30 September 2026.
Now read the bill's own title: "An act to amend Section 637.2 of the Penal Code, relating to crimes."
Section 637.2 is the civil remedy. Not the prohibition. SB 690 does not legalise pen registers or repeal anything. It changes who is allowed to sue over the pen register theory for conduct on a website or app, handing that exclusively to the Attorney General, and it applies retroactively to claims commenced within two years before its operative date.
So the bill disarms the easy theory, the one that needs no contents and drove the volume. Section 631 is untouched. Private plaintiffs keep the wiretap claim in full.
Which is the claim that beat a motion to dismiss against Realtor.com.
An earlier version of SB 690 would have created a broad "commercial business purpose" exception that really would have ended most of this. That version was abandoned in July 2026. If you read a summary saying SB 690 ends CIPA website litigation, you are reading about a bill that no longer exists.
What the Ninth Circuit actually decided in 2025
Four decisions, and they do not point the same way.
- Gutierrez v. Converse, No. 24-4797, decided 9 July 2025. Summary judgment for Converse affirmed. Web chat is not a "telephone communication" within the reach of Section 631.
- Mikulsky v. Bloomingdale's, No. 24-3837, decided 20 June 2025, unpublished. Dismissal reversed. The complaint plausibly alleged Bloomingdale's aided session replay providers in reading the contents of communications in transit.
- Thomas v. Papa John's, No. 24-3834, decided 18 June 2025, unpublished. Dismissal affirmed.
- Popa v. Microsoft, No. 24-14, decided 26 August 2025. Dismissed for lack of Article III standing under TransUnion v. Ramirez, because the alleged harm did not resemble a common law privacy tort. The Third Circuit reached a similar standing result on 7 August 2025.
Two things follow. The merits picture inside one circuit is inconsistent, and three of the four are unpublished, so none of them settles much. Meanwhile the standing decisions are the more useful development for a defendant, because a standing dismissal ends a case regardless of what the statute means.
Does a cookie banner fix it
Only if it actually stops the scripts before they run.
The distinction courts draw is between consent obtained before the tracker fires and a banner that appears while tracking is already underway. In one case the pen register claim survived specifically because the tracking started before the plaintiff had any chance to reject it. Another court rejected a consent defense built on a footer link to a privacy policy, holding that a disclosure with no affirmative assent mechanism fails the conspicuousness requirement.
The practical version: a banner that loads after your pixel has already reported the visit is documentation of the tracking, not consent to it. If your consent tool does not actually gate script execution, it is decorative.
This is the same shape as the accessibility problem we wrote about in ADA compliance for real estate websites. The widget that promises to solve it often does not, and the promise is what gets sold.
Florida is the second front
If you operate outside California, the exposure does not disappear.
Fla. Stat. 934.03 makes it unlawful to intentionally intercept, or to disclose the contents of, a wire, oral or electronic communication, and Florida is an all-party consent state. In W.W. v. Orlando Health a federal court denied dismissal of a claim under it on 6 March 2025, where a hospital system's pixel allegedly transmitted content revealing a substantive message rather than mere keystrokes.
Several other states have wiretap statutes plaintiffs have tested. We did not verify Illinois and make no claim about it, although two of the 2022 Zillow suits were reportedly brought there.
What is actually on your brokerage site
Map it honestly. Most brokerage sites carry five things, and they are not equally exposed.
- Meta Pixel. The most exposed item on the list, and the technology in the live Realtor.com case. It exists to report what a visitor looked at, which is the contents question in one sentence.
- Session replay. The technology in most of the appellate decisions above, including both Bloomingdale's and Papa John's.
- Chat widget. Litigated repeatedly on the aiding and abetting variant, and the subject of Converse.
- Google Analytics. Named generically across the advisory literature. We did not find a decision resting on analytics alone.
- IDX feed and lead forms. IDX and standard lead capture did not appear as the subject of any claim we found. Form inputs show up only as data incidentally swept up by session replay.
The ranking is roughly the order above, and it tracks one question: does the tool report what the visitor did, or only that they arrived?
Nobody neutral has counted these cases
Here is the part that should change how you read everything else written about this.
You will see specific figures quoted with confidence: roughly 3,968 California cases, 811 in Florida, 108 in Illinois, retail at 1,817 and technology at 542. We tried to source them. Every one traces to a tracker operated by a company selling consent banners or compliance software. No court system, no legal analytics publication, no law review and no bar journal reproduces them.
The nearest thing to an independent number is Senator Caballero's own floor testimony, reported secondhand, that pen register cases had grown to more than 4,000. A bill sponsor arguing for their bill is a real source, and it is not a neutral count.
We are not saying the numbers are wrong. We are saying nobody has checked them, and the people publishing them sell the remedy. That is the same pattern we found when we counted the claims made by website vendors selling to brokerages: the category does not publish false numbers so much as unfalsifiable ones.
What to do
Nothing on this list requires a lawyer or a purchase.
Find out what your site actually loads. Open your own homepage with the browser's network tab open and read the list of third-party requests. Most brokers have never done this and are surprised by the count. You cannot assess anything until you know what is firing.
Decide whether you need the pixel. If you are not running paid retargeting, the most exposed item on your site is doing nothing for you. Removing an unused pixel is free, instant, and removes the theory entirely.
If you keep it, gate it properly. Consent has to block the script, not describe it. Verify by loading the page and confirming nothing fires before you click.
Watch the Governor's desk. If SB 690 is signed by 30 September 2026, the pen register claims go to the Attorney General only, retroactively. The wiretap claims do not.
If you want a second pair of eyes on what your site loads, that is a fifteen minute job and we are happy to just tell you. We build brokerage websites, which is a commercial interest of exactly the kind this post has been flagging, so everything above is sourced to a document you can open.
Checked 2026-09-08 and unusually perishable. SB 690's status on the Legislature's own page reads "Active Bill - Enrolled" with no signature or veto, and the Governor's deadline is 30 September 2026, so this post's central section has a three week shelf life. Apaydin v. Move is past its motion to dismiss and moving. Three of the four Ninth Circuit decisions above are unpublished.