Consumer Protection
Florida Security of Communications Act Matters
Website Wiretapping Claims Under Fla. Stat. § 934.01 et seq. — Tracking Pixels, Session Replay & Chat Widgets in Florida’s Courts
The digital age has prompted a flood of wiretapping litigation, and the wave has reached Florida. The Florida Security of Communications Act (FSCA), enacted in 1969 to guard against unauthorized interception of wire and oral communications, is now being applied to the software that runs an ordinary e-commerce website — tracking pixels that report a shopper’s activity to advertising platforms, session-replay tools that record clicks and keystrokes, and chat widgets whose transcripts sit on a vendor’s server. Between March 2022 and March 2026, 586 website-wiretapping suits were filed in Florida, second in the nation behind only California, and the pace accelerated sharply after a March 2025 federal ruling let a tracking-pixel class action against a hospital system proceed. The reason is the statute’s remedy: liquidated damages of $1,000 per violation or $100 per day, whichever is greater, without proof of actual harm, plus punitive damages and attorney’s fees — multiplied across a class of every Florida visitor to the site.
Our Miami intellectual property attorneys defend e-commerce vendors, healthcare providers, financial-services firms, and marketing platforms against FSCA demand letters, class actions, and the newer wave of small-claims “tester” suits, and audit the tracking, consent, and vendor arrangements that determine whether a site is exposed in the first place.
What the FSCA Prohibits — and What It Pays
An all-party-consent wiretap statute with liquidated damages, punitive damages, and one-way fee shifting
Section 934.03(1), Florida Statutes, makes it unlawful to intentionally intercept, endeavor to intercept, or procure another person to intercept any wire, oral, or electronic communication; to intentionally disclose the contents of a communication knowing it was obtained through an unlawful interception; or to intentionally use those contents. Florida is an all-party consent state: the private-party exception in § 934.03(2)(d) applies only where all parties to the communication have given prior consent, unlike the federal Wiretap Act, which requires the consent of just one. The statute was modeled on the federal act and closely tracks California’s Invasion of Privacy Act (CIPA), whose $5,000-per-violation remedy launched the national wave of website-tracking suits; Florida’s remedy design is what has made it the second most active forum.
| Provision | What It Says | Why It Matters |
|---|---|---|
| Prohibition — § 934.03(1) | No person may intentionally intercept, disclose, or use the contents of a wire, oral, or electronic communication without authorization. | Interception, disclosure, and use are each separately actionable; a website that both captures and forwards data to a vendor faces multiple theories. |
| All-party consent — § 934.03(2)(d) | Interception is lawful where all parties to the communication have given prior consent. | The website operator’s own knowledge is not enough; the visitor must consent before the tool fires — the reason cookie banners and privacy-policy language are the battleground. |
| Definitions — § 934.02 | “Electronic communication” means any transfer of signs, signals, writing, images, sounds, data, or intelligence by wire, radio, electromagnetic, or similar system; “contents” means any information concerning the substance, purport, or meaning of the communication; “intercept” means acquisition of contents through any electronic, mechanical, or other device. | Whether a tracking tool captures “contents” or merely routing and movement data is the element on which most Florida decisions turn. |
| Civil remedies — § 934.10(1) | Preliminary and other equitable or declaratory relief; actual damages but not less than liquidated damages computed at $100 per day of violation or $1,000, whichever is higher; punitive damages; reasonable attorney’s fees and litigation costs. | No proof of actual harm is required; the $1,000 floor applies per plaintiff per violation and is the number the plaintiffs’ bar multiplies by the size of a Florida class. |
| Good-faith defense — § 934.10(2) | Complete defense for good-faith reliance on a court order, subpoena, legislative authorization, or statutory authorization. | Rarely available to a commercial website; the defenses that matter are the elements themselves. |
| Limitations — § 934.10(4) | Suit must be brought within two years after the claimant first has a reasonable opportunity to discover the violation. | Short and discovery-based; a tracker that has run for years may still be actionable as to visits within the window. |
| Attorney’s fees | Available to a prevailing plaintiff only; no fee award to a prevailing defendant. | The asymmetry that drives demand letters — a defendant that wins recovers nothing, and § 768.79 proposals for settlement are the principal counterweight. |
| Stored communications — §§ 934.21–.28 | Separate prohibition on unauthorized access to stored electronic communications, with its own civil remedy in § 934.27. | Access to a message already delivered and at rest is not an “interception”; the two regimes are pled together but proved differently. |
Together those features produce the litigation economics that define this practice area: a tester plaintiff need not prove a dollar of loss; the statutory floor is $1,000; the fee shift runs one way; and a class of Florida website visitors can turn a single pixel configuration into a theoretical exposure in the tens of millions of dollars. Realistic mid-market class settlements have run from the low to the mid seven figures, and pre-suit demand letters typically open in the $15,000 to $50,000 range.
The Legal Landscape: How Florida Became the Second-Busiest Wiretap Forum
From Jacome and Goldstein to Orlando Health, Cobbs, and the small-claims tester wave
For the first three years of the national wave, Florida courts were inhospitable to website-wiretap claims. In Jacome v. Spirit Airlines, Inc., No. 2021-000947-CA-01 (Fla. 11th Cir. Ct. June 17, 2021), a Miami-Dade circuit judge dismissed an FSCA claim over session-replay software, holding that mouse clicks, keystrokes, pages viewed, and similar interactions merely tracked the movement of a communication rather than intercepting its substance, and therefore were not “contents.” Federal courts in the Southern District reached the same conclusion in Goldstein v. Costco Wholesale Corp., 559 F. Supp. 3d 1318 (S.D. Fla. 2021), and Goldstein v. Luxottica of America, Inc. (S.D. Fla. 2021), and the claims largely stopped being filed.
That changed on March 6, 2025. In W.W. v. Orlando Health, Inc., No. 6:24-cv-1068 (M.D. Fla.), the court declined to dismiss a putative class action alleging that a hospital system’s website and patient portal embedded Meta and Google tracking pixels that transmitted patients’ appointment, provider, and condition searches to those platforms. The court distinguished Jacome and Goldstein: session replay records how a user moves through a site, but a pixel that forwards the substance of a patient’s inquiry — a search for a specialist or a condition — communicates a substantive message, and whether the technology actually did so was a “highly technical question” not resolvable on the pleadings. The plaintiff voluntarily dismissed the case in February 2026, but the ruling had already reopened the forum.
On January 14, 2026, the Southern District went further in Cobbs v. PetMed Express, Inc., 824 F. Supp. 3d 1257 (S.D. Fla. 2026), a nationwide putative class action brought by California consumers under the federal Wiretap Act and CIPA against a Florida-based online pharmacy. The court held that URLs, search terms, form entries, and button clicks transmitted to third-party tools in real time can constitute “contents”; that interception allegations satisfied standing without any financial loss; and that a privacy policy alone could not establish consent at the pleading stage. Two months earlier, Magenheim v. Nike, Inc., No. 9:25-cv-81573 (S.D. Fla.), had been filed on behalf of “hundreds of thousands” of Florida visitors alleging that Nike’s site installed tracking software, ignored Global Privacy Control opt-out signals, and kept harvesting data after users opted out; the court set a November 2026 trial, and Nike settled and the case was dismissed with prejudice on March 12, 2026, before its motion to dismiss was decided.
Beneath the class actions runs a second, higher-volume current. Since 2025, tester plaintiffs represented by a small number of firms have filed hundreds of nearly identical suits in Florida county and small-claims courts alleging that a website’s live-chat widget recorded their conversation without consent, and have sent thousands of demand letters — including a newer “trap and trace” theory aimed at open-tracking technology in marketing email. Because the statutory floor is $1,000 and fees are recoverable, each case is priced to settle for less than the cost of a defense. Four plaintiff firms have been identified as driving most of the Florida activity.
| Decision | Court / Date | Technology | Outcome on the FSCA (or CIPA) Claim |
|---|---|---|---|
| Jacome v. Spirit Airlines, Inc. | Fla. 11th Cir. Ct. (Miami-Dade), June 17, 2021 | Session replay | Dismissed — clicks, keystrokes, and pages viewed are movement data, not “contents” |
| Goldstein v. Costco Wholesale Corp., 559 F. Supp. 3d 1318 | S.D. Fla. 2021 | Session replay | Dismissed — “information inputted” and “pages viewed” insufficient to allege interception of contents |
| Goldstein v. Luxottica of America, Inc. | S.D. Fla. 2021 | Session replay | Dismissed on the same reasoning |
| W.W. v. Orlando Health, Inc., No. 6:24-cv-1068 | M.D. Fla., Mar. 6, 2025 | Meta and Google pixels on a hospital website and patient portal | Motion to dismiss denied — pixel forwarding the substance of patient searches plausibly intercepts contents; voluntarily dismissed Feb. 2026 |
| Magenheim v. Nike, Inc., No. 9:25-cv-81573 | S.D. Fla., filed Dec. 16, 2025 | Tracking software; Global Privacy Control signals ignored | Trial set for Nov. 2, 2026; settled and dismissed with prejudice Mar. 12, 2026 |
| Cobbs v. PetMed Express, Inc., 824 F. Supp. 3d 1257 | S.D. Fla., Jan. 14, 2026 | Third-party tracking tools capturing search terms, URLs, form entries (ECPA and CIPA claims) | Motion to dismiss denied on core wiretap claims — contents plausibly alleged; no financial loss required; privacy policy not consent as a matter of law |
The Technologies at Issue: Session Replay, Chat Widgets & Tracking Pixels
What each tool captures, where the data goes, and how Florida courts have treated it
Every e-commerce site runs some combination of three technologies, each with a different risk profile under the “contents” element. A 2017 Princeton study found session-recording scripts from seven major providers on roughly one in ten of the million most-visited websites; tracking pixels appear on approximately thirty percent of the 100,000 most popular sites, with Meta’s pixel alone on roughly nine percent of all websites; and chat widgets, whether staffed by a person, an AI agent, or both, are now standard on retail, healthcare, and financial sites.
| Technology | What It Is and What It Captures | Where the Data Goes | FSCA Risk Profile |
|---|---|---|---|
| Session replay | Analytics software that records a visitor’s interaction with the site: mouse movements and hovering, clicks on buttons, links, and filters, keystrokes in search bars and checkout fields, scroll depth, the sequence of pages and products viewed, cart additions and removals, and data entered into shipping, billing, and account forms. | The vendor’s servers (FullStory, Hotjar, Clicktale, SmartLook, and similar), where sessions are stored and replayed for analytics. | Lowest under current Florida law — Jacome and Goldstein treat movement and navigation data as non-content — unless form fields capture names, addresses, health, or payment information, which shifts the analysis toward contents. |
| Chat widgets | The bottom-corner interface through which a visitor messages customer service — a live agent, an AI chatbot, or a hybrid — asking about orders, sizing, returns, or products. Messages are routed through and typically stored on a third-party platform (LiveChat, Drift, Intercom, Zendesk, Salesforce), which often retains full transcripts for quality assurance, dispute resolution, or AI training. | The chat vendor’s servers; transcripts may include personal details, order and account information, and anything else the visitor typed. | Highest for small-claims and tester suits — the typed conversation is unmistakably “contents,” so the case turns on consent, on whether the vendor is an independent interceptor or the operator’s own recording tool, and on whether any human or system beyond the operator received the transcript. |
| Tracking pixels | A 1×1 transparent image or JavaScript snippet that fires an HTTP request to an advertising platform (Meta, Google, TikTok, LinkedIn) the moment a page loads, transmitting device metadata, session identifiers, and configured “events”: page and content views, add-to-cart events with product ID, category, price, and quantity, checkout starts and purchases, form submissions and sign-ups, click IDs such as fbclid and gclid that tie a purchase to a specific ad, and button-level interactions. | The ad platform’s servers in real time, matched to the visitor’s platform account where possible. | Highest for class actions after Orlando Health and Cobbs — where the fired event reveals the substance of what the visitor asked for (a condition, a provider, a prescription, a search term), courts now treat the transmission as an interception of contents. |
Elements of an FSCA Claim — and the Defenses That Defeat It
Four elements, each with a defense built into it
| Element | What the Plaintiff Must Show | Where the Defense Lives |
|---|---|---|
| 1. An electronic communication | A transfer of data by wire or electronic system — website requests, chat messages, form submissions, and email all qualify. | Rarely contested; the fight is over what part of the transfer was acquired. |
| 2. Interception of the contents | Contemporaneous acquisition, through a device, of information concerning the substance, purport, or meaning of the communication — not merely the fact, timing, or route of it. | The decisive element. Movement, navigation, and routing data (Jacome, Goldstein) are not contents; searches, messages, and form entries that convey what the visitor said or sought (Orlando Health, Cobbs) are. Access to stored data after transmission is not interception at all. A vendor that merely records on the operator’s behalf, with no independent use of the data, is arguably the operator’s own tape recorder rather than a third-party interceptor. |
| 3. Intent | The interception was intentional — deliberately configured, not accidental or negligent. | Inadvertent capture, a misconfigured event, or a vendor default the operator neither chose nor knew of can defeat the element, though “willful” ignorance of what a tool collects is a weak position. |
| 4. Absence of all-party consent | No party consented, or the visitor did not consent before the tool fired. | Consent obtained through a functioning opt-in banner before trackers load, an acknowledged chat disclosure, or explicit terms accepted before the communication is a complete defense; a privacy policy linked in the footer is not (Cobbs). |
Defenses beyond the elements
- Standing and manufactured injury. A tester who visits a site to generate a claim may lack a concrete injury under TransUnion LLC v. Ramirez, 594 U.S. 413 (2021), and a plaintiff’s litigation history is discoverable — though Cobbs shows Florida federal courts will not require financial loss.
- Arbitration and class waivers. Terms of use accepted at account creation or checkout can compel individual arbitration and eliminate the class exposure that gives these cases their leverage — if the terms were presented and assented to in a manner Florida courts enforce.
- The two-year limitations period. Section 934.10(4) runs from the claimant’s first reasonable opportunity to discover the violation; a disclosed tracker in a privacy policy or banner can start the clock on the first visit.
- Proposals for settlement. Because the FSCA shifts fees only to a prevailing plaintiff, a timely proposal under § 768.79 is the defendant’s principal means of creating fee exposure on the other side and pricing a nuisance claim realistically.
- Federal removal and preemption arguments. Where a plaintiff pleads a nationwide class or federal wiretap claims, removal to federal court under CAFA and the Eleventh Circuit’s pleading standards can change the trajectory of the case; the federal one-party-consent rule does not preempt the FSCA, but it narrows the companion federal count.
Understanding Your Obligations: A Website Compliance Program
Consent before capture, and a paper trail that proves it
Amid the uncertainty and the volume of claims, e-commerce vendors and every business whose website collects visitor interactions should treat FSCA compliance as an ongoing program rather than a one-time fix. Websites change with every marketing campaign and platform update, and a tracker added by a vendor or an agency is the operator’s liability. The controls that matter:
- Inventory your tracking stack. Conduct a thorough review of every analytics, advertising, replay, and chat tool on the site, what data each captures, which events are configured to fire, and whether each is essential to business operations. Keep a current list of every third-party server interacting with the site and how each stores visitor data.
- Consent before capture. Deploy an opt-in consent mechanism that blocks trackers, replay scripts, and chat recording until the visitor affirmatively agrees; honor Global Privacy Control and other opt-out signals; and maintain consent logs — timestamp, mechanism, and version of the disclosure — as the shield against a demand letter. Passive disclosures and footer privacy policies do not establish consent.
- Disclose the three W’s. Revise privacy disclosures to name the data-capturing technologies specifically, identify the third parties receiving data, and explain what is collected, who collects it, and where it is sent. For chat, present a recording and vendor disclosure before the first message.
- Minimize content capture. Configure pixels to exclude search terms, form entries, and health, financial, and account fields; mask keystrokes in session replay; and never deploy tracking on patient portals, account pages, or checkout without a specific legal review. The less “content” a tool acquires, the weaker the second element.
- Contract with vendors. Require vendors to disclose their data practices, permit audits, restrict their own use of the data (which also supports the “operator’s own recording” defense), and indemnify the business against third-party claims arising from their tools; review those terms whenever a vendor changes its defaults.
- Prepare the response playbook. Preserve the site configuration on receipt of a demand; retrieve consent logs; evaluate the plaintiff’s filing history; and decide within days whether the answer is a motion, a proposal for settlement, or a negotiated resolution. The same first-days discipline that governs an ADA website suit governs an FSCA claim.
The FSCA is one of several overlapping Florida privacy regimes; how it fits alongside the common-law privacy torts, FDUTPA, and the Digital Bill of Rights is compared in our Right of Privacy Matters summary, and unauthorized commercial use of a visitor’s name or image is addressed in our Right of Publicity Matters summary. Website operators facing the parallel wave of accessibility suits should see our Websites & ADA Compliance summary.
Full Capability