Florida Law Firm Wiretapping Liability: $100 a Day Plus Their Fees
Florida's 1969 wiretap law demands all-party consent before a pixel reads your intake form. Lose, and § 934.10 hands the plaintiff your fee invoice too.
Your Florida law firm’s wiretapping liability runs at $100 a day, with a $1,000 floor and the other side’s legal bill on top. The statute that gets you there is not the one your vendor pitched. Nobody is coming for your Boca Raton practice under GDPR. CCPA almost certainly does not reach you either. What reaches you is Fla. Stat. § 934.03, a 1969 wiretapping law that requires consent from all parties before a communication is intercepted, and § 934.10, which hands a private plaintiff your opponent’s attorney’s fees.
If a Meta Pixel is live on your intake form, content is leaving that form without consent. A privacy policy is disclosure. A banner is consent. You need the second one.
I am not a lawyer and none of this is legal advice. Every factual claim below links to what it rests on, statute text or the docket order itself. Check them. This is the same method behind why your accessibility widget is not a defense either. Take the law from counsel. Take the script inventory from me.
What Florida law firm wiretapping liability actually costs
Before anything else, the numbers. Most articles on this subject blur three separate figures into one scary number, and the $5,000 you have seen quoted is the least likely of them to land on you.
The $5,000 is real and it appears twice. First, in Fla. Stat. § 775.083(1)(c), which sets the maximum fine for a third-degree felony, the grade § 934.03(4)(a) assigns to an illegal interception. That is criminal. Essentially nobody prosecutes a business for website tags, and I am not going to pretend otherwise.
Second, and this is the one with teeth, in Cal. Penal Code § 637.2(a), which lets a plaintiff recover “the greater of… Five thousand dollars ($5,000) per violation” or treble actual damages. Subsection (c) then removes the hurdle that kills most privacy claims: an actual-damages showing is “not a necessary prerequisite.”
Florida’s own civil number is structured differently, and § 934.10 gets the full walkthrough further down. The short version: a floor, not a cap. The fee-shifting matters more than the dollars.
GDPR and CCPA do not reach your Florida law firm
Every consent pitch a firm receives leads with one of these two. Both are wrong for you, in different ways, and it is worth knowing why so you can stop paying for the wrong fix.
GDPR needs targeting, not accessibility
Article 3(2) reaches a controller outside the EU only where processing relates to offering goods or services to data subjects in the Union, or to monitoring their behavior inside the Union.
It is a location test, not a citizenship test. The European Data Protection Board says application “is not limited by the citizenship, residence or other type of legal status of the data subject.” A French national living in Tampa sits outside GDPR. A US citizen sitting in Lisbon sits inside it. So “an EU citizen filled out our form” is the wrong question.
And a reachable website is not a targeted one. From EDPB Guidelines 3/2018:
“The mere accessibility of the controller’s or processor’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention.”
EDPB Guidelines 3/2018 on territorial scope, v2.1, adopted 12 Nov. 2019
The provision reaches conduct that is “intentional, rather than inadvertent or incidental.” There is one Florida practice area where that bites. The EDPB lists paid search aimed at consumers in the Union and advertising campaigns directed at an EU country audience among its indicators of intent. A Miami immigration firm running Meta ads at Venezuelan nationals living in Spain should talk to privacy counsel. A Broward County personal injury firm should not spend another dollar on GDPR consulting.
CCPA does not apply, and never required an accept button
A business falls under CCPA only if it clears one of the § 1798.140(d) thresholds. The revenue threshold reads $25 million in the statute, but it is CPI-adjusted in every odd-numbered year, and the California Privacy Protection Agency set it at $26,625,000 effective January 1, 2025, with the next adjustment due January 1, 2027. The alternatives are handling personal information on 100,000 or more consumers and households, or deriving half your revenue from selling data. No Florida law firm clears any of them.
Even if one did, CCPA is an opt-out regime. You disclose, then you offer a “Do Not Sell or Share My Personal Information” link. You also honor opt-out preference signals, which 11 CCR § 7025(b) makes mandatory rather than optional. Anyone telling you CCPA requires an accept/decline banner is describing GDPR and mislabeling it.
Florida wiretapping law: the statute that actually reaches your firm
Here is the inversion worth sitting with.
Florida’s own consumer privacy law, the Florida Digital Bill of Rights at § 501.702(9), effective July 1, 2024, covers a for-profit controller only if it exceeds $1 billion in global gross annual revenues and also meets one of three business-model tests, such as deriving half its revenue from online advertising or running an app store carrying at least 250,000 applications. It was drafted around Big Tech and it is the narrowest applicability threshold in the country. No law firm on earth qualifies.
Chapter 934 has no threshold at all. No revenue floor, no industry carve-out. It was passed in 1969 and modeled on Title III of the federal Omnibus Crime Control Act of 1968. It has been sitting there the whole time.
The four § 934.02 definitions that do the work
§ 934.03(1)(a) prohibits intentionally intercepting an electronic communication, or procuring somebody else to. Endeavoring to do it counts too. Then § 934.02 supplies the terms:
- “Intercept” means “the aural or other acquisition of the contents” of a communication through “an electronic, mechanical, or other device.”
- “Contents” means “any information concerning the substance, purport, or meaning of that communication.”
- “Electronic, mechanical, or other device” means any device or apparatus that can be used to intercept a communication. A script in a browser is not excluded.
- “Electronic communication” at § 934.02(12) carves out anything coming from a device that “permits the tracking of the movement of a person or an object.”
That last carve-out decided the early Florida cases. It does not help when the intercepted material is what a visitor typed rather than where her cursor went.
Florida wiretapping law requires all-party consent
This is why plaintiffs’ counsel like this venue.
“It is lawful under this section and ss. 934.04-934.09 for a person to intercept a wire, oral, or electronic communication when all of the parties to the communication have given prior consent to such interception.”
Fla. Stat. § 934.03(2)(d)
No proviso. No exception for someone who is a party to the communication. Compare the federal Wiretap Act at 18 U.S.C. § 2511(2)(d), which permits interception where the actor “is a party to the communication or where one of the parties… has given prior consent.” Federal courts dismiss pixel claims on that party exception constantly. Florida is one of roughly a dozen all-party states, and it gives private defendants no equivalent exit.
Your real civil exposure under § 934.10
“(a) Preliminary or equitable or declaratory relief as may be appropriate; (b) Actual damages, but not less than liquidated damages computed at the rate of $100 a day for each day of violation or $1,000, whichever is higher; (c) Punitive damages; and (d) A reasonable attorney’s fee and other litigation costs reasonably incurred.”
Fla. Stat. § 934.10(1), civil remedies
Read subsection (b) twice. The $1,000 is the floor. The per-day rate runs past it on any tag that sat on your site for a year. Punitive damages are on the menu. And (d) is the provision that makes a small claim economically rational for the other side, because your downside includes their invoice.
§ 934.10(3) sets a two-year limitations period running from “the date upon which the claimant first has a reasonable opportunity to discover the violation.” That is a discovery trigger. The clock did not start when the pixel fired.
Florida wiretapping case law is contested, and it cuts both ways
I am not going to sell you a settled rule, because there isn’t one.
Early Florida decisions went for defendants on session replay. In Goldstein v. Costco Wholesale Corp., 559 F. Supp. 3d 1318 (S.D. Fla. 2021), the court dismissed with prejudice, reasoning that tracking a user’s movements on a website was “the cyber analog to record information” a store could have captured on a security camera. A Miami-Dade circuit court reached the same result in Jacome v. Spirit Airlines on June 17, 2021, leaning partly on that tracking-device exclusion.
Then the theory changed. On March 6, 2025, in W.W. v. Orlando Health, Inc., No. 6:24-cv-1068-JSS-RMN (M.D. Fla.), Judge Julie Sneed denied a motion to dismiss FSCA claims over Meta and Google tracking tools on a hospital’s patient-facing site. The distinction she drew is the one that should worry a law firm:
“The information at issue here is the message Plaintiff sought to convey to Defendant through its website, information related to her medical conditions and providers, and thus constitutes the substance, purport, or meaning of her communications.”
W.W. v. Orlando Health, Inc., M.D. Fla., Mar. 6, 2025
On the mechanism, the court described the pixel as instantaneously duplicating the contents of the communication and sending the duplicate from the user’s browser directly to Facebook’s server. On the implied-consent defense most firms are quietly relying on, it said these technologies “are hidden from users’ view and difficult to avoid, even for the particularly tech-savvy user.” It expressly distinguished Jacome as addressing a different technology in a generic commercial setting.
Now the honest part, and it is the part the compliance vendors leave out.
Orlando Health never reached the merits. The parties filed a joint stipulation of dismissal on February 13, 2026, and Judge Sneed closed the case the same day. No class certification, no ruling on liability. And in Cobbs v. PetMed Express, Inc., No. 9:25-cv-80458 (S.D. Fla.), where federal and California wiretap claims had survived a motion to dismiss in January 2026, the court dismissed the amended complaint on July 31, 2026 for lack of Article III standing. Discovery had shown one named plaintiff kept shopping the site with the same browser settings while prosecuting the case, and the other admitted her only concern was “the violation itself.”
No Florida appellate court has ruled on FSCA liability for website tracking. The entire body of law here is trial-level and non-binding, and it splits both ways. Standing has become the defense bar’s best weapon. That is not a reason to relax. It is a description of what you are actually managing: an unsettled statute with no threshold, worked by a plaintiffs’ bar whose fees you pay if it wins.
Florida ranks second for wiretapping suits, and California can still reach you
Fisher Phillips maintains a Digital Wiretapping Litigation Map. Per its privacy lawyer Usama Kahf, quoted in Privacy Daily on February 26, 2026, Florida now has the second-highest volume of website-tracking suits in the country and is “on the cusp” of becoming the new California. The tracker was following more than 5,400 cases nationwide at that point. DarrowEverett’s March 2026 state-by-state guide reads the same way, naming Florida as the focal point of the second wave alongside Pennsylvania. Both are law firm estimates rather than official court statistics, and the ranking is consistent across them.
You might assume a Fort Lauderdale firm with no California practice cannot be hauled into a California court. That had real force until April 21, 2025, when the Ninth Circuit decided Briskin v. Shopify, Inc., No. 22-15815, sitting en banc. It reversed a jurisdictional dismissal and overruled its own line of cases requiring “differential targeting” of the forum state.
“We now take this opportunity to overrule AMA and any other cases that require some sort of differential treatment of the forum state.”
Briskin v. Shopify, Inc., 9th Cir. en banc, Apr. 21, 2025
A platform “expressly aims” at a forum when its contacts there are its own choice rather than random or fortuitous, the court held, even where it cultivates a nationwide audience. Shopify conceded its geolocation technology let it know the plaintiff’s device was in California when it set cookies. Running identical tags for every visitor is precisely what the court said does not save you.
And no, SB 690 does not fix this. California’s legislature passed it 39 to 0 on Senate concurrence on August 28, 2026, and it went to Governor Newsom, whose signing deadline is September 30, 2026. If enacted it becomes operative January 1, 2027. It amends § 637.2 to strip the private right of action for pen-register claims under § 638.51 arising from website conduct, leaving those to the Attorney General. The retroactivity reaches pending claims in actions commenced within two years before the operative date.
One detail trips up anyone writing from 2025 sources. Earlier drafts carried a broad “commercial business purpose” exemption covering §§ 631, 632, 632.7 and 638.51. On July 2, 2026 the bill was gutted and rewritten and that exemption came out. Sections 631 and 632 are untouched, and those are the theories that reach pixels. Nothing in the bill touches Chapter 934, and Florida has seen no comparable reform effort.
Why your intake form carries the most wiretapping liability
Look at what Orlando Health actually turned on. Not that tracking occurred. That the intercepted content was the substance of what the visitor was trying to tell the defendant.
Now picture a personal injury intake form. Nature of the injury. How the crash happened. Treatment so far. Which providers. Sometimes prior claim history. Someone filling that out is not browsing. She is describing a medical event to a lawyer, in her own words, in a text field.
Under § 934.02(7) as that court read it, that is information concerning the substance and meaning of her communication, arguably more plainly than the hospital search data in the case itself. If a Meta Pixel is live on the page, the content is duplicated out of her browser to a third party as she types. The tracking-device exclusion that saved Costco and Spirit does not reach it, because nobody here is tracking movement.
Two related exposures ride along. Intake and thank-you pages are the high-value target, which is a reason to look hard at how your intake system is wired end to end. And embedded video, meaning attorney bios and client testimonials, adds a separate federal theory under the Video Privacy Protection Act, 18 U.S.C. § 2710(c), at $2,500 in liquidated damages per violation. The Supreme Court hears argument on who counts as a “consumer” under that statute in Salazar v. Paramount Global, No. 25-459, on October 14, 2026.
What a Florida wiretapping claim looks like when it actually happens
Here is why firms underestimate all of it. Search the reported decisions for one naming a law firm as the defendant in a website-tracking wiretap case and you come back empty. Not in Florida, not anywhere.
That does not mean nothing happens. It means what happens leaves no public record.
The mechanism is a demand letter. A plaintiffs’ firm scans for sites loading a Meta Pixel, a TikTok pixel, session replay, or third-party chat. It finds someone who visited. It sends a letter citing § 934.10 with the arithmetic attached, and offers to resolve. No docket entry, no coverage. The model runs on volume and on the calculation that defending costs more than paying, which means every published filing count understates real activity by an unknown and probably large multiple.
Two provisions make it work. Fee-shifting under § 934.10(1)(d), and the discovery-based limitations trigger in § 934.10(3) that keeps 2023 conduct actionable today. California claims carry a further lever, no injury prerequisite under § 637.2(c). SB 690’s retroactivity reaches pending claims in filed actions. It does nothing about a letter.
A law firm also has two exits that are not lawsuits at all. A bar grievance requires no standing and no contingency-fee lawyer willing to front the work. It requires one person who filled out your intake form and later saw your retargeting ad on Instagram. Separately, cyber and malpractice applications increasingly ask about website data practices, and an inaccurate answer there is its own problem.
The reason no firm has been the test case is probably not immunity. Plaintiffs’ firms have been working retail, healthcare, e-commerce and media, where defendants settle faster. Law firms fight back. That makes them a worse target economically, not a protected one.
The law firm ethics gap nobody has closed
There is a second exposure no bar has addressed, and I want to describe it precisely, including its limits.
ABA Formal Opinion 10-457 (Aug. 5, 2010) held that where a lawyer’s website invites submission of information about forming a client-lawyer relationship, a “discussion” under Rule 1.18 results when a visitor submits it. So an intake form triggers the prospective-client rule. Florida Rule 4-1.18(b) says that even when no representation follows, a lawyer who learned information from a prospective client may not use or reveal it. Rule 4-1.6(e) requires reasonable efforts to prevent inadvertent or unauthorized disclosure of information relating to a representation.
Now the honest part. No ABA formal opinion and no Florida Bar ethics opinion addresses marketing pixels or analytics vendors receiving prospective-client information. Not 477R, not 483, not 498, not 512, and nothing in the Florida Bar’s technology ethics packet. Opinion 10-457 predates the 2012 Model Rule amendments and concerns information a visitor deliberately submits, not data a script copies out silently. Comment [3] to Model Rule 5.3 imposes reasonable-efforts duties toward outside vendors, but its examples are providers doing work in service of the representation, and Florida never adopted the 2012 retitling that broadened that rule. Florida Rule 4-5.3 still reads “Nonlawyer Assistants.” I found no reported Florida disciplinary matter on point.
So this is a gap, not a holding. A grievance still requires none of the things that make a civil claim hard to bring.
How I would fix a Florida law firm site, in order
Start with the script inventory, not the banner. Know what loads on every template and what each tag sends where. A Meta Pixel, a TikTok pixel, session replay, and third-party chat are the litigated targets. GA4 in a standard configuration is materially lower risk, and it gets disproportionate attention because it is the easiest thing to name in a sales pitch.
Block the tags, do not just flag them. The common failure is this: the banner renders and the visitor clicks accept. The pixel already fired on page load, because nobody gated it in the tag manager. That is worse than having no banner, because you have created a record that you knew consent was required and collected it afterward. Google’s Consent Mode v2 governs Google tags; it does not put a Meta Pixel behind a trigger. Healthline paid $1.55 million in the largest CCPA settlement to date, announced July 1, 2025, in part over a banner whose checkbox did not actually disable anything.
Take ad pixels off intake entirely. Not gated. Removed. That means every page carrying a form, plus whatever thank-you screen it redirects to. Fire the conversion server-side from your own backend after submission. You lose almost nothing in measurement and you eliminate the highest-value claim against you. Cost: an hour of somebody’s attention.
Add the policy language, and know its limit. A privacy policy is disclosure. The statute asks for consent. Courts have split on whether a footer-linked policy establishes implied consent, and the judge in Orlando Health called these same technologies hidden from view.
Keep records, and find out who installed the tags. Consent logs and a dated script inventory. Write down who configured what. When a letter arrives, the question is what you knew and when. If an agency built your tag manager, their contract is part of your posture, and I have written about why firms end up unwinding those arrangements.
One last practical note. Expect fewer attributed conversions once pixels are gated, and take a baseline before you change anything so you read the drop correctly. Server-side conversion APIs recover part of it. The rest was attribution built on data you had no legal right to collect in the first place.
Frequently asked questions about Florida wiretapping law
Does a Florida law firm need a cookie consent banner? Not for GDPR or CCPA. Neither applies to most firms. But if your site runs a Meta Pixel or session replay, § 934.03(2)(d) requires all-party consent before interception, and that means gated tags, not a disclosure link.
What are the penalties under Florida’s wiretap law? Criminally, a third-degree felony: up to five years under § 775.082(3)(e) and a $5,000 fine under § 775.083(1)(c). Nobody prosecutes a business for tags. Civilly, § 934.10 sets liquidated damages at $100 per day or $1,000, whichever is higher. Punitive damages and the plaintiff’s attorney’s fees ride on top.
Does GDPR apply to a US law firm? Almost never. Article 3(2) requires intentional targeting of people located in the EU, and the EDPB says mere accessibility of your site is insufficient. The realistic exception is an immigration practice actively advertising abroad.
Can a Florida firm be sued in California? Yes. Briskin v. Shopify removed the requirement that a defendant treat California differently from other states, and Cal. Penal Code § 637.2 carries $5,000 per violation with no injury prerequisite.
Did SB 690 end these lawsuits? No. If signed, it eliminates private pen-register claims under § 638.51. Claims under §§ 631 and 632 survive, and nothing in it touches Florida law or a presuit demand letter.
If this is the problem
The pattern running through these complaints is always the same shape: a template privacy policy on one side, an ungated tag manager on the other. That combination is the exposure. The fix is boring engineering work on the site itself, done once and documented, and it costs less than the first hour of defending a letter.
If that is the problem you are sitting with, write us at hi@carlosarias.com with the URL of your intake page. We will send back a list of what loads on it.
General information, not legal advice, and no attorney-client relationship is created by reading it. I am not a lawyer. The law here is unsettled. The Florida decisions discussed are trial-level and non-binding, and no Florida appellate court has ruled on FSCA liability for website tracking. California’s SB 690 was pending signature as of September 26, 2026. Consult privacy counsel before relying on any position described here.
Marketing Engineer for law firms. I combine digital marketing, software, data, automation and AI to improve the whole system — from first click to signed case.
Continue reading
Measuring AI Search Visibility for Law Firms: Your Report Still Leads With Rankings
Measuring AI search visibility for law firms starts where the ranking report stops. What to track, what to drop, and the one number nobody can attribute.
Your Law Firm Can Get Sued Over Its Own Website (The Widget Won't Save You)
Your law firm can get sued over its own website. The ADA names lawyers' offices by statute, the overlay widget is not a defense, and the fix pays twice.
Law Firm AI Search Indexing: Four Retrieval Pipeline Tests
Law firm AI search indexing, tested in an afternoon. Four checks that tell you whether ChatGPT and Claude can retrieve your practice pages at all.