This article is intended for informational purposes and does not constitute legal advice. Those who have received demand letters are encouraged to consult with qualified legal counsel.
CIPA Demand Letters are on the Rise
Over the past few years, there has been an increase in businesses across the U.S. receiving pre-litigation demand letters alleging that their websites violate the California Invasion of Privacy Act (CIPA). The reason? Plaintiffs allege that standard website analytics tools, such as Google Analytics, Meta Pixel, chat widgets, and other similar tools, automatically collect and share visitor data (such as IP addresses and browser identifiers) with third parties the moment a page loads, before they have a chance to consent. Under California law, the plaintiffs argue that this constitutes unlawful use of a “pen register,” a device that records communications routing information (USLegal).
The reason you need to know about this? If your website can be accessed in California, you could be at risk.
How do Plaintiffs Even Find this Information?
Many repeat plaintiffs use automated scanners to visit business websites to learn about these analytics tools and capture the data the sites transmit to build their case. This is referred to as a “tester plaintiff” model. These scanners are designed to detect when tools like Google Analytics or the Meta Pixel fire on page load without a consent layer. When the scanners discover these, they send a demand letter. The statutory damages are $5,000 per violation, or three times the actual damages plus attorney fees. This is what makes smaller sites more attractive targets. And in cases where there is no legal team on staff to push back or provide legal counsel, demand letters often wind up being paid rather than fought.
While it’s estimated that CIPA claims volumes total between 50,000 and 100,000 since 2022, most are resolved quietly via demand letter. Settlements are quick and relatively inexpensive to pursue. It’s an easy way for people to get money, so they keep doing it.
However, this issue is not completely settled from a legal point of view. One federal court says CIPA isn’t well-suited for modern internet technologies (DataGrail) because businesses don’t have a reliable way to know whether these standard practices expose them to liability.
So What are the Courts Looking At?
There are two main questions being considered as of mid-2026. First, did tracking start before a visitor was able to provide consent? And second, does the website’s behavior align with what the consent banner explained to visitors?
Unfortunately, simply having a cookie banner in place will not protect you if scripts run before someone has a chance to consent, nor will it protect you if tracking doesn’t actually stop when a visitor declines.
What Should I Do to Ensure My Website Is CIPA-Compliant?
To ensure your website is compliant:
- Audit Your Website: Work with your developer to compile a list of all third-party scripts, tags, and pixels currently on the site. You can’t fix things if you don’t know what’s there to begin with.
- Press Pause on Non-Essential Tracking: Until you have a consent gate in place, temporarily pause tracking. Having a small gap in analytics data is much better than receiving a demand letter.
- Implement a Consent Management Tool: A cookie banner alone is not sufficient. You need a tool in place that ensures tracking does not take place unless a visitor chooses to accept.
- Ensure the Decline Option Works: Sites that offer a decline option not connected to a consent management tool, or where the tool is not configured properly so it does not actually stop tracking, are being punished by the courts. Work with your developer to confirm your consent management tool is working properly.
- Update Your Privacy Policy and Terms of Service: These pages should reflect your actual practices moving forward and the measures you’ve put into place to prevent tracking until a visitor opts in. This also includes listing out the third-party tools you use on your site, how you use them, linking to their respective privacy policies, and reiterating that no tracking takes place until a user gives their consent. You should also note any third-party tools that fire immediately for the sole purpose of the functionality of the website.
- Preserve Your Records: Maintain screenshots, consent logs, and configurations. You’ll need these records if you do receive a demand letter.
Our Solution
We are rolling out a compliance plugin for clients to add consent pop-ups to their websites, as well as ongoing monitoring to ensure new tools added to their sites are always routed through the consent layer. Learn more about how we do this here.
What Should I Do if I Get a Demand Letter?
Don’t ignore any demand letters. However, don’t panic and settle either. Just because you receive a demand letter does not necessarily mean your site is in violation of the law. Many letters are sent as a result of automated site scans and boilerplate allegations.
Seek legal counsel. General business attorneys are not always up to speed with niche areas like this, so it is ideal to seek counsel from an attorney with CIPA experience.
Also, make sure you preserve your current site configurations before you make any changes to your website.
Need Help With Your Website?
If you need help ensuring your site is compliant, contact us to request a proposal.


