CIPA Lawsuits, Cookie Consent, and Website Tracking: What Small Businesses Need to Know (And What to Do If a Demand Letter Arrives)
Over 1,000 CIPA lawsuits were filed in 2025 targeting ordinary business websites running Google Analytics and Meta Pixel without a proper consent banner. This is a calm, practical guide to what the California Invasion of Privacy Act actually says, why the law is unsettled, and what your website should do right now, whether or not a demand letter has already arrived.
Introduction
Over 1,000 CIPA lawsuits were filed in 2025 alone, and the businesses getting targeted weren't reckless data brokers or shady ad networks. They were ordinary small businesses running Google Analytics, Meta Pixel, and HubSpot, tools their developers installed years ago and nobody thought twice about. CIPA website tracking is the issue at the center of all of it, and if you run a website with standard marketing tools, you need to understand what it is.
CIPA stands for the California Invasion of Privacy Act, a 1967 California wiretapping law that courts have been extending to website tracking technology. The statutory damages are $5,000 per violation, or three times actual damages, whichever is greater, and plaintiffs often count each site visit as a separate violation. The math gets scary fast.
Legal disclaimer: Sproutbox is a marketing agency, not a law firm. Nothing in this post is legal advice. If you've received a demand letter, talk to a privacy attorney before you respond, pay anything, or make retroactive changes to your site.
Here's what this post actually covers: what CIPA is and which sections drive the lawsuits, what a demand letter looks like and why the economics behind it work, where courts actually stand (it's genuinely mixed, not a slam dunk for plaintiffs), what a real consent setup looks like versus the broken installs we see everywhere, and what to do if a letter is already on your desk. Calm, practical, no fearmongering.
What Is CIPA, and Why Is Your Website Suddenly a Target?
CIPA was written in 1967 to cover phone wiretapping. There is nothing in the original statute about websites, browsers, or tracking pixels. Courts have done the extending, and that's where the current litigation wave comes from. Three sections of the California Invasion of Privacy Act now drive nearly every active claim against businesses running standard website tracking tools.
- Section 631 (Wiretapping / Third-Party Interception): This section prohibits third parties from intercepting communications in real time. Plaintiffs argue that when a visitor types something into a form field or a site search bar and that data is transmitted to Google, Meta, or HubSpot before the page is submitted, a third party has intercepted a communication without consent. This is the wiretap theory.
- Section 632 (Recording Confidential Communications): This section covers recording confidential communications without the consent of all parties. It comes up less frequently than the other two but still appears in some complaint packages.
- Section 638.51 (Pen Registers and Trap-and-Trace Devices): Courts have held that software-based trackers, including pixels, can qualify as pen register or trap-and-trace devices under this section. Pen register and trap-and-trace claims make up roughly two-thirds of active California privacy litigation right now. This is the section driving the highest volume of demand letters.
One thing that trips people up: CIPA follows the visitor, not the business. A business in Portland, Oregon, or Austin, Texas, or Miami, Florida can be targeted under California law if a California resident visits its website. Generic disclaimers like 'we don't target California customers' provide no legal defense. The visitor doesn't need to be targeted, they just need to visit.
Damages are $5,000 per violation or three times actual damages, and plaintiffs routinely argue that every individual site visit constitutes a separate violation. For a business with any meaningful web traffic from California, the potential exposure numbers in a complaint can be enormous, even before you factor in attorneys' fees. The ArentFox Schiff privacy counsel team has written about how this targeting dynamic works and why ordinary businesses are now in the crosshairs.
What a CIPA Demand Letter Actually Looks Like
If you've received one of these and you're wondering whether it's real, the short answer is: probably yes, and you should treat it seriously. Here's what a typical demand packet contains.
The cover letter requests 'informal resolution' before anything is filed. Attached to it is a boilerplate LA Superior Court complaint, often pre-signed and ready to file, and screenshots showing your site transmitting data in real time to Google Analytics, Meta Pixel, HubSpot, or whatever tracking tools you're running. The screenshots are produced by opening your site in a browser with the network tab open, a task that takes about three minutes. These packets are designed to look ready-to-file because that's exactly what makes them credible enough to settle.
There are two distinct plaintiff streams generating these letters. The first is class action litigation firms pursuing large settlements, the kind where a settlement like the $3.85 million Mirmalek v. LA Times resolution in June 2026 is the outcome. The LA Times didn't concede liability; it settled to avoid the uncertainty of litigation. The second stream is pro se plaintiffs sending waves of demand letters engineered to target businesses where settling is cheaper than hiring a defense attorney to respond. And honestly, for a lot of small businesses, that's exactly the math.
That's not an accident. Statutory damages let plaintiffs make credible demands without proving that any actual harm occurred. The demand amount is typically calibrated to fall below the cost of a legal defense. You're not being extorted in a criminal sense, but you are being presented with a purely economic calculation.
The wrong move is ignoring the letter. The letter doesn't disappear if you don't respond, and silence can complicate a later defense. But the equally wrong move is reflexively paying it. Some claims have real defenses. Some don't. The outcome depends on which sections are alleged, which court has jurisdiction, and what your site was doing at the time. This is exactly why proper consent setup matters starting at the build stage, which is something we address in our website design and development work. And it's exactly why a privacy attorney's read on the specific letter matters before you do anything.
Where the Courts Actually Stand (It's Genuinely Unsettled)
The courts are genuinely split on CIPA website tracking claims. Plaintiffs win. Defendants win. Cases get dismissed on standing, on statutory interpretation, on the merits. Anyone who tells you this is clear-cut liability, or that you have nothing to worry about, isn't reading the case law.
What is consistent across the cases that do survive: courts increasingly expect a real, functional consent mechanism, not a footer link to a privacy policy. That thread runs through the plaintiff-favorable decisions. The Spencer Fane team has put together one of the most useful summaries of where the case law stands and where it's going, and we used it heavily in building out this section.
Cases Where Plaintiffs Won or Settled
Mirmalek v. LA Times ended in a $3.85 million settlement approved in June 2026. The LA Times did not concede liability. It settled because the cost and uncertainty of continuing the litigation outweighed the settlement amount. That's a rational business decision, and it's also the clearest example of why demand math works: you don't have to lose in court to lose money.
Camplisson v. Adidas is the case that should change how you think about your consent banner. The motion to dismiss was denied entirely on Section 638.51 claims. The key holding: a privacy policy link sitting in the footer, with no affirmative consent mechanism like a real cookie banner, doesn't meet conspicuousness requirements. The court wasn't impressed that a policy existed. It asked whether a visitor was meaningfully notified and given a real choice before data was transmitted. A footer link doesn't answer that question.
That holding matters. It suggests that courts aren't just looking for disclosure, they're looking for a functional consent mechanism that operates before tracking begins.
Cases Where Defendants Won
Defendants win these cases. Regularly. Rodriguez v. Ink America was dismissed at the state court level on pen register claims, with the court holding that the statute was designed to target phone surveillance, not website analytics. Heiting v. Wildflower Brands was dismissed with prejudice. Shah v. Talentbridge was dismissed on standing grounds. Outcomes depend heavily on which claims are alleged, which court picks up the case, and what defenses are available given the specifics of the site's setup.
The point isn't that you should feel safe ignoring the issue. It's that when a demand letter arrives, the right response is a careful legal assessment, not a panic payment. Some of these claims lose. Knowing which is which requires someone who reads California privacy law for a living.
Two California appellate cases, Variety Media v. Superior Court and Reuters News & Media v. Superior Court, are expected to directly address whether website pixels qualify as pen registers under Section 638.51. Decisions are expected within roughly a year, and they'll be precedent-setting. On the legislative side, California SB 690 would add a commercial business purpose exemption, remove the private right of action for pen register claims, and shift enforcement to the Attorney General. The amended version was heard July 1, 2026 with two-year retroactivity proposed. It would not affect Section 631 wiretap claims. Both of those developments matter, but neither resolves the exposure businesses face today.
The Real Problem: Most Consent Banners Are Installed Wrong
We call this The Consent Gap, and it's the single most common place where small business website setups fail on CIPA exposure. The Consent Gap is the window between when a page loads and when the consent banner actually renders, during which trackers can, and often do, fire before any consent has been collected. It's not a niche technical edge case. It's the default behavior of most DIY consent installs.
There's a second, newer version of the problem: banners that appear to work but don't. A visitor clicks 'Reject All,' the banner confirms the rejection, and the pixels fire anyway. State regulators are now running automated website scanning to verify that opt-outs are actually honored on the back end. A banner that says no while the tags say yes is its own lawsuit theory, and it's one that's increasingly being pursued.
The Consent Gap: When Your Banner Loads After Your Trackers
Here's how The Consent Gap happens technically. Google Analytics or Meta Pixel is baked into the site's global header, either hardcoded or loaded through a tag manager configuration. That script executes on every page load, immediately. The consent management platform, the thing that renders your banner, is a separate JavaScript tag that runs slightly later in the page load sequence. By the time the banner appears and the visitor can make a choice, Google has already pinged Google and Meta has already pinged Meta.
The banner in this scenario is disclosure, not consent. The data was already sent before any choice was offered. Camplisson v. Adidas is an example of courts taking notice of exactly this sequencing problem. The question isn't whether you have a banner. The question is whether the banner runs before the trackers do.
A consent management platform configured correctly will suppress trackers entirely until consent is affirmatively given. That's what 'blocking until consent' actually means, and it's the architecture distinction that matters most. A banner that appears after your trackers have already fired is a legal liability, not a compliance solution.
The Newer Theory: Banners That Lie
The second enforcement angle is the one that's gaining traction with state regulators specifically. If a visitor clicks 'Reject All' and your pixel fires anyway, your banner is decorative, not functional. Regulators are using automated scanning tools to verify that opt-outs are actually honored, including Global Privacy Control signals sent automatically by browsers that indicate a user's preference to opt out. A consent system that ignores GPC signals is a growing target for this kind of scrutiny.
This is why the 'verify the rejection actually works' step matters so much, and why we treat it as a non-negotiable part of any consent setup we build for clients. More on that in the next section.
What to Do Right Now: The CIPA Consent Compliance Checklist
The CIPA Consent Compliance Checklist below is a practical starting point for businesses that want to get their consent setup right. This is prospective risk reduction, not a cure for active litigation. If you've already received a demand letter, read the next section before acting on any of this, and talk to a privacy attorney first.
- Audit what your site actually collects. Use CookieYes's built-in scanner or open your browser's network tab and watch every third-party request that fires on page load. Most business owners are surprised by what a past developer, plugin, or tag manager template left behind. Ignorance isn't a defense.
- Map where the data goes. Document every third-party tool your site shares data with: Google Analytics, Meta Pixel, HubSpot, Hotjar, Intercom, Klaviyo, whatever is in there. This mapping step also tells you what your privacy policy needs to say.
- Deploy a consent management platform configured to block trackers before they fire. Not a banner that shows up while the pixels are already running. The opt-in consent mechanism has to come first. This is the core architecture requirement for CIPA website tracking compliance.
- Test that rejections actually work. Click 'Reject All' yourself. Open the network tab. Verify that the tracking scripts did not fire. This is the step most DIY installs skip, and it's also the step that state regulators are checking with automated scanning tools.
- Honor Global Privacy Control signals. Your consent management platform should be configured to detect browser-level GPC settings and respond to them automatically. If your platform doesn't do this, that's a configuration gap worth closing.
- Update your privacy policy to match reality. An outdated policy that doesn't disclose your current third-party tools is its own exposure. The policy should accurately describe every tool that touches visitor data.
- If you've received a demand letter, do not treat this checklist as a legal response. Steps 1 through 6 reduce future exposure. They don't extinguish claims for past conduct. Talk to a privacy attorney before you do anything.
This is the kind of cookie consent compliance work we build into our website design and development work from the start, so clients aren't scrambling to retrofit it later. Retroactive is always harder and more expensive than built-in.
Legal disclaimer: Sproutbox is a marketing agency, not a law firm. This checklist is educational, not legal advice. If you've received a demand letter, talk to a privacy attorney.
If You've Already Received a Demand Letter
If you're reading this because a letter is sitting on your desk right now, here's the clear direction.
Don't ignore it. A CIPA demand letter doesn't go away if you don't respond. Ignoring it doesn't create a defense and can complicate the situation if the case actually gets filed.
Don't reflexively pay it either. Some claims, particularly pen-register-only claims under Section 638.51, have real defenses depending on which court has jurisdiction, the specifics of the complaint, and what your site's consent infrastructure looks like. The dismissed cases in this post prove that defendants win. The outcome of your specific letter depends on the specific facts.
Don't assume that quickly installing a consent banner fixes the problem. Retroactive compliance doesn't necessarily extinguish claims for conduct that already occurred. Installing a banner today doesn't rewrite what your site was doing six months ago.
Talk to a privacy attorney, specifically one with California privacy law experience, before you respond, pay, or make any site changes related to the letter. That sequencing matters.
Preserve your evidence. Don't delete analytics data, server logs, or documentation of what your site was doing at the time described in the letter. That record may matter in your defense.
Again: Sproutbox is a marketing agency, not a law firm. If a demand letter has arrived, this post is not a substitute for legal counsel.
How Sproutbox Handles Cookie Consent for Clients
Sproutbox is a Portland-based full-service digital marketing agency specializing in website design and development, and CIPA-aware consent architecture is something we build into client sites deliberately, not as an afterthought.
When we start a website audit, the first thing we usually find is trackers that nobody consciously chose to install. A WordPress plugin added Hotjar. A previous developer hard-coded a Meta Pixel. Tag Manager has a dozen rules that nobody remembers setting up. The audit step surprises almost every client. And that's not a knock on those clients, it's just how these sites accumulate stuff over time.
For most SMB websites, we recommend CookieYes as the consent management platform. Here's specifically why it fits: it blocks trackers before they fire rather than notifying visitors after the fact, it honors manual rejections on the back end, it responds to Global Privacy Control signals automatically, it supports geo-targeted banner display so California visitors see the banner even if you're running a regional business, and it generates a consent log. Those aren't nice-to-haves in a CIPA context. They're the pieces that actually matter.
And installation matters as much as the tool itself. We set up and test CookieYes as part of our website work, including the step most DIY installs skip: verifying that tags actually stay suppressed after a visitor clicks 'Reject All.' We open the network tab, click reject, and check. If a tracker fires, the configuration is wrong and we fix it before launch.
On our own site, we use a click-to-load consent gate on our Calendly scheduling embed. The scheduling tool's third-party cookies don't activate until a visitor actively chooses to load it. That was a deliberate decision, made specifically with CIPA-style exposure in mind. It's a small example of what intentional tracker suppression looks like in practice, and it's the kind of choice that's easy to make when you're thinking about it at the design stage and much harder to retrofit.
Most people think the cookie banner is the whole solution. In practice, the banner is just the visible layer. The real work is in what happens before the banner renders and what happens when a visitor says no. If you want us to audit what's firing on your site, that's something we do as part of our website design and development work.
Frequently Asked Questions
What is CIPA and does it apply to my business if I'm not in California?
CIPA, the California Invasion of Privacy Act, is a California state law originally written to cover phone wiretapping. Courts have extended it to website tracking technology. It applies based on where your visitors are, not where your business is located. If any California residents visit your site, CIPA exposure is real regardless of your home state.
This is the piece most small businesses outside California miss. A geo-exclusion disclaimer or a statement that you don't target California customers provides no defense. The statute follows the visitor.
Do I need a cookie consent banner on my website?
If your website runs any third-party tracking tools, Google Analytics, Meta Pixel, HubSpot, Hotjar, or similar, a properly implemented consent banner is increasingly considered the baseline for compliance under CIPA and other state privacy laws. Courts have cited the absence of an affirmative consent mechanism, not just a footer privacy policy link, as a factor in denying motions to dismiss.
A banner alone isn't enough. It has to block trackers before it renders and honor rejections on the back end. The banner that appears after Google Analytics has already fired is not a consent mechanism. It's a disclosure that arrived too late.
I got a letter threatening a CIPA lawsuit. What should I do?
Don't ignore it, but don't pay it immediately either. Some CIPA claims, particularly pen-register claims under Section 638.51, have real defenses, and defendants do win. Talk to a privacy attorney with California privacy law experience before you respond, pay, or make retroactive site changes. Preserve any documentation of your site's state at the time described in the letter.
Sproutbox is a marketing agency, not a law firm. If a demand letter has arrived, get legal counsel before taking any action.
Is it illegal to use Google Analytics or the Meta Pixel without a consent banner?
Not illegal in a criminal sense, but running these tools without prior consent from California visitors creates civil liability exposure under CIPA. Plaintiffs can claim each visit is a separate violation at $5,000 per violation in statutory damages. Courts are split on whether pixels qualify as pen registers under Section 638.51, but the risk is real enough that a consent mechanism is considered basic risk management.
Two California appellate cases are expected to clarify whether website pixels qualify as pen registers, with decisions expected within roughly a year. That clarity will matter, but it doesn't reduce today's exposure while the question is still open.
Does a cookie consent banner fully protect me from being sued under CIPA?
No. A banner reduces exposure but doesn't eliminate it. The banner must block trackers before it renders, and rejections must genuinely suppress tags on the back end. A banner that appears after Google Analytics has already fired, or one where a visitor clicks 'Reject All' but the pixel fires anyway, is now its own lawsuit theory being pursued by plaintiffs and tracked by state regulators.
Implementation quality matters as much as having a banner at all. A misconfigured consent management platform is, in some ways, worse than no banner, because it creates a documented promise the system then breaks.
The Bottom Line: Compliance Is Cheap. Litigation Isn't.
The law here is genuinely unsettled. Defendants win. Cases get dismissed. Legislation is moving. We're not going to pretend this is clear-cut liability, because it isn't.
But the signal that runs consistently through every case that survives is this: courts expect a real, functional consent mechanism. Not a footer link. Not a banner that loads after your trackers already fired. Not a 'Reject All' button that doesn't actually suppress the tags. A real opt-in consent mechanism, configured correctly, that operates before any tracking begins.
The cost of a properly implemented consent platform is low relative to the cost of a legal defense, even a successful one. That's not a scare tactic. That's just the math.
If you want to see what's actually firing on your site and make sure the consent setup is solid, that's part of our website design and development work. We're not going to pressure you into anything. But if you've been wondering whether your current setup holds up, the honest answer is: it's worth checking.
Legal disclaimer: Sproutbox is a marketing agency, not a law firm. Nothing in this post is legal advice. If a demand letter has arrived, talk to a privacy attorney before you respond, pay, or make any site changes related to the claim.
Want help with websites?
Your website is often the first impression people have of your business, and it either builds trust or loses it. We build sites that are fast, clear, and designed to get people to take action.
Keep reading
Local SEO Citations: What They Are, Why They Matter, and How to Build Them Right
Local SEO citations, your business name, address, and phone number listed consistently across the web, are one of the most overlooked ranking factors in local search. Here's what they are, why they still matter in 2026, and a step-by-step process for building and maintaining them correctly.
WebsitesIs a Website Redesign Worth It? What Businesses Actually Get (With Real Numbers)
A website redesign feels expensive until you run the numbers on what a broken site is costing you. This post breaks down the real business case, with actual results from businesses that made the investment, and shows you exactly what changes (and what doesn't) when you rebuild.
Search & AIHow to Do an SEO Audit: A Step-by-Step Guide for Small Businesses
A gut feeling that your SEO isn't working isn't enough to fix it. This step-by-step guide walks small business owners through a complete SEO audit, from pulling baseline data to building a prioritized action plan, so you know exactly what to fix and in what order.
Schedule a 30-min call.
Thirty minutes to talk about your business. Where you are, where you want to go, and whether we're the right fit to help you get there.
No pitch deck. No pressure. And no long-term contracts. We'd rather earn your business every step of the way.
