Skip to content
CIPA

Someone Is Threatening To Sue You Over CIPA. Here’s What It Means.

By Dana Schumacher| 8 Min Read | July 2, 2026
Add as a preferred source of Google
cookie crumbs on screen

It usually shows up by email, and it’s built to ruin your afternoon. Someone you’ve never heard of says your website broke the law by tracking them without permission. There’s a statute cited, a dollar figure hinted at, and a not-so-subtle suggestion that the whole thing disappears if you just settle.

Before you panic, or worse, ignore it, here’s what these letters are about, why they’re landing in so many inboxes right now, and what it takes to address the problem at its source.

What is CIPA?

CIPA is the California Invasion of Privacy Act, a state privacy law that has been on the books since 1967. It lives in the California Penal Code and was written for the telephone era, when the worry was people secretly recording or tapping private phone calls. California is an all-party consent state, which generally means that everyone in a conversation must consent before it can be recorded or intercepted.

Two features make the law potent today. First, it generally doesn’t require the person bringing the claim to show they lost money or suffered measurable harm. Second, it sets fixed statutory damages for each violation, so the totals can climb quickly across a single website’s traffic. Both come up again below.

What CIPA was never written for is the modern web. It says nothing about cookies, pixels, or analytics, and that gap is exactly where a small group of plaintiffs has learned to operate.

What the letter is really about

So how does a 1967 wiretapping law end up pointed at your website? Those same plaintiffs and their attorneys have realized that CIPA’s vague, decades-old language can be stretched to cover the cookies and tracking pixels on nearly every modern website. The argument runs like this: when your site loads Google Analytics or a Meta Pixel and starts tracking a visitor before that visitor has consented, that counts as “intercepting” a private communication. Digital wiretapping, in effect.

Is it a stretch? Yes. But it works often enough to have become a business model. Many of these letters go out in bulk: the sender sends a high volume of near-identical complaints and relies on a percentage of recipients to settle quickly to make the discomfort go away. If you received one, you’re likely among thousands who received the same notice.

That doesn’t mean you can shrug it off. It means you should understand the leverage before you respond.

Why your business specifically?

The most common first reaction is some version of “But we don’t even sell anything on our website.”

It doesn’t matter. The complaint isn’t about whether you run an online store. It’s about whether your site quietly collects visitor behavior, and almost every site does the moment you add analytics, an ad pixel, a chat widget, or a tag manager. If a California resident can visit your site, you can be a target, even if your company has never set foot in the state and your site is little more than a digital business card.

This isn’t a problem reserved for big e-commerce brands. It targets exactly the kind of ordinary business website most companies run.

The part that makes these letters effective

The uncomfortable math is what gives these claims their teeth.

CIPA can carry statutory damages of up to $5,000 per alleged violation, and plaintiffs argue they don’t have to prove actual harm to collect. Multiply that by enough alleged “violations” and the theoretical exposure climbs quickly. Most of these matters never reach a courtroom. They’re designed to be resolved through a quiet settlement that costs far less than fighting but still means real money out the door.

That’s the strategy: make litigation look expensive and uncertain, and make settlement look like the easy way out. Efforts to reform the law and carve out routine business tracking haven’t gone anywhere so far, so the letters are likely to keep coming. The goal isn’t to scare you into paying. It’s to make sure that if a letter lands, you choose your response from knowledge rather than fear.

The fix is real, and it’s manageable

What the sender is counting on you missing is consent. And getting consent right is a well-understood, solvable problem.

You’ve seen the solution countless times without thinking about it: the banner that asks you to accept or decline cookies when you land on a site. That banner is run by a content management platform, and the part that matters for your risk is whether it actually controls when your tracking turns on.

When set up correctly, none of your tracking fires until the visitor interacts with the banner and opts in. No analytics, no ad pixels, nothing. If they ignore or close it, they move through your site without being tracked. The visit still happened; you simply didn’t record it. That one behavior, tracking that waits for permission, is what directly addresses the core accusation in these letters.

For California specifically, the recommended setup is explicit consent: visitors are tracked only if they actively opt in, rather than being tracked by default and left to opt out. These platforms can also apply different rules by region, so you can run the strictest settings for California (and other areas like Europe that have their own privacy laws) without imposing them on every visitor worldwide.

For most small and midsize sites, this is a modest project rather than a months-long overhaul.

The trade-off worth knowing up front

Compliance comes with a cost, and it isn’t money. It’s visibility.

Once you ask permission before tracking, a meaningful share of visitors will decline or never engage with the banner at all. Those visits still happen, but they disappear from your analytics. Depending on your audience, you can expect to lose roughly 40% to 70% of the traffic data you’re used to seeing.

This catches people off guard, so it’s worth going in with eyes open: you’re trading some analytics visibility for compliance and peace of mind. For a business whose website isn’t its primary sales engine, that’s usually an easy call. Better to expect it than to discover it three weeks after launch and assume something broke.

A quick word on how your banner makes you look

There’s a right way and a wrong way to ask. California regulates not just whether you get consent but how you word the banner and your privacy policy, including how you describe the data you store and whether you share or sell it.

Beyond the legal requirements, there’s a brand question. You’ve seen the manipulative version: a giant “Accept All” button beside a buried, grayed-out “Reject,” or an opt-out flow designed to make you give up. You don’t have to play that game. A clean, honest banner can meet the requirements and still leave visitors with a better impression of your company than a sneaky one would. Compliance and good manners aren’t in conflict.

What to do if a letter has already arrived

A few practical moves, in rough order:

  1. Loop in your attorney early. The technical fix and the legal response are two separate tracks, and you want both moving. Nothing here is legal advice, and your counsel should weigh in on how to handle the specific demand.
  2. Document your current setup. Take screenshots, note which tracking tools and pixels are running, and capture whatever consent mechanism you have (or don’t have) today.
  3. Fix the root cause. Put a properly configured consent platform in place: explicit consent for California, tracking that is held until a visitor opts in, and privacy policy language reviewed by your legal team.
  4. Test it, then test it again. This approach only holds up if the tracking behaves as you say it does, so verify every tag before launch and recheck it afterward.

The bottom line

A letter like this is engineered to make you feel exposed and alone. You’re neither. This is a known pattern with a known fix, and the businesses that handle it well treat it as a prompt to do something they probably should have done anyway: ask visitors for permission before tracking them, and make sure their website does what their privacy policy says it does.

If you’d rather not navigate it alone, this is exactly the kind of problem we help businesses solve, from the technical fix to coordinating with your legal team.


This article is for general informational purposes and is not legal advice. Specific obligations under CIPA and related privacy laws vary by situation; consult qualified legal counsel about your particular circumstances.


Dana Schumacher - Analytics Team Lead

Written by Dana Schumacher

With expertise in Google Analytics implementation, data strategy & analysis, data visualization and complex data collection solutions, Dana has made all things analytics her professional specialty for more than a decade. At DOM, she has been helping clients develop and leverage insightful data that align with their business goals to maximize success and uncover opportunities.

View Dana Schumacher's Full Bio