If you run a business with a website in California, there's a new wave of lawsuits hitting small and mid-sized businesses across nearly every industry. The threat doesn't come from a hacker or a disgruntled customer — it comes from a 1967 wiretapping law that's being reinterpreted by plaintiff law firms in ways the original legislators never imagined.
The result: thousands of California businesses are receiving demand letters and lawsuits demanding $5,000 to $50,000 in statutory damages — often for nothing more than having Google Analytics or a Facebook Pixel installed on their website.
Here's what's happening and what California business owners need to understand.
What CIPA Actually Is
CIPA stands for the California Invasion of Privacy Act, originally passed in 1967. Its purpose was straightforward: prevent people from secretly recording phone conversations without the consent of everyone on the call. It was the digital-age equivalent of the federal wiretap statutes, written for an era of rotary phones and party lines.
For 50 years, CIPA largely operated in that lane — used to prosecute illegal phone recordings and unauthorized eavesdropping on private communications.
Then plaintiff law firms found a new use for it.
How a 1967 Wiretap Law Became a 2026 Website Lawsuit Trigger
Beginning around 2022, attorneys began arguing that modern websites — specifically, websites using common tracking tools like Google Analytics, Meta Pixel, chatbots, and ad tracking scripts — were essentially the equivalent of installing a hidden recording device on a phone line.
The argument runs like this:
- When someone visits your website and interacts with it (filling out a form, chatting with a widget, clicking around), that's a “communication” between the visitor and your business.
- If your website has third-party tracking tools embedded — meaning code from outside companies like Google, Meta, LinkedIn, HubSpot, or analytics platforms — those tools simultaneously receive a copy of the visitor's actions.
- That, the argument goes, is the modern equivalent of an unauthorized wiretap on the conversation between the visitor and your business.
It's an aggressive interpretation. Critics — including many privacy attorneys — argue it stretches the original statute beyond recognition. But California courts have, in several key cases, allowed these claims to proceed past initial motions to dismiss. That's all plaintiff firms need to make the lawsuits a profitable business model.
The Legal Theory in Plain English
The core of the argument hinges on who counts as a “party” to the communication on your website.
Under California law, a party to a conversation generally can't “wiretap” their own conversation. So if it were just you and your visitor, there'd be no claim. But plaintiff attorneys have argued that third-party tracking tools change that equation entirely:
- The visitor is one party.
- The website owner (your business) is the other party.
- The third-party tracker (Google, Meta, LinkedIn, etc.) is, in this argument, an “uninvited interloper” — receiving the communication without being a party to it.
- By embedding the tracking code on your site, the argument goes, you're “aiding and abetting” the third party's eavesdropping.
The other key piece is timing. The argument is that consent must come before any tracking begins. If your cookie banner displays but the tracking scripts have already fired — which is the case on most small business websites — the consent was never legally obtained in the first place. The banner is effectively cosmetic.
What Plaintiffs Are Looking For on Your Website
The plaintiff playbook is methodical. Tools like browser developer consoles and network monitors are used to capture what happens the moment a user lands on a website. Common indicators that draw lawsuit attention include:
- Tracking pixels from Meta (Facebook), Google, LinkedIn, TikTok, or other ad platforms
- Analytics tools like Google Analytics that capture visitor actions
- Chatbots and live chat widgets that route conversations through third-party platforms
- Embedded forms that send data to CRMs or marketing tools outside the business
- Session replay tools that record visitor behavior on the page
- Cookies and trackers that fire before a visitor has agreed to be tracked
The common thread: any tool that sends visitor data to an outside service — even if the business owner didn't realize the tool was doing that — is potential litigation fuel.
What's Actually at Stake
The damages structure under CIPA is what makes these lawsuits so dangerous for small businesses:
- $5,000 per violation, per visitor
- Each third-party data recipient potentially counts as a separate violation
- No proof of actual harm required — the statute allows recovery without showing the visitor suffered any monetary loss
- Attorney's fees on top for prevailing plaintiffs
Recent reports indicate that across thousands of demand letters sent to California businesses, the average pre-litigation settlement has been around $15,000. Most businesses settle because the cost of fighting in court — even when the underlying claim is weak — typically exceeds the settlement amount.
That's the entire economic logic of the model: make litigation more expensive than settlement.
How to Tell If Your Website Has Exposure
The honest answer is that almost every modern business website has some level of CIPA exposure unless steps have been taken to address it. A few questions to start with:
- Does your site have Google Analytics or any visitor tracking installed?
- Do you run Facebook, Instagram, Google, or LinkedIn ads pointing to your site?
- Do you have a chat window, contact form, or booking form?
- Have you ever installed something like a “Facebook Pixel” or “Google Tag Manager”?
- Do you send email newsletters or marketing emails with link tracking?
- Does your site embed third-party tools like calendars, video players, or social feeds?
If you answered yes to any of those — and most California businesses will answer yes to several — your site likely has some level of CIPA exposure.
The follow-up question is whether your website has any of the standard defenses in place: a working cookie consent banner that actually blocks tracking until visitors agree, a privacy policy that accurately describes what your site does, a Global Privacy Control configuration, and documented compliance work.
For most small business websites, the answer is no — because these protections weren't standard practice until very recently.
What to Do About It
There are a few practical steps California business owners can take:
1. Audit what your website is actually doing. Most business owners don't know exactly what tracking is installed on their site, especially if a previous developer or SEO contractor added tools over time. The first step is knowing what's there.
2. Implement a real consent management system. A cookie banner that displays but doesn't actually block tracking scripts from running before visitors agree is not a defense. The banner has to gate the trackers.
3. Rewrite your privacy policy to match what your site actually does. Most small business privacy policies are generic templates that don't describe the specific trackers in use. That's a problem for both compliance and defensibility.
4. Document everything. If a demand letter does land, documented evidence of your compliance work — what was reviewed, when, what changed — is one of the strongest defenses available.
5. Don't respond to a demand letter without an attorney. If you've received one, talk to a privacy attorney before responding. The wrong response can make the situation worse.
The Bottom Line
These lawsuits aren't going away soon. SB 690, a California reform bill that would create a commercial business purpose exception under CIPA, has stalled and won't apply retroactively even if eventually passed. The most defensible position is one built in advance — not in response to a demand letter.
We help California small businesses audit their websites for CIPA exposure and implement the technical and documentation defenses that reduce risk. If you'd like to know where your site stands, we offer a no-obligation review.
Schedule a 15-minute site review →
This article is for general informational purposes and does not constitute legal advice. If you've received a demand letter or are facing potential litigation, consult a qualified attorney.
















































0 Comments