Short answer: possibly, and it has nothing to do with anything unusual you're doing. Plaintiffs' firms are using a 1967 California wiretapping law to sue ordinary companies over routine tools like chat widgets, analytics, and ad pixels - and the exposure applies to any business with California site visitors, not just companies doing anything wrong.
What is CIPA, and why is it suddenly about cookies?
The California Invasion of Privacy Act (CIPA) is a decades-old law written to stop illegal phone taps. Plaintiffs' firms are now applying it to websites, arguing that a tracking pixel or session-recording tool "intercepts" a visitor's activity the same way a wiretap intercepts a phone call. Two fact patterns drive most current cases: tracking that fires the instant a page loads, before a visitor has made any choice, and tracking that keeps running even after someone clicks "Reject" on the cookie banner.
Am I actually at risk?
If your site uses a chatbot, session-recording software, or an advertising pixel (Meta, Google, TikTok, or similar), the underlying tools are in scope. Risk isn't limited to large companies - plaintiffs' firms can find targets through automated scans of public websites, not by singling anyone out. Bigger, higher-traffic sites tend to be attractive targets, but smaller companies are being swept in too. Statutory damages can run to $5,000 per violation, and courts don't always require proof of actual harm to let a claim proceed.
What's the fix?
In most cases, less than it sounds like. It usually comes down to making sure your cookie banner is a genuine gate - nothing fires until a visitor actually chooses - and that your privacy policy accurately describes what's running on your site. Companies that get this right are largely insulated from the theory these cases rely on.
Frequently Asked Questions:
Q: Does CIPA only apply to California companies?
A: No. It applies to any business with California site visitors, regardless of where the company is based.
Q: Is Google Analytics automatically a problem?
A: Not necessarily; it depends on backend configuration, like whether it's set to be used for advertising. Presence alone isn't proof of an issue.
Q: What's the difference between "clickwrap" and "browsewrap" consent?
A: Clickwrap requires an affirmative action (a click) before tracking starts; browsewrap just assumes consent from continued use. Courts increasingly treat browsewrap as insufficient.
Q: Can I get sued even if I haven't received a demand letter yet?
A: Yes. Not receiving a demand letter yet doesn't mean a site is compliant - it may just mean it hasn't been scanned yet.
Q: What should I do first?
A: Get a quick, no-obligation review of what's actually running on your site and how your consent banner behaves. That's usually enough to know where you stand.
Curious where your site stands? [Schedule a free 10-minute consultation] with General Legal's data privacy team.