Short answer: possibly, and it has nothing to do with anything unusual you're doing. Plaintiffs' firms are using a 1967 California wiretapping law to sue ordinary companies over routine tools like chat widgets, analytics, and ad pixels—and the exposure applies to any business with California site visitors, not just companies doing anything wrong.
What is CIPA, and why is it suddenly about cookies?
The California Invasion of Privacy Act (CIPA) is a decades-old law written to stop illegal phone taps. Plaintiffs' firms are now applying it to websites, arguing that a tracking pixel or session-recording tool "intercepts" a visitor's activity the same way a wiretap intercepts a phone call. Two fact patterns drive most current cases: tracking that fires the instant a page loads, before a visitor has made any choice, and tracking that keeps running even after someone clicks "Reject" on the cookie banner.
Am I actually at risk?
If your site uses a chatbot, session-recording software, or an advertising pixel (Meta, Google, TikTok, or similar), the underlying tools are in scope. Risk isn't limited to large companies—plaintiffs' firms can find targets through automated scans of public websites, not by singling anyone out. Bigger, higher-traffic sites tend to be attractive targets, but smaller companies are being swept in too. Statutory damages can run to $5,000 per violation, and courts don't always require proof of actual harm to let a claim proceed.
What's the fix?
In most cases, less than it sounds like. It usually comes down to making sure your cookie banner is a genuine gate—nothing fires until a visitor actually chooses—and that your privacy policy accurately describes what's running on your site. Companies that get this right are largely insulated from the theory these cases rely on.
Curious where your site stands? [Schedule a free 10-minute consultation] with General Legal's data privacy team.
- Plaintiffs' firms are using CIPA, a 1967 California wiretapping law, to sue ordinary companies over routine website tools like chat widgets, analytics, and ad pixels.
- The exposure applies to any business with California site visitors regardless of where the company is based, and doesn't require the company to be doing anything unusual.
- The two fact patterns driving most cases are tracking that fires before a visitor makes any consent choice, and tracking that keeps running after a visitor clicks "Reject" on the cookie banner.
- Statutory damages can run to $5,000 per violation, and courts don't always require proof of actual harm before letting a claim proceed.
- The fix is usually straightforward: make the cookie banner a genuine gate where nothing fires until a visitor chooses, and ensure the privacy policy accurately describes what's actually running on the site.
| What CIPA is | A 1967 California wiretapping law now being applied by plaintiffs' firms to argue that tracking pixels and session-recording tools "intercept" website visits like a wiretap intercepts a call. |
|---|---|
| Who's at risk | Any business with California site visitors, regardless of location or size, though higher-traffic sites tend to attract more attention. |
| The two trigger patterns | Tracking that fires the instant a page loads, before any visitor choice, and tracking that keeps running after a visitor clicks "Reject." |
| Financial exposure | Statutory damages can reach $5,000 per violation, and courts don't always require proof of actual harm to let a claim proceed. |
| The fix | Make the cookie banner a genuine gate so nothing fires until a visitor chooses, and make sure the privacy policy accurately reflects what's actually running. |
| Detection risk | Plaintiffs' firms find targets through automated scans of public websites, so not receiving a demand letter yet doesn't mean a site is compliant. |
Does CIPA only apply to California companies?
No. It applies to any business with California site visitors, regardless of where the company itself is based.
Is Google Analytics automatically a problem?
Not necessarily; it depends on backend configuration, such as whether it's set to be used for advertising. Presence alone isn't proof of an issue.
What's the difference between "clickwrap" and "browsewrap" consent?
Clickwrap requires an affirmative action, like a click, before tracking starts. Browsewrap just assumes consent from continued use, and courts increasingly treat browsewrap as insufficient.
Can I get sued even if I haven't received a demand letter yet?
Yes. Not receiving a demand letter doesn't mean a site is compliant; it may just mean it hasn't been scanned yet.
What should I do first if I'm worried about exposure?
Get a quick review of what's actually running on your site and how your consent banner behaves. That's usually enough to know where you stand.
