Short answer: possibly, and it has nothing to do with anything unusual you're doing. If you're running a growing company without an in-house legal team, this is exactly the kind of thing that's easy to miss. Plaintiffs' firms are using a 1967 California wiretapping law to sue ordinary companies over routine tools like chat widgets, analytics, and ad pixels, and the exposure applies to any business with California site visitors, regardless of size.
What is CIPA, and why is it suddenly about cookies?
The California Invasion of Privacy Act (CIPA) is a decades-old law written to stop illegal phone taps. Plaintiffs' firms are now applying it to websites, arguing that a tracking pixel or session-recording tool "intercepts" a visitor's activity the same way a wiretap intercepts a phone call. Two fact patterns drive most current cases: tracking that fires the instant a page loads, before a visitor has made any choice, and tracking that keeps running even after someone clicks "Reject" on the cookie banner.
Am I actually at risk?
If your site uses a chatbot, session-recording software, or an advertising pixel (Meta, Google, TikTok, or similar), the underlying tools are in scope. This isn't just an enterprise problem. If you don't have someone in-house who can answer "is our tracking actually compliant," you're in the exact position these cases target. Plaintiffs' firms find targets through automated scans of public websites, not by singling anyone out, and growing companies without dedicated legal or technical review get swept in just as often as large ones. Statutory damages can run to $5,000 per violation, and courts don't always require proof of actual harm to let a claim proceed.
What's the fix?
In most cases, less than it sounds like. It usually comes down to making sure your cookie banner is a genuine gate, nothing fires until a visitor actually chooses, and that your privacy policy accurately describes what's running on your site. You don't need an in-house privacy team to get this right. Companies that address it are largely insulated from the theory these cases rely on.
Frequently Asked Questions:
Q: Does CIPA only apply to California companies?
A: No. It applies to any business with California site visitors, regardless of where the company is based.
Q: Is Google Analytics automatically a problem?
A: Not necessarily; it depends on backend configuration, like whether it's set to be used for advertising. Presence alone isn't proof of an issue.
Q: What's the difference between "clickwrap" and "browsewrap" consent?
A: Clickwrap requires an affirmative action (a click) before tracking starts; browsewrap just assumes consent from continued use. Courts increasingly treat browsewrap as insufficient.
Q: Can I get sued even if I haven't received a demand letter yet?
A: Yes. Not receiving a demand letter yet doesn't mean a site is compliant - it may just mean it hasn't been scanned yet.
Q: What should I do first?
A: Get a quick, no-obligation review of what's actually running on your site and how your consent banner behaves. That's usually enough to know where you stand.
Curious where your site stands? [Schedule a free 10-minute consultation] with General Legal's data privacy team.