If your website uses Google Analytics, HubSpot, Microsoft Clarity, a chat widget, or even a contact form powered by a third-party tool, you may be exposed to lawsuits under a California law written before the internet existed. It’s called the California Invasion of Privacy Act (CIPA), and right now it’s fueling one of the most aggressive privacy litigation waves in the country.
Here’s the uncomfortable part: it doesn’t matter whether you knew your website was tracking visitors. If the tracking is happening, you can be a target.
CIPA provides a private right of action with statutory damages of up to $5,000 per violation (or treble actual damages, whichever is greater), plus injunctive relief. Multiply $5,000 by every visitor to your website in a class action, and the math gets terrifying fast.
The tools being targeted are the ones almost everyone uses
This isn’t about shady data brokers or specialized surveillance tech. The lawsuits and demand letters name the everyday tools of digital marketing:
Analytics platforms. Google Analytics, Google Tag Manager, HubSpot Analytics, and Adobe Analytics all collect visitor behavior data and transmit it to third-party servers. Demand letters routinely include screenshots showing tracking data flowing in real time to Google Analytics, Meta Pixel, and HubSpot.
Session replay and heatmap tools. Microsoft Clarity, Hotjar, and FullStory record mouse movements, scrolling, and keystrokes to reconstruct a visitor’s session. Plaintiffs argue this is textbook interception of a communication.
Advertising pixels. The Meta Pixel, TikTok Pixel, and similar web beacons are among the most frequently named technologies, because they explicitly exist to share visitor data with an outside company.
Chatbots and live chat widgets. An entire wave of CIPA suits has claimed that third-party chat providers “eavesdrop” on conversations between visitors and websites, since the chat vendor sees (and often stores and analyzes) everything typed into the widget.
Forms and embedded tools with their own analytics. Here’s where it gets sneaky. Many form builders, scheduling tools, and marketing platforms bundle their own tracking into their embed code. You may have added a simple contact form and unknowingly deployed a third-party tracker along with it. CIPA plaintiffs don’t care that you didn’t know.
“But the courts are split, right?” Yes, and that’s exactly the problem
If you’ve read that CIPA website cases are getting mixed reviews in court, you’ve read correctly. The rulings in 2026 alone have been whiplash-inducing.
On the plaintiff-friendly side:
- In June 2026, a federal court granted final approval to a $3.85 million class settlement against the Los Angeles Times over three third-party trackers on its website and apps, alleged to violate CIPA’s pen register provision.
- Forbes Media agreed in principle to a $10 million settlement in a wiretapping suit alleging its website trackers sent identifiers like IP addresses to third parties without adequate consent.
- In Ortiz v. Foris Dax (the Crypto.com case, May 2026), a federal court issued one of the most thorough analyses to date and concluded that CIPA’s pen register provision does apply to internet tracking.
- In a case against CNN, a federal judge in New York allowed a CIPA class action to proceed, finding that aggregating tracking data into detailed, non-anonymous user profiles resembles the traditional privacy tort of intrusion upon seclusion.
On the defense side:
- In Blaker v. NetScout Systems (May 2026), a Los Angeles Superior Court judge dismissed pen register claims with prejudice, holding that CIPA’s pen register and trap-and-trace provisions apply to telephone communications, not software on commercial websites. The court reasoned that the internet was in widespread use when these provisions were added in 2015 — if the legislature had meant to cover websites, it would have said so.
- In Sisti v. Bosley (April 2026), a federal court tossed all CIPA claims with prejudice, finding that browsing behavior and device identifiers weren’t sensitive enough to constitute a concrete privacy injury.
- A near-identical tracking case against USA Today was dismissed by a Northern District of California judge just days before the CNN ruling went the other way.
Read that again: courts have reached opposite conclusions on essentially identical facts, sometimes within days of each other. In one striking stretch in April 2026, four rulings in ten days split down the middle. A federal court approved the LA Times settlement three weeks after a state court dismissed a nearly identical claim with prejudice.
For plaintiffs’ attorneys, that uncertainty isn’t a bug — it’s the business model. As long as some courts let these claims survive, demand letters keep working, and many businesses settle rather than gamble on which judge they’ll draw.
The consent trap: your cookie banner probably isn’t saving you
Here’s the detail that trips up even privacy-conscious businesses. Having a cookie banner is not the same as having tracking that actually waits for consent.
In Garcia v. Anschutz Entertainment Group (May 2026), AEG had a consent banner — but its third-party cookies fired the moment a visitor landed on the site, before the banner even loaded. The court let the CIPA pen register claim survive. The consent mechanism existed; it just arrived after the data was already flowing.
This is the default configuration on an enormous number of websites. Google Tag Manager fires all tags on page load. Analytics starts collecting instantly. The banner pops up a second or two later. In the eyes of a CIPA plaintiff, those first few seconds are the violation.
Recent litigation increasingly focuses on this gap between the consent experience users see and what the site technically does: banners that let pixels fire before interaction, or preference centers that record a choice but never actually propagate it to the tracking scripts.
Who’s at risk? Probably more businesses than you’d think
You don’t have to be based in California. If California residents can visit your website — and they can — you’re potentially exposed. Businesses across the country have received demand letters. And the volume is staggering: more than 800 CIPA claims were filed in 2025 alone, with a steady stream of demand letters that never make it to the courthouse.
The typical playbook: a demand packet arrives with a cover letter, a draft complaint ready for filing, and screenshots showing your site transmitting visitor data to Google Analytics, Meta, HubSpot, or similar tools. The implicit message is “settle now or we file.” Some serial plaintiffs send these packets in bulk — one filed 21 lawsuits in the first half of 2026 from a much larger stack of demand letters.
And CIPA is spreading conceptually, too. Plaintiffs are pairing these claims with the federal Wiretap Act, Florida’s and Pennsylvania’s wiretapping statutes, and other theories, turning what started as a California problem into a multistate litigation campaign.
Is relief coming? Maybe — but don’t count on it yet
California legislators have noticed. Senate Bill 690 would amend CIPA to add a broad “commercial business purpose” exemption that would effectively shut down most of these website tracking class actions. The bill stalled in 2025, but it’s moving again — amended language was heard in an Assembly committee in July 2026, and its odds of passing appear to have improved.
Meanwhile, two California Courts of Appeal are poised to issue the first appellate rulings on whether CIPA’s pen register provisions reach website tracking at all. Either decision could reshape the landscape — but rulings could take a year or more.
Until the legislature or the appellate courts settle the question, CIPA remains an active, enforceable law, and the lawsuits keep coming.
What you can do right now
The good news: the highest-risk configuration — third-party tracking with no functioning consent mechanism — is fixable. Steps worth taking:
- Audit your tracking stack. Inventory every third-party script, pixel, SDK, chat widget, and embedded form on your site. Use the same free scanning tools plaintiffs use to find targets. Pay special attention to tools you embedded for one purpose (a form, a scheduler) that quietly include their own analytics.
- Fix the timing, not just the banner. Configure your tag manager so tracking scripts don’t fire until after a visitor consents. A banner that appears while Google Analytics is already collecting data offers little protection.
- Verify consent actually propagates. Test that an opt-out genuinely stops the tags from firing across your whole site, including embedded third-party widgets.
- Update your privacy policy and website terms. Disclosures should match your technical reality — every tracker, every third party. Consider terms that include a class action waiver and arbitration clause.
- Look hard at chat and session replay. These tools draw disproportionate litigation attention because they capture the content of user interactions, not just metadata. Weigh whether the insight is worth the exposure, and at minimum disclose them clearly and get consent before they activate.
- Treat tracking as regulated infrastructure, not a marketing setting. The businesses getting caught aren’t villains — they’re companies where marketing installed a pixel and legal never heard about it. Bringing those teams together is the single biggest risk reducer.
The bottom line
CIPA litigation sits in a strange place: the legal theory is genuinely contested, courts are openly split, a legislative fix is pending, and appellate clarity is on the horizon. But none of that helps you if a demand letter lands in your inbox next week. The law is on the books, plaintiffs are actively enforcing it, and “I didn’t know that tool was tracking anyone” is not a defense.
If your website collects visitor analytics — knowingly or not — now is the time to find out exactly what’s firing, when it fires, and whether your visitors ever actually said yes.
This post is for general informational purposes and isn’t legal advice. If you’ve received a CIPA demand letter or want to assess your exposure, talk to a privacy attorney.

