If you have a website, there’s a legal trend you need to understand right now. Over the last few years, thousands of ordinary businesses – retailers, healthcare providers, media companies, local services, and B2B firms – have been sued or hit with demand letters over something most of them didn’t even know they were doing: loading tracking tools like Google Analytics and advertising pixels before a visitor agrees to it.
The frustrating part? In most cases the business did nothing malicious. They installed the same analytics and marketing tools that nearly every website uses. But under an ever-evolving set of privacy laws, that ordinary setup has become a legal target – and a lucrative one for the lawyers and plaintiffs who go looking to exploit it.
Here’s a clear breakdown of what’s happening, who’s exposed, why it matters, and what you can actually do about it:
What Are These Laws, Exactly?
Most of these lawsuits are built on wiretapping and electronic surveillance laws that were written decades ago – long before modern websites existed – and are now being applied to web tracking technology.
The most active battleground is the California Invasion of Privacy Act (CIPA). Plaintiffs are using two main theories:
- The “wiretapping” theory (CIPA § 631). This older theory argues that tools like tracking pixels and “session replay” software (which records how you move your mouse, scroll, and type on a page) illegally “intercept” a visitor’s communications with the website.
- The “pen register” theory (CIPA § 638.51). This is the newer and faster-growing wave. A “pen register” was originally a device that recorded the numbers dialed from a telephone. California Penal Code § 638.51(a) makes it unlawful to “install or use a pen register” without a court order or the user’s consent. Plaintiffs argue that the third-party trackers on your website – the scripts that fire the instant a page loads and quietly send a visitor’s IP address and device / browser identifiers off to Google, Meta, ad networks, and analytics vendors – are effectively modern pen registers” capturing “routing, addressing, and signaling information.”
Whether that argument is correct is unsettled (more on that below). But the legal theory is real, it’s being filed in volume, and the defending against it costs real money and time.
Disclaimer: Canned Spinach is not a law firm, and this post is general information, not legal advice. The reason this topic is on our radar is that our CEO, Andrew Savitz, serves on ACT’s Member Advisory Board, an organization that researches and promotes policy environments that reward innovation while helping companies raise capital, create jobs, and keep building great technology. Data privacy is one of ACT’s core policy priorities, and how websites collect and share user data is becoming an increasingly large area of focus in the policy world. That vantage point is a big part of why I want our clients and network to get ahead of where this is heading.
Who Does This Apply To?
This is the part that surprises most business owners: it probably applies to you.
You don’t have to be a big tech company or a Fortune 500. You don’t even have to be based in California. These laws are written to protect California residents, so if your website can be visited by someone in California – which is virtually every public website – you’re potentially in scope.
You are most likely exposed if your site does any of the following – and almost every modern site does at least one:
- Uses Google Analytics or any analytics platform
- Runs advertising or conversion pixels (Google Ads, Meta / Facebook, TikTok, The Trade Desk, etc.)
- Uses retargeting, attribution, or audience-building tools
- Loads third-party scripts, tags, or SDKs that fire automatically on page load
- Has no cookie consent banner, or has one that doesn’t actually block trackers until the visitor opts in
Industries that have been hit especially hard include healthcare, retail and eCommerce, media and entertainment, financial services, and travel – but the demand-letter campaigns increasingly are targeting small and mid-sized businesses across every sector, precisely because smaller companies are more likely to settle quickly.
Why It Matters: The Risks of Non-Compliance:
1. The damages are designed to hurt
Under California Penal Code § 637.2, a plaintiff can seek statutory damages of $5,000 per violation – or three times actual damages, whichever is greater. Critically, the plaintiff does not have to prove they suffered any actual harm.
Now do the math. When a “violation” can be argued on a per-visitor basis, a website with thousands of California visitors faces a theoretical exposure that climbs into the millions very quickly. That math is the entire engine behind the settlement pressure.
2. This has become an organized cottage industry
According to the law firm Fisher Phillips, more than 5,000 companies have already been sued or sent CIPA demand letters. Many of these claims are driven by a small number of plaintiffs’ firms and “serial plaintiffs” who use automated tools to scan large numbers of websites, detect trackers firing without consent, and then send out demand letters or file suit in bulk. Law firms now publish guides specifically on how to respond to these demand letter campaigns.
Because so many of these claims are resolved quietly – through pre-suit settlements or private arbitration – the publicly filed lawsuits are just the tip of the iceberg.
3. Even “winning” is expensive
Settlements in the broader website tracking litigation wave have been substantial. Reported examples include the Los Angeles Times’ $3.85 million settlement, Inova Health’s $3.1 million settlement over tracking pixels on a healthcare site, Fubo’s $3.4 million settlement, and a $1.2 million settlement involving GameSpot / Fandom – all tied to claims that trackers shared visitor data without proper consent. (Source)
4. The legal landscape is shifting
Courts are currently divided, and the trend has actually been moving in defendant’s favor. Several courts have recently pushed back hard on the pen-register theory. In May 2026, a Los Angeles Superior Court judge dismissed a pen-register claim, reasoning that the statute was written for telephones, not commercial websites. Federal courts have dismissed cases on standing grounds (Popa v Microsoft. Khamooshi v. Politico) and on the merits (Cole v. Quest Diagnostics, Torres v. Prudential). California appellate courts are expected to provide clearer guidance soon.
And here’s the point that’s easy to miss: winning is still loosing, financially. Even when a business ultimately prevails, getting there means months of litigation, attorney’s fees that can run well into five or six figures, document discovery, and a steady drain on leadership’s time and attention. A “win” on paper can still cost you a small fortune and a lot of sleep. The plaintiffs and firms running these campaigns know that – it’s exactly why the model works. They’re betting that defending yourself is painful enough that you’ll pay to make it go away, regardless of the merits.
So why act if the tide may be turning? Two reasons. First, “the law is unsettled” is not the same as “you’re safe” – federal district judges have been largely willing to let these claims proceed, outcomes still vary by court, and a pending demand letter costs you money and time regardless of how an appeal eventually shakes out. Second, the single most reliable defense across all of these theories is consent. Where courts have ruled for defendants on the merits, a recurring reason is that the visitor consented before tracking occured (see Lakes v. Ubisoft). Getting consent right doesn’t just reduce your risk – it removes you from the “easy target” list these plaintiffs are scanning for in the first place.
What The Policy World Is Saying
This concern isn’t only coming from the businesses on the receiving end of these letters. It’s being raised at the policy level, too. Graham Dufault, General Counsel at ACT | The App Association, the organization whose global advisory board I serve on, put it plainly:
Unscrupulous opportunists are seeking to distort CIPA, a telephone surveillance law originally enacted in 1967, claiming that everyday third-party analytics tools on websites and apps are “pen registers” or “trap and trace devices.” This is proof that laws with broad private rights of action are open invitations for trial lawyers to develop new theories of liability and small businesses are the favorite target. We cannot let them succeed. Website operators and app developers use consent mechanisms and disclosures that comport with consumer expectations, context, and modern privacy laws. A law from the ’60s should not be read to suddenly undo more recently enacted privacy laws designed for the digital age just so that plaintiffs’ attorneys can be enriched at the expense of small businesses.
Graham Dufault, General Counsel, ACT | The App Association
That last point is the practical takeaway for business owners. You can’t control how the courts ultimately resolve this question, and you can’t stop a demand letter from landing in your inbox. What you can control is whether your website uses clear consent mechanisms that match what visitors actually expect and what modern privacy law is built around. That’s what moves you out of the target pool, and it’s very fixable.
How to Protect Your Business (and Drastically Reduce the Risk)
Nearly every one of these claims hinges on the same technical fact: third-party trackers fire the moment your page loads, before the visitor has agreed to anything. Fix that, and you pull the rug out from under the entire theory.
A properly configured cookie consent and consent-management system does exactly that. Done right, it:
- Blocks third-party trackers from firing until the visitor opts in. This directly removes the “tracking without consent” hook the lawsuits depend on.
- Captures and documents valid consent, which is the strongest defense courts have recognized.
- Brings your site in line with where privacy law is clearly heading – not just CIPA, but the growing patchwork of state privacy laws (CCPA / CRPA and a dozen-plus others) that are converging on the same principle: get permission before you collect and share.
- Takes you off the serial-plaintiff radar, since automated scanners are specifically looking for sites where trackers fire pre-consent.
The good news is that this is not a massive, expensive overhaul. It’s a targeted, one-time fix.
Let’s Get Your Site Compliant – It’s Easier Than You Think
For most websites, getting properly set up takes Canned Spinach just a handful of hours, with minimal time or effort required from you. We handle the technical configuration so your trackers behave the way the law expects – collecting consent first, firing second – and documenting it properly. It’s a small, one-time investment to take a real and growing legal exposure largely off the table.
If you’d like to understand your specific risk or talk through what this would look like for your site, we are very happy to jump on a call to discuss. Reach out and we’ll walk you through it – no pressure, just an informative conversation about protecting your business.
Frequently Asked Questions
It’s a lawsuit alleging that a website used third-party tracking technology – like analytics scripts or advertising pixels – to capture a visitor’s routing and device information without consent, in violation of California’s pen register statute (Penal Code § 638.51) Plaintiffs argue these trackers function like the “pen registers” the law was originally written to regulate.
No. These laws protect California residents, so any website that California visitors can access may be in scope, regardless of where the business is located.
California law allows statutory damages of $5,000 per violation (or three times actual damages), with no requirement to prove actual harm. Reported settlements in the broader website tracking wave have ranged from roughly $1 million to nearly $4 million, and even early settlements of weaker claims commonly reach tens of thousands of dollars.
A consent banner only helps if it’s configured correctly – meaning it actually blocks third party trackers from running until the visitor opts in, and documents that consent. A banner that appears but lets trackers fire away provides little protection and is exactly what plaintiffs look for.
Yes – the law is currently unsettled, and several recent rulings have favored businesses. But outcomes still vary by court, demand letters cost money and time regardless of how cases eventually resolve, and properly captured consent remains the most reliable defense across every version of these claims.
This article is provided for general educational purposes and does not constitute legal advice. For advice about your specific situation, consult a qualified attorney. Canned Spinach helps businesses implement the technical consent management and tracking configuration measures that reduce privacy litigation risk.
Sources & Further Reading
- California Penal Code § 638.51 (pen register prohibition)
- California Penal Code § 637.2 (statutory damages)
- Holland & Knight – Uncertainty Continues in California on CIPA Section 638.51 Claims: https://www.hklaw.com/en/insights/publications/2026/02/uncertainty-continues-in-california-on-cipa-section-63851-claims
- Fisher Phillips – Courts Still Divided on Whether California Privacy Law Applies to Website Tracking: https://www.fisherphillips.com/en/insights/insights/courts-still-divided-on-whether-california-privacy-law-applies-to-website-tracking
- Inside Class Actions – 2025 Website Wiretapping Roundup: https://www.insideclassactions.com/2026/01/27/2025-website-wiretapping-roundup/
- CIPAWorld – California Superior Court Dismisses Website Tracking Claims: https://cipaworld.com/2026/06/01/cipa-win-california-superior-court-sustains-dismissal-of-website-tracking-claims-holding-cipas-pen-register-provisions-do-not-apply-to-routine-web-analytics-technologies/
- JMBM – CIPA Demand Letters Against Business Websites: How To Respond: https://articles.jeffer.com/2026/04/01/vivek-shah-cipa-demand-letters-against-business-websites-how-to-respond/
- Nixon Peabody – CIPA Trap and Trace Poses Litigation Risk: https://www.nixonpeabody.com/insights/articles/2024/04/03/cipa-trap-and-trace-poses-litigation-risk-for-businesses-with-public-facing-websites
- ACT | The App Association – Labelling Third-Party Tools as Wiretapping Will Negatively Impact Small Businesses: https://actonline.org/2023/07/19/labelling-third-party-tools-as-wiretapping-will-negatively-impact-small-businesses/

