A number of years ago, I wrote a series of articles for another well-known industry publication (Agency Sales from the Manufacturers’ Agents National Association) titled, “What Happens in California Doesn’t Necessarily Stay in California,” which focused on California laws that reach beyond the borders of the state. 

One such law, known as Proposition 65 (Prop 65), requires that consumers in California be warned of the health risks associated with hundreds of chemicals used in everyday products and environments. This law was (and likely still is) a bane to manufacturers and others who brought products to market, and a boon to sign and label makers everywhere. 

By now, everyone is familiar with labels on products — whether sold in California or in Maine — stating: “WARNING: Risk of cancer and reproductive harm from exposure to [name of chemical]. See P65 Warning.”

Violations of Prop 65 have resulted in numerous claims for statutory damages for each product sold that failed to bear the required warning. 

As I wrote in that earlier article series, while the underlying purpose of Prop 65 was sound — to protect the health and well-being of consumers — it became a nightmare in application because it provided a “private right of action” for individual consumers and their attorneys to bring, or threaten to bring, litigation against everyone in the stream of commerce selling such products, including manufacturers, distributors, dealers and even sales representatives. 

Since statutory damages included the recovery of attorneys’ fees incurred by the allegedly “harmed consumer,” suddenly there were attorneys and law firms that specialized in handling such cases, whose clients were “consumers” who purchased products online that did not yet have the necessary Prop 65 warning. 

Businesses throughout the country received demands from those firms or directly from the allegedly harmed consumer, threatening legal action unless the claim was immediately settled. After weighing the cost of hiring an attorney in California to defend the case and the possibility of losing and paying significant damages, including attorneys’ fees, many recipients chose not to fight and settled the claim. 

How CIPA became the new demand-letter tool

Regrettably, that same game plan is now being used by those who are sending letters to businesses, threatening litigation for their alleged violation of the California Invasion of Privacy Act (CIPA), a law passed in 1967. As with Prop 65, violations of CIPA can result in statutory damages of up to $5,000 for each individual violation, which can compound through digital tracking, together with the recovery of attorneys’ fees. 

It also provides a basis for self-help remedies for those who feel they have been victimized by someone violating CIPA. Also, similar to Prop 65, CIPA has a valid underlying purpose, namely to deal with illegal wiretapping and recordings of phone conversations. 

As noted by the California legislature in adopting this law 60 years ago: 

“The Legislature hereby declares that advances in science and technology have led to the development of new devices and techniques for the purpose of eavesdropping upon private communications and that the invasion of privacy resulting from the continual and increasing use of such devices and techniques has created a serious threat to the free exercise of personal liberties and cannot be tolerated in a free and civilized society.

“The Legislature by this chapter intends to protect the right of privacy of the people of this state.”

At this point, many of you undoubtedly are thinking, “What does this have to do with me and my business?” — especially if you are not in California, or engaged in wiretapping or the illegal recording of phone conversations. While that may be the case, never underestimate the ingenuity of someone trying to make a fast buck at your expense. 

Why website tracking tools are being targeted

The problem is that some alleged “victims” have discovered CIPA and are trying to repurpose it to apply to websites that use tracking technologies, such as cookies, pixels, tags and beacons, to collect and use personal information of people who visit these websites — just as many of you use in your company’s own website. 

As a result, these victims spend their days searching for websites they claim are noncompliant with CIPA, then send letters threatening litigation unless the claim is immediately settled. Typically, the settlement demand is less than the cost of defending the claim. As a result, many businesses decide it is better to settle than fight. 

Three ways to respond to a CIPA demand letter

Many of you likely already have had to deal with this issue. In the last couple of months, I have been contacted by several businesses that received such letters (including, in one instance, a letter enclosing a copy of a complaint ready to file in court). 

One such letter read as follows: 

“To Whomever This May Concern:

“This is regarding your violation of California’s [sic] Invasion of Privacy Act (CIPA), Cal. Penal Code § 638.5 1(a). You have installed and used multiple pen registers on your website without consent. Seeking injunctive relief, declaratory relief and statutory damages [sic]. The attached Complaint is prepared and ready to be filed with the Los Angeles Superior Court should this matter remain unresolved.”

If you or your business should be unlucky enough to receive such a letter, you have the following three courses of action:

1. Do nothing and see if anything happens. It is possible that the so-called victim has sent out so many letters he will forget about those who do not respond. And he will likely send a follow-up letter and a renewed demand before taking further action.

2. Respond to the demand letter and try to negotiate a settlement. The problem with this alternative is that you are now playing in the claimant’s ballpark according to his rules, where negotiations are not guided by typical business concerns. The claimant won’t be moved by your defenses. You will never convince him that his claim is baseless. He doesn’t care. Be prepared to spend $10,000 to $15,000 or more.

3. Fight, especially if you have valid defenses relating to the content of your website. In addition, there are various potential legal defenses. Yes, fighting in court will cost money, but perhaps not as much as you may fear. Also, many courts are now aware of these types of cases, especially multiple cases filed by the same plaintiff (claimant) and are dealing with them appropriately. 

When fighting back may make sense

For instance, in a recent decision (July 20, 2026) in the case of Vivek Shah v. Crain Communications, Inc. (Case No. 2:26-cv-03070-RGK-CTS), the U.S. District Court for the Central District of California, after noting that the plaintiff (Shah) had filed seven complaints against different defendants, which were all nearly identical to the complaint then before the court, and that all the prior cases had been dismissed voluntarily or by the court at the infancy of the case, ruled:

“For the foregoing reasons, the Court GRANTS Defendant’s Motion to Declare Plaintiff a Vexatious Litigant. The Court ORDERS as follows: 

“(1) The Court declares Plaintiff Vivek Shah a vexatious litigant; 

“(2) A Prefiling Order is hereby entered against Plaintiff for any new case filed in the Central District of California that alleges any claims arising under the California Invasion of Privacy Act … or other related digital privacy claims.” 

Note that this order is now the subject of an appeal.

While this is only one case in one jurisdiction, it provides guidance on how to attack such claims. There are also other cases in which CIPA claims have been defeated. So, if you do receive a letter regarding an alleged CIPA violation, please know that you may have legal recourse, provided that you wish to invest the time and resources necessary to defend any resulting litigation. 

In addition, as a strategic maneuver, you can take the initiative by initiating litigation against the claimant by filing a lawsuit for declaratory and injunctive relief (ask your attorney).

Finally, before receiving such a letter, you should ask your IT service, consultant or employee to audit your website to ensure it is fully compliant with the requirements of CIPA and other privacy protection statutes.