Moz Pro - Research, Refine & Rise in AI Search. Start Your FREE 7-Day Trial

CIPA Demand Letters Are Piling Up for Small and Local Businesses

Cookiebot by Usercentrics discusses why website tracking tools are pulling small businesses into a wave of privacy litigation, and what agencies should check before a letter arrives.
CIPA Demand Letters Are Piling Up for Small and Local Businesses
[Source: DesignRush]
Article by reviewed by Enrique Jose TabuenaMarta Janosi
|

Roughly 70% of wrongful data collection claims now cite the California Invasion of Privacy Act, or CIPA, according to cyber insurer Coalition.

More than 1,500 CIPA lawsuits were filed in the 18 months prior to August 2025, according to Security Boulevard's tracking of court filings, more than 1,000 of them in 2025 alone.

That is why a letter citing CIPA deserves a serious look. The law dates to 1967. It was written for telephone wiretapping, decades before websites existed.

The penalty is steep. A business can face $5,000 for every instance a tracking tool collects visitor data before consent, or three times actual damages, whichever is greater.

Furthermore, no harm has to be proven for the penalties to be enforced, per the California Penal Code.

According to Melanie Baker at Cookiebot by Usercentrics, that low bar is exactly why small and local businesses are increasingly the ones opening these letters.

Cookiebot is a consent management platform built to address exactly this kind of tracking risk.

In this DesignRush interview, Baker also covers what to check before a letter ever lands.

designrush

Who Is Melanie Baker?

Melanie Baker is a tech industry veteran who has spent her career writing and editing across a range of companies, from early-stage startups to major tech firms.

Her work centers on where privacy regulation, tech innovation, and the real-world business landscape intersect.

Small Sites Are the Easiest Targets

Demand letters are automated at scale now. Tools crawl websites for common tracking technology, and the pipeline that turns a scan into a letter runs with little human input.

So why do small businesses end up in that pipeline so often?

"Small businesses are a really large pool, and the economics favor volume," Baker says.

And here's the part few business owners expect. A company does not need California customers or a California office to be included. A publicly accessible website is enough.

That same scale works against businesses once a letter arrives, not just before.

"Small businesses are particularly vulnerable given they often don't have a lot of in-house resources to fully understand the threat and fight it," Baker says.

"An agency may have helped with their tracking setup, and they probably don't have legal counsel on staff, or dedicated compliance personnel."

That combination makes a letter feel more threatening than it might otherwise, and it pushes many businesses straight to settlement.

Settling at scale, not winning any single case, is the business model behind these letters.

CCPA Compliance Isn't CIPA Protection

CIPA and CCPA are both California laws, but they serve different purposes. CCPA is a notice-and-choice framework.

Businesses generally don't need prior consent to collect data, but they must offer rights like access, correction, deletion, and the ability to opt out.

"It's enforced by the Attorney General and the California Privacy Protection Agency, not by individual lawsuits, and its private right of action, where individuals can sue companies directly, is narrow, limited to data breaches," Baker explains.

CIPA works differently. Any individual can sue directly, without a regulator involved.

"The claim isn't about a consumer's right to opt out of a data sale, but whether a third-party tool intercepted a communication before the visitor's consent was obtained, like a search term or chat message," she adds.

In effect, any tracking that fires before consent is potentially a CIPA violation.

"That pushes businesses toward an opt-in model closer to what the GDPR requires than anything typical under current U.S. privacy law," Baker says.

That is why a fully CCPA-compliant business can still be exposed under CIPA. The two laws address different concerns, so meeting one does not satisfy the other.

What to Do After the Letter Lands

Evidence preservation comes first. HAR and page snapshots, tag inventories, and existing consent records need to be captured before the website changes at all.

From there, the letter itself needs to go in front of privacy litigation counsel, not a marketing team or a generalist attorney.

"Talk to qualified counsel, especially if a letter actually arrives. Don't ignore it, but don't rush to respond or change your website either," Baker says.

A demand letter is not a lawsuit yet. It is an invitation to settle before litigation begins. That window closes fast, though. Firms typically file within weeks of a missed deadline.

Insurance review belongs in that same conversation with counsel.

"It is worth checking early whether cyber liability or general liability coverage responds to CIPA claims, since gaps discovered mid-litigation are costly," Baker says.

The technical fix, the pixel or script that fired without consent, comes after both pieces are settled.

"Only once those two pieces are settled should the technical fix come next," she adds.

Settling without remediating leaves a business exposed to the next letter from the next firm. A standing playbook, built before any letter arrives, closes that exposure.

CIPA won't be the last statute read this way, so the pressure will resurface elsewhere even if this particular threat fades.

"Deciding in advance who reviews a letter, within what timeframe, and what the escalation path looks like beats assembling a plan under a 20-day deadline," Baker says.

"Again, not legal advice. Talk to counsel both about building the plan and about any letter you actually receive."

One Browser Tab Reveals the Exposure

Fixing the problem is one thing. Spotting it before a letter arrives is another, and it takes less time than most agencies assume.

Asked what would be a good start, Baker says a good start for pretty much anyone would be to run a website scan with the Cookiebot™ cookie scanner.

That surfaces every active cookie and tracker along with its compliance status. For a closer look, she recommends a five-minute network audit.

That means opening the client's site in a private browser window.

After that, open the network tab before touching anything, and then reload and watch what fires before any interaction with the consent banner.

"That list, the live chat and chatbot widgets, session replay or heatmap tools, and ad or analytics pixels with behavioral tracking, is the exposure map, since the latest lawsuits focus specifically on firing order," Baker explains.

She also adds that scripts firing before a visitor confirms consent give plaintiffs grounds to argue the interception already occurred, regardless of what happens afterward.

The second check matters just as much. It tests whether the consent banner truly blocks anything before a visitor responds.

"A banner that displays but doesn't block is the most common failure, and it's arguably worse than having no banner at all, since it creates the appearance of compliance while the underlying scripts keep running," Baker says.

A Consent Platform Only Works Going Forward

A consent management platform (CMP) does not undo a violation already alleged.

"Courts have generally held that CIPA requires prior consent, which means that retroactive consent doesn't help," Baker says.

"If tracking already fired before consent on a past visit, installing or fixing a CMP today doesn't erase or mitigate that."

What it does change is the risk going forward.

A CMP that gates third-party tracking behind prior consent, Cookiebot by Usercentrics is one example, reduces the basis for further unauthorized-interception claims.

Cookiebot's product homepage.

Sequence matters too. Changing the site or deleting logs right after a letter arrives can make it harder to establish what actually happened, so review comes before remediation.

That review should also confirm if the old setup was blocking anything at all.

"A CMP set up for CCPA compliance, for example, quite likely wasn't blocking before consent because that's not a CCPA/CPRA requirement in most cases," Baker explains.

Once counsel has reviewed the letter and the setup, fixing or properly configuring the CMP becomes the more durable protection against future letters and demands.

This article reflects a professional perspective on consent management and is not legal advice. Businesses facing a CIPA demand letter should consult qualified legal counsel.

👍👎💗🤯
Latest Cybersecurity News
Receive our NewsletterJoin over 70,000 B2B decision-makers growing their brands