Businesses that operate commercial websites are increasingly receiving demand letters alleging that ordinary website technologies, including cookies, advertising pixels, analytics tools, session-replay software and other third-party scripts, violate state or federal privacy laws.

These claims can resemble the high-volume demand-letter litigation that businesses have encountered in other areas of law: a claimant visits a website, uses technical software to identify tracking technology, and then alleges that information was transmitted to a third party without legally sufficient consent.

The legal theories, however, are not all the same. A demand may invoke the California Invasion of Privacy Act (CIPA), the federal Electronic Communications Privacy Act (ECPA) and Wiretap Act, or several statutes at the same time.

Receiving such a demand does not establish liability. The strength of the claim often turns on what technology actually operated, what information was transmitted, when the transmission occurred, what role a third-party vendor played, and whether the visitor consented.

What Types of Website Technology Are Being Challenged?

Privacy claims have targeted a wide variety of ordinary website tools, including:

  • advertising and conversion pixels;
  • analytics cookies;
  • session-replay technology;
  • chat and customer-service widgets;
  • device or browser identifiers;
  • advertising and attribution software; and
  • third-party scripts that transmit information about a visitor’s activity.

A technical report accompanying a demand letter may show communications between the visitor’s browser and an outside company. But the existence of a third-party request does not, by itself, answer whether a particular privacy statute was violated.

The analysis can depend on what was transmitted. An IP address or technical routing identifier may raise different issues from a full URL revealing a search query, products viewed, information typed into a form, or other information reflecting the substance of the visitor’s activity.

Under the federal Wiretap Act, for example, an “intercept” concerns acquisition of the contents of an electronic communication, and the statute defines contents as information concerning the substance, purport or meaning of the communication.

CIPA Section 631: California’s Wiretapping Theory

California Penal Code section 631 prohibits specified forms of unauthorized interception or acquisition of communications and includes language concerning obtaining the “contents or meaning” of communications while they are in transit.

Website plaintiffs have attempted to apply section 631 to third-party tracking technology that allegedly receives a visitor’s communications contemporaneously with the website operator.

Consent and Timing Can Matter

Consent can be an important issue in website privacy litigation, but the existence of a privacy policy or consent banner does not necessarily resolve the analysis.

In Javier v. Assurance IQ, LLC, the Ninth Circuit concluded that consent obtained after an alleged interception could not retroactively authorize conduct that had already occurred under CIPA section 631.

Accordingly, disputes may focus on what information was allegedly collected or transmitted, when that occurred, what disclosures were presented to the visitor, and whether legally sufficient consent preceded the challenged conduct.

The analysis remains fact-specific. A website’s use of cookies or third-party technology does not by itself establish either the absence or existence of valid consent.

CIPA Sections 638.50 and 638.51: The “Pen Register” Claims

Another wave of California litigation relies on CIPA’s provisions governing a pen register or trap-and-trace device.

Section 638.50 defines a pen register in terms of a device or process that records or decodes dialing, routing, addressing or signaling information, but not communication contents. Section 638.51 generally prohibits installation or use of such a device without a court order, subject to statutory exceptions.

Plaintiffs have argued that modern software collecting IP addresses, device identifiers and related Internet routing information can constitute such a “process.”

CIPA presently provides a private civil remedy that may include $5,000 per violation or three times actual damages. Actual damages are not necessarily required.

That potential statutory remedy is one reason relatively small website-tracking disputes can generate significant settlement demands.

Federal ECPA and the Wiretap Act

A demand letter may instead, or additionally, rely on federal law.

The federal Wiretap Act, as amended by the Electronic Communications Privacy Act, generally prohibits specified intentional interceptions of wire, oral or electronic communications. A civil remedy is available under 18 U.S.C. section 2520.

The federal law differs from CIPA in several important respects.

One important provision, section 2511(2)(d), generally permits an interception where the interceptor is a party to the communication or one party has given prior consent. But this rule has an important exception where the communication was intercepted for the purpose of committing a criminal or tortious act.

This is commonly called the crime-tort exception.

What Does the Crime-Tort Exception Actually Require?

The exception does not automatically apply merely because the plaintiff alleges that the interception itself was unlawful.

The Ninth Circuit has held that the relevant inquiry is whether the defendant had a criminal or tortious purpose for the interception, separate from the interception itself.

In Sussman v. American Broadcasting Companies, Inc., the Ninth Circuit explained that where the means of obtaining information may itself be tortious but the purpose of the recording is not criminal or tortious, the federal exception does not necessarily apply. Later, in Planned Parenthood Federation of America, Inc. v. Newman, the Ninth Circuit again required a criminal or tortious purpose that was separate and independent from the recording itself and existed when the interception occurred.

Recent district court decisions applying that rule to website tracking have not been uniform.

For example, in Smith v. Rack Room Shoes, Inc., a Northern District of California court allowed a federal Wiretap Act theory to proceed where the plaintiffs alleged that tracking technology collected personally identifiable communications and that the retailer intended to use that information for advertising in a manner allegedly contrary to its privacy commitments.

Other courts have taken a narrower view of attempts to characterize routine commercial tracking or profit motives as the required independent tortious purpose.

The result is a developing area of law rather than a rule of automatic liability.

Federal Statutory Damages Are Not Simply “Per Cookie”

Demand letters sometimes cite the federal statutory-damages provision in 18 U.S.C. section 2520.

The statute permits appropriate civil relief, including attorney’s fees and, in appropriate cases, punitive damages. For most Wiretap Act actions, the court may assess the greater of actual damages plus violator profits or statutory damages calculated as the greater of $100 per day of violation or $10,000.

That language should not automatically be translated into “$10,000 for every cookie,” every network request or every page view.

The actual damages analysis depends on the claims, facts and applicable authority.

What Is SB 690, and Will It Eliminate These Cases?

California Senate Bill 690 is particularly important to the current wave of CIPA litigation, but its effect should not be overstated.

Earlier versions of the legislation contemplated a much broader commercial-business exemption. The bill was substantially narrowed in 2026.

Under the current July 2, 2026 version, SB 690 would amend Penal Code section 637.2 only. For a section 638.51 pen-register or trap-and-trace claim arising from conduct on a website, online application or mobile application, a civil action against a private actor could be brought under section 637.2 only by the California Attorney General.

The current bill also expressly provides for retroactive application to certain pending claims in actions commenced within two years before its operative date.

But the limitation is crucial: SB 690 does not presently eliminate CIPA section 631 claims, and it does not amend or eliminate federal ECPA or Wiretap Act claims.

Accordingly, even if SB 690 becomes law, a claimant may attempt to proceed under a different legal theory.

As of September 2026, SB 690 has passed the California Legislature and has been sent to Governor Gavin Newsom. It has not yet been signed into law. For further discussion, see California Passes SB 690: What Could Change for CIPA Website Claims?

What Should a Business Do After Receiving a Demand Letter?

A business receiving a website privacy demand should first identify the precise statutes and factual allegations being asserted.

Counsel may need to evaluate:

  • the particular cookies, pixels, software, or third-party technology identified by the claimant;
  • what information allegedly was collected or transmitted;
  • whether the information constituted communication contents, technical metadata, or some other category of data;
  • the timing and manner of the alleged acquisition;
  • the role of any third-party technology provider;
  • the disclosures, terms, and privacy policies in effect at the relevant time;
  • the asserted basis for consent or lack of consent;
  • whether the claimant can satisfy the statutory elements of CIPA, ECPA, or another asserted law; and
  • the claimed measure of statutory or actual damages.

Relevant technical evidence should be preserved before material changes are made to the website configuration involved in the dispute.

Practical Takeaway

Website privacy demand letters can create substantial pressure because claimants may rely on statutory-damages provisions and threaten class litigation.

But the absence of a cookie banner does not, standing alone, establish a violation of CIPA or federal ECPA.

The actual analysis can turn on the difference between contents and technical metadata, contemporaneous interception, consent, the role of third parties, the intended use of the data and the particular statute invoked.

Businesses receiving these demands should consider consulting experienced California litigation counsel promptly to assess the asserted claims, preserve relevant evidence, identify defenses and determine whether the matter is better contested or resolved through an appropriate negotiated settlement.

Legal Authorities

  • California Penal Code sections 631, 637.2, 638.50, 638.51
  • 18 U.S.C. sections 2510, 2511, 2520
  • Javier v. Assurance IQ, LLC
  • Sussman v. American Broadcasting Companies, Inc.
  • Planned Parenthood Federation of America, Inc. v. Newman
  • Smith v. Rack Room Shoes, Inc.
  • SB 690 (2025–2026 Reg. Sess.)

Related practice areas: Civil Litigation · Business and Commercial Litigation

This publication provides general information about California and federal law. It is not legal advice and does not address any particular person’s or business’s circumstances. Reading this publication or contacting the firm does not, by itself, create an attorney‑client relationship. The law in this area is developing, legislation referenced may change, and the outcome of any matter depends on its particular facts and applicable law.

Related Insights

← All Insights