A CIPA demand letter is a private claim under the California Invasion of Privacy Act alleging that a tracking script on your website recorded a visitor before they agreed. It is not a government action. The leverage is statutory damages of $5,000 per violation under section 637.2. Do not reply before a lawyer reads it, preserve the site, and find every script that fires before consent.
What the letter is, and what it is not
The California Invasion of Privacy Act, CIPA, is Penal Code sections 630 to 638.55. The legislature passed it in 1967 to stop phone tapping and eavesdropping. The letter on your desk applies that statute to a piece of JavaScript.
Three sections do the work. Section 631(a) makes it unlawful to read the contents of a communication in transit without consent, and, in the clause aimed at you, to aid, agree with or conspire with anyone who does. The letter calls the pixel or session-replay vendor the eavesdropper and calls you the party who aided it by installing the code.
Section 632.7 covers communications involving a cellular or cordless phone, and shows up in letters about chat widgets opened from a mobile browser. Section 638.51 prohibits installing a pen register or a trap and trace device without a court order. The letter argues that a script recording IP addresses, device details and referrer data is such a device.
The leverage is section 637.2. It lets a person sue for $5,000 per violation or three times actual damages, whichever is greater, and states that no actual damage is required. Multiply $5,000 by the visits a firm can plausibly claim and you have the reason the letter exists.
Now what it is not. It is not a government enforcement action, and neither the Attorney General nor the California Privacy Protection Agency is involved. It is not a finding that you broke the law; it is one person's claim, through a firm, that no court has examined yet.
Firms send these letters at volume, and the filed cases show the scale. Suitcast's search of CourtListener records for the Act and for pen register claims returned 455 civil dockets in federal district courts between 2025-09-12 and 2026-09-09, after removing 160 criminal pen register and appellate dockets that the same search pulls in. Not every one of them is about a website; the lawsuits data counts only those verified as website cases. The filings concentrate in California: the Northern District of California holds 173 of them and the Central District of California 113. Letters are not filings, and most letters never become a docket, so the true volume is larger than any count.
Why your site was picked
Your site loads a third-party script before the visitor answers a consent banner, or without any banner at all. That is the whole selection method. Firms run automated tools that open a page, record which requests leave the browser before any click, and flag sites where a pixel, a session-replay recorder or a chat widget fires at load.
The scripts named most often are Meta Pixel, which sends page views, clicks and sometimes form entries to Meta; Microsoft Clarity and Hotjar, which record mouse movement, scrolling and typing into a replay; TikTok Pixel; and chat widgets such as Intercom, Drift and LiveChat, which store conversations. The live counts by script, drawn from complaint text, are on the trackers page and update daily.
Three things raise a site's odds. A California audience, since the claim depends on a visitor in California whose visit was recorded. A form, a chat box or a checkout, since typed content supports the section 631 theory better than page views alone. And a banner that shows but does not block, which is common on Shopify and WordPress sites where the app was installed outside the consent tool.
The letter often includes a screenshot from a browser network panel or a report from a scanning tool, with timestamps. That is the plaintiff's evidence that the script fired before consent. You want your own version of that evidence, dated today, which is the second item in the next section. Suitcast's methodology page describes how the free scan records requests to known tracking scripts with their timing, then clicks reject when the banner offers it and lists what keeps firing.
In Suitcast's pull of federal filings, the same handful of firms account for most of the volume. Bursor & Fisher appears on 55 civil dockets in the last 12 months, Nathan & Associates on 26, Gutride Safier on 22, Tauler Smith on 21 and the Law Offices of Ross Cornell on 19, per the firms page. If the letterhead matches one of those names, the firm has done this many times and the letter is a template.
What to do in the first week
Do not reply before a lawyer reads it. A reply that says "we had no idea the pixel did that" is an admission that the pixel did that. A reply that asks what they want signals you will pay. Silence for a week costs nothing; the letter's deadline is set by the firm, not a court.
Preserve the site as it is today. Take full-page screenshots of the home page, any page with a form, the checkout and the privacy policy, with the date visible. Export the script list from your tag manager or theme. Run a scan and save the report, so the record shows exactly which requests fired, when, and whether a banner was present.
Identify every script and when it fires. Open the site in a fresh private window with the browser's network panel recording, and note every third-party host that receives a request before you touch the banner. Then click reject and repeat. Do this on a product page and a page with a form, not only the home page.
Gate or remove. For each script, decide whether it earns its place. If it does, set it to load only after accept: Shopify's customer privacy banner, a WordPress consent plugin such as Complianz or CookieYes, or Google Tag Manager consent mode with the right consent signal on each tag. If nobody looks at the recordings or the ads have ended, remove it.
Keep the record. Save the before and after scans, the change log from your tag manager and the date each change went live. Each new visit after the letter can be argued as a new violation, so the date you closed the gap matters.
Check your insurance. Cyber, media liability and some general liability policies cover privacy claims, and the duty to defend is often broader than the duty to pay. Send the letter to your broker inside the notice window in the policy.
Talk to a lawyer who has handled CIPA matters. Not your business lawyer, unless they have. The defenses, the settlement patterns and the current state of the pen register theory are specialized, and a lawyer who has handled a dozen of these letters knows what the firm on the other side accepts.
What it usually costs
Settlement amounts in these matters are almost always confidential, and I have not found a public source that supports a specific range for individual demand letters, so I do not print one. What can be said honestly is structural. A pre-suit settlement is typically small relative to the cost of defending a filed case through a motion to dismiss, and firms price letters with that gap in mind.
The costs you can estimate are on your side. A lawyer's review of the letter and a first response is a few hours of time. Gating or removing scripts is a developer afternoon on most Shopify and WordPress sites. A scan and captures are free.
The variable that moves the number most is exposure going forward. A firm that sees the script still firing a month after the letter has a stronger claim than one that sees it gated the week the letter arrived. The pricing page sets the cost of weekly re-scans against one hour of legal time; the point is that the scan is cheaper than the hour.
Two things reduce cost that owners often skip. Insurance, covered above, can shift the defense cost entirely. And a written record that the script was installed by a platform app with the banner on, rather than by you deliberately, supports the argument that you did not knowingly aid anything, which is the intent element in section 631.
How these cases have gone in court
Mixed, and it depends on the theory. The section 631(a) aiding theory has survived motions to dismiss in many California federal cases where the script captured typed content or chat messages, and has been dismissed where the plaintiff could not show the third party captured contents rather than record data. The party exception, that a website owner cannot eavesdrop on its own conversation, covers the owner directly but not the vendor, which is why the letter frames you as the aider.
The section 638.51 pen register theory is newer and less settled. Between 2024 and 2026, federal district courts split on whether an IP address collected by a script is the kind of routing information the statute covers and whether a visitor who volunteered it by opening the site has standing. Some courts let the theory proceed; others dismissed it. I am not linking a single ruling here because the landscape changes monthly, and any one case would be out of date by the time you read this. SB 690, described below, would take this theory away from private plaintiffs for websites and apps if it becomes law.
Most filed cases end in settlement before a ruling on the merits, which means the published decisions skew toward the contested minority. The California filings page lists current federal dockets with links to their CourtListener records, so you can read the complaint that most closely matches your letter and see how far it got.
A legislative note. SB 690 passed the California Legislature on August 28, 2026 and was presented to the Governor on September 4, 2026. As passed, it lets only the Attorney General sue over pen register claims under section 638.51 that arise from a website or an app, and it applies to pending claims in actions filed within two years before it takes effect. It does not change the wiretap claim under section 631. Ask your lawyer whether it has been signed and how it affects your letter.
Reply yourself, hire a lawyer, or ignore it
The decision most owners face by day three. Here is how the three options compare on the things that matter.
| Option | What it costs now | What it risks | When it fits |
|---|---|---|---|
| Reply yourself | Nothing | Admissions in writing, a signal you will pay, no privilege on what you say | Almost never; at most an acknowledgment of receipt with no substance |
| Lawyer replies | A few hours of fees, often covered by insurance | Little; a letter that raises the party exception and standing usually resets the negotiation | The default for any letter naming a firm on the firms page |
| Ignore it | Nothing now | A filed complaint, service costs, and a default judgment if you keep ignoring it | Never as a strategy; only if your lawyer advises that the letter is defective |
The same table exists for the script itself. Gate it if you use it, remove it if you do not, and never leave it as is while you wait, because each day adds visits to the claim.
One more choice: whether to change the privacy policy. Adding a disclosure after the fact does not cure past recordings and can read as an admission that the earlier policy was incomplete. Let the lawyer decide the wording and the timing.
Limitations
This guide covers the letter pattern visible in federal court records. It does not cover California state court filings, which Suitcast tracks only partially through curated sources, as the data page explains. It does not cover the separate consumer claims some firms add, such as unfair competition or intrusion upon seclusion, which change the analysis.
The court split described above is a summary, not a survey. Rulings on the pen register theory are issued every month, and a summary written in September 2026 will be behind by the time you read it. Read the current dockets on the California page and ask your lawyer about the most recent decisions in your district.
Nothing here is legal advice, and a scan does not determine whether any script violates any statute. The scan shows what a complaint would cite; it does not stop anyone from filing. The not legal advice page says this in full, and the scanner policy describes what the scan does and does not load. If you received a letter, the next step is a lawyer, not a tool.
The related guide on which tracking scripts appear most in website privacy lawsuits explains what each script records and how to gate it, and the guide on ADA website lawsuit letters covers the other letter type owners receive.
Suitcast identifies risk indicators. It is not legal advice and does not determine compliance.
Last updated September 13, 2026.
