A lot of business owners outside California read about CIPA lawsuits and think the same thing: that’s not my problem.
They assume California laws apply to California companies. They’re wrong, and the courts have made that very clear.
Your Location Doesn’t Determine Your Exposure
CIPA wasn’t written to regulate California businesses. It was written to protect California residents.
The law doesn’t ask where your company is headquartered. It asks whether a California resident visited your website and had their data intercepted without consent. If the answer is yes, you’re exposed — regardless of where your office is or where your servers sit.
A few things to keep in mind:
- California has nearly 40 million residents
- Any public-facing website almost certainly receives California visitors
- The law applies the moment a CA resident’s data is collected without consent — wherever you’re based
The Ninth Circuit Made This Official
In May 2025, the Ninth Circuit Court of Appeals issued a landmark decision in Briskin v. Shopify that settled the question.
Shopify, a Canadian company, was found subject to California jurisdiction for installing tracking cookies on a California resident’s device without consent. The court also eliminated a prior standard that required businesses to have specifically “targeted” California. The new standard is simpler and broader:
- You don’t need to focus on California or treat it differently from other states
- You just need to knowingly collect data from California residents
- Any website running analytics or tracking tools is almost certainly doing that already
That ruling didn’t get much mainstream coverage. For businesses outside California, it should have.
What Actually Triggers the Exposure
The mechanism is straightforward. A California resident visits your site. Your tracking tools fire and transmit data to a third party before the visitor has given consent. That’s the violation.
Common tools that create this exposure include:
- Google Analytics
- Meta Pixel
- Live chat and chatbot platforms
- Session replay software
- Call tracking systems
It doesn’t matter that you’re based in Nashville or Chicago or Miami. What matters is that the data was collected, and a California resident was involved.
SB 690 Was Supposed to Help. It Didn’t.
California legislators recognized the problem. Senate Bill 690, introduced by Senator Anna Caballero, would have created a “commercial business purpose” exemption under CIPA, protecting routine tools like analytics and chat features from wiretapping claims.
Here’s where things stand:
- The bill passed the California Senate 35 to 0
- It stalled in the Assembly in July 2025 and was shelved as a two-year bill
- An earlier retroactivity provision — which would have covered pending lawsuits — was stripped before the Senate vote
- As of mid-2026, SB 690 remains in limbo; even if it passes, it won’t take effect before 2027
Waiting for a legislative fix isn’t a strategy. Lawsuits are still being filed, and the timeline for any relief keeps moving.
What Businesses Should Do Now
Whether your company is in California or not, the practical steps are the same:
- Identify which third-party tracking tools are active on your site
- Confirm whether those tools fire before or after visitor consent is captured
- Verify that your cookie banner actually blocks scripts, not just displays a notice
- Make sure your privacy policy reflects what’s actually happening on your site
These aren’t complicated changes. They just require someone to look. Most businesses haven’t done that yet.
How Social Spice Media Can Help
Social Spice Media works with businesses across the country to evaluate website tracking configurations and implement consent frameworks that hold up under scrutiny.
If you’ve assumed geography protects you from CIPA exposure, now is the right time to take a second look. Reach out to the Social Spice Media team to schedule a compliance consultation.
Up Next in the Series
Part 3 takes on one of the biggest misconceptions we see: the belief that having a cookie banner means you’re covered. Spoiler — most banners aren’t doing what business owners think they are. We’ll break down the difference between a decorative pop-up and a consent management platform that actually protects you. The Broken Banner: Is Your Cookie Consent Actually Working? coming soon.
Sources:
- Briskin v. Shopify: Ninth Circuit Broadens Jurisdiction Over Out-of-State Data Collectors — McDonald Hopkins LLP
- California SB 690 Stalls in Assembly: CIPA Liability Remains at Least Through 2026 — Duane Morris LLP
- Updates on CIPA Reform: CA SB 690 Progresses to the Assembly — Benesch Law
- CIPA Claims Surge: What Every Company with a California-Facing Website Must Know — Jackson Walker















