It’s one of the most common things we hear when small business owners ask about CIPA: “I get like 200 visitors a month. Nobody’s going after me.”
We get it. But that logic is exactly backwards, and understanding why could save your business from a lawsuit you never saw coming.
Privacy Attorneys Aren’t Browsing the Web. Their Bots Are.
These firms use automated software that scans thousands of websites per minute, reading source code for specific tracking scripts. Common targets include:
- Meta Pixel (Facebook Pixel)
- Google Analytics
- LinkedIn Insight Tag
- Live chat and chatbot platforms
- Session replay tools
If your site has one of those scripts firing without proper consent, it gets flagged. The bot doesn’t care how many visitors you get. It cares whether the code is there.
The Math Is What Makes Small Sites Attractive
Under CIPA, damages are $5,000 per violation, per visitor tracked without consent. Large companies fight back and litigate. Small businesses settle, because a $5,000 to $15,000 payout is cheaper than a defense attorney. Plaintiff firms have built entire practices around that reality.
Even low traffic creates real exposure. Ten California visitors tracked without consent is $50,000 in statutory damages. That number can sink a small business before a case ever reaches a courtroom.
How Tracking Code Ends Up on Your Site Without You Knowing
The scripts creating exposure usually weren’t put there with bad intentions. They accumulated over time while everyone’s attention was somewhere else.
Zombie marketing pixels. An agency installs a Meta Pixel for a campaign. The campaign ends, the agency is gone, but nobody removes the code. That pixel keeps firing quietly for years until a bot finds it.
Third-party plugins that bundle trackers. A lot of free WordPress and Shopify plugins quietly bundle tracking scripts inside their code. Installing a simple contact form may have given a third party permission to drop cookies on every visitor to your site.
Piggyback trackers from embedded content. Embedding a YouTube video or Google Map brings tracking ecosystems along with them. You wanted to show a map. The map dropped advertising cookies on your visitors without any action on your end.
Malicious code injection. Hackers insert unauthorized scripts into vulnerable websites. These behave exactly like marketing cookies, except the data goes to a criminal’s server.
What Actually Protects You
There’s really only one reliable fix: a consent setup that blocks scripts from firing until a visitor explicitly says yes. That means:
- A properly configured Consent Management Platform, not just a banner that displays a notice while scripts keep running
- Tags set to wait for consent before firing
- Opt-out signals that actually reach every connected vendor
- Consent records stored with timestamps
CIPA doesn’t make exceptions for good intentions. If the script fired and a California resident’s data was collected without consent, the violation already happened.
Where to Start
Most of the time, the fix comes down to configuration, not cost. The bigger challenge is knowing what’s actually running on your site in the first place. Most businesses have more in the background than anyone on the team is aware of.
Not sure what’s firing on your site? Reach out to our team for a compliance consultation. We’ll walk through exactly what’s there and what needs to change before a bot finds it first.















