If you run a business with a website, and let’s be honest, that’s every business, there’s a new legal threat you need to know about. It has nothing to do with data breaches or hackers. It’s a decades old wiretapping law being used against ordinary websites, and it’s already cost California organizations well over a billion dollars.
The Law: CIPA, Reimagined for the Internet Age
The California Invasion of Privacy Act (CIPA) was written in 1967, long before websites, cookies, or chat widgets existed. It was designed to stop illegal wiretapping, such as phone taps and hidden recording devices. Today, plaintiffs’ attorneys have found a way to stretch that language to cover ordinary website tools like Google Analytics, marketing pixels, session replay software, and even live chat plugins. They argue these tools function as illegal “pen registers” or “trap and trace” devices that intercept visitor data without consent.
The result is a wave of demand letters and lawsuits hitting businesses, nonprofits, churches, food banks, school districts, and even local news outlets. These organizations were simply using standard, widely available website technology.
The Numbers Are Staggering
According to Reform CIPA, a coalition of California businesses and nonprofits pushing back on this trend, the damage is significant. More than a billion dollars has already been lost to these lawsuits and demand letters, an estimated 120,000 businesses and nonprofits are considered at risk, and roughly 50,000 organizations have already faced the choice of paying up or getting sued.
Independent legal trackers back up the trend. Filings under CIPA’s wiretapping provisions have exploded, growing from just 54 cases in 2022 to more than 2,800 in 2025, bringing the cumulative total to nearly 3,000 lawsuits in a little over three years. For every lawsuit that becomes public record, attorneys are estimated to send another 10 to 15 demand letters that get quietly settled and never see a courtroom. Typical settlement demands range from $10,000 to $25,000, though some have reportedly gone much higher.
It’s Not Just a California Problem
While CIPA is a California statute, the fallout isn’t staying within state lines. Similar digital wiretapping claims have now been filed in 28 states, and any business with website visitors from California, regardless of where the company is headquartered, can be a target. If your site collects visitor data through analytics, advertising pixels, or chat tools and even a single visitor is browsing from California, you could be exposed.
Recent settlements illustrate just how costly this can get. The LA Times paid $3.85 million over claims involving website and app tracking technology, and Inova Health settled for $3.1 million after tracking pixels on its site allegedly shared patient data without consent. Those are large, high profile cases, but the same legal theory is being used against small businesses and nonprofits with a fraction of those resources available for defense.
Why This Keeps Happening
Fighting one of these claims in court is often more expensive than settling, even when a business believes it did nothing wrong. That imbalance is exactly what’s fueling the surge. Plaintiffs’ firms know most organizations will pay rather than litigate, and once a business settles, it isn’t uncommon for a different firm to send another demand letter shortly afterward.
There is a legislative fix in motion. California’s SB 690 aims to modernize CIPA and clarify that routine website tools should be governed by modern privacy laws, such as the California Consumer Privacy Act (CCPA), rather than a 1960s wiretapping statute. The bill has been advancing through committee, but as of now it has not become law. Even if it passes, it will not eliminate the exposure businesses face in the meantime.
What You Can Do Now
Waiting for legislation is not a strategy. The organizations that are best protected today are the ones that have proactively reviewed their websites for tracking technology, implemented a compliant consent management system, and ensured that no scripts run until a visitor actively opts in. That approach is fundamentally different, and far more defensible, than the implied consent setup many websites still use.
If you haven’t had your website evaluated for CIPA exposure, now is the time to do it, before a demand letter arrives in your inbox. A short technical audit can tell you exactly where your site stands and what it would take to close any gaps.
Your website shouldn’t be the reason your organization ends up writing a five figure settlement check for using the same analytics tools everyone else does. Get ahead of it.















