Education, not advice
The privacy laws that actually reach your website.
Plain-English explanations of the US laws that apply to tracking and cookie consent — what each one covers, who it applies to, and what a demand letter actually claims. Read this, then check your site. This is education, not legal advice.
Current as of August 2026 · The figures here are general information, not advice about your situation.
CIPA
California Invasion of Privacy Act · Cal. Penal Code §§ 630–638.51CIPA is a wiretapping statute, not a data-protection regulation. It predates the web — it was written about telephone wiretapping — and has been extended to electronic communications. Plaintiffs use it to sue over tracking technology that reads or records a visitor's activity before they've agreed to anything.
Why a two-person business gets a letter
There's no revenue threshold and no consumer-count trigger. Unlike CCPA, nothing about CIPA scales with the size of your company. The smallest site is in scope, and that's exactly why the letters go where they go.
And you don't have to be in California
This is the part most business owners don't know until it happens to them. CIPA is a California statute, but it reaches communications to or from California — which means a business in Florida, or Ohio, or anywhere else, with a website a Californian can load, can find itself on the receiving end of a claim under a law it has never heard of, from a plaintiff it has no other connection to.
Who it binds
Anyone communicating to or from California. There is no revenue floor and no consumer-count trigger, so none of the thresholds that keep a small business outside CCPA apply here.
What it requires
Everyone in a conversation has to agree before it's recorded or intercepted. In practice, the claim is that screen recorders, chat widgets and advertising pixels “intercept” or “record” what a visitor types, where they move their mouse, and what's on the page — before that visitor has agreed to anything.
The tracker angle
It's rarely “cookies” in the abstract. It's screen recorders, keystroke capture, and advertising pixels from other companies. Most claims cite some combination of the sections listed below.
Penalties
A private plaintiff's remedy for CIPA violations, including pen-register claims, runs through § 637.2: the greater of $5,000 per violation or three times actual damages, plus injunctive relief. The per-violation structure is what makes exposure scale so fast — the number that matters isn't the per-violation figure, it's how many times a plaintiff says it happened.
What a demand letter alleges
- § 631Wiretapping: reading or learning the contents of a communication in transit.
- § 632Recording a confidential communication.
- § 632.7Intercepting a communication involving a cellular or cordless telephone. It shows up in some website claims by analogy, but § 631 and § 638.51 are the theories carrying the wave.
- § 638.51The pen register / trap-and-trace provision, which has become the theory plaintiffs increasingly favor. It doesn't require reading the contents of anything — the allegation is that the tracking technology captured routing or signaling information about the visitor. Courts are split: some federal courts have let these claims proceed, while California state trial judges have more often read the provision narrowly in website cases.
The reform nobody should plan around yet
California SB 690 has been under consideration since 2025, and its scope has changed across amendments. As of August 2026 it has not passed. Meanwhile demand-letter volume has gone up, not down, since it was introduced, and it has reached businesses nobody would have predicted: nonprofits, B2B companies, small food businesses, the foreign parents of US subsidiaries. Courts have begun pushing back on the highest-volume senders.
A bill that hasn't passed is not a plan, and we're not going to characterize what it would do to your exposure. Ask your counsel.
How Consentinel helps
Hold the recorder until your visitor agrees. Check in a real browser that it didn't run. Keep a dated record linking every consent to the exact banner that visitor saw — one nobody can edit afterwards. That isn't a legal conclusion — it's a technical record of what your site did and when, of the kind your lawyer would otherwise have to reconstruct after the fact.
Education, not legal advice. Statutes and enforcement change — confirm current text and talk to a lawyer for your situation.
Scan your site freeBeyond California
Other state wiretapping statutes and federal wiretap lawCalifornia gets the attention because CIPA has the most developed body of website-tracking claims and the largest per-violation figures. But the underlying theory — that tracking technology intercepts a communication without consent — exists in other state wiretapping statutes too.
The practical takeaway
It's the same one this whole site is built on: where your business is registered doesn't determine which of these reaches your website. Who loads it does.
Who it binds
Wiretapping statutes generally reach communications to or from the state in question, and federal wiretap law applies nationwide. As with CIPA, the connection that decides it is where your visitor is — not where you are.
What it requires
Consent before intercepting or recording a communication. The consent standard varies by state: some require all parties to agree, others only one, and that difference is often what decides whether a website claim gets off the ground.
The tracker angle
The same shape of claim as CIPA — that tracking technology intercepted a communication, or captured information about it, before the visitor agreed to anything. The technology named is the same too: screen recorders, chat widgets, and advertising pixels from other companies.
Penalties
Florida's Security of Communications Act has supported website-tracking claims, and it carries statutory damages — the amount turns on how long the conduct ran, so ask your lawyer what it means for your situation. Federal wiretap law carries $10,000 or actual damages, whichever is greater.
How Consentinel helps
One approach answers all of them, because they all turn on the same fact: did the tracker run before your visitor agreed? Hold it until consent, check in a real browser that it was held, and keep a dated record nobody can edit — the same posture whichever law a claim is brought under.
Education, not legal advice. Statutes and enforcement change — confirm current text and talk to a lawyer for your situation.
Scan your site freeCCPA
California Consumer Privacy Act · Cal. Civ. Code § 1798.100 et seq.CCPA gives California consumers the right to know, delete, and opt out of the 'sale' or 'sharing' of their personal information. 'Sale' is defined broadly — it includes sharing data for cross-context behavioral advertising, not just money changing hands.
Who it binds
For-profit businesses processing CA consumers' personal information that meet a threshold: over $25M annual revenue, or data of 100,000+ consumers per year, or 50%+ of revenue from selling or sharing personal information.
What it requires
A 'Do Not Sell or Share My Personal Information' link if it applies to you, notice at the point you collect data, and a way to act on opt-out requests. Tracking that shares data with advertisers before consent can count as a sale.
The tracker angle
Pixels and trackers that send identifying information to advertising companies before consent fall squarely inside the 'sharing' definition. A banner that loads them anyway undermines the very right it's supposed to protect.
Penalties
$2,500 per violation, or $7,500 for an intentional violation or one involving a consumer under 16, assessed by the enforcing agency. Separately, a limited private right of action applies to certain data breaches, with statutory damages of $100–$750 per consumer per incident. That private right does not extend to the tracking and opt-out rules described above.
How Consentinel helps
A consent layer that holds advertising trackers until your visitor agrees, “don’t sell my data” browser settings honored automatically, and a preferences screen a visitor can actually read.
One honest limit: on a California opt-out we deny consent signals and clear cookies. If your site is advertising-heavy and depends on sale-or-share mechanics, talk to your counsel about what a complete Do-Not-Sell posture requires — cookie clearing is privacy hygiene, and it is not the same thing.
Education, not legal advice. Statutes and enforcement change — confirm current text and talk to a lawyer for your situation.
Scan your site freeCPRA
California Privacy Rights Act · CCPA as amended (effective 2023)CPRA expanded CCPA: it added a 'sensitive personal information' category, a right to limit its use, a correction right, a 12-month lookback for data-portability requests, and created the California Privacy Protection Agency (CPPA) as the dedicated enforcer.
Who it binds
Similar business thresholds to CCPA, with adjusted contract and service-provider definitions. The CPPA can investigate and fine even outside of breach incidents.
What it requires
Limit use of sensitive data (precise geolocation, biometrics, racial/ethnic data, browsing and purchase history) to what's necessary, plus honor opt-out preference signals for sale/share. Sensitive-data handling now has its own notice and consent lane.
The tracker angle
Trackers collecting precise geolocation or building cross-site behavioral profiles touch 'sensitive' and 'sharing' rules at once. Consent must be specific to the category, not a single blanket accept.
Penalties
Enforcement is administrative: the CPPA and the Attorney General can investigate and assess penalties under the CCPA structure ($2,500 per violation; $7,500 for intentional violations or those involving consumers under 16). There is no general private right of action for the rights described here.
How Consentinel helps
Consent by category, with sensitive data switched separately. Opt-out signals honored. A report showing which categories each tracker touched.
Education, not legal advice. Statutes and enforcement change — confirm current text and talk to a lawyer for your situation.
Scan your site free“Don’t sell my data” signals
Global Privacy Control — a browser opt-out signal, not a lawGPC is a technical standard: an HTTP header and a JavaScript property a browser sends to express the user's opt-out of 'sale' or 'sharing.' It isn't legislation, but California's regulations recognize an opt-out preference signal — and GPC is the one in practice.
Who it binds
Wherever CCPA/CPRA-style opt-out rules apply and the visitor's browser sends the signal. Coverage is widening as more states adopt opt-out-signal requirements.
What it requires
Treat a valid GPC signal as a binding opt-out request for sale/share — without requiring the visitor to also click a banner or find a link. Silently ignoring it is the risk.
The tracker angle
If a visitor has GPC enabled and your site still fires cross-context advertising pixels, that's an opt-out request your site ignored. The signal is the request; the banner is optional.
Penalties
No standalone GPC penalty, but ignoring it is evidence of a CCPA/CPRA opt-out violation. The exposure flows through the underlying law.
How Consentinel helps
We detect the signal and apply the opt-out automatically. Advertising trackers are held, your visitor doesn't have to touch the banner, and the action is recorded in the report.
The same honest limit as on the CCPA panel: when we apply a GPC opt-out we deny consent signals and clear cookies. If your site is advertising-heavy and depends on sale-or-share arrangements, talk to your lawyer about what a complete Do-Not-Sell position requires — clearing cookies is privacy hygiene, and it is not the same thing.
Education, not legal advice. Statutes and enforcement change — confirm current text and talk to a lawyer for your situation.
Scan your site freeOther states
A growing patchwork beyond CaliforniaBeyond California, a growing number of states have their own consumer privacy laws. Most require an opt-out — sometimes consent — for targeted advertising, sensitive data, and 'selling.' Several are starting to name profiling, fingerprinting and screen recording specifically. One consent setup, tuned to the strictest rule that applies to your visitors, is the practical answer.
Table current as of August 2026. Effective dates are general information, not advice about your situation.
Virginia CDPA
Opt-out for targeted ads, profiling, sale.
Colorado Privacy Act
Universal opt-out signal required; sensitive data consent.
Connecticut Data Privacy Act
Opt-out for targeted ads, profiling, sale.
Utah Consumer Privacy Act
Opt-out for targeted advertising and sale.
Texas Data Privacy & Security Act
Opt-out for targeted ads, sensitive data.
Oregon Consumer Privacy Act
Sensitive data consent; broad small-business coverage.
Florida Digital Bill of Rights
Children-focused; opt-out for sensitive data.
Montana Consumer Data Privacy Act
Opt-out for targeted ads, profiling, sale.
Delaware Personal Data Privacy Act
Opt-out for targeted ads, profiling and sale; consent for sensitive data.
New Hampshire Privacy Act
Opt-out for targeted advertising and sale.
New Jersey Data Privacy Act
Opt-out for targeted ads, profiling, sensitive data.
Iowa Consumer Data Protection Act
Opt-out for targeted ads; notice-based.
Nebraska Data Privacy Act
Opt-out for targeted ads, profiling, sale.
Minnesota Consumer Data Privacy Act
Opt-out for targeted ads and profiling.
Tennessee Information Protection Act
Opt-out for targeted ads, profiling, sensitive data.
Maryland Online Data Privacy Act
Strict data-minimization; sensitive data limits.
Indiana Consumer Data Protection Act
Opt-out for targeted ads, sensitive data.
Rhode Island Data Transparency and Privacy Protection Act
Opt-out for targeted ads, profiling, sale.
Kentucky Consumer Data Protection Act
Opt-out for targeted ads, profiling, sale.
How Consentinel helps
Most of these require an opt-out for targeted advertising, profiling and 'selling,' and several require honoring a universal opt-out signal. One consent setup, tuned to the strictest rule that applies to your visitors — which is what we build.
Education, not legal advice. Statutes and enforcement change — confirm current text and talk to a lawyer for your situation.
Scan your site freeConsentinel provides software and documentation, not legal advice. Nothing on this page creates an attorney-client relationship or guarantees compliance, and statutory figures are general information that may have changed. Talk to a lawyer about your situation.