Education, not advice

The privacy laws that actually reach your website.

Plain-English explanations of the US laws that apply to tracking and cookie consent — what each one covers, who it applies to, and what a demand letter actually claims. Read this, then check your site. This is education, not legal advice.

Current as of August 2026 · The figures here are general information, not advice about your situation.

★ The one a demand letter actually cites

CIPA

California Invasion of Privacy Act · Cal. Penal Code §§ 630–638.51

CIPA is a wiretapping statute, not a data-protection regulation. It predates the web — it was written about telephone wiretapping — and has been extended to electronic communications. Plaintiffs use it to sue over tracking technology that reads or records a visitor's activity before they've agreed to anything.

Why a two-person business gets a letter

There's no revenue threshold and no consumer-count trigger. Unlike CCPA, nothing about CIPA scales with the size of your company. The smallest site is in scope, and that's exactly why the letters go where they go.

And you don't have to be in California

This is the part most business owners don't know until it happens to them. CIPA is a California statute, but it reaches communications to or from California — which means a business in Florida, or Ohio, or anywhere else, with a website a Californian can load, can find itself on the receiving end of a claim under a law it has never heard of, from a plaintiff it has no other connection to.

Who it binds

Anyone communicating to or from California. There is no revenue floor and no consumer-count trigger, so none of the thresholds that keep a small business outside CCPA apply here.

What it requires

Everyone in a conversation has to agree before it's recorded or intercepted. In practice, the claim is that screen recorders, chat widgets and advertising pixels “intercept” or “record” what a visitor types, where they move their mouse, and what's on the page — before that visitor has agreed to anything.

The tracker angle

It's rarely “cookies” in the abstract. It's screen recorders, keystroke capture, and advertising pixels from other companies. Most claims cite some combination of the sections listed below.

Penalties

A private plaintiff's remedy for CIPA violations, including pen-register claims, runs through § 637.2: the greater of $5,000 per violation or three times actual damages, plus injunctive relief. The per-violation structure is what makes exposure scale so fast — the number that matters isn't the per-violation figure, it's how many times a plaintiff says it happened.

What a demand letter alleges

  • § 631Wiretapping: reading or learning the contents of a communication in transit.
  • § 632Recording a confidential communication.
  • § 632.7Intercepting a communication involving a cellular or cordless telephone. It shows up in some website claims by analogy, but § 631 and § 638.51 are the theories carrying the wave.
  • § 638.51The pen register / trap-and-trace provision, which has become the theory plaintiffs increasingly favor. It doesn't require reading the contents of anything — the allegation is that the tracking technology captured routing or signaling information about the visitor. Courts are split: some federal courts have let these claims proceed, while California state trial judges have more often read the provision narrowly in website cases.

The reform nobody should plan around yet

California SB 690 has been under consideration since 2025, and its scope has changed across amendments. As of August 2026 it has not passed. Meanwhile demand-letter volume has gone up, not down, since it was introduced, and it has reached businesses nobody would have predicted: nonprofits, B2B companies, small food businesses, the foreign parents of US subsidiaries. Courts have begun pushing back on the highest-volume senders.

A bill that hasn't passed is not a plan, and we're not going to characterize what it would do to your exposure. Ask your counsel.

How Consentinel helps

Hold the recorder until your visitor agrees. Check in a real browser that it didn't run. Keep a dated record linking every consent to the exact banner that visitor saw — one nobody can edit afterwards. That isn't a legal conclusion — it's a technical record of what your site did and when, of the kind your lawyer would otherwise have to reconstruct after the fact.

Education, not legal advice. Statutes and enforcement change — confirm current text and talk to a lawyer for your situation.

Scan your site free

Consentinel provides software and documentation, not legal advice. Nothing on this page creates an attorney-client relationship or guarantees compliance, and statutory figures are general information that may have changed. Talk to a lawyer about your situation.