Website privacy demand letters with legal documents gavel money and data protection symbols

A One-Page Letter, a Draft Lawsuit, and a Five-Figure Ask: The Website Privacy Demand Wave Every Business Should Understand

A manufacturer in the Midwest that sells almost exclusively to other businesses opens its email and finds a demand letter accusing it of illegal wiretapping. Attached is a draft lawsuit and a set of screenshots of its own website. The sender isn’t a regulator or a competitor. It’s a private individual in California, someone the company has never done business with demanding money to make the claim go away.

If that scenario sounds far-fetched, it isn’t. Thousands of businesses and nonprofits across the country have received nearly identical letters over the past year, and a large share of them trace back to a single sender. Understanding what’s behind this campaign and what to do if a letter lands on your desk has become an unavoidable part of running a website in 2026.

What’s Actually Happening

Vivek Shah, a prolific claimant, has been mailing demand letters at scale, by some estimates in the thousands between the fall of 2025 and mid-2026, with no sign of stopping. Mr. Shah’s activities were mentioned during a July 2026 hearing in Sacramento for SB 690 a proposed law we support that may reduce but not stop these lawsuits. Each letter accuses the recipient’s website of violating California’s decades-old wiretapping statute through the everyday tracking technology that sits on almost every modern site: cookies, pixels, analytics tags, and session-recording tools.

What makes the wave so unsettling is how indiscriminate it is. Targets have included schools, auto dealerships, retailers, mining and manufacturing companies, and businesses that sell only to other businesses. Some recipients have no obvious connection to California at all. The common thread isn’t industry or geography it’s simply having a website that collects information from visitors. In practice, that’s nearly everyone.

Why Cookies are Being Called “Wiretapping”

The legal hook is the California Invasion of Privacy Act, or CIPA. The law is not new; it has prohibited unauthorized wiretapping for close to sixty years. What is new is applying a statute written for phone lines to the plumbing of the modern web.

The theory works like this. When a visitor interacts with a website, say, by typing a term into a search bar, the site often passes that activity to third parties such as analytics providers. Plaintiffs argue that transmitting a user’s data to an outside party, without first getting the user’s clear opt-in consent, is the digital equivalent of tapping a communication line. Cookies and tracking pixels, on this reading, become the wiretap.

Courts have not settled the question, which is precisely why the letters keep coming. Uncertainty is leverage.

Anatomy of a Demand Letter.

The mechanics of these demands are strikingly consistent. The claimant reportedly visits a target’s website and uses a feature like the search bar, sometimes typing something as casual as his own first name in capital letters and then alleges that the site passed on that input to a third party like an analytics service. That interaction becomes the basis for the claim.

The letter itself is usually brief: a single paragraph, a draft complaint ready to file, and screenshots offered as proof. The threat is to file in state court or in arbitration if the website’s terms of use happen to contain an arbitration clause, unless the business pays to drop the matter.

There’s also a shifting legal foundation underneath the campaign. Early letters leaned on CIPA’s classic anti-wiretapping provision, which targets intercepting communications or helping a third party do so. More recently, the theory has migrated to a different section of the statute aimed at “pen register” and “trap and trace” devices – tools historically used to capture the numbers dialed from a phone. Some courts have been willing to stretch that language to cover website cookies; others have flatly rejected the idea. That split is the whole ballgame, and it’s currently unresolved.

The Number That Gets People’s Attention

CIPA allows statutory penalties of up to $5,000 per violation. On a single website with meaningful traffic, “per violation” math escalates quickly, and class actions built on these theories have historically settled in the high six figures and sometimes into seven. Even when an individual demand is smaller, the cost of ignoring it can be far larger. That asymmetry, a modest ask backed by an expensive worst case — is what pushes some businesses to simply pay.

It’s worth noting that the picture isn’t one-sided. At least one federal court has tossed one of these claims for lack of standing, though that ruling is now on appeal at the Ninth Circuit. The claimant has typically represented himself when pursuing CIPA claims directly but has used an attorney when moving to compel arbitration. None of that makes a letter safe to ignore, but it does mean these claims can be and are being contested.

If a Letter Shows Up, Resist Both Extremes

The two instinctive reactions are usually the wrong ones. Throwing the letter in a drawer invites escalation. Firing off a response directly to the sender can hand ammunition to the other side. The sounder path is to loop in counsel who has actually dealt with this type of claim and knows the claimant’s patterns, then decide on strategy from a position of information rather than panic.

One practical, do-it-now step: document your website exactly as it exists on the day the letter arrives. Capture your current tracking technologies, cookie banner, privacy policy, and terms of use. If you later decide to change anything, you’ll want a clear record of what your practices were at the moment the demand was made.

Turning the Threat into a Compliance Upgrade

Whether or not a letter ever reaches you, the smartest response to this wave is to close the gaps it targets. Think of it as an audit you were probably overdue for anyway.

Know what’s actually running on your site. Inventory every pixel, cookie, analytics tool, and session-replay script. For each one, be able to answer three questions: what data does it collect, who receives that data, and what do they do with it? Most organizations are surprised by how long that list turns out to be.

Make your disclosures do real work. A banner that vaguely says the site “uses cookies to improve your experience” is not the same as one that tells visitors their data may be shared with third parties for advertising. Disclosures should describe who receives the data and how it’s used, and they should appear before a visitor hands anything over.

Give people a genuine choice. Visitors should be able to opt in or opt out, and opting out should be exactly as easy as opting in. This idea, sometimes called symmetry of choice, matters. The strongest defensive posture is often withholding third-party data sharing until a user affirmatively clicks to allow it, rather than firing trackers the moment the page loads.

Stay current. This area of law is moving fast, and a position that looks safe today can shift with the next appellate ruling. Treat website privacy compliance as an ongoing practice, not a one-time project.

Get advice before you act. Don’t respond to a demand or change your site until you’ve spoken with someone who regularly handles these issues. The right sequence of moves depends heavily on the specifics of your site and your situation.

The Bigger Picture

For years, the compliance conversation around business websites centered on accessibility and the steady stream of ADA-related litigation. This privacy wave is a reminder that the risk surface has widened. The same trackers that power analytics and advertising can now attract a very different kind of legal attention, and the businesses least prepared are often the ones who assumed a low-profile, B2B site made them invisible.

The good news is that the defensive playbook and the good-practice playbook are largely the same. A site that’s transparent about what it collects, honest about who it shares data with, and respectful of a visitor’s right to say no is both harder to target and simply better for the people who use it. In a landscape where the next demand letter could arrive in anyone’s mailbox, building that kind of site is well worth the effort.

Share: