Insights · Privacy

The new wave of website-privacy lawsuits — and how to get ahead of it

A decades-old California wiretapping law is being aimed at ordinary websites over the tracking tags almost every site runs. The exposure is real — and largely preventable with the right setup. Here's what's happening, who's at risk, and the fix we now build for clients.

Not legal advice. Generation Web builds, hosts, and maintains websites — we're not a law firm. This article is informational. It describes technical safeguards that materially reduce litigation risk; it doesn't eliminate legal risk, and your final privacy-policy language should be reviewed by your own counsel.

Over the past two years, a handful of plaintiff law firms turned a 1960s California criminal statute into a high-volume litigation business — aimed not at hackers, but at everyday websites running ordinary analytics and marketing tags. If your site loads tracking before a visitor opts in, you have some exposure. The good news: it's an engineering problem, and engineering problems we can fix.

What's actually happening

The law is the California Invasion of Privacy Act, or CIPA — written decades ago to stop telephone wiretapping. The new theory stretches it onto the web: the third-party tools sitting on almost every modern site (Google Analytics, ad pixels, marketing trackers, chat widgets, booking and checkout embeds) "intercept" a visitor's data without consent, making them illegal "wiretaps" or "trap and trace devices."

The reason this became a business is the math. CIPA carries statutory damages of $5,000 per violation — counted per visitor or per visit. Multiply that across a site's traffic and even a mid-sized business is looking at a paper liability in the six or seven figures. That number isn't really the goal; it's leverage. It pressures defendants into quick settlements, usually tens of thousands of dollars, whether or not anyone was actually harmed.

The playbook is industrialized:

  1. Automated scanning crawls sites to detect which trackers fire before a visitor consents.
  2. "Tester" plaintiffs visit flagged sites — sometimes hundreds — generating the "interception" they'll later sue over.
  3. Demand letters and mass-filed claims arrive, citing the per-violation damages.
  4. Settlement pressure does the rest. The settlement, not a trial, is the model.
Targets are chosen for collectability and traffic — not for wrongdoing. Being right is small comfort if defending it costs more than settling.

Why "California" reaches your site

CIPA protects the communications of California residents — but you don't have to be in California to be sued. You only need California visitors. Any site with meaningful U.S. traffic is in scope, and California-based organizations with California customers are the most attractive targets of all. Filings climbed from roughly 54 in 2022 to about 675 in 2024, with more than 1,500 in the 18 months ending mid-2025 — and many more matters settle quietly before they ever reach a public docket.

Who's most at risk

Exposure rises with sensitive data, deep pockets, and high traffic. The hardest-hit groups:

  • Healthcare and health-adjacent — clinics, therapy, health insurance, wellness commerce. The most-targeted sector nationally.
  • Regulated finance — banks, credit unions, insurers, advisors, law firms.
  • Consumer brands and e-commerce — anyone running ad pixels, checkout, or accounts.
  • Travel, tourism, and hospitality with third-party booking embeds, where real personal data flows to an outside vendor.
  • Government and public-adjacent sites — high traffic, sensitive interactions.

But honestly, the line is simpler than the list: if your site loads marketing or analytics trackers before a visitor opts in — the default for most sites — you have some exposure.

What the fix looks like

Here's the part that matters: this is largely preventable, and the defense is well understood. A CIPA tracking claim is defeated by prior, informed consent — the visitor agreeing before the trackers fire. That's a configuration problem, and it's exactly what we build.

We recently took a tourism client with online ticketing through this after a peer in their industry was sued. What we found was typical: Google Analytics, Tag Manager, a marketing tracker, and a third-party booking embed all firing before any consent was collected — and no privacy policy in the footer. What we did is the framework we now offer every client:

  1. Privacy & tracking scan — a full inventory of every tag, pixel, and embed, and where personal data is going.
  2. A consent management platform with a real Accept / Reject / Customize banner.
  3. A true consent gate that blocks analytics and marketing trackers until the visitor opts in — not a cosmetic banner that sets a cookie after the pixels have already loaded.
  4. Google Consent Mode v2, defaulting to "denied."
  5. Tag audit and minimization — remove what you don't need; shrink the attack surface.
  6. A privacy & cookie policy disclosing every third party, with a footer link, for your counsel to review.
  7. Ongoing consent logging — a dated record that you acted in good faith.

The distinction that matters legally: consent has to come before the trackers fire. A banner that merely records a click while the pixels have already loaded doesn't establish the prior consent that defeats a CIPA claim. The gate, not the banner, is the defense.

What to do now

  1. Assume you have trackers firing pre-consent. Almost every site does.
  2. Know where your risk concentrates — your booking, checkout, contact forms, and chat are where real personal data leaves your site for outside vendors.
  3. Put a real consent gate in place before a demand letter forces a rushed, expensive scramble.
  4. Document it. A timestamped remediation and consent log is itself a defense.
  5. Have counsel review your final privacy policy and overall position.

Acting proactively costs a fraction of a settlement — and unlike a settlement, it actually fixes the problem. If you'd like us to scan your site and show you what's firing before consent, reach out and we'll take a look.

Want to know what's firing before consent on your site?

We'll scan your site, inventory the tags and embeds collecting visitor data, and show you exactly what a real consent gate would change — before a demand letter ever arrives.