CIPA Demand Letters: Cookies, Tracking, & Website Compliance

If your website loads analytics, ad pixels, chat widgets, or session-replay tools before a visitor consents, you could be a target for a California Invasion of Privacy Act (CIPA) demand letter. It doesn't matter where your business is based, only that California residents can reach your site. The fix is largely technical: block non-essential trackers until someone opts in, keep a record of that choice, and disclose what you're running. That's it.

Below is what's happening, why it's happening now, and what a compliant setup actually looks like.

Key takeaways

  • CIPA, a decades-old wiretapping law is being applied to modern website trackers, with $5,000-per-violation damages and no need to prove harm.
  • Location doesn't protect you. If California residents can reach your site, you're potentially in scope.
  • A properly configured consent solution is a documented defense against CIPA.
  • Timing is everything. Non-essential cookies must not fire before consent.
  • Consent management can go out of date. New tags mean new exposure, so sites that change often need ongoing coverage.

What is CIPA & why are these lawsuits suddenly everywhere?

CIPA isn't new; it was written in 1967 to deal with wiretapping and telephone surveillance. What's new is how plaintiffs' attorneys are using it. They have reframed everyday website tools, such as Google Analytics, Google Tag Manager, Meta Pixel, Microsoft Clarity, Hotjar, and similar trackers, as illegal "wiretapping" or "pen register" devices when those tools collect or share visitor data before consent is obtained.

What makes it so attractive is that CIPA pays $5,000 per violation with no need to prove anyone was actually harmed or injured. Pair that with the fact that the targeted tools like Google Analytics, the Meta Pixel, Hotjar, chat widgets sit on nearly every website, and attorneys have a low-risk, high-volume playbook.

What does a CIPA-compliant consent setup look like?

So how do you stay out of the crosshairs? For most organizations, the exposure can be handled through technical controls. A properly implemented consent management solution should:

  • Block non-essential trackers until a visitor opts in. Cookies shouldn't fire the second someone lands on your page.
  • Record visitor choices and keep an auditable consent history you can produce if challenged.
  • Display a clear cookie policy and accurate privacy disclosures for the technologies you actually use.
  • Apply geolocation-based rules

This is not a one-time project. Every time your marketing team adds a new tag, pixel, or plugin, that's a new tracker. Consent management can drift out of date the same way your site content can.

How GraVoc helps you get compliant

We handle website consent management two ways, depending on how often your site changes:

  • Fortified WordPress Plan (Tier 4 — $420/domain/month): Our top managed-care tier folds consent management into everything else we do for your site: hosting, security monitoring and malware removal, scheduled WordPress core/theme/plugin updates, ADA accessibility, NitroPack performance optimization, and ongoing consent monitoring and validation. This is the right fit for sites that change often.
  • Annual Consent Package ($500/year): For stable sites without a managed plan, we audit your trackers, install and configure consent management for CIPA, CCPA, and GDPR, set up your cookie policy display and geolocation-based controls, and re-check it once a year. It's a clean, one-and-done option if you just want this handled. However, note that no continuous coverage means consent management might go out of date between annual checks as your site evolves.

Either way, the goal is to reduce your risk by blocking non-essential tracking until visitors consent and keeping an auditable record while preserving your essential marketing tools. 

Frequently asked questions about CIPA & cookies

$

What are CIPA violations?

A CIPA violation is when your website lets tracking tools collect or share a visitor's data before they've consented. It carries $5,000 in statutory damages per violation.

$

Does CIPA apply to my business if I'm not in California?

Yes. CIPA claims target any website California residents can access, regardless of where your company is located

$

What tools trigger a CIPA risk?

Analytics (Google Analytics), tag managers, advertising pixels (Meta Pixel), session-replay and heatmap tools (Hotjar, Microsoft Clarity), and chat widgets are the usual suspects.

$

Do I need a cookie policy on my site?

Yes, if you run any non-essential tracking. A clear cookie policy discloses what you're collecting and supports the argument that visitors consented, which helps defend against a CIPA claim. Just know it only works paired with a consent setup that actually blocks trackers until someone opts in.

$

Which option is right for me — Fortified or the Annual Package?

If your site changes frequently or you'd rather we manage it continuously, go Fortified. If your site is stable and you just want consent handled once with a yearly re-check, the Annual Consent Package is the fit.

Curious where your website stands?

We'll review what's running on your site, point out any gaps in your consent setup, and walk you through the options. Contact us to get started or learn more about our compliance solutions.