Skip to Content

The $5,000 Cookie: How a 1967 Wiretapping Law Is Coming for Law Firm Websites

July 23, 2026 |

Builden Partners is a legal marketing and business development consultancy, not a law firm. This alert does not constitute legal advice. Firms with questions about specific exposure should consult general counsel or outside privacy counsel before deciding how to proceed.

Law firms have received demand letters seeking between $5,000 and as much as $50,000 per violation, with no proof of actual harm required, over something almost every firm website does: running Google Analytics or similar tracking tools on pages where visitors submit personal information.

The unlikely source is the California Invasion of Privacy Act (CIPA), a 1967 California wiretapping statute now being applied to modern website tracking technologies. The legal claim is straightforward: deploying tracking tools on pages where visitors enter personal information, such as contact or intake forms, without first obtaining affirmative consent constitutes illegal interception of a communication.

For years, this kind of tracking was considered routine and drew no scrutiny. That has changed, and law firms are now squarely in the pool of defendants.

Here is what law firms need to know.

What Is CIPA and How Does It Apply to Websites?

CIPA is a 1967 California statute originally written to prohibit tapping telephone lines and recording phone calls without consent. In recent years, courts and creative plaintiffs’ attorneys have extended the statute to cover website tracking. Plaintiffs’ attorneys argue that tools like Google Analytics are eavesdropping on visitors. They capture what a visitor types or clicks on a page and sends it to a third party, in this case Google, before the visitor has agreed to anything. Under CIPA, that transmission is the alleged wiretap.

Courts have been inconsistent in applying the theory, and the inconsistency itself creates risk. CIPA allows individuals to sue directly without proving actual damages, which means the financial pressure to settle can be significant even when the legal theory is contested.

Who Is Sending These Letters?

The demand letter campaign is not random. Serial litigants and plaintiffs’ firms have identified website contact forms and search bars as a reliable litigation target, since both transmit user-entered data to third-party analytics providers. They have built efficient, largely automated strategies for pursuing claims at scale. Many demand letters are nearly identical, generated by AI and sent to thousands of businesses with minimal additional investment.

The economics make this model attractive. A $5,000 statutory damages figure, multiplied across thousands of demand letters with low overhead, creates a profitable volume model for claimants even when most businesses settle for far less.

Why Are Contact Pages the Highest Risk for Law Firms?

Contact and intake pages carry the most exposure because tracking tools can capture and transmit form data before a visitor consents. When a website visitor enters a name, phone number or email address, their data may be sent to third-party servers before clicking submit, without the visitor’s knowledge or agreement.

Courts applying this theory have focused on that moment of transmission. Data flowing before consent is the alleged violation, which puts law firm contact forms directly in the crosshairs.

What Out-of-State Firms Should Know

Case law generally supports that simply having a website accessible to California residents does not create personal jurisdiction over an out-of-state business. Despite this, plaintiffs are sending demand letters to firms nationwide, broadly asserting that CIPA applies to any website a California resident can access.

Firms receiving these letters should consult with counsel before taking any action, including settling. The legal theory behind many of these letters is contested, and settling without understanding the available defenses can encourage further demand letters without reflecting genuine legal liability.

California Senate Bill 690, introduced in 2025, is proposed legislation that would narrow the reach of CIPA claims, but it has not passed. Even if enacted, it would not take effect before January 1, 2027, and current versions are designed to address a narrower set of CIPA claims than the wiretapping theory driving most demand letters. As of this writing, no statutory safe harbor has been enacted, and filings are expected to continue at pace.

What Does a Compliant Solution Require?

The fix is a cookie consent solution that genuinely blocks tracking scripts from firing until a visitor actively agrees. A banner that appears on the page is not enough, and one that pops up after tracking has already begun may make things worse, since it demonstrates awareness of the consent requirement without actually meeting it.

A properly implemented cookie consent solution should:

  • Block all nonessential tracking scripts until a visitor actively consents
  • Provide accept and decline options that are equally visible
  • Log consent events in case documentation is ever needed

Firms should also take stock of every third-party tool running on the website. Analytics platforms, advertising pixels, session replay tools, chat widgets and embedded forms all carry potential exposure. Many websites accumulate these tools over time, and it is not uncommon to find scripts running that no one on the current team even remembers adding.

The question every firm should be asking its web vendor: are tracking scripts blocked until a visitor consents, or are they firing the moment someone lands on the page? The answer to that question determines the exposure.

Sources:

Case Studies