Businesses are being threatened over common tools such as Google Analytics and Meta Pixel. Let’s talk about what is really happening.
![]()
Businesses across the country are receiving intimidating website privacy demand letters accusing their websites of violating the California Invasion of Privacy Act, commonly known as CIPA.
These letters often target ordinary website technologies such as Google Analytics, Google Ads tags, Meta Pixel, cookies and chat tools. Some arrive with a draft lawsuit attached, accusing the business of operating an illegal “pen register” or intercepting private communications without consent.
It sounds scary, sure.
It also sounds like something Saul Goodman would come up with. Find an obscure interpretation of a nearly 60-year-old California law, identify thousands of websites using the same ordinary marketing tools, hand the list to a room full of interns (or, more realistically, an automated website scanner) and start sending threatening letters, and start the “paperwork trail.”
Then offer businesses an unpleasant choice: pay a settlement or spend even more money hiring an attorney to fight a claim in another state.
We are not saying that every privacy claim is fraudulent or that businesses have no responsibility to protect consumer information. Websites should be transparent about the information they collect, and there are legitimate concerns when trackers capture sensitive health, financial, employment or form-submission data.
But threatening small businesses over the routine use of widely adopted analytics and advertising tools looks a lot less like consumer protection and a lot more like a settlement-driven legal shakedown.
How the website privacy demand-letter playbook works
The basic strategy is not complicated:
- Visit or scan a business website.
- Identify common technologies such as Google Analytics, Google Ads or Meta Pixel.
- Claim those technologies are illegal wiretaps or pen registers under CIPA.
- Send the business an intimidating demand letter, sometimes accompanied by a draft lawsuit.
- Count on the business deciding that settlement is cheaper than defending itself.
The strength of the underlying legal argument may be almost beside the point.
Even a business that believes it has done nothing wrong must still spend time reviewing the allegations, consulting an attorney, preserving website records and deciding whether to respond. Fighting a weak claim may cost more than making it disappear.
That is what gives these letters their leverage. The sender does not necessarily need to prove that the business has caused meaningful harm. The sender only needs to create enough uncertainty, expense and anxiety that paying a settlement starts to look attractive. That is not how privacy protection should work.
A telephone-surveillance law is being stretched to cover Google Analytics
CIPA was enacted in 1967. It was intended to address telephone wiretapping, electronic eavesdropping and surveillance technologies such as pen registers and trap-and-trace devices.
It was not written to regulate websites, cookies, digital advertising or Google Analytics. None of those technologies existed yet.
These lawsuits are only coming from a small number of firms. According to cyber insurer Coalition, just four law firms were responsible for 72% of the web privacy claims in its dataset, using templated demand letters to pursue pre-litigation settlements at scale.
Plaintiffs and their attorneys (attorneys often simply represent themselves as the plaintiff) are now advancing a newer interpretation of the law. They argue that when a website sends an IP address, device identifier, pageview or advertising identifier to a third party, the website is effectively operating an illegal digital wiretap or pen register.
Under this theory, a standard Google Analytics request can be presented as though a local business installed secret surveillance equipment on someone’s telephone line.
We think that comparison is a stretch, to say the least.
Google Analytics and Meta Pixel are not unusual tools hiding in obscure corners of the internet. They are standard technologies used by millions of organizations to answer basic business questions:
- How many people visited the website?
- Which pages did they view?
- Did an advertising campaign generate traffic?
- Did someone submit a form or complete a purchase?
- Is the website functioning properly?
That does not mean these tools should be installed carelessly. It does mean that using them for ordinary measurement and advertising purposes should not automatically transform a small business into an illegal surveillance operation.
Why businesses are still taking these letters seriously
CIPA allows plaintiffs to pursue significant statutory damages. That creates a powerful incentive to file claims even when the individual visitor cannot demonstrate meaningful financial loss or personal harm.
Courts have also reached conflicting conclusions about whether website analytics and advertising technologies qualify as illegal wiretaps or pen registers.
Some courts have allowed these cases to move forward. Others have rejected similar theories, particularly when the information involved consists of routine technical details such as an IP address, browser type or device identifier.
This unsettled legal landscape is ideal for demand-letter campaigns.
When the law is clear, both sides generally know where they stand. When courts disagree, a claimant can make an aggressive allegation and hope the recipient would rather pay than become a test case.
California lawmakers are considering a fix
California lawmakers themselves appear to recognize that CIPA is being stretched far beyond its original purpose.
Senate Bill 690 is currently active in the California Assembly and is scheduled for a hearing before the Assembly Privacy and Consumer Protection Committee on July 1, 2026.
The proposed legislation would amend CIPA to create protections for processing personal information for legitimate commercial business purposes. It would also clarify that a device or process used for a commercial business purpose (including ordinary business analytics and data processing) does not automatically qualify as a prohibited pen register or trap-and-trace device.
In plain English, lawmakers are considering legislation that could help stop plaintiffs from treating routine website technologies as though they were illegal telephone-surveillance equipment.
SB 690 has not yet become law, and its final language or outcome could still change. But its continued progress through the legislature underscores the central problem: businesses are being threatened under a decades-old statute that was never written with Google Analytics, advertising pixels or modern websites in mind.
Until lawmakers or higher courts establish clearer limits, plaintiffs and attorneys will likely continue exploiting that uncertainty to pressure businesses into settlements.

Are these letters scams?
Well, let’s just say… we understand why businesses describe them that way.
Some letters appear highly automated and may contain boilerplate allegations, stale corporate information, incorrect or outdated names or exaggerated descriptions of ordinary website activity. A packet may look official while being nothing more than an unfiled draft complaint prepared by the person demanding money.
That does not necessarily make the letter legally fraudulent. It also does not make the allegations valid.
The most accurate description is often a mass-produced, pre-litigation settlement demand based on an aggressive and disputed legal theory.
That is more sophisticated than ordinary spam, but the economic objective can look remarkably similar: send enough intimidating messages and see who pays.
Businesses should not assume that a demand letter is a court order, a government enforcement action or proof that a law was violated.
Unfortunately, they also should not throw it in the trash. Some of the people and firms behind these letters do file lawsuits when their demands are rejected or ignored.
Does every website need an opt-in cookie banner now?
No.
The spread of these demand letters does not mean every local business in Ohio must immediately install a European-style consent system because someone in California might visit its website.
A local service business that does not advertise, sell or operate in California does not have the same risk profile as a national ecommerce company, healthcare organization, financial institution, recruiting platform or business collecting sensitive personal information.
Nearly every public website can be opened by someone in California. That fact alone should not allow California demand-letter operations to dictate how every small business in America runs its website.
Our position at ruef is straightforward:
If you have not received a demand letter, do not panic.
There is no reason to assume that your website is suddenly illegal because it uses Google Analytics, Google Ads or Meta Pixel.
Businesses concerned about their specific legal exposure should consult with a qualified privacy attorney. A marketing agency can inspect a website, identify installed technologies and implement technical changes, but it cannot determine a company’s legal obligations.
Taking precautions does not mean the claimants are right
Some businesses may decide that the easiest way to reduce risk is to update their privacy policy and add a cookie notice or consent-management system.
That is a reasonable business decision.
It is not an admission that an analytics tag is a wiretap or that every aggressive demand letter has merit. Businesses make practical risk-management decisions all the time because avoiding a dispute may cost less than winning one.
A proactive website review may include:
- Updating the privacy policy to accurately describe the website’s practices
- Adding a visible cookie notice
- Adding a true opt-in consent tool that blocks nonessential tags until approval
- Identifying which analytics and advertising technologies are installed
- Documenting what tags are being used (screenshots with dates)
- Removing duplicate or genuinely obsolete tags
- Confirming that the website behaves as its privacy policy and consent settings promise
A basic cookie notice and an opt-in consent system are not the same thing.
A notice simply informs visitors that cookies are being used. A true consent platform prevents selected technologies from loading until the visitor approves them. Businesses should understand the difference before paying for a solution they may not need.
Any consent tool should also be tested. A banner that promises to reject advertising cookies while continuing to load them can create a new problem instead of solving the original one.
What should you do if a letter arrives?
Do not panic, do not send money immediately and do not communicate directly with the claimant before obtaining advice.
A demand letter is not necessarily a lawsuit. A draft complaint with a blank case number is not a court order. Accusations written in legal language are still only accusations.
Send the packet to an attorney and let the attorney determine:
- Whether a lawsuit has actually been filed
- Whether the allegations accurately describe the website
- Whether California has jurisdiction over the business
- Whether the claimant has a valid legal theory
- Whether the business should respond, contest, negotiate or take no action
- Whether website changes should be made and when they should occur
The business should also preserve its current website configuration before making changes. That includes documenting installed tags, plugins, privacy policies, consent settings and advertising configurations.
ruef’s position
We support meaningful consumer privacy. Businesses should know what their websites collect, avoid collecting information they do not need and communicate their practices clearly.
We do not support twisting an old telephone-surveillance law into a mass settlement machine aimed at businesses using ordinary website tools.
Our recommendation is simple:
If you have not received a letter, do not worry unnecessarily.
If you are concerned about your legal exposure, talk with an attorney.
If you would rather get ahead of the issue, update your privacy policy and consider adding a properly configured cookie notice or consent tool.
ruef can review the technologies installed on your website, update website content and implement privacy and cookie tools based on your company’s preferences and guidance from legal counsel.
But we are not going to pretend that every small business using Google Analytics is secretly running an illegal wiretap.
Sometimes a demand letter is about protecting consumers. Sometimes it is about finding a creative interpretation of an old law and seeing who is willing to pay to make the problem go away.
Businesses deserve to understand the difference. In the meantime, we will keep an eye on this issue as it develops.
This article is provided for general informational purposes and does not constitute legal advice. Privacy requirements and litigation risks vary by business, jurisdiction and website configuration. Consult a qualified attorney regarding your organization’s specific obligations.



