a sledgehammer with "CIPA" printed on it crushes a cookie with cookie monster aghast: metaphors for privacy cookie management systems and CIPA

Cookie Banners, CIPA & Privacy Compliance: A Practical Guide

David Gibson

Originally published July 2025. Fully updated June 25, 2026

Last summer I wrote a guide on cookie banners and CIPA because clients kept asking me the same thing: does my cookie banner actually protect me from these website tracking lawsuits? A year later the question hasn't changed, but almost everything around it has. The filings are way up, the legal theories got sharper, and now AI is in the mix on both sides of the fight. So this is a full refresh.

Quick reminder of what we're dealing with. CIPA is the California Invasion of Privacy Act, a 1967 wiretapping law. Plaintiff attorneys spent the last few years arguing that ordinary website tracking (your analytics, your pixels, your chat widget, your session replay tool) is the modern version of tapping a phone line. Statutory damages run $5,000 per violation, no proof of actual harm needed, and they'll argue every California visitor who hit your site is a separate violation. That math is the entire game.

Disclaimer: this post is for informational purposes only and is not legal advice. See the full disclaimer at the bottom.

What actually changed since last year

If you just want the short version of where things stand in 2026, here it is:

  • Volume blew up. More than 800 CIPA claims were filed in 2025, and 2026 is projected to top 3,500. This stopped being a quirky California thing and became a national operating cost.
  • The question moved. Courts aren't really asking "do you have a banner" anymore. They're asking whether tracking fired before the user said yes. Firing order is the whole ballgame now.
  • There's no safe harbor. SB 690, the bill that would have calmed this down, passed the California Senate 33 to 0 and then stalled in the Assembly. It's a two-year bill now, with the earliest possible relief in 2027... if ever. Plaintiff firms know this and are filing aggressively ahead of any exemption.
  • AI is pouring gas on it. Plaintiff firms are using AI to scan thousands of sites for violations and crank out demand letters at almost no cost. And AI chatbots are now a target in their own right.
  • Your search bar is in the crosshairs. Yes, the search box. I'll explain.
  • They're stacking a federal claim on top. Attorneys now pile a federal ECPA claim ($10,000 per violation) on top of the CIPA claim ($5,000). Bigger number, more pressure to just settle.

Now let's get into it, including the part nobody selling you a cookie tool wants to say out loud, which is how real the risk actually is.

The privacy law mess, quickly

The headache hasn't changed: different regions, totally different rules.

Europe wants permission before you track anyone. Not a single non-essential cookie drops until the user says yes. Get it wrong and the fines reach into a percentage of global revenue.

Most US state laws are looser. California's CCPA/CPRA lets you track by default as long as you give people a clear way to opt out. Close to twenty states now have their own comprehensive privacy laws, most of them following California's opt-out model with small variations, a few (Colorado, Connecticut) getting stricter on sensitive data.

And then there's CIPA, sitting off to the side, doing its own weird thing. CCPA/CPRA cares about categories of data and your opt-out mechanism. CIPA doesn't care about any of that. It cares about one question: did interception happen before the person consented. That's a higher bar, and it's the bar plaintiffs are using.

CIPA: the 1967 law that still won't die

A wiretapping statute written for rotary phones is now the favorite tool of the privacy plaintiff's bar. Session replay that records what users do on your site? They call it a wiretap. Pixels that ship data to Meta or Google? Wiretap. AI chat widget? Wiretap. Since 2022 the filings have gone from a few dozen a year to many hundreds, hitting everyone from hospitals to fast food chains. Headline settlements like Oracle's $115 million made sure everybody noticed.

So far so scary. Here's the part the CMP vendors leave out.

Let's be honest about the actual risk, because it's genuinely mixed. Courts are split. California state courts have increasingly rejected the theory that routine tracking is an illegal "pen register." Plenty of cases got tossed in 2025, the TikTok pixel line of cases, a session replay case (Torres v. Prudential) thrown out because the data wasn't read "in transit," tester-plaintiff cases dismissed for lack of standing, even a Ninth Circuit decision (Popa) that made standing harder. A hotel website tracking suit (Crano v. Sojern) got dismissed in late 2025. And in June 2026 a federal court dismissed one of serial-litigant Vivek Shah's CIPA claims, ruling that generic searches on a website don't even implicate a protectable privacy interest.

So no, this is not "you will get sued and you will lose." Nothing in this wave has really gone to trial. It's settle or dismiss.

But (and it's a big but) in November 2025 the Camplisson v. Adidas decision rejected that defense-friendly pixel line and held trackers can plausibly be a pen register. That created a real split. Federal courts are friendlier to these claims at the pleading stage than state courts are. So the actual state of the law is uncertainty, not safety. And uncertainty is the plaintiff's best friend, because here's the business reality: it's cheap to file and expensive to defend. Plaintiffs price their settlement demands right below what it would cost you to win. So a lot of companies write the check even when the claim is weak. That's not a legal outcome. That's a math problem.

Your risk tracks how much real-time content leaves your site to a third party before consent:

  • Session replay and AI chat (Hotjar, FullStory, live chat that records): highest risk.
  • Pixels and tag-based trackers (Meta Pixel, GA via GTM): medium, and very volume-driven.
  • Plain first-party analytics, especially IP-only theories: lower, and getting lower as courts dismiss these.

The practical takeaway is the same as last year, just louder. If something records or transmits user content to an outside party before the user agrees, that's your exposure. Find it and gate it.

The bar moved: it's firing order now, not "do you have a banner"

This is the single most important shift since I first wrote this, so read it twice.

In 2025 the compliance question was basically "is there a cookie banner on the site." In 2026 that question is dead. The litigation has moved to timing. Did your tracking scripts fire before the user had any chance to consent? Did your consent platform actually block those scripts, or did it just show a pretty notice while the trackers ran in the background?

Courts and plaintiffs are now asking, in effect: did your system enforce the user's choice before data was collected? That's a completely different test than "did you display a notice." A banner that pops up while Google Analytics and the Meta Pixel already fired is not protection. It's decoration. Worse, it's evidence that you knew you should be asking.

If you take one thing from this whole post, take this: the banner is not the thing. The blocking is the thing.

AI is now an accelerant, on both sides

This is new since the original post, and it's structural, not cosmetic.

First, the plaintiff side automated discovery. Checking whether a site fires trackers before consent used to take a human poking around with browser dev tools. Any developer can still do it in about five minutes. The difference is plaintiff firms now run that check automatically across thousands of sites at once. They scrape, they script, they flag the easy targets, and they move on. That's a big reason the filing numbers exploded. The cost of finding a victim dropped to near zero.

Second, AI writes the paperwork now. Attorneys are using AI to draft demand letters and complaints faster and cheaper than ever. When the marginal cost of sending one more demand letter is basically nothing, the only limit on volume is how many sites have the flaw. A lot of them do.

Third, and this is the one most people miss: AI chatbots are now a CIPA target themselves. The usual defense for a third-party tool is the "tape recorder" idea, that the vendor only uses your data to serve you, so it's like an extension of you rather than an eavesdropper. The problem is most AI chat vendors train their models on the conversations. That's independent commercial use, and that's exactly the thing courts have said breaks the tape-recorder defense. Cases are already moving on this: a chat tool on Nationwide's site (Valenzuela) and an AI call assistant used by restaurants (the ConverseNow and Ambriz line) both survived motions to dismiss. Chatbot wiretap claims went from 2 in 2021 to 30 in 2025, the fastest-growing slice of AI litigation per a Baker Botts analysis.

And here's the trap. California's new chatbot disclosure law (SB 243) makes you tell users they're talking to AI. Satisfying that does NOT satisfy CIPA. Disclosure is "you're chatting with a bot." Consent is "you agreed before we intercepted the conversation." Two different obligations. Doing the first one does nothing for the second.

If you run an AI chat widget, go read the vendor's data terms. If they train on your visitors' conversations, you need real consent before the chat opens, and your privacy policy needs to name the vendor and describe what they do.

Your search bar might be the problem (no, really)

Here's a risk almost nobody knows about, and it's worth its own section.

A serial litigant named Vivek Shah has been mailing demand letters to companies all over the country focused on one thing: website search bars and contact forms that transmit what the user types to third parties like Google, HubSpot, and Meta before the user has consented to anything. His method is simple and kind of brilliant. He opens your site with browser dev tools running, types his own name into your search box, and screenshots the network requests showing "VIVEK" being shipped off to a handful of outside domains in real time. Then he argues that's an interception of communication content, a digital wiretap, with you as the conspirator who installed the search function.

Most site owners have no idea their search bar does this. If you use HubSpot, Google Analytics, or a Meta Pixel and your search or forms wire keystrokes out before consent, you fit his target profile exactly.

Now the honest part, because I'm not here to scare you into a panic purchase. These are mostly demand letters, not filed lawsuits, at least so far. Shah has a checkered history (he's a convicted felon from an old extortion scheme), and as I mentioned, a federal court just tossed one of his claims for lack of standing. So this is pressure, not a guaranteed loss.

But the underlying technical issue is real, it's trivially easy to verify, and it's easy to fix. So check your search bar and your forms. Mask or suppress what you can. Don't let a five-minute problem turn into a settlement conversation.

The federal stack: ECPA on top of CIPA

One more reason demands are getting heavier. Attorneys now routinely pair the state CIPA claim with a federal Electronic Communications Privacy Act (ECPA) claim. ECPA carries statutory damages of $10,000 per violation versus CIPA's $5,000, and because it's federal, it can be filed in any state, not just California.

That said, keep some perspective. ECPA is a one-party consent law, and your website is a party to the communication, which gives defendants a real shot at dismissal early. So plaintiffs aren't stacking ECPA because it's a sure thing. They're stacking it because a bigger headline number and a nationwide reach create more pressure to settle. Knowing why it's there helps you not overreact to it.

Who's actually getting hit

Healthcare is the most-targeted sector by a wide margin. Hospitals have collectively paid north of $100 million over the same Meta and Google pixels embedded in patient portals. Sutter Health just settled for $21.5 million over tracking tools (Meta Pixel and Google Analytics) on its MyHealthOnline patient portal. Patient portal plus pixel is about the worst fact pattern there is, because the data is sensitive and the consent gate usually wasn't there.

Hospitality and travel are on the radar too, though the picture is more mixed (remember, the Sojern hotel case got dismissed). If you run a resort or destination property, your risk profile is worth naming honestly. You probably get meaningful California visitor traffic. You likely run booking integrations, session replay on your purchase and reservation funnel, and maybe a chat widget for conditions and lodging questions. Stack all of that with no real consent gate and you fit the description plaintiffs look for. Not because resorts are being singled out, but because that particular combination of tools is exactly the high-content, third-party-heavy setup these claims feed on.

The pattern across every sector is the same: the more user content you ship to outside parties before consent, the more you look like a target.

Your cookie banner options

Same menu as last year, from least to most protective. What changed is that the first two options below (notice only and basic opt-out) aren't enough anymore, and unless you've figured out how to keep Californians off your website, that includes you.

  1. Privacy notice only. A "we use cookies" message with an OK button. No opt-out, no blocking. Fails CCPA, fails GDPR, gives you zero CIPA protection. This was fine in 2018. It is not fine now.
  2. Basic opt-out banner. Notice plus a "Do Not Sell or Share My Personal Information" link. Cookies still load immediately. This satisfies CCPA/CPRA and most other US state laws, but it offers no CIPA protection because tracking starts before consent. And as of the 2025 CPRA expectations, a footer link alone isn't enough in California: the agency expects a balanced first-layer choice, a clear "Reject All" sitting right next to "Accept All," plus a Notice at Collection and honoring Global Privacy Control signals.
  3. GDPR-style opt-in with granular controls. Blocks all non-essential cookies until the user consents, with Accept All, Reject All, and Customize. Reject has to be as easy to find as Accept (hiding it in a submenu violates the freely-given-consent rule). This is the gold standard, and because nothing fires before consent, it effectively kills your CIPA exposure.
  4. Geo-targeted hybrid. Modern consent platforms (CookieYes, Cookiebot, OneTrust) show different banners by location. Opt-in for the EU/UK and California, simpler opt-out elsewhere. For most US businesses with some California traffic, this is the sweet spot: real consent where you need it, without nuking your analytics for every visitor in the country. VPN spoofing is a minor concern next to the compliance benefit.

You can also make these banners feel like part of your brand instead of an apology. A well-written, on-brand consent prompt converts better than corporate privacy mumble.

Picking a consent platform, briefly

If you're doing anything past a basic notice, you need a Consent Management Platform (CMP). Some overpromise badly, so judge them on four things: real audit trails (proof of who consented to what), Global Privacy Control support, accessibility (it has to work for users with disabilities, more on that in a second), and honest pricing without bait-and-switch tiers.

The usual suspects: Cookiebot (strong blocking, can occasionally break a site), CookieYes (affordable, solid, what we generally land on for our clients), CookieScript (similar tier), Osano (pricey, includes a compliance guarantee), and Termly (budget, more manual work). There's no single right answer. There's a right answer for your stack and your risk.

How to test if your CMP actually works (do this first)

This is the same five-minute check the plaintiff firms automated. So run it on yourself before they do.

Open your site in an incognito window. Before you touch the cookie banner, open a cookie inspector (a browser extension like Cookie-Editor works, or just hit F12 and look under the Application tab, Cookies). If you see _ga (Google Analytics), _fbp (Meta), or other tracking cookies sitting there before you clicked Accept, your CMP isn't blocking anything. It's running in "notice only" mode while the trackers fire in the background.

While you're in there, type something into your search bar and watch the Network tab. If your search terms get shipped to Google, HubSpot, or Meta as you type, that's the exact thing the demand letters are about.

Finding this stuff is easy. The good news is that fixing it (flipping your CMP to true blocking mode, or replacing one that can't) is usually straightforward.

The accessibility piece everyone forgets

Your cookie banner has to work for people with disabilities. That's not a nice-to-have, the ADA requires it, and an inaccessible consent mechanism is its own lawsuit waiting to happen. This is the part we obsess over, since accessibility is what our Accessibility.Works team does all day.

The common failures: you can't reach the banner by keyboard, focus doesn't land on it when the page loads, there's no visible focus on the buttons when you tab, contrast is too low, screen readers can't make sense of it, or it falls apart when someone zooms in. The fix isn't exotic: clean HTML, real contrast, clear labels, proper focus handling. But plenty of CMPs that claim "WCAG compliant" flunk a basic test. So verify it yourself rather than trusting the badge.

What I'd actually do

If you want a short list, here it is.

  1. Inventory every third-party script on your site: pixels, analytics, chat, session replay, SDKs. Know what loads and exactly when.
  2. Test firing order in incognito with dev tools before you touch the banner. Anything tracking before consent is your problem to fix.
  3. Make California and the EU opt-in so nothing non-essential fires until yes, and geo-target so you keep your US analytics everywhere else.
  4. Check your search bar and forms specifically. Mask or suppress keystroke transmission where you can.
  5. If you run an AI chatbot, read the vendor's data terms. If they train on conversations, get consent before the chat opens and name them in your privacy policy.
  6. Keep consent records, make the banner accessible, and re-check the whole thing quarterly. Your tools change, the laws change, the banner that worked in spring breaks by fall.

FAQ

Does CIPA apply to me if I'm not in California?

Yes, if Californians can reach your site. It's about who's visiting, not where you're headquartered. A Vermont shop with California customers is in scope.

I already have a cookie banner. Am I protected?

Not automatically. If your banner shows a notice while your scripts have already fired, it's decoration. The thing that protects you is blocking non-essential tracking until the user agrees.

What's the difference between CIPA and CCPA/CPRA?

CCPA/CPRA is about data rights and opt-out, and it's mostly enforced by regulators. CIPA is a wiretapping law with an all-party consent rule, and it lets individuals sue you directly at $5,000 a pop. That private right of action is exactly why CIPA, not CCPA, is the litigation magnet.

Which tracking tools are highest risk?

Session replay and AI chat at the top, pixels in the middle, plain first-party analytics lower (and dropping as courts dismiss IP-only theories). Risk tracks how much real-time user content goes to a third party.

What does "pre-consent tracking" mean and how do I check?

It's any tracker that fires before the user agrees. Open your site in incognito, hit F12, look under Application or Network, and watch for tracking cookies or calls before you click anything. Five minutes, no special tools.

Can I get sued just for using Google Analytics?

Sued, maybe, it's cheap to file. But plain GA cases, especially IP-only ones, have been getting dismissed more often lately. It's lower risk than chat or session replay, not zero risk.

I got a CIPA demand letter. What now?

Don't ignore it, and don't gut your site before preserving evidence (that can look like spoliation). Screenshot your current configuration and your third-party scripts, then call a privacy attorney. These letters are designed to get a fast, nervous response, so slow down and get advice.

Is there a safe harbor or exemption I can count on?

Not yet. SB 690 would have helped but it stalled and won't take effect before 2027, if it ever does. Plan as if there's no safe harbor, because right now there isn't.

Are AI chatbots on my site a CIPA risk?

Yes, and a growing one, especially if the vendor trains its models on your visitors' conversations. Be clear on this: a disclosure that says "you're chatting with AI" is not the same as consent to intercept. You need both.

How do I know if my CMP is actually blocking cookies or just showing a banner?

Same incognito plus dev tools test. If trackers load before you click Accept, your platform is in "notice only" mode, not blocking. Flip it to blocking, or get a CMP that actually does it.

What's coming

SB 690 is the bill to watch. It would ease CIPA for standard web tracking if you're already CPRA-compliant, basically saying that if you follow the privacy law, it isn't wiretapping. It passed the Senate unanimously, stalled in the Assembly, and is now a two-year bill. Earliest relief is 2027, and even that's uncertain. Until then, the lack of any safe harbor is actually pushing plaintiffs to file faster, to lock in claims before any exemption arrives.

Meanwhile more states keep passing privacy laws and they keep getting stricter, federal privacy legislation stays perpetually "next year," and the wiretap theory keeps spreading to new statutes (the federal ECPA, Florida's communications act, and others). The direction of travel is clear even if the destination isn't.

The smart move is to stop treating this as a compliance tax and start treating it as basic hygiene. Gating your tracking properly protects you legally, yes, but it also forces you to actually know what's running on your own site, which almost nobody does. That's worth doing regardless of what any court decides. Get it right once and it's one less thing to worry about, plus you earn some trust from the growing pile of customers who actually care about this stuff.

If you want help auditing what your site is really doing before someone with dev tools and an AI script does it for you, that's exactly the kind of work we do. Reach out and let's take a look.


DISCLAIMER: The content provided in this blog post is for informational purposes only and does not constitute legal advice. While we strive to offer accurate and up-to-date information, privacy laws and regulations may vary by jurisdiction and evolve over time. You should consult with a qualified attorney or privacy professional to ensure that your privacy policy and practices meet applicable legal requirements. Propeller Media Works disclaims any liability for actions taken based on this content.