
As of January 2026, twenty US states have comprehensive privacy laws in force, with more moving through statehouses now. And separately, there’s been a significant uptick in pre-litigation demand letters sent to businesses over their websites’ tracking practices. At least one serial litigant has issued thousands of these letters to sites across the country. We’ve seen them land on ordinary small-business websites, not just big brands.
The old law causing new concerns
The newer wave of claims leans on the California Invasion of Privacy Act (CIPA) rather than the better-known CCPA. CCPA has clear thresholds that determine whether a business is even covered. CIPA is an older statute written for phone wiretapping, and how it applies to modern website tracking is currently a legal grey area. Lawmakers have discussed updating it, nothing has passed, and while many of these cases have been dismissed in court, defending one is expensive either way. Grey areas are exactly where demand-letter campaigns thrive. What to do about a letter is a question for your attorney. We’re not lawyers, and this isn’t legal advice. What’s actually running on your website, however, is a technical question, and it’s one most businesses can’t currently answer.
The trackers MOST businesses have
When we audit sites, there are a handful of trackers that we see all the time, often installed years apart for reasons nobody remembers:
- Google Tag Manager, a container that fires other scripts. It transmits little itself but controls when everything else does. These can be loaded with tracking scripts that agencies have included over the years.
- Google Analytics 4, which sets a first-party cookie with a client ID to correlate a visitor’s activity across sessions.
- Retired scripts still loading, including old Google Universal Analytics code running alongside GA4 years after Google moved on, doing nothing but adding weight and liability.
- The Meta (Facebook) Pixel, which transmits browser and activity data to Meta for ad targeting and conversion tracking. This is the category of tool most often named in these claims.
- Embedded streaming videos, which carry their own tracking scripts and Analytics integration most site owners never think of as “trackers.”
- And anti-bot tools like Cloudflare Turnstile, which collect IP and behavioral signals. As security functions, these are treated differently from marketing trackers.
None of these are exotic, and that’s the point. The tracking practices drawing demand letters are the default setup of a normal business website.
Steps to move toward compliance
If you manage an existing site, and want to take steps to address your compliance, your exposure and next actions should be discussed with your legal counsel. Some high level steps to move you toward compliance include:
- Update your Privacy Policy. Published, linked, and ACCURATE to the tools and data practices currently in use by your company, not only limited to your site, but we’d recommend outlining how any user data is stored and used by your team. A template policy that isn’t reality isn’t protection, and can actually get dismissed in a legal setting for that reason. We help clients identify the actual scripts that are in place and need to be addressed
- Remove the Bloat. Take out retired scripts and abandoned tools. If you aren’t sure who is looking at the tracking on the scripts, check with your existing partners and internal team, and disable any that are unclear.
- Add the Consent Banner. This isn’t just a visible notice. It should also functionally control the tracking scripts on your site. A proper implementation categorizes each tool (security functions as “functional” and required; analytics and pixels as optional), and, critically, verifies that optional scripts don’t fire until consent is given. A banner that announces trackers after they’ve loaded is the exact pattern the litigation targets.
- Decide, opt-in versus opt-out. Opt-in: nothing fires until the visitor agrees, which is what strict GDPR requires and what the CIPA grey area leans toward, at the cost of lost analytics data, since you can’t measure visitors who never consent. Opt-out: tools run until declined, which is what CCPA permits, provided tracking genuinely stops on request. We can’t tell you the right legal answer; the right posture is based on your risk tolerance and legal advice, and merits a deliberate informed choice.
If this feels like a lot to untangle, we’d be happy to discuss with you. If you are building a new site with us, you don’t have to worry about retrofitting any of this later. We inventory your trackers, establish your consent posture, and map out privacy requirements right from the start in our Website Blueprint phase.

