Published August 15, 2026 · 8 min read · RegSentry blog
The letter says your website "wiretapped" visitors. It cites California Penal Code § 631, mentions statutory damages of up to $5,000 per violation, and demands a response by a date a few weeks out. If you're like most owners who receive one, your first reaction is some mix of disbelief and panic — your site is a normal business website with a normal analytics setup. Here's a calm, plain-language walkthrough of what the letter is, why you got it, and what actually happens next.
A demand letter is not a lawsuit. It's a letter from a law firm — usually representing one named individual who says they visited your website — asserting that your site's tracking tools intercepted their communications without consent, in violation of the California Invasion of Privacy Act (CIPA), Penal Code § 631. The letter typically offers to settle the claim for a payment before any case is filed, and gives you a deadline to respond.
The legal theory behind the letter is the same across almost all of them: when a session-replay tool, chat widget, or advertising pixel captured what the visitor did on your site and transmitted it to a third-party company before the visitor consented, that transmission is characterized as an intercepted communication. CIPA's damages provision (§ 637.2) allows up to $5,000 per violation, and plaintiffs argue each affected visit can be a separate violation — which is how the letters arrive at intimidating numbers.
Two things are worth internalizing early. One: receiving a letter is not a finding that you broke the law. Whether any statute was actually violated depends on facts and legal questions the letter doesn't resolve. Two: the letter is also not nothing. Ignoring it entirely is generally regarded as the worst available option, because the sender's next step can be filing an actual complaint.
Owners often assume they were individually targeted. Usually the truth is more mundane: the firms behind these letters use automated scanners that crawl large numbers of business websites looking for one specific technical pattern — third-party tracking scripts that contact their servers before any consent choice is made. Session-replay tools (which record clicks, scrolling, and typing), live-chat widgets, and ad pixels are the usual finds. If your site loads one of those tools on page load, an automated scan can flag it in seconds, and company size offers no protection — the scanner doesn't check.
This matches what we see from the other direction. Across the 3,891 small-business sites in our own scanning data, 61% fired at least one tracker before consent — and sites with a recognized consent platform fired at a higher rate, 74%, than sites without one. The pattern the letters look for is genuinely common, which is exactly why the letters are common.
Note who sent it, who the claimant is, what tools it names (many letters identify the specific vendor — a session recorder, a chat provider, a pixel), and the response date. Keep the envelope and any email headers.
This is the step everything else supports. CIPA demand letters have become a recognizable genre, and attorneys who handle them know the current state of the case law, which letters tend to be filed versus abandoned, and what response postures make sense. A one-hour consult is cheap relative to any other path. If you have business insurance, ask your broker whether your policy has cyber or media-liability coverage that could apply — some policies require prompt notice, so ask early.
Before you can respond to a claim about what your website transmits, you need to know what your website transmits. Run a scan of your own site — the same kind of real-browser check the plaintiff-side scanners run — and document what fires before consent, with dates. This gives your lawyer something concrete to work from, and it tells you honestly whether the letter's technical premise is accurate on your site. (It sometimes isn't; letters go to sites where the named tool was removed months earlier, or was configured in ways the letter doesn't reflect.)
Whatever the legal outcome, the technical fix is the same and is worth doing on its own merits: no tracking tool should transmit anything until the visitor has made a consent choice. In practice that means gating each tool behind your consent platform, wiring Google's Consent Mode if you use Google tags, and removing tools you don't actually need — session replay is the one most owners discover they can simply live without. Then verify the fix in a real browser, because a consent banner that displays but doesn't block changes nothing about the network traffic.
A dated scan showing the problem, a dated fix, and a dated re-scan showing clean behavior is the strongest good-faith record you can build. It doesn't erase the past conduct the letter complains about — but demonstrating that the practice ended promptly matters in negotiations, and it protects you against the next letter, because sites that stay noncompliant can hear from more than one firm.
Responses range from negotiating a settlement, to contesting the claim's factual or legal basis, to a holding reply while facts are gathered. Which one fits depends on the letter, the evidence, and the current case law — a moving target that is precisely why this step belongs to counsel, not to a blog post.
We won't invent settlement figures — amounts vary widely and most are confidential. What an owner can control is the cost of the next letter: near zero, if the site is verifiably clean and stays that way. The recurring pattern in this entire litigation wave is that the sites receiving letters almost always believed they were fine — usually because a cookie banner was installed and nobody ever verified what the banner actually blocked.
The single most useful thing you can do this week — whether or not a letter ever arrives — is find out what your own site transmits before visitors consent. Our free checker runs a real browser against your site and shows you exactly that, with the evidence.
See what fires on your site before visitors consent — free, 30 seconds, no signup.
Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.
If you'd rather have the site watched continuously — with an email the moment a new tracker appears — that's what monitoring is for ($99/mo, cancel anytime).