Last week we hosted a webinar called From Pixels to Plaintiffs, with my guest Usama Kahf, a partner at Fisher Phillips who helps run their privacy, cyber, and AI practice. He works these cases every day, and if you missed the webinar, you can catch the recording here. If you have been treating cookie and pixel lawsuits as a California problem, this is your heads-up that it is not.

The scale

Usama painted a picture of the scale of this litigation. Almost 5,800 lawsuits nationwide, with California accounting for about 80 percent of them. Ten to fifteen times as many claims sit in arbitration demands and letters that never reach a docket, which puts the real number north of 82,000 claims across more than 80,000 businesses. Settlements are $15,000 to $25,000; about 90 percent settle. Over four years, by his estimate, close to a billion dollars has been funneled to fewer than ten law firms.

What began in California under an old wiretapping law, the California Invasion of Privacy Act, or CIPA as it’s more commonly referred to, has spread to Florida, Illinois, Pennsylvania, New York, and federal court. The industries that are hit the most are retail, then technology, and then it trickles down from there. Much of it is the same serial plaintiffs filing the same complaint again and again, sometimes with tools that scan websites to find the next target. The demand letters are short, often one paragraph with a draft complaint attached, usually a first and final offer. It is a business model.

We like to kick off webinars with a poll question. We asked attendees what concerns them the most about the recent rise in CIPA litigation. Check out their responses:

SB 690 helps, but do not exhale

You have probably heard about SB 690. It passed the California legislature unanimously and is waiting on the governor’s signature, with an effective date of January 1, 2027.

What it does is narrow. It would eliminate any pending claim filed in the prior two years that is a pen register or trap and trace claim tied to online conduct, including website cookies and pixels. That claim goes away, and for the people who have received Vivek Shah letters in the last few months, the pen register claim has been his only claim, so those letters lose their footing.

What it does not do is end the litigation. Plaintiffs pivot and firms are already saying they will switch to wiretapping claims under Section 631 and to federal claims. SB 690 makes life harder for the plaintiffs and takes some risk off the lawyers who only ever brought that one claim, but it is really just moving the problem somewhere else.

If you get a demand letter, don’t do these things

Usama told the participants that if a demand letter shows up to not settle, not respond, and not start changing things without first talking with counsel. He also said not to paste anything into ChatGPT or Claude either, because anything entered can be discoverable in litigation. 

Banner or no banner

One of the most common questions we get is whether you even need a cookie banner. And here’s what Usama said straight from the transcript:

Usama called it a damned if you do, damned if you don’t decision, because if you install a banner, even if you don’t have to, you take on obligations, and those obligations involve having someone at the wheel who knows exactly how it’s working all the time. You can’t simply install it, forget about it, and then two years later get sued because it wasn’t working the way it was supposed to and didn’t block everything.

A lot of people start with the question, am I legally required to have a banner? That’s a nuanced answer. If we’re talking about the 23 states with comprehensive consumer privacy laws like the CCPA, none of them actually require that you have a banner. The only exception is a couple of states that require opt-in consent to collect certain sensitive data, like precise geolocation. Generally, there is no requirement in any of these states to have a banner.

You just need to provide notice and an opportunity to opt out of certain cookies, not even all of them, just the marketing, retargeting, and profiling cookies and behavioral analytics, and that notice can be a link at the bottom of your page. That’s the bare minimum compliance. Then you take the litigation risk on top of that.

Laws like CIPA weren’t written for the internet. There’s no guidance, no regulation, nothing in any of these wiretapping laws that tells you how to configure a cookie. So if you want to mitigate that litigation risk, you should have a banner, because it’s the only way to get opt-in consent before any third-party, non-essential cookie fires, even analytics.

My advice has been yes, install a banner, but it comes with a whole lot of maintenance work, and if you don’t have anyone in-house that knows how to manage it and maintain it, that’s when you engage your consultants, like Jodi, for example, to manage it for you, and to make sure that it continues to run properly.

🤗 Thanks, Usama, for the kind shout-out! We do love helping companies set up these cookie consent solutions!

Put your terms of use in the banner

Usama highlighted that most companies miss listing the terms of use in the banner. The suggestion is to link to both your privacy policy and your terms of use, right in the banner, so people can review both before they click anything. Part of that is disclosure. The other part matters in litigation.

If your terms of use include an arbitration agreement, it is only enforceable if you presented it conspicuously, not buried in a link at the bottom of the page. A clickwrap, like a cookie banner, is one of the ways courts will actually enforce it, and an enforceable arbitration agreement is one of the strongest tools you have to keep a claim out of a class action. Usama described one company that used a choice of law provision in its terms of use to move a California case to Massachusetts, where the claim did not exist at all.

It comes down to one question

Most of these cases are not about the wording of a wiretapping statute. They are about whether your website does what you told people it does.

The newest and stickiest claims prove it. Companies often put up a banner that says people can opt out. Except we see all the time that the trackers are still firing even after someone opts out. Some courts are now saying the promise itself creates an expectation of privacy, which makes those cases much harder to defend. The banner you added to protect yourself gets used against you because it did not work.

This is where the former auditor in me loves to tick & tie things (anyone else here know what I’m talking about?)! Do the cookie categories and names match across the banner, the cookie policy, and the privacy policy? I have done numerous audits and find this isn’t the case. Often it’s called something targeting in one place and interest-based in another, analytics or performance, but not the same thing.

Those discrepancies seem like they are SO small who would notice? Plaintiff testers and regulators do. It’s another example where privacy program elements aren’t done in a vacuum – they have to work together.

Please, no more dark patterns

My latest mission on earth is to flag and stop dark patterns. The FTC does not like them, state regulators do not like them, and they will not help you here.

And yet, they are EVERYWHERE! There are so many to discuss. One of them is that consent options need to be symmetrical. One click to opt in means one click to opt out, and on the preference center page it needs a clear reject all button.

If accepting is one click and rejecting takes six trips through a preference center, that is a dark pattern. 

Test it like a real person

You can design a clean setup, and it still has to work. Have real people test it just like a consumer would experience it. Test on both desktop and mobile, which is a common platform companies forget to test.

I’ve said it before, and I’ll keep saying it, it’s not a one-time test. Websites are updated constantly. Technology isn’t perfect. That combo means stuff breaks and it needs to be caught before someone else finds it.

Do not trust cookie scans alone. Usama shared one case that makes the point. A company geofenced its site to California, blocked all cookies and pixels, and ran monthly scans. A year and a half later, a class action letter arrived saying six tags were still sharing data with data brokers. The scans never caught it because data can leave through tags and back-end connections a cookie scan does not see, and nobody was testing for those.

The pixel nobody remembers adding

My favorite line came from an attendee 👇:

A pixel goes up, the person who added it moves on, and it stays because nothing ever takes it off.

No one person can do this alone. Know who owns the tool, who owns the site code, who approves new trackers, and who makes the final call on risk. That is your cookie team, and yes, you can call it the pixel team, but cookie is more fun. You are all on the same team in the same company, and if you coordinate and talk, you get where you are trying to go. Do not assume your vendors have it handled either. The buck stops with you. You cannot blame the agency that built your site ten years ago, and the regulators will tell you the same thing.

It is a lot, but it is manageable if you know what the site collects, who it’s shared with, and whether the site actually behaves the way the notice says it does.

Your homework for the week? Work on one of the practical tips above!

Wishing you a great week!

Jodi


💡 When you’re ready, here’s how we can help:

⚙ Privacy Advisory & Implementation: We help companies navigate privacy requirements with confidence. Our advisory support covers strategy, operations, and real-world implementation.

⚙ Fractional Privacy Services: We provide fractional privacy leadership tailored to your needs and pace. From program development to day-to-day support, we help you build and sustain a strong privacy program.

The post The lawsuit hiding on your website appeared first on Red Clover Advisors.