CartStars
Knowledge Exchange · July 31, 2026

Your website could get you sued

Two privacy litigators walked the room through the tracking lawsuits hitting ecommerce brands right now, what the letters actually cost, and the audit worth doing before one lands.

$5,000 per violation
4,700+ lawsuits since 2022
No proof of harm required
Brought to the room by
Manatt, Phelps & Phillips, LLP
Harrison Brown (he/him)
Partner, Consumer Protection and Advertising, Privacy

Harrison litigates these cases, so he is the one who sees what happens after the letter arrives.

Brandon Reilly
Partner and Leader, Privacy and Data Security

The compliance work is Brandon's practice, and the California bill that would shut a chunk of this down is being written with Brandon at the table.

If you only read this

Six things to do before the letter

  1. Inventory your tags, then delete what nobody uses.Most sites carry trackers no one has looked at in a year. That is pure risk with zero return, and it is the cheapest win available to you.
  2. Test that your cookie banner actually blocks.If it promises people can opt out and the tracking continues anyway, the banner itself becomes the evidence against you.
  3. Check your insurance, including the notice window.Some policies give you as little as 30 days to report a claim. Miss it and you can lose the coverage entirely.
  4. Do not switch to opt-in consent without measuring it first.One member tried it and lost about a third of their California traffic in three weeks. No US law requires opt-in.
  5. Get page-level control of your pixels.The one-click app integrations fire on every page with no way to exclude any, including logged-in account pages.
  6. If you have had a letter, tell a lawmaker.California's SB 690 would shut these suits down retroactively, and it reaches the Assembly floor within weeks. Reply and I will connect you.

The full story

Open only what applies to you. Each section stands on its own.

The claim A 1967 wiretapping law, pointed at your Meta pixel Why a statute written for rotary phones is now an ecommerce problem.

The California Invasion of Privacy Act was written in 1967 to stop the government from tapping landlines. It says nothing about websites, cookies or pixels, because none of those existed yet.

Starting around 2022, plaintiffs' lawyers began arguing that a pixel sending browser activity to a third party is the modern version of a wiretap. Courts are split, and there is no binding appellate ruling either way. Harrison told the room that a judge recently described the statute in an opinion as "a total mess."

That uncertainty is the business problem. Every trial judge is starting from scratch, so the outcome depends on which plaintiff, which firm and which courtroom you draw.

The math Nobody has to prove they were harmed $5,000 per violation, the $500 million arithmetic, and three settlements that actually happened.

These are statutory damages, which means the law sets the dollar amount and the plaintiff only has to show the thing happened. They never have to prove that anything bad came of it.

$5,000Per violation under California's CIPA, with no proof of harm required
$10,000Per violation under the federal ECPA, which also lets them plead a nationwide class
4,700+Lawsuits filed since 2022, and the real number is higher because letters and arbitrations never reach a docket

Here is how the number gets scary. A plaintiff browses your site, opens the browser console, counts your third-party trackers, and multiplies. Then they add every California resident who visited in the last twelve months and call it a class.

Manatt put the arithmetic on a slide. One hundred thousand visitors multiplied by $5,000 is $500 million in theoretical exposure, from a site doing nothing unusual.

That number is theoretical. These are not.

SettlementCase
$46MDoe v. Kaiser Foundation Health Plan
$3.85MMirmalek v. Los Angeles Times
$1.2MShah v. Fandom, Inc. (GameSpot)

Underneath those sit countless demand letter settlements that nobody ever reports.

The surface The tools in question are the ones you already run Pixels, session replay, chat widgets, email tracking, and the banner that can be used against you.

None of this requires you to be doing anything unusual. Look down this list and count how many are live on your site right now.

ToolThe argument against it
Ad pixelsMeta, TikTok and Google tags get called the eavesdropper, quietly forwarding a visitor's activity to a third party
Session replayHotjar, FullStory and Clarity get framed as intercepting a confidential communication when they record mouse movement and form input
Chat widgetsZendesk and Intercom claims are what launched this wave, with plaintiffs arguing their support conversation was wiretapped by the vendor
Email trackingOpen and click pixels get pulled into the same theory as web tracking
Analytics and SDKsIP and device logging gets called a pen register, which is the old device that recorded who called whom
Your cookie bannerIf it promises to block trackers and then does not actually block them, the banner itself becomes the evidence

That last one is the newest theory and it is the one that stings. A banner you installed to protect yourself can be turned into proof that you knew and did it anyway.

Two code sections do most of the work. Penal Code 631 is the wiretapping and eavesdropping provision, and Penal Code 638.51 is the pen register and trap-and-trace provision. Section 631 carries a large share of these claims, which matters for the bill below.

There are strong arguments against all of it

Manatt was clear that these theories are contestable. The statutes were written for telephones, there is no actual harm, users often consent through banners and policies, many courts have dismissed these claims outright, and criminal statutes are supposed to be read narrowly under the rule of lenity.

The problem is not the strength of your defense. The problem is that the statutes define almost nothing, binding appellate precedent barely exists, and judges are landing all over the map. A key California appellate decision in the Variety Media case is still pending.

The target You are the sweet spot Who gets picked, which states are active, and the three kinds of firms sending letters.

They sue aerospace companies and janitorial staffing firms, so there is no clean profile. But the volume filers lean toward small and mid-size businesses on purpose.

You are big enough to write a settlement check, and you are not big enough to hire forty lawyers and fight it to the end of the earth. That is the whole calculation.

A few things move you up or down the list. Health, wellness and financial brands are more attractive because it is easier to argue the browsing data is sensitive. Pure B2B has stronger arguments but is not immune.

Watch for the double hit, too. The same firm will increasingly pair the privacy claim with an accessibility claim about your site in the same letter.

California is ground zero, but it is not the only front

WhereVolumePer violation
California3,100+ under CIPA, the highest anywhere$5,000
Florida580+ under the FSCA, surging since 2025$1,000 plus fees
IllinoisAbout 95, an emerging frontVaries
PennsylvaniaAbout 48 under WESCA, all-party consent$1,000 plus punitive
FederalECPA claims, filed in any court, nationwide$10,000

Only Tennessee, New Hampshire and Alaska have carved out exclusions. Most states have not, so a fix built only for California does not travel.

Five ways the claim actually arrives

They do not all look like a lawsuit. You might get a class action, a pre-litigation demand letter, a mass arbitration filed without warning with thousands of demands at once, a small claims filing as one of hundreds of identical suits, or a serial tester plaintiff who files at volume for profit.

Three kinds of letters, and they behave differently

  • The volume filers want a fast settlement, usually somewhere between five and thirty thousand dollars, deliberately priced below what your first round of defense would cost.
  • The true believers see themselves as privacy advocates and often want commitments and changes rather than only money.
  • The sharks are well resourced, they will litigate for a long time, and they are the ones running the newest theories.
The trap Fixing one law can break another Twenty-plus state privacy laws already regulate this, and your lawsuit fix can violate them.

There are now more than twenty state privacy laws that actually do regulate cookies, pixels and advertising directly. Those laws require specific privacy policy disclosures, a real opt-out, honoring automated browser opt-out signals, vendor contract terms, deletion and access rights, and data minimization.

Regular people cannot sue under those laws, so state attorneys general enforce them instead. That is why they get less attention even though they are the ones genuinely aimed at this.

Brandon's warning was blunt. Teams often write a cookie banner purely to answer the lawsuit risk, and the wording they choose puts them in violation of the privacy laws that actually apply to them.

Whatever you change, change it against both rulebooks at once.

The debate The opt-in question, with real numbers A member measured what explicit consent costs. It was about a third of their California traffic.

Someone in the room asked the question everyone actually wants answered. Going to explicit opt-in consent is close to bulletproof against these claims, so should everyone just do it?

Here is what that same operator measured when they turned it on. California traffic dropped about a third, revenue followed it down, abandoned-cart flows broke, and only 0.83% of visitors touched the banner at all. They turned it back off.

Brandon's answer came in two parts. On the law, with the caveat that he is a self-described privacy nerd and there are edge cases:

For all intents and purposes, there is no law in the United States that requires opt-in consent.

Brandon Reilly, Manatt

And on what companies actually do:

Based on my sample size, which is hundreds of companies that I've worked with, the vast majority do not implement opt-in consent.

Brandon Reilly, Manatt

He added a detail worth keeping. During the California rulemaking, regulators considered requiring opt-in and heard testimony from the privacy agency's executive director that almost nobody engages with those banners, so it is not a meaningful privacy protection in practice.

Treat it as a business decision rather than a compliance answer. There is a whole spectrum between firing everything on page load and blocking everything until someone clicks yes, and most of the value sits in the middle.

The work The full audit, in eight steps What to hand your dev team or your agency on Monday.

Nobody can sell you CIPA compliance, because the law is too unsettled for anyone to know what compliance would mean. What you can do is lower the odds of being picked and be in a much better position if you are.

  1. Inventory every tag on the site

    List every pixel, script and SDK, and note which ones fire before consent versus after. Check your subdomains and do not skip the logged-in account pages.

  2. Delete what nobody is using

    Most sites are carrying trackers that no one has looked at in a year. Those are pure litigation risk with zero business return.

  3. Weigh each tool honestly

    Ask whether that session replay tool is worth a potential lawsuit. Some of them are, and the point is to make that call deliberately rather than by default.

  4. Take control of which pages fire

    The one-click app integrations drop the pixel on every page with no way to exclude any. A tag manager or a consent platform lets you keep the pixel where it earns money and pull it off account pages and anything that implies something sensitive about the visitor.

  5. Test that your banner does what it says

    If someone clicks reject and the cookies still drop, you have handed them a second claim. Verify the blocking behavior yourself and re-test it regularly, because a banner that looks right and works wrong is worse than none.

  6. Give people a real choice, and keep the receipts

    Offer accept, reject and manage rather than one giant accept-all button. Then log every consent event with a timestamp, because that log is your evidence if you are ever challenged.

  7. Send less data, and send it server-side

    Server-side tracking moves collection off the visitor's browser and weakens the third-party interception argument. Hashing identifiers before they leave your systems cuts exposure further, and Google's consent mode adjusts tag behavior automatically where you can use it.

  8. Read your insurance policy before you need it

    Check whether your policy covers privacy and wiretapping litigation specifically, and whether the limits are anywhere near the statutory exposure. Ask your broker about an Enhanced Privacy Liability endorsement, which closes gaps standard policies leave open.

    Then find the notice requirement and write it down. Some policies give you as little as 30 days to report a claim.

This is not a one-time review, because marketing, developers and agencies all keep adding tags. Drift is the enemy.

The window There is about a month to change the law SB 690, what it would do, and the one thing they need from operators who have been hit.

Brandon has been working with California State Senator Anna Caballero on Senate Bill 690, a two-year effort to amend the statute for the internet age.

It passed the California Senate unanimously in 2025 and cleared the Assembly Privacy Committee in July 2026. As written now, it removes the private right of action for pen register and trap-and-trace claims, and it applies retroactively two years, which would reach claims already filed.

The fight left is over Section 631, the wiretapping and eavesdropping provision. Some lawmakers believe the problem is already solved.

The ask

They are looking for operators who have been hit under Section 631 to talk to lawmakers and reporters. Real stories from real brands are what moved this bill the last two times.

If you have received one of these letters and would be willing to say so out loud, that is the single highest-leverage thing you can do here. It goes to Appropriations and then the Assembly floor within weeks.

Manatt's own advice on the slide was blunt, and it is worth repeating. Don't wait for the legislature to save you.

Members only · flat-rate audit

Manatt built an offer for this room

They will run the site audit at a flat rate rather than on the clock, so you know the cost before you start.

The audit reads every tracker on your site against all of the privacy laws that actually apply to you, and it comes back as options with the pros and cons of each spelled out rather than one answer. The recommended cookie banner and privacy policy language comes with it.

Ask me for the introduction

Peer intelligence for commerce leaders at the world's top brands.

This session happened because a member asked for it. That is how the room works, and it is why nobody in it is selling you anything.

Debbie Pearce, Founder & CEO, CartStars
LinkedIn · cartstars.com

This is a summary of a session held for CartStars members on July 31, 2026 and it is not legal advice. Nothing here creates an attorney-client relationship, statutes and case law are moving quickly, and your own facts matter. Please talk to qualified counsel before making changes to your site.