California Invasion of Privacy Act Claims Targeting Businesses

August 27, 2026  |  Carole Clark Isakson

Privacy Alert: Please be aware that demand letters alleging violations of the California Invasion of Privacy Act (“CIPA”), which often seek statutory damages of up to $5,000 per alleged violation, are being sent to businesses all over the country. Have you received one? We have had many calls about these demands.

The California Invasion of Privacy Act (CIPA), originally enacted in 1960 to prohibit the unauthorized recording of confidential communications, is increasingly being invoked against businesses. It forms the basis for claims challenging common website tracking technologies such as cookies, pixels, chat features, digital marketing and other analytics tools. Under the CIPA, every party to a communication must consent to that communication being recorded, which, decades after enactment of CIPA, now implicates these technologies.

Businesses with websites accessible to the state of California, even those located elsewhere, may face claims that these technologies collect user data without proper notice or consent. In other words, the fact that your business is located in another state won’t stop the parties currently threatening these suits from reaching out to you. To reduce risk to your business, please review your websites to ensure users receive clear disclosures about what information is collected, how it is used, and options to opt in or opt out of collection. If you have any questions, please contact info@bgs.com.