Last updated: June 30, 2026 · By Kenneth G. Eade, Founding Attorney, AMZ Sellers Attorney
A new species of shakedown is arriving in the inbox of business owners across the country, and it has nothing to do with a faulty product, a contract dispute, or anything a customer actually complained about. It is a demand letter, often styled as a "Notice of Dispute and Demand," claiming that your own website illegally wiretapped a visitor because a tracking pixel, a search bar, or a contact form transmitted data to Meta, Google, or TikTok before the visitor consented. The letter cites a federal wiretapping statute and a 1967 California telephone-surveillance law, attaches screenshots of network traffic as evidence, and puts a number on the table designed to look cheaper than a fight.
I have responded to these demands on behalf of business clients, and the pattern is unmistakable. This article explains where these letters come from, who is targeted (it is not just e-commerce), what the law actually says in 2026, and the concrete steps that prevent and defeat the practice, including the defense arguments our firm has used to push back.
Anatomy of the demand
The template is mechanical and built for volume. A demand our firm recently defended is representative of the genre. It came from a plaintiff's firm on behalf of an individual claimant, and it followed the now-standard script:
- The theory. By installing the Meta Pixel, a few lines of JavaScript that virtually every business running Facebook or Instagram ads uses, the website owner supposedly procured and aided Meta to intercept the visitor's electronic communications with the site.
- The manufactured visit. The claimant visits the target site, often a single time, with developer tools or a capture proxy running. In the matter we handled, the claimant's own evidence (an off-Facebook activity log pulled from their personal account) confirmed exactly one page view. The claimant's listed contact email routed straight to the plaintiff's attorneys, and the demand instructed the business not to contact the claimant directly. These are hallmarks of a manufactured, tester-style claim, not an aggrieved consumer. Note that Google Ads uses the same type of pixel.
- The evidence. Screenshots from the Meta Pixel Helper browser extension and from network-capture tools like Fiddler, plus a downloaded HAR file, are attached to show data flowing to third parties. In our matter the demand admitted that the HAR screenshot was not even a capture of the claimant's own session. That admission matters.
- The kitchen-sink statute list. The letter stacks a dozen or more theories on top of the core wiretapping claim: the federal Electronic Communications Privacy Act (ECPA), California Invasion of Privacy Act (CIPA) Sections 631 and 638.51, intrusion upon seclusion, trespass to chattels via cookies, the Unfair Competition Law, the Consumer Legal Remedies Act, even statutory larceny and wire fraud. The volume is theater.
- The stacking math. Each third-party recipient and each statute is counted as a separate violation. In our matter, a single page view was leveraged into a demand exceeding 40,000 dollars, plus attorney fees.
- The forum trap. Sophisticated demands invoke the arbitration clause in your own Terms and Conditions, framing the letter as a mandatory pre-arbitration notice, because individual arbitration filing fees can make settlement look cheaper than defense.
Plaintiff-side operations now scan websites at scale, identify the tracking stack, and generate these letters by the hundreds. The technology that lets a marketer fingerprint a visitor is the same technology that lets a claims mill fingerprint a defendant.
Who is actually targeted: any business with a website
If you think this is an e-commerce problem, look again. The only prerequisite is a public website running a third-party tag, and that describes nearly every business in America. These demands target tour and hospitality companies, retailers, healthcare and wellness providers, professional-services firms, SaaS companies, local service businesses, restaurants, and nonprofits.
Three features make almost any site a target. First, the modern marketing stack is built to share data with advertising and analytics partners, which is the entire point of a pixel. Second, most sites load those scripts the instant the page renders, before any consent interaction, which is precisely the timing the plaintiff's theory depends on. Third, small and mid-sized businesses tend to settle, because a founder weighing a 40,000 dollar demand against the cost and uncertainty of litigation is exactly the target a claims mill is betting on. That settlement reflex funds the next hundred letters.
The legal reality in 2026: unsettled, but far from hopeless
Here is what the demand letter will not tell you. Applying a telephone-wiretapping statute to ordinary website code remains genuinely contested, and through 2025 and into 2026 the case law has tilted in meaningful ways toward defendants on the core theories. The cases these demands cite are, by and large, non-binding trial-court orders denying motions to dismiss, the lowest bar in litigation, and many later decisions have cut the other way.
- The party exception. A business generally cannot eavesdrop on a conversation to which it is itself a party. In Thomas v. Papa John's International, a non-published 2025 Ninth Circuit opinion, the court reaffirmed that a website owner using third-party software is like a person recording their own phone call with a tape recorder: a tool, not a third-party eavesdropper. Plaintiffs preemptively argued that the simultaneous duplication of browser GET requests defeats this exception, but the recent Ninth Circuit opinion has raised, not lowered, the bar they must clear.
- In transit and contents are real requirements. Section 631 reaches the contents of a communication captured while it is in transit. In Torres v. Prudential Financial (N.D. Cal. 2025), summary judgment was granted against a session-replay claim because the data became readable only after transmission.
- Internet is not a telephone wire. Several federal decisions, including Ninth Circuit treatment in Gutierrez v. Converse (2025), have questioned whether Section 631(a)'s first clause reaches internet communications at all.
- The pen-register theory is weak. Courts have held that Section 638.51's pen-register and trap-and-trace provisions reach telephone communications, not ordinary website software.
- Thin pleadings die. A plaintiff who merely browsed a site and recites the categories of data a pixel could collect has not alleged that their communications were actually intercepted. When the plaintiff's own evidence is a single page view, and an admittedly non-personal traffic capture, the contents element is where the claim collapses.
The defenses that actually work
These are the arguments we deploy when a client forwards one of these letters. No single defense fits every fact pattern, but in combination they routinely deflate the demand.
- Consent through the visitor's own Facebook account. If the claimant holds a Facebook account, they have already agreed to Meta's Terms of Service and Data Policy, which expressly disclose that Meta receives information about the websites you visit and cookie data, including through Social Plugins and the Meta Pixel. A visitor who consented to Meta collecting exactly this category of data cannot credibly claim the same collection was a non-consensual interception. We make the claimant prove they lack a Facebook account before their no-consent theory gets off the ground.
- The party exception. The website owner is a party to its own communications with visitors, and the pixel functions as its tool. Under Papa John's, that is not unlawful eavesdropping.
- No interception of contents in transit. Routing and metadata are not the contents of a communication, and data assembled after transmission is not captured in transit. Both are required and both are frequently absent.
- Demand authentication and the complete data. The screenshots in these letters are cherry-picked, undated, and unauthenticated, and sometimes are not even the claimant's own session. We insist on the date, source, and authentication of every exhibit, plus the complete underlying data report and identification of the tools used. Manufactured evidence rarely survives that request.
- Single-visit, single-violation reality. When the claimant's own off-Facebook activity shows one page view, the 40,000 dollar stacking theory is fiction, and saying so reframes the entire negotiation.
- The manufactured-plaintiff problem. Claimants who seek out pixel-bearing sites for the express purpose of generating demands, and who route all contact through counsel, face serious standing and good-faith problems. Visiting every website that uses Meta advertising to manufacture claims is not the injury these statutes were written to redress.
- Standing and the pen-register defense. Generic device metadata does not confer Article III standing, and Section 638.51 was not written for website JavaScript.
- Watch the crime-tort framing. These demands deliberately allege the tracking was done for the purpose of committing further criminal and tortious conduct, language aimed at defeating the consent exception under the ECPA. Courts are split, and the framing is vulnerable where, as is typical, there is no actual crime or tort beyond the alleged tracking itself.
Prevention: close the surface before the letter arrives
The same operational facts that create exposure can be re-engineered to defeat it. A privacy-and-consent audit of your website is the single highest-return move available right now.
- Control the firing order, not just the banner. A cookie banner is decoration if your tags fire on page load before any choice is recorded. Configure your consent-management platform to actually block non-essential pixels, analytics, and session-replay scripts until the visitor affirmatively consents.
- Honor Global Privacy Control in real time. A browser GPC or Do Not Track signal should stop non-essential tracking across every connected vendor instantly, not on a delay and not only on paper.
- Use clickwrap, not browsewrap. Courts have grown hostile to "by using this site you agree" notices buried in a footer. An affirmative, recorded acceptance of your Terms and arbitration clause is the difference between an enforceable defense and a dead letter.
- Mind the visitor-versus-customer line. The people who send these demands are almost never customers; they are drive-by testers. If your arbitration and consent terms attach to customers, accounts, purchases, and form submissions, rather than mere visitors, the serial filer often has nothing to stand on.
- Reduce client-side exposure. Where feasible, move tagging server-side so visitor data is not handed directly to third parties from the browser, and audit every script so your privacy policy reflects what is actually transmitted. Accuracy of disclosure is itself a defense.
- Document everything now. Keep dated records of your tag configuration, consent flows, and vendor contracts, including indemnity terms. The defenses that win are proven with firing logs and data-flow documentation, not a privacy-policy page.
Defense: what to do the day a demand arrives
- Do not ignore it. These letters are engineered to punish silence with a filed arbitration or lawsuit. A measured, counsel-drafted response protects you; non-response invites escalation.
- Preserve evidence before you change anything. Screenshot and log your site's current configuration and consent mechanisms first, then remediate. Altering the site without preserving its prior state can hand the other side a spoliation argument. Order matters.
- Put the burden back on the claimant. Demand authentication and the complete underlying data behind every exhibit, the date and purpose of the alleged visit, the email addresses actually used, and the specific confidential content supposedly intercepted. These demands routinely cannot withstand that scrutiny.
- Weigh arbitration carefully, both ways. An arbitration clause can compel an individual claim out of the class arena, but serial filers have learned to weaponize arbitration filing fees. The right move depends on your clause, the number of claimants, and the strength of your defenses, exactly the cost-benefit analysis our arbitration practice runs every day.
- Choose resolution or defense deliberately, not reflexively. If a claim carries genuine merit and exposure, an early, confidential resolution with a full release and no admission can be the disciplined choice. But most of these are templated drive-bys built on a single page view, and for those a firm response is usually the better and cheaper path, because paying one mill teaches the next one your address.
The bottom line
This is the same playbook businesses already know from other arenas: an automated system identifies a target, asserts a violation framed for maximum statutory leverage, and counts on the target paying to make it stop. CIPA and ECPA wiretapping demands reward preparation and punish panic. The businesses that come through this well audit their tracking stack and consent flow before a letter arrives, and answer the letter with current case law and pointed evidentiary demands rather than a checkbook. The law is unsettled, but it is moving, and, as we have seen first-hand, the defenses are real.
Frequently asked questions
What is a CIPA or ECPA wiretapping demand letter?
It is a pre-litigation demand claiming a business website illegally intercepted a visitor's communications because a tracking tool such as the Meta Pixel, Google Analytics, or a TikTok tag sent data to a third party before the visitor consented. It cites the California Invasion of Privacy Act (Penal Code Sections 631 and 638.51) and the federal Electronic Communications Privacy Act, and demands statutory damages, often framed as 5,000 dollars per violation.
Why did my business receive a Meta Pixel demand letter?
Because your public website runs a third-party tracking tag. Plaintiff-side operations scan sites at scale, identify the Meta Pixel or similar tags, and send demands in volume. The recipient usually did nothing unusual. The only prerequisite is a website that shares data with an advertising or analytics partner.
Are these CIPA demand letters legitimate or a scam?
They are real legal demands, but the underlying claims are contested and the damages are typically inflated. Many are sent by serial or tester claimants who visit a site once for the purpose of generating a demand. The law applying a 1967 telephone-wiretapping statute to ordinary website code remains unsettled, and recent court decisions have increasingly favored businesses.
How much money do these demand letters demand?
Demands commonly range from several thousand dollars to tens of thousands, built by stacking statutes and counting each third-party recipient as a separate violation. A single page visit can be leveraged into a demand exceeding 40,000 dollars, even though the realistic exposure is usually far lower.
What should I do if my business receives a CIPA demand letter?
Do not ignore it, but do not pay reflexively. Preserve evidence of your current website configuration before changing anything, then have counsel evaluate the claim, demand authentication of the claimant's evidence and the complete underlying data, and assess defenses such as consent and the party exception before deciding whether to resolve or fight.
Can I be sued just for using the Meta Pixel or Google Analytics?
A claim can be filed, but using common analytics and advertising tools is not automatically unlawful. Defenses include the party exception, because the website owner is a party to its own communications, the lack of any intercepted communication contents in transit, visitor consent through the visitor's own Facebook or platform account, and lack of standing for generic metadata.
How can I prevent CIPA wiretapping claims against my website?
Configure your consent platform to block non-essential tags until the visitor affirmatively consents, honor Global Privacy Control signals in real time, use clickwrap terms with an arbitration clause, consider server-side tagging, and keep your privacy disclosures accurate. A privacy and consent audit is the most effective preventive step.
About the author. Kenneth G. Eade (California State Bar No. 93774) has practiced law since 1980 and is the founding attorney of AMZ Sellers Attorney, a Sermondo Top 10-listed e-commerce and intellectual property law firm in Beverly Hills, California.
Received a CIPA or ECPA demand letter? Contact AMZ Sellers Attorney at [email protected] or +1-888-806-2440 for privacy demand-letter defense or a website privacy and consent audit.
This article is for general informational purposes and is not legal advice. It does not create an attorney-client relationship. CIPA and ECPA case law is evolving rapidly and outcomes are fact-specific; consult qualified counsel about your particular situation.

RSS Feed