Here is the new website shakedown pattern every California business owner needs to understand.
Updated July 5, 2026: California SB 690 is still pending, not current law, and the public docket trend has continued to expand across retail, finance, insurance, ecommerce, restaurant, sports-betting, and local small-business examples.
First, someone visits a public website and checks what tracking technology loads in the background. They look for cookies, analytics scripts, advertising pixels, chat widgets, session recording tools, form tracking, and tag-manager behavior. Then a claim arrives saying the website tracked or transmitted visitor activity without proper consent, sometimes under California wiretapping or privacy statutes that were designed to protect the public from invasive monitoring.
Those privacy protections matter. Businesses should respect visitor privacy, disclose what they collect, and give people meaningful choices. The problem is the predatory playbook now forming around those laws: small businesses are being pressured over ordinary website tools, often with the threat of statutory damages or settlement demands that can reach five figures. For a local contractor, medical office, retail shop, nonprofit, or professional service firm, even a demand approaching $50,000 can create real damage.
This is where business owners need to pay attention. Your website can look completely normal to customers while still carrying hidden exposure in the background.
How This Can Hit a Normal Business
You are busy running the company. You have someone working on ads. Someone else built or manages the website. Google Analytics is tracking traffic. A Meta Pixel or Google Ads tag is helping measure leads. Maybe there is a chatbot so customers can ask a quick question. Everything seems normal.
Then a demand letter shows up. It says your website tracking did not get proper consent from the visitor in California, a state commonly described as a two-party or all-party consent state. The claim may point to wiretapping-style privacy law, cookies, pixels, chat tools, analytics scripts, or a missing cookie consent banner. Suddenly, a normal marketing setup is being framed as a privacy violation, and the demand is not for a few hundred dollars. It may be five figures.
Take the example reported by the Elk Grove Citizen. The paper reported that Belinda Gutierrez, owner of Elk Grove Plumbing, Drain, Heating and Air, received a demand letter in November 2025 tied to her company’s website privacy practices. According to the report, the claims centered on the website not having a cookie consent banner and included multiple alleged violations. The article reported that the case initially sought about $20,000, and described the business owner’s pressure as a choice between spending heavily to fight or paying less to settle.
That is the part business owners immediately understand. The legal theory may be complicated, but the business problem is not: a demand letter can turn ordinary website tracking into a sudden legal and financial decision.
The Questions Business Owners Are Asking First
Could this happen to us if we are just a small company?
Yes. That is exactly why this trend matters. A small company may have a simple website, a few ad tags, a contact form, and a chat widget, but those are the same ingredients being examined in many website privacy claims. You do not need to be a national brand to become a target. You only need a public website with tracking technology that someone can inspect.
The Elk Grove example is important because it involved a local plumbing, drain, heating, and air business, not a tech giant. The owner told the Elk Grove Citizen she was shocked and confused when the demand arrived. That is the real-world risk for small businesses: by the time the owner understands the claim, the business may already be weighing legal costs, settlement pressure, technical fixes, and reputational stress.
Are these website privacy plaintiffs winning?
They are winning enough to create real leverage. That does not mean every claim is valid or every lawsuit succeeds. Courts are still sorting through these theories, and outcomes are mixed. Some cases survive early motions, some settle, and some are dismissed. New complaints keep being filed, but a filing is not a verdict. The practical issue is that settlement pressure can start long before a judge decides the final legal question.
That is the part that hurts small businesses: even if you have defenses, the cost of fighting may be higher than the cost of settling.
Have plaintiffs successfully won any of these cases?
There have been important plaintiff-side wins and settlements in website tracking and privacy cases. For example, Javier v. Assurance IQ became a major case because the Ninth Circuit allowed a CIPA session-replay claim to move forward on the question of prior consent. Other appellate cases, including Calhoun v. Google, Doe v. Cedars-Sinai Health System, and Briskin v. Shopify, show courts taking website, browser, pixel, analytics, and embedded-platform privacy claims seriously, even when those opinions are procedural or consent-focused rather than final liability rulings.
Regulators are also winning public settlements involving online tracking and opt-out behavior, including California Attorney General settlements with Sephora, Healthline, and Disney. Those regulator matters are not the same thing as a small-business demand letter, but they explain why tracking, consent, opt-outs, and ad-tech data sharing are now high-attention issues.
But many private CIPA website cases do not end with a public trial verdict. They may settle confidentially, get narrowed, move to arbitration, or get dismissed. As of our July 5 review, public CourtListener opinion searches still did not show a merits opinion for the newer CIPA section 638.51 website wave. So the better business question is not only “are they winning at trial?” It is “can this create an expensive legal problem before I ever get to trial?” The answer is yes.
What are the settlement ranges?
Public numbers vary widely depending on the type of case. Large public enforcement or class-action matters can reach seven or eight figures. The California Attorney General announced a $1.2 million Sephora settlement and a $1.55 million Healthline settlement. Those are not the same thing as a small-business demand letter, but they show why online tracking has become a serious enforcement and litigation topic.
For small businesses, demand and settlement amounts are often not public. Local reports and business-owner accounts describe five-figure pressure. Even a demand in the $10,000 to $50,000 range can be enough to force a hard decision, because defending a privacy lawsuit can cost more than the settlement demand.
Are people using small claims court for this?
We have not yet found reliable public reporting showing California small claims court as a primary venue for the current website-tracking and CIPA demand-letter wave. A July 5 public CourtListener opinion search for “CIPA,” “small claims,” and “website” still returned no matching opinion results. The better-documented pattern is demand letters, Superior Court cases, federal cases, confidential settlements, and sometimes arbitration or removal battles.
But small claims is worth watching. California’s court system says an individual can generally sue for up to $12,500 in small claims court, while a business plaintiff is generally capped at $6,250, and lawyers cannot represent parties in the small-claims hearing. CIPA’s statutory damages provision separately allows $5,000 per violation in covered claims. That overlap means one or two alleged violations could fit within small-claims dollar limits, even if we are not yet seeing this as the main public pattern.
For now, the bigger immediate threat to most small businesses is the demand letter itself. The financial pressure can start before the case is ever tested in court.
Are businesses successfully fighting back?
Yes, some businesses are fighting back successfully. Defenses can include consent, lack of standing, whether the data qualifies as protected communication content, whether the tool fits the statute, whether a third-party vendor is acting as a service provider, arbitration clauses, and whether the plaintiff can prove the technical allegations. Courts have dismissed some claims and narrowed others.
The problem is that fighting back still takes time, legal budget, technical evidence, and a clear explanation of what the website actually did. A business with no tag inventory, no consent records, no privacy review, and no evidence trail starts that fight from a weaker position.
What does it cost to become compliant?
There is no one-size-fits-all price because the work depends on the website, the industry, the tracking stack, and whether ads are running. A basic technical review may be a few hundred dollars. A normal small-business implementation may be several hundred to a couple thousand dollars when it includes cookie/consent configuration, tag review, privacy-policy coordination, testing, and documentation. Regulated or complex sites, such as health, finance, ecommerce, membership portals, or heavy ad-tracking environments, can cost more and should involve legal review.
The important point is that prevention is usually far cheaper than responding to a demand letter after the fact.
Should my normal web guy or gal handle this?
Maybe. But this is not just a design task, and it is not just installing a cookie popup. It requires someone who understands WordPress or your website platform, hosting, Google Tag Manager, ad pixels, analytics, consent behavior, privacy signals, conversion tracking, and how to preserve marketing attribution without creating avoidable privacy exposure.
If your normal web provider has not already brought this issue to your attention, you may want a second opinion from someone who is already watching website privacy, hosting, infrastructure, and marketing operations together. The stakes are too high for a set-it-and-forget-it plugin approach.

The Legal Angle Being Used
Many of these claims rely on California privacy laws, including the California Invasion of Privacy Act. A key case in this area is Javier v. Assurance IQ, where the Ninth Circuit addressed prior consent under CIPA in a website session-replay context. Plaintiffs have also used California’s pen register and trap-and-trace statutes, arguing that some website technologies collect routing, addressing, signaling, or browsing data without proper consent or authorization.
The pressure point is the damages provision. California Penal Code section 637.2 allows a private action for the greater of $5,000 per violation or three times actual damages in covered CIPA claims. That does not mean every demand is valid. It does explain why these claims can become expensive quickly, even when the underlying website technology was installed for normal business, marketing, or analytics reasons.
The law is meant to protect privacy. The abuse is in turning technical ambiguity into a settlement machine against businesses that had no idea their cookie banner, ad pixel, or chat widget could become a legal target.
This Is No Longer Just a Big-Tech Problem
Large companies have already been pulled into privacy and tracking disputes. The California Attorney General has announced enforcement actions involving online tracking, targeted advertising, Global Privacy Control signals, and cookie/opt-out behavior, including public settlements with Sephora and Healthline. Investigative reporting from The Markup has also documented sensitive data being transmitted from health-related websites through common tracking tools such as Meta Pixel.
More recently, Barron’s reported that financial firms including Morgan Stanley, Fidelity, Estee Lauder, and Edward Jones had been sued in California over alleged website tracking and data collection through tools such as pixels and web beacons.
But the trend is moving closer to Main Street. Local reporting has described small businesses facing demand letters or lawsuits tied to website privacy practices and cookie disclosure issues. The Elk Grove Citizen story also connected this small-business pressure to support for California Senate Bill 690, a pending bill aimed at narrowing some CIPA-related exposure for ordinary commercial business activity.
That should get the attention of every California business with a website.
Current Cases We Are Watching
The current filings do not support a simple “one plaintiff, one law firm” explanation. Public court records show multiple plaintiffs, multiple plaintiff-side firms, and several pleading styles. Some complaints focus on ad pixels and URL/referrer transmissions. Some focus on cookie banners that allegedly do not stop tracking after a reject or decline choice. Others use pen register or trap-and-trace theories tied to data-broker or ad-platform software.
Examples from public records include Elmarouk v. Morgan Stanley & Co. LLC, where the complaint alleges ad-tracker transmissions involving Google/DoubleClick, Microsoft/Bing UET, and The Trade Desk; Maurer v. Edward D. Jones & Co., L.P., where the complaint alleges financial-services website and portal tracking involving analytics, ads, session replay, and CIPA pen-register/trap-and-trace theories; and Kirkpatrick v. Crocs, Inc., a July 2026 case alleging Meta and Google tracking on an ecommerce site. These are allegations, not proven facts.
Public docket searches also show newer complaint clusters involving businesses such as DraftKings, Farmers Insurance, Brooklinen, Fender, CKE Restaurants/Carl’s Jr., Landry’s restaurant brands, National Debt Relief, Pfizer, Burberry, auto-brand websites, and online marketplaces. That does not mean those defendants did anything wrong. It means the targeting pattern is broad enough that ordinary business websites should be reviewed before a demand letter arrives.
Why Ordinary Website Tools Are Being Targeted
Modern websites are rarely just a few static pages. A typical business website may include:
- Google Analytics or GA4
- Google Ads conversion tags
- Meta Pixel or other social advertising pixels
- Microsoft, LinkedIn, TikTok, or other ad platform tags
- Google Tag Manager
- Chat widgets
- Call tracking scripts
- CRM or scheduling embeds
- Heatmap or session recording tools
- Cookie consent banners
- Form analytics or enhanced conversion tracking
Each of those tools may serve a legitimate business purpose. They help measure ad performance, improve user experience, attribute leads, route support requests, and understand what marketing is working.
The risk comes from the details: when the tool loads, what it collects, what it sends, whether the visitor had notice or a meaningful privacy choice, whether sensitive page information is included, and whether the privacy policy accurately explains what is happening.
That is why this is not only a legal issue. It is a hosting, infrastructure, marketing operations, analytics, and website governance issue.
What They Are Looking For
Many claims start with a technical review of the public website. A tester or automated scanner can load a page, watch network requests, check cookies, identify third-party scripts, and compare that behavior against the site’s privacy policy or cookie banner.
Common risk signals include:
- Advertising or analytics tags firing before a visitor makes a cookie choice
- A cookie banner that appears to offer a choice but does not actually suppress tracking
- No obvious “Do Not Sell or Share” or privacy choices path where one is needed
- Failure to honor browser-based opt-out preference signals such as Global Privacy Control where applicable
- Meta Pixel, Google tags, or other ad tools running on sensitive pages
- URLs, page titles, search terms, button labels, or form data being shared with third parties
- Chat widgets or session replay tools recording user interactions without clear disclosure or controls
- Privacy policies that do not match the actual technology running on the site

For businesses running ads, the challenge is even sharper. Blocking or delaying tags can reduce conversion attribution and remarketing audience size. Leaving everything running without governance can increase privacy risk. The right answer usually requires both legal review and technical implementation: consent-aware tracking, clean tag management, verified opt-out behavior, and careful handling of ad conversion data.
Senate Bill 690 May Help, But It Is Not Protection Today
California Senate Bill 690 is directly connected to this issue. As of July 5, 2026, SB 690 remains an active bill in the Assembly committee process. The official status page lists the bill in Assembly Appropriations, with the last amended date shown as July 2, 2026. The official history shows the Assembly Privacy and Consumer Protection Committee reported it out as amended and re-referred it to Appropriations after a 14-0 vote from the July 1 hearing.
The July 2 Assembly amendment changed the bill significantly. Earlier versions aimed at a broader “commercial business purpose” carveout. The current text focuses on Penal Code section 637.2 and would restrict private-actor claims under section 638.51 involving internet websites, online applications, or mobile applications so that those actions could be brought only by the Attorney General. The text also includes a two-year pending-claim retroactivity clause and severability language.
That matters, but businesses should not wait for the Legislature to solve this. SB 690 is not active law today. It may change again. It may not cover every theory being pleaded, including CIPA section 631, CIPA section 632, Federal Wiretap Act, CDAFA, privacy-policy, unfair competition, cookie-banner, or regulator enforcement theories. And until it is enacted and effective, it is not a shield against a demand letter.
The practical move is to reduce risk now.
What SKY1 Is Watching For
At SKY1, we look at this from the operational side: what is actually loading on the website, what infrastructure is serving it, which tags are managed through WordPress plugins or Google Tag Manager, which tools are needed for advertising performance, and where the privacy policy or consent layer no longer matches reality.
A real website privacy and tracking review should answer questions like:
- Which third-party scripts load on first page view?
- Which cookies are set before any consent choice?
- Does the site have a visible privacy policy and privacy choices path?
- Does the consent banner actually control ad and analytics tags?
- Does the site honor opt-out preference signals where required?
- Are ad pixels firing on sensitive pages?
- Is Google Consent Mode configured correctly?
- Are form submissions, call tracking, chat widgets, or session replay tools capturing more than they should?
- Will privacy changes break Google Ads, Meta Ads, or lead attribution?
- Is there an evidence trail showing what was reviewed and corrected?
This is the difference between installing a generic cookie plugin and actually managing website privacy risk.
What Business Owners Should Do Now
If your business operates in California or serves California visitors, start with a technical exposure review. Do not assume your site is fine because it has a privacy policy. Do not assume your site is fine because it has a cookie banner. And do not assume your marketing tags are harmless because they were installed for normal advertising or analytics purposes.
At minimum, your website team should inventory the scripts, cookies, tags, pixels, forms, call tracking, chat tools, and tracking behavior on your site. Then your attorney can review the legal language and policy obligations with a clear understanding of what the technology is actually doing.
SKY1 can help with the technical side: website scanning, tag inventory, cookie and consent behavior review, tracking audit, ad conversion impact review, and implementation planning.
This article is not legal advice. Privacy laws are fact-specific, and final policy language should be reviewed by qualified legal counsel. But from an infrastructure and marketing operations standpoint, one thing is clear: website tracking can no longer be treated as a set-it-and-forget-it plugin decision.
Request a Website Privacy & Tracking Evaluation
Sources and Further Reading
- California Attorney General: California Consumer Privacy Act overview
- California Attorney General: Global Privacy Control
- California Attorney General: Privacy enforcement actions
- Javier v. Assurance IQ, Ninth Circuit opinion
- Calhoun v. Google, Ninth Circuit opinion
- Doe v. Cedars-Sinai Health System, Ninth Circuit opinion
- Briskin v. Shopify, Ninth Circuit en banc opinion
- California Penal Code section 637.2
- California Penal Code section 638.51
- California Courts Self Help Guide: Small claims in California
- California SB 690 official status page
- California SB 690 official bill text
- Elk Grove Citizen: Local business owner speaks out against shakedown website lawsuits
- CourtListener/RECAP search: “638.51” and “website”
- CourtListener/RECAP search: CIPA and cookie banner
- CourtListener opinion search: “638.51” and “website”
- CourtListener opinion search: CIPA, small claims, and website
- CourtListener docket: Kirkpatrick v. Crocs, Inc.
- The Markup: Facebook receiving sensitive medical information from hospital websites
- The Markup: Tax filing websites sending financial information to Facebook
- Barron’s: California lawsuits over financial-firm website data collection
Web & Mobile
We create responsive web and mobile experiences tailored to your audience, ensuring seamless usability across all devices and platforms.
Brand Identity
We craft unique brand identities that resonate with your target market, blending visual storytelling with strategic messaging.
UX design
Our UX design services prioritize user-centered solutions, delivering intuitive and engaging interfaces that enhance user satisfaction.
Digital Marketing
We drive measurable growth with comprehensive digital marketing strategies, integrating SEO, social media, and data-driven campaigns.
Prototyping
Transforming ideas into tangible concepts, we develop functional prototypes to bring your vision to life and streamline the design process.
E-Commerce
Our e-commerce solutions combine design, functionality, and scalability, empowering businesses to sell effectively and grow online.

