If you run a business website, there is a legal wave you should know about, and it is coming out of California.
Over the past two years, plaintiffs’ firms have filed a growing pile of lawsuits and demand letters against ordinary business websites. The claim is almost always the same: the site loaded tracking technology, analytics, an advertising pixel, a chat widget, before the visitor ever agreed to it. Under California’s privacy laws, that is being framed as illegal surveillance. And the businesses on the receiving end are not just tech giants. They are dentists, contractors, retailers, credit unions, and local shops.
Here is what is actually happening, and what you can do about it.
Why a cookie banner is not enough anymore
Most websites already show a cookie banner. The problem is that on the majority of sites, the banner is decoration. Google Analytics, the Meta pixel, ad tags, and session-recording scripts fire the moment the page loads, long before anyone clicks “accept.” The banner asks politely while the tracking has already happened.
That gap is exactly what the lawsuits are built on. A federal appeals court has already held that consent collected after the fact does not undo tracking that already fired. In other words, a banner that “asks but does not block” may be worse than no banner at all, because it looks like consent while collecting none.
The two laws driving it
CIPA, the California Invasion of Privacy Act. This is a decades-old wiretapping statute written for phone taps. Plaintiffs are now applying it to website trackers, arguing that a tracker capturing a visitor’s activity without consent is the digital equivalent of an unauthorized recording. The exposure is what makes it serious: statutory damages of up to 5,000 dollars per visitor, per violation, with no requirement to prove any actual harm. On a site with real traffic, that math adds up fast.
CCPA, the California Consumer Privacy Act. This is the broader privacy law that gives California residents the right to know what data a business collects, to opt out of the “sale” or “sharing” of their data, and to have their browser’s Global Privacy Control signal honored automatically. California regulators have already issued significant fines to companies whose consent tools looked compliant but did not actually honor those choices.
Who is being targeted
The uncomfortable truth is that small and mid-size businesses are the sweet spot for this. The demand letters are largely cookie-cutter: the same template, sent at volume, priced to settle. Reported settlements commonly land in the range of tens of thousands of dollars, deliberately set below what it would cost to fight the claim in court. For a small business, that is a brutal choice.
And while these are California laws, the reach is wider than the state line. If your website has visitors from California, and almost every website does, you can be pulled in.
To be clear, this is not us giving legal advice. If you have received a letter, talk to a lawyer. But you do not have to wait for a letter to close the gap that these claims depend on.
The fix: consent before tracking fires
The defense that actually matters is technical, not cosmetic. It comes down to one principle: no non-essential tracker runs until the visitor opts in. That means:
- Prior blocking. Trackers are held, genuinely neutralized, until consent is given, not just hidden behind a banner while they run in the background.
- Default-deny. Advertising and analytics signals start in a denied state and only turn on for the categories a visitor actually agrees to.
- Honoring browser signals. The Global Privacy Control signal and a clear “Do Not Sell or Share” option are respected automatically, which is exactly what CCPA regulators have been enforcing.
- Proof of consent. A timestamped record of each visitor’s choice, so if you are ever asked, you can show what was agreed to and when.
A consent tool that does all of that turns your banner from a liability into a working control.
What we built, and why
When this wave reached one of our own clients, we did not wait. We built our own consent-management tool, called Handshake, and rolled it across every client website we run, the same day. It holds every non-essential tracker until a visitor opts in, runs Google Consent Mode v2 in default-deny, honors the Global Privacy Control signal, exposes a “Do Not Sell or Share” opt-out, and keeps a timestamped record of consent. It is open source, and we run it.
Every deploy failure during that rollout failed safe. Zero client sites were left broken. Our clients are protected.
Handshake gives you technical controls, not legal advice, and we always recommend your own counsel review the configuration for your business. But the technical part, the part that closes the gap the lawsuits target, is exactly what we do.
Want to know what your site is doing before consent?
We will scan your website for free and send you exactly what fires before a visitor agrees to anything. No obligation. If you want the gap closed, we can run the fix for you.
You can start at standandstretch.ai/handshake.
The lawsuit wave is not slowing down. The good news is that the fix is straightforward, and you can get ahead of it before a letter ever shows up.