CIPA And CCPA In 2026: Why US Ecommerce Brands Are Getting Demand Letters (And What Actually Fixes It)

Published:
August 17, 2026

US ecommerce brands face two separate privacy risks in 2026: CIPA demand letters over trackers firing before consent, and CCPA enforcement over broken opt-outs. A correctly wired consent management platform addresses both, but only if it actually blocks scripts.

Quick Decision Framework

  • Who This Is For: Shopify and DTC operators doing $250K to $20M who sell to US customers and run analytics, ad pixels, chat widgets, or session replay on their storefront.
  • Skip If: You sell exclusively B2B through a closed portal with no third party tracking scripts, or your store is not yet live and taking orders.
  • Key Benefit: Know which of the two US privacy risks actually applies to you, and which specific scripts on your store create the exposure.
  • What You’ll Need: Admin access to your Shopify store, your Google Tag Manager container, a browser with dev tools, and roughly 45 minutes.
  • Time to Complete: 11 minutes to read. 45 to 90 minutes for the tracker audit. Two to four hours to remediate if you find gaps.

The thing that triggers a demand letter is not what your privacy policy says. It is what your store does in the first 300 milliseconds after a page loads, before anyone has clicked anything.

What You’ll Learn

  • Why a 1967 wiretapping statute has produced thousands of claims against ordinary retail websites, and what plaintiffs actually allege
  • What a CIPA demand letter costs to settle, and why the number is lower than you fear but higher than you should pay
  • How SB 690 changes the picture if it passes by the August 31, 2026 deadline, and why it does not close your exposure
  • Where CCPA enforcement money is actually landing in 2026, with the specific technical failures regulators cited in each action
  • What to audit on your Shopify store this week, sequenced by revenue stage rather than by legal theory

Why a 1967 Wiretapping Law Became Your Biggest Website Risk

The California Invasion of Privacy Act was written to stop people from tapping telephone lines, and it is now the single most active source of privacy litigation against ecommerce websites in the United States. The mechanism is simple. CIPA allows statutory damages commonly cited at $5,000 per violation with no requirement to prove any actual harm, and plaintiffs argue that each visitor, sometimes each interaction, is a separate violation. That math scales in a way that gets attention.

The theory being pleaded in 2026 is narrower and more technical than the early cases. Attorneys at Loeb and Loeb describe it as a question of timing rather than technology: plaintiffs no longer argue about whether a pixel can constitute an interception, they argue about exactly when the tracker fired relative to the moment the visitor was given a choice. A Meta, TikTok, or Google tag that fires on page load, before the banner is even painted, is the fact pattern. A banner that appears but fails to actually block anything is the second fact pattern.

Two things about this surprise almost every merchant I talk to. First, you do not need a California entity, a California warehouse, or even California customers to be a target. A publicly accessible website is enough. Second, CCPA compliance does not protect you here. These are different statutes with different tests, and a store can be fully compliant with one while exposed under the other.

The exposure is not evenly distributed. Retail is the most targeted industry in the tracked filings, ahead of technology and professional services, which makes sense: retail sites carry the heaviest tracking loads because that is how retail marketing works.

What a CIPA Demand Letter Actually Costs

Most CIPA claims never become lawsuits, they become settlement demands in the $10,000 to $25,000 range, sent at volume by a small number of firms and pro se filers. Counsel at CyberAdviser, tracking the Assembly hearings on reform legislation, put tens of thousands of these demand letters in circulation over recent years, with settlements typically landing in that band. The letters are templated, they arrive with a draft complaint attached, and they usually give you 20 to 30 days.

The economics are deliberate. Twenty thousand dollars is painful but cheaper than defending a class action, which is precisely the calculation the sender wants you to make. Courts have started to notice. In July 2026 a federal judge declared one of the most prolific individual filers a vexatious litigant, entering a pre-filing order requiring court permission before he could file further CIPA suits in that district.

The genuine class actions are a different scale. Spencer Fane’s practitioners note that a federal court in the Northern District of California granted final approval to a $3.85 million settlement against the Los Angeles Times on June 26, 2026, over three specific advertising trackers running on its website and mobile apps, pleaded under the pen register provision. Three weeks earlier, a California state court dismissed a near identical claim with prejudice. That inconsistency is the actual problem: the same website configuration can produce a dismissal in one courtroom and a seven figure settlement in another.

What decides your position is evidence. Plaintiffs build these cases from a HAR file, a network capture showing exactly which requests fired and when. If you can produce a timestamped record showing consent preceded the tracker, the conversation changes fast. If you cannot produce anything, you are negotiating blind.

SB 690 Is Not the Rescue Most Merchants Think It Is

California’s SB 690 would strip the private right of action from pen register claims, but it does not touch the wiretapping provision that half of these cases rely on, and it is not law yet. The bill passed the Senate 35 to 0 back in June 2025, stalled in the Assembly, and was revived and heavily narrowed on July 1, 2026. As Covington’s privacy team explains in their breakdown of the amended bill, it would leave enforcement of website pen register claims exclusively with the California Attorney General, and it would apply retroactively to claims filed within the prior two years.

Three constraints matter for planning. The bill must clear the Assembly floor and return to the Senate before the August 31, 2026 adjournment. If it passes and is signed, it becomes operative January 1, 2027. And critically, it addresses Penal Code section 638.51 only. Claims under section 631(a), the wiretapping provision, survive untouched, and plaintiffs have been stacking both theories in the same complaint precisely because they are separate.

There is also a perverse near term effect. Plaintiffs’ firms have every incentive to file as much as possible before any safe harbor takes effect, which means the window between now and the end of the year is likely to be busier, not quieter.

I want to be direct about what this means operationally, because I have watched merchants make this mistake with other regulatory deadlines. Waiting for legislative relief is not a strategy. Even in the best case for California businesses, the bill closes one theory, in one state, prospectively from 2027, while leaving the wiretapping claims, the Florida filings, and every state regulator entirely alone. The fix is the same either way, and the fix is technical.

CCPA Enforcement Moved From Tech Giants to Ordinary Retailers

California regulators are now fining mid market companies six figures for broken opt-out mechanisms, and the pattern in every recent action is a consent tool that malfunctioned rather than a policy that was missing. This is the shift most operators have not internalized. The early enforcement era targeted household names to set precedent. The current era targets whoever has a broken toggle.

Look at what regulators actually cited. Todd Snyder, the clothing retailer, paid $345,178 in May 2025 after its cookie preference popup appeared and then vanished before anyone could click it, leaving opt-out requests unprocessed for 40 days. Not a missing banner. A banner that was there and did not work. Honda paid $632,500 in March 2025. Healthline settled at $1.55 million in July 2025. Tractor Supply paid $1.35 million in September 2025.

Then 2026 escalated. The California Attorney General announced a $2.75 million settlement with Disney on February 11, 2026, at the time the largest CCPA penalty on record, over opt-outs that worked on one device but not across a logged-in account, and Global Privacy Control signals honored at the device level only. Ford paid $375,703 in March. PlayOn Sports paid $1.1 million. General Motors settled at $12.75 million in May 2026.

Two rule changes took effect January 1, 2026 that raise the floor further. A business must now visibly display that it has processed a Global Privacy Control opt-out, and a visitor closing or navigating away from a consent popup without affirmatively accepting does not constitute consent. Penalty amounts were also inflation adjusted to $2,663 per unintentional violation and $7,988 per intentional violation. If you are running a consent banner you inherited from a theme or an app three years ago, both of those rules are worth checking this week.

The Twenty State Patchwork Is Simpler Than It Looks

Twenty US states now have comprehensive consumer privacy laws in effect, with Indiana, Kentucky, and Rhode Island joining on January 1, 2026, and the practical compliance burden is far smaller than that number suggests. The IAPP maintains the authoritative tracker if you want to see the full picture with effective dates.

Here is the part nobody tells early stage founders: you almost certainly do not need twenty configurations. The state laws converge on the same core obligations, which are notice at collection, a right to opt out of sale and sharing, a right to access and delete, and honoring universal opt-out signals. Build to the strictest common denominator, which in practice means California plus Colorado’s universal opt-out requirements, and you have covered the substance of the rest.

What varies and genuinely matters is the applicability threshold. Most state laws only bite above a revenue or data volume floor. A store doing $400K with 15,000 US customers is below the threshold in most of these states, and treating a $400K store like a regulated enterprise is exactly the premature complexity that stalls brands at this stage. That is the pattern I watched hundreds of times during my years at Shopify: a founder adds tooling for a problem they do not yet have, then cannot afford the tooling for the problem they do.

The thresholds do not help you with CIPA, though. That statute has no revenue floor. A $200K store with a Meta pixel firing on page load carries the same theoretical per-violation exposure as a $200M one, which is why the tracker audit matters more than the state law matrix for most readers of this piece.

The Millisecond Problem on a Real Shopify Store

On most Shopify stores under $2M, tracking scripts are firing before consent that nobody on the team knows about, because they were installed by apps rather than by a developer. This is the load bearing claim of this article and I will defend it: every time I have sat with an operator and opened the network tab on their own storefront, we have found requests going out to domains they could not name.

The reason is structural. An app that adds reviews, or a chat widget, or a heat map, or an upsell engine, injects its own scripts and often its own third party calls. Nobody removes the scripts when they uninstall the app. Nobody documents what each one talks to. Six apps become twelve, twelve become twenty, and the consent banner sitting on top of that stack has no idea any of it exists unless it was configured to know. This is the same accumulation problem I have written about in the context of app bloat and operational drift, showing up in a legal register instead of a performance one.

The test takes ten minutes. Open your storefront in a private window, open dev tools, go to the network tab, filter to third party domains, and hard reload without touching the banner. Everything you see in that list fired before consent. Now do it again on a product page and on your cart, because tag configurations frequently differ by template.

The remediation is a category mapping exercise, not a banner swap. Every script gets assigned to strictly necessary, analytics, or marketing, and every non-essential category gets genuinely blocked until the visitor chooses. A consent management platform is the mechanism that enforces this. Cookiebot by Usercentrics takes the approach of scanning your domain, producing an inventory of what it finds, and blocking by category, which is useful precisely because the inventory step surfaces the scripts you forgot about. OneTrust and TrustArc serve the same function at a heavier enterprise weight, and Shopify’s own customer privacy settings cover the basics in the admin if your stack is genuinely simple. The honest guidance is that the tool matters less than whether the blocking actually works, which is a thing you test rather than assume.

What to Fix This Week, by Stage

Your first move depends on revenue and traffic mix, not on which statute worries you most, because the audit is identical and only the depth of the response changes. Here is how I would sequence it.

Under $500K, do the network tab test and nothing else this week. If you find non-essential scripts firing pre-consent, install a consent management platform, categorize your scripts, and verify the blocking. That is a half day of work and it removes the fact pattern that generates demand letters. Do not build a data inventory, do not hire privacy counsel, do not buy governance software. You are below the threshold on most state laws and your risk is concentrated in one place.

Between $500K and $5M, add two things. Confirm your Global Privacy Control handling, including the new visible display requirement that took effect January 1, 2026, and confirm your opt-out actually propagates to your ad platforms rather than just setting a cookie locally. The Todd Snyder and Disney actions both turned on opt-outs that existed and did not fully work. This is also the stage where the shift toward zero party and first party data stops being a nice idea and starts being how you keep marketing effective while collecting less.

Above $5M, you need the record, not just the configuration. Retain consent logs with timestamps, run the tracker audit quarterly rather than annually, and build the data inventory that maps where customer data actually lives. If you build or commission Shopify apps, the protected customer data requirements apply to your development pipeline too.

Across every stage, the durable version of this is worth stating plainly. Privacy law will keep changing, and any specific rule cited in this article could be amended within eighteen months. What will not change is that a store which knows what fires, when, and with whose permission is in a defensible position, and a store which does not is negotiating from ignorance. Build the knowledge, not the paperwork.

Frequently Asked Questions

What is a CIPA demand letter and do I have to respond to it?

A CIPA demand letter is a pre-litigation notice alleging that tracking technologies on your website intercepted visitor communications without consent under the California Invasion of Privacy Act, and you should respond rather than ignore it. The letters are typically templated, arrive with a draft complaint attached, and give you 20 to 30 days to settle, usually in the $10,000 to $25,000 range. Ignoring the deadline strengthens the sender’s position and forfeits your chance to evaluate or negotiate. Get counsel involved, and simultaneously capture evidence of your current consent configuration, because a timestamped record showing consent preceded tracking materially changes your negotiating position.

Does my Shopify store need a cookie banner if I only sell to US customers?

Yes, if you run any third party analytics, advertising pixels, chat widgets, or session replay tools, even selling exclusively to US customers. There are two separate reasons. Twenty states now have comprehensive privacy laws requiring opt-out mechanisms for the sale and sharing of personal information, and California’s regulations as of January 1, 2026 require visible confirmation that Global Privacy Control signals were processed. Separately, CIPA claims have no revenue threshold and no California nexus requirement, so any publicly accessible site running trackers before consent carries exposure. A banner that does not actually block scripts satisfies neither requirement.

Will SB 690 stop CIPA lawsuits against ecommerce websites?

No, SB 690 would only eliminate private lawsuits under CIPA’s pen register provision, leaving wiretapping claims under section 631(a) fully available to plaintiffs. The bill was narrowed substantially on July 1, 2026, must clear both chambers before the August 31, 2026 adjournment, and would become operative January 1, 2027 if signed. It would shift pen register enforcement to the California Attorney General and apply retroactively to claims filed in the prior two years. Because plaintiffs routinely plead both theories together, and because the bill does not affect other states or state privacy regulators, businesses should not treat it as a reason to defer technical remediation.

How much are companies actually being fined under the CCPA in 2026?

Recent CCPA penalties range from roughly $345,000 to $12.75 million, with California regulators announcing over $4 million in the first quarter of 2026 alone. The largest actions include General Motors at $12.75 million in May 2026, Disney at $2.75 million in February 2026, PlayOn Sports at $1.1 million, and Ford at $375,703. Statutory amounts were inflation adjusted for 2026 to $2,663 per unintentional violation and $7,988 per intentional violation, calculated per affected consumer. Notably, every one of these actions involved a broken or incomplete opt-out mechanism rather than a missing privacy policy.

How do I check whether my cookie banner is actually blocking trackers?

Open your storefront in a private browsing window, open your browser’s developer tools to the network tab, hard reload the page, and do not interact with the banner. Every third party request that appears in that list fired before consent. Repeat the test on a product page and on your cart, because tag configurations often differ by template. If you see calls to advertising or analytics domains, your banner is collecting preferences without enforcing them, which is the exact fact pattern in both the Todd Snyder enforcement action and the current wave of CIPA filings. Fix it by categorizing every script and blocking non-essential categories until consent is given.

FIND US ONLINE

WEEKLY DTC INSIGHTS

TRUSTED BY THOUSANDS

TRUSTED PARTNERS

Choose a language