Right now, businesses operating in the US are getting sued for functions on their website they don't even know could be illegal.
Not just European businesses. Not just big tech companies. We're talking small businesses, local businesses — the kind of agency clients you're probably working with right now.
And here's the part that should make you stop: some of these businesses already have a cookie banner. They're compliant with laws like the CCPA. They think they're covered.
They are not.
The warning letters arriving in mailboxes every single week are designed to induce urgency, if not outright panic. What these plaintiff law firms want is for companies to pay settlements, often in the five-figure range. But if they don't? See you in court, where the damages could run into six figures.
Watch: How CIPA Exposure Is Hitting Real Agency Clients
Below is the full breakdown of why an ordinary cookie banner leaves your clients exposed, and what to actually do about it. Here's what you'll take away from it.
What You'll Learn in This Post
- Your cookie banner likely handles CCPA (opt-out rights) but completely ignores CIPA (interception at communication)
- Tools that fire before consent — chat widgets, session replay, ad pixels — create potential wiretapping exposure
- Demand letters are landing in the $10K–$30K range, with settlements reaching $200K
- The fix costs a fraction of what a settlement costs, and the audit is squarely in the agency lane
Table of Contents
- What Is CIPA and Why Does Your Cookie Banner Ignore It?
- CCPA vs. CIPA: Two Different Legal Mechanisms
- Which Website Tools Are Actually In Scope?
- The Real Cost of Getting This Wrong
- How to Audit Your Clients' Sites for CIPA Exposure
- The Agency Opportunity Nobody's Talking About Yet
What Is CIPA and Why Does Your Cookie Banner Ignore It?
Here's what most business owners believe: “I've got a cookie banner. I'm CCPA compliant. I'm fine.”
And I get why they think that. CCPA compliance is real. Cookie banners are real. But there's a completely separate exposure that neither one covers.
It's called CIPA. California's Invasion of Privacy Act.
Here's the thing — this law is old. Like before the moon landing old. It was written in 1967 for wiretapping. But it's now being applied to ordinary business websites.
Specifically, it's being applied to the chat widgets, session recording tools, and analytics scripts that are running on your site right now.
The argument being made in these demand letters is that those tools are “intercepting” communications without consent. And courts have mostly let these claims move forward — though legal experts say this is still being tested and it's not fully settled.
There is legislation moving forward very slowly, but that wouldn't change anything until 2027 at the earliest. And it only addresses part of the problem.
That's the legal framing. I'm not saying it's right or wrong. What I'm saying is: these legal claims are working, and businesses are settling, because fighting it costs more than settling.

CCPA vs. CIPA: Two Different Legal Mechanisms
So when I say your cookie banner doesn't cover this — I mean it probably doesn't the way it's currently configured.
CCPA compliance addresses data collection and user rights. It requires visitors to be able to opt-out. It doesn't require prior opt-in in most cases.
CIPA exposure is about interception at the point of communication. It's a completely different law, working through a completely different mechanism.
| Factor | CCPA | CIPA |
|---|---|---|
| Focus | Data collection & user rights | Interception of communications |
| Mechanism | Opt-out requirement | Prior consent requirement |
| Law Type | Modern privacy regulation | 1967 wiretapping statute |
| Cookie Banner Coverage | Usually addressed | Usually NOT addressed |
| Trigger | Data practices | Tools firing before consent |
This means most compliance setups don't touch CIPA exposure, because they haven't needed to. The cookie banner displays, the user clicks accept (or doesn't), and the site owner assumes everything's handled.
But if those scripts fired before the user made a choice? That's where the exposure lives.
Which Website Tools Are Actually In Scope?
Let's get specific, because “wiretapping” sounds abstract until you see what's actually on your clients' sites. These letters and subsequent litigation keep pointing to the same categories of tools.
Live chat and chatbot widgets are the most common ones:
- Intercom
- Drift
- Zendesk Chat
The moment someone opens that chat window and starts typing, that text can be transmitted to a third-party server in real time.
Session replay and heatmap tools are the next big category:
- Hotjar
- FullStory
- Microsoft Clarity
These record what visitors type into forms and search bars, where they move their mouse, what they click. Incredibly useful for UX work. Also exactly what these claims are targeting.
Advertising pixels and analytics scripts with behavioral components:
- Meta Pixel
- Google Ads conversion tracking
- Analytics tools that capture form interactions and pass them off-site
Here's the thread that connects all of them: they fire on page load, before the visitor has done anything — before consent, before opt-in, before the person even knows the tool exists.

That's the actual technical trigger in these cases. Not the tool itself — when it fires relative to consent.
The Real Cost of Getting This Wrong
Let me put a number on this so it's not abstract.
Reports on these cases show initial demand letters landing in the $10,000 to $30,000 range. And full settlements have run as high as $200,000, depending on how many violations and how much California traffic is involved.
Now compare that to the fix.
One of the more effective things to do is get the right consent mechanism in place. We're talking a few hundred dollars a year in some cases. This gives you more protection, but even that is not a guarantee.
The math here is brutal. A $300/year tool versus a $30,000 demand letter. And most businesses don't even know they're exposed until that letter shows up.

What I'm Seeing in the MeasureU Community
I want to tell you what I'm seeing with my own eyes.
Inside MeasureU Pro — that's the private community for advanced professionals I run — there's a weekly mastermind where members share what's happening with their clients in the real world.
And almost every single week, someone posts about a client who just got hit.
A demand letter saying “you have 20 days to respond.” These are real agency clients, real businesses, sitting there with a letter from a law firm they've never heard of, asking for money they don't have, for a tool they didn't know was a problem.
And the agency owner is the one who has to explain it.
That's a rough conversation. “Hey, I set up your chat widget two years ago. Turns out that might be why you're getting sued.” Nobody wants to have that conversation. But it's happening.
How to Audit Your Clients' Sites for CIPA Exposure
The good news is this is not a huge project. An afternoon, maybe two, and you have a deliverable.
Step 1: Document What Fires Before Consent
Pick a client site right now. Open it in an incognito window. Before you click anything, open the browser's network tab. Watch what fires.
That list is your exposure map.
Tag auditing tools like Ghostery or a browser extension can speed this up if you're doing it across multiple pages. Or check out Fred Pike's new CMP Audit tool.

Step 2: Test Your Cookie Banner (Does It Actually Block?)
This is where most sites fail.
Cross-reference that script list against whatever consent banner they have. And I mean actually test it — load the page, don't click anything on the banner, and see if those scripts fired anyway.
A banner that displays but doesn't block is the number one failure mode I see. The site looks compliant, but it isn't — the scripts are already running.

Step 3: Implement Proper Consent Management
If there are gaps — and there almost always are — implement a consent management platform that actually gates the scripts behind real consent and honors Global Privacy Control signals.
Cookiebot is one option that handles this. They have a free cookie checker tool you can run for your site. There are others. The point is the consent tool has to do the blocking, not just the displaying.
That's the service: audit, document, fix. Squarely in the agency lane, no legal expertise required.

The Agency Opportunity Nobody's Talking About Yet
Here's where I want to shift gears, because I don't want this to just be a warning. That's where the business opportunity comes in.
Think about what your clients are running on their sites right now. Live chat, session recording tools, analytics scripts with behavioral tracking — every single one of those is potentially in scope for this kind of exposure.
And most of your clients have no idea.
That means you can be the person who finds it, explains it in plain English, and gets it fixed before a plaintiff law firm's scanning software finds it first.
No, I'm not talking about a legal service. I'm not suggesting that you begin practicing law. I'm talking about a technical audit and a compliance configuration as part of your agency services.
And the timing matters here. This is still early enough that most agencies aren't offering it yet. The businesses getting hit right now are getting hit because nobody in their orbit knew to look. You can be the person who looks.
The Conversation Shift
The agencies who are ahead of this — the ones who already know about it — they're having a completely different conversation than the ones who aren't.
The reactive conversation: “Hey, I set up your chat widget two years ago. Turns out that might be why you're getting sued.”
The proactive conversation: “We found something on your site that could expose you. Would you like us to fix it?”
That's a very different call to make.
Your Next Steps
So here's where I want to leave you.
Your clients' sites are probably exposed right now. And their existing cookie banner, whatever it is, almost certainly doesn't cover CIPA compliance. The business opportunity is real. The window to get ahead of it is still open.
Your next step is to perform that audit:
- Open a client site in incognito mode
- Before clicking anything, open the network tab
- Document every third-party script that fires
- Test whether the cookie banner actually blocks those scripts
- Start a real conversation with existing or potential clients
Want more details on this? There's a great article from Cookiebot on CIPA compliance that goes deeper into the legal specifics and technical solutions.
And if you're looking for a community of agency owners and analytics professionals who are navigating this stuff together in real time — that's exactly what we do inside MeasureU Pro. Weekly masterminds, real problems, real solutions. Come join us in MeasureU Pro.




















