Introduction to Florida's Legal Landscape
A Florida FSCA demand letter claims your website's tracking scripts illegally intercepted a visitor's data. It names a decades-old anti-eavesdropping statute, cites a dollar figure per violation, and gives you a short window to respond. Here's what it means and the moves to make in the next 48 hours — before you make the mistakes that turn a defensible claim into a costly one.
If you're reading this because a letter just landed in your inbox or your general counsel's, you're not alone. One plaintiff's firm alone has reportedly filed more than 160 of these suits against Florida-facing e-commerce sites, according to a WPBF investigation — and demand letters, which precede many of these filings, are landing on businesses that have never operated in Florida beyond having customers there.
This guide walks through what the letter is actually alleging, the response steps that matter most in the first 48 hours, and why the businesses that come out ahead are the ones who can prove what their site was doing — not just say it.
For the full breakdown of the legal theory behind these suits — what the FSCA's pen-register and interception provisions actually say, and why a decorative cookie banner doesn't protect you — see our companion piece, Florida's 1969 Wiretapping Law Is Being Used to Sue E-Commerce Sites.
What the demand letter is actually alleging
Strip away the legal formatting, and most of these letters make one of two claims under Florida's Security of Communications Act (Chapter 934):
Pen register / trap-and-trace (§ 934.31). The letter argues that a tracking script — a Meta pixel, analytics tag, chat widget, or session-replay tool — functions like a device that captures routing information (in this case, a visitor's IP address and browsing behavior) without consent.
Interception (§ 934.03).
The letter argues the same script intercepted and forwarded a visitor's data to a third party the moment the page loaded, without the prior consent Florida's all-party-consent rule requires.
The letters typically name a statutory damages figure — the FSCA allows recovery of the greater of $100 per day or $1,000, plus attorney's fees — and often reference a specific plaintiff or firm associated with a wave of similar filings (the Johnson | Dalal suits are the most publicly reported example). The economics matter here: the individual claim amounts are small by design, calibrated so that settling quietly is often cheaper than defending, regardless of the claim's merit.
The first 48 hours: what to do (and not do)
Don't touch your site, tag manager, or code yet.
The instinct to rip out the offending script immediately is understandable — resist it until you've talked to counsel. Altering the evidence of what your site was doing can look like spoliation, and it destroys the record that might actually help you (for instance, proof that consent controls were already in place and working).
Confirm the deadline.
These letters and any accompanying filings often carry a short, specific response window. Calendar it the day the letter arrives, not after you've read it twice.
Engage a Florida-licensed attorney.
This is a state statute with state-specific procedure. A generalist privacy consultant or your existing corporate counsel may not be enough on their own — you need someone who has actually handled FSCA matters.
Pull your consent and tag records before you do anything else.
The single most useful thing you can hand your lawyer is a clean, timestamped answer to: what tags were firing on your site, when, and whether they waited for visitor consent. If you don't have that record, start reconstructing it now.
Loop in your consent management vendor immediately.
If your CMP or tag-blocking platform can produce logs showing pre-consent blocking was active, get that evidence into your attorney's hands early — it's often the difference between an early dismissal and a prolonged discovery fight.
Why "we have a cookie banner" won't be your defense
This is the mistake that turns a defensible site into a real liability, and it's worth understanding before you respond to the letter. A banner that displays while your Meta pixel, Google tags, and analytics scripts fire in the background regardless of what the visitor clicks is not consent — it's decoration.
Plaintiffs' counsel in these cases increasingly know to check exactly this: did the tracking tags wait for an opt-in, or did they fire on page load no matter what the visitor did? A banner that collects a click without changing what already happened is not going to hold up, and a vague line buried in a privacy policy about "collecting usage data" isn't the specific, prior consent the statute is read to require.
If your answer to "did the scripts wait for consent" is "we're not sure" or "probably," that's the gap the letter is aimed at.
How to actually respond from a position of proof
Every count in an FSCA claim depends on the absence of consent. That means the strongest response isn't a longer legal argument — it's evidence. Specifically:
- A timestamped record showing when your consent controls went live
- Network-level logs showing the named trackers didn't fire before a visitor opted in
- Documentation of consent language and mechanism in place at the time in question
- A current, accurate list of every third-party script running on the site, so nothing is missed in the response
This is the gap most consent tools leave open — they'll tell you a banner was generated, but not what actually happened at the network level when a real visitor arrived. PieEye's scanner runs your site the way a visitor's browser does, reports exactly what fires before consent, and keeps the timestamped records that turn "we believe we were compliant" into "here's the proof." For a demand letter response specifically, that proof is what your attorney needs, and it's what a plaintiff's firm is least prepared to argue against.
FSCA vs. FDBR — don't confuse the two
If you're researching this, you may run into content about Florida's Digital Bill of Rights (FDBR) — a separate, comprehensive consumer privacy law. It is not the statute behind these demand letters. The FSCA (Chapter 934) is Florida's decades-old wiretapping and electronic-interception law, and it's the pen-register and interception provisions within it — not the FDBR — driving this litigation wave. Some vendors' content blends the two; make sure your own understanding, and your attorney's brief, is anchored to Chapter 934.
Frequently asked questions
Can I just ignore the demand letter?
Not advisable. Ignoring it doesn't make the underlying claim disappear, and it forecloses the option of an early, lower-cost resolution or dismissal. It can also remove your ability to shape the narrative before a complaint is filed.
Do plaintiffs have to send a demand letter before suing in Florida?
Not always — practice varies by claim type and by the firm involved. Some send a letter first as a settlement play; others go straight to filing. Either way, the response fundamentals (preserve records, get counsel, gather proof) are the same.
Can responding to a demand letter backfire?
It can, if the response is rushed, admits more than necessary, or is sent without counsel review. This is why the "don't touch your site yet, don't respond without a lawyer" guidance above matters — an unreviewed response can hand the other side language to use against you.
What shouldn't I say in a response to one of these letters?
Avoid admissions about what your scripts do or don't do until you've verified it with actual logs, avoid speculative statements about your compliance status, and avoid anything that reads as a final, unequivocal position before your attorney has reviewed the underlying facts.
PieEye POV
From PieEye's perspective, the implication of these lawsuits for mid-market eCommerce brands is clear: the stakes are high and ignorance is not an option. Next sprint, prioritize an immediate audit of your chat tools and associated data flows. Align your compliance strategy with legal requirements as outlined in Florida's wiretapping laws to avoid becoming another statistic in the litigation avalanche. Navigating this regulatory minefield requires not just awareness, but decisive action and continuous adaptation.