Demand letter response · Free scan · No signup

Received a CIPA demand letter?

You’re one of thousands of businesses that got one this year. Before you respond — or pay — see the evidence the letter is built on: a free scan shows every tracker your site fires before visitors consent, graded in 90 seconds.

Which law do you want to check?

Letter in hand and need to move fast?

Book a 20-min call — we’ll walk your scan results and show what a fix looks like.

Book a call →

Why you got this letter

CIPA — the California Invasion of Privacy Act — carries $5,000 per violation in statutory damages with no proof of harm required. Plaintiffs’ firms and individual claimants run automated tooling that scans websites for trackers firing before consent, then send templated letters in batches. More than 800 CIPA suits were filed in 2025 alone, and pen-register (“trap and trace”) filings under § 638.51 grew from roughly 600 to over 4,000. Your site was almost certainly found by a scanner, not an investigator.

Recognize the letterhead?

A handful of senders account for most of the volume. If your letter matches one of these, you are one of hundreds of recipients of a template campaign — which changes how your counsel will price it. Everything below is drawn from court records and legal-industry reporting.

What to do in the first 48 hours

  1. 1

    Don’t ignore it — but don’t pay it today either

    These letters usually carry a response deadline and settle for four to five figures precisely because that is cheaper than a defense. Ignoring one can turn a letter into a filed complaint or arbitration demand; paying immediately marks you as a soft target. You have time to understand your actual exposure first.

  2. 2

    Find out what your site actually exposes

    Every one of these claims is built on the same evidence: trackers that fire before a visitor consents. The free scan above loads your site from a California IP without touching the consent banner and records every pixel, cookie, session-replay script, and chat widget that fires — the same picture the sender’s tooling captured. Knowing whether the claim is accurate changes every decision that follows.

  3. 3

    Stop the pre-consent tracking now

    CIPA claims accrue per violation, so trackers that keep firing while you deliberate keep adding theoretical damages. Blocking pixels, analytics, and session replay until after consent doesn’t erase past exposure, but it caps it — and a documented fix date is something your counsel will want.

  4. 4

    Bring the letter and the scan report to defense counsel

    Whether to respond, negotiate, or contest is a legal call — CIPA defense outcomes vary a lot by claim theory, letterhead, and forum, and several pen-register theories have been rejected outright by California courts. A defense attorney who has handled these letters can price yours quickly. PieEye is not a law firm and nothing on this page is legal advice.

CIPA demand letter FAQ

Is a CIPA demand letter legitimate? Can they really sue over a chat widget or pixel?
The legal theory is real: CIPA carries $5,000 per violation in statutory damages with no proof of harm required, and courts have allowed claims over chat widgets, session replay, and tracking pixels to proceed. But outcomes vary widely — several courts have rejected the pen-register (§ 638.51) theory, and in 2025 one court dismissed a serial "tester" plaintiff for lack of standing. Most letters are templates sent in bulk, not the product of an investigation into your business specifically.
What do CIPA demand letters settle for?
Defense-side publications report typical individual settlements in the four-to-low-five-figure range, with mass-arbitration campaigns demanding far more before negotiating down. The senders’ economics rely on settlements being cheaper than defense costs. What a specific letter is worth depends on the claim theory, the sender’s track record, and what your site actually does — which is why the scan matters.
If I fix my website, does the claim go away?
No — fixing pre-consent tracking stops new violations from accruing but does not extinguish claims about past conduct. It does materially improve your position: it caps exposure, removes the ongoing-violation leverage from any follow-up letter, and takes you off the target list these campaigns rescan.
What is a "pen register" or "trap and trace" demand letter?
CIPA § 638.51 prohibits installing a device that captures dialing or routing information without consent. Since a 2023 ruling that software can qualify as a pen register, plaintiffs have applied it to analytics scripts, pixels, and search bars that capture visitor identifiers like IP addresses. It is now the highest-volume CIPA theory — filings grew from roughly 600 to more than 4,000 — though several California courts have rejected it as applied to ordinary web analytics.
I got a similar letter about a Florida statute (FSCA). Is that the same thing?
It is the same playbook under Florida’s wiretap statute, the Florida Security of Communications Act. A March 2025 federal ruling opened the door, and hundreds of FSCA suits and small-claims actions have followed. The same scan covers FSCA — or use the dedicated Florida scanner.
Will PieEye tell me whether to pay or fight?
No. PieEye is not a law firm and does not give legal advice. What we give you is the factual record: exactly which trackers fire on your site before consent, graded against CIPA, FSCA, and three other regimes — the evidence baseline you and your attorney need to evaluate the letter. Fixing what the scan finds is what our consent platform does.

Go deeper

PieEye is a privacy-compliance software company, not a law firm. Nothing on this page is legal advice, and reading it does not create an attorney–client relationship. Statements about specific senders are drawn from the cited court records and legal-industry publications. If you have received a demand letter or arbitration demand, consult a licensed attorney about your specific situation.