A new demand letter reviewed by Captain Compliance shows a self-represented California claimant, Seyed Hosseini, using a familiar tactic: visit a website, open browser developer tools, type information into a search bar, watch the resulting network traffic, identify third parties receiving the data, and convert those transmissions into alleged statutory privacy violations.
California businesses that thought the Vivek Shah wave represented the outer edge of pro se website privacy demands may want to take another look at their tracking on their site and may want to hire us to remediate their site and stand up our software to avoid a series of these pro-se plaintiffs for privacy violations that we have been warning about.
Another Vivek Shah or is Seyed Hesseini Different? A New Pro Se Privacy Claimant Is Testing an Expanded CIPA and ECPA Demand Playbook
The basic methodology will immediately look familiar to anyone who has dealt with Vivek Shah.
But the similarities end there.
Hosseini’s demands are typically 30 pages long and attempts to transform a relatively simple website-tracking allegation into a much larger theory involving the California Invasion of Privacy Act, the federal Electronic Communications Privacy Act, California’s pen-register statute, computer-access law, consumer-protection statutes, common-law privacy claims and other theories.
He also demands in the range of $35,000 – $75,000 to resolve the matter before litigation, based on his calculation of alleged statutory damages.
The demand is worth studying even apart from whether each of its legal theories would ultimately survive a motion to dismiss.
It shows how the privacy demand-letter model is evolving.
The Vivek Shah Playbook, With More Causes of Action
Vivek Shah became one of the most recognizable names in California website privacy litigation by repeatedly pursuing essentially the same technical theory.
The usual pattern is straightforward.
A visitor accesses a website and enters text into a search field or other input. Browser developer tools allegedly show that the contents of the field are transmitted to companies such as Google, Meta or another analytics provider. The claimant then argues that the third party received the “contents” of an electronic communication contemporaneously with its transmission.
That matters because California Penal Code Section 631 prohibits certain unauthorized interceptions of communications while they are in transit.
Shah’s litigation became prolific enough that, on July 20, 2026, U.S. District Judge R. Gary Klausner declared him a vexatious litigant in the Central District of California and entered a prefiling order covering new CIPA and related digital-privacy cases. The court record reflects that Shah had repeatedly pursued materially similar digital-privacy cases.
Hosseini’s demand uses a remarkably similar technical starting point.
According to the letter, he visited the targeted website on August 17, 2026 with Chrome DevTools running, entered his surname into the site’s search field, submitted the search and watched network traffic allegedly transmit the search term to outside entities. He states that he repeated the search several times to verify what he saw.
That is essentially the Shah search-bar experiment.
The difference is what Hosseini builds on top of it.
Six Trackers Become Four Separate Alleged Violations
The letters claims that four third-party technologies received information from the browsing session:
- Attentive
- TikTok
- Adroll
- DoubleClick Ad Services
- Google Analytics
- Meta/Facebook Pixel
The demand letters that he sends out then treats each recipient as a separate alleged statutory violation.
That multiplication theory is important.
Hosseini calculates four alleged CIPA Section 631 violations at $5,000 each, four alleged Section 638.51 pen-register violations at another $5,000 each, and a $10,000 federal ECPA statutory minimum.
His resulting calculation is:
CIPA §631: $20,000
CIPA §638.51: $20,000
ECPA: $10,000
Total claimed statutory exposure: $50,000.
The settlement demand is going to cost at least $35,000 and this does not include your legal fees and time.
Whether a court would accept the premise that every technology receiving information creates a separately recoverable $5,000 statutory violation is a different question. The letter presents that calculation as the claimant’s position, not as an established measure of damages.
That distinction matters.
The Search Bar Is the Center of the Case
The strongest factual allegation in the letter is not that cookies existed.
It is that text deliberately entered into a search field allegedly left the website and reached third parties.
Hosseini says he typed his surname into the site’s search bar and observed it being transmitted contemporaneously with the search. He characterizes the search term itself as the “contents” of a private electronic communication.
That is materially different from a demand based only on an IP address, browser identifier or page URL.
Courts evaluating Section 631 claims increasingly examine exactly what information was supposedly intercepted. A 2026 Northern District of California ruling, for example, distinguished between merely alleging trackers existed and alleging that a plaintiff actually generated communicative content capable of being intercepted.
That is why search fields, chat boxes, health questionnaires, appointment forms and similar interactive elements present a different litigation profile from ordinary page analytics.
The more closely the transmitted information resembles something the user consciously communicated, the easier it becomes for a plaintiff to argue that the information represents the “contents” of a communication rather than routing or device metadata.
It does not automatically establish liability. But technically it gives the plaintiff a more concrete factual allegation.
Hosseini Adds the Federal Wiretap Act
This is where the demand becomes more ambitious than many Shah letters.
Hosseini also invokes the Electronic Communications Privacy Act, or ECPA, 18 U.S.C. §2510 et seq.
Ordinarily, website defendants facing federal wiretap claims have several defenses, including arguments related to consent and the statutory exception applicable when a party to the communication participates in the interception.
The Hosseini demand attempts to get around that problem using ECPA’s crime-tort exception.
The letter argues that the tracking allegedly occurred for the purpose of further unlawful conduct. It then identifies a long list of alleged underlying violations, including:
California’s constitutional privacy right; the Federal Trade Commission Act; intrusion upon seclusion; trespass to personal property; the Consumer Legal Remedies Act; California’s Computer Data Access and Fraud Act; CalOPPA; California’s breach-notification statute; the Unfair Competition Law; and CIPA Sections 631 and 638.51.
This is a significant expansion of the standard demand-letter formula.
Hosseini specifically cites Doe v. Tenet Healthcare, a 2025 Eastern District of California decision involving tracking technologies on healthcare websites.
The citation is not imaginary. The Tenet court did allow certain ECPA allegations to proceed, including an argument involving the statute’s crime-tort exception. But the underlying case involved allegations concerning personally identifiable information and protected health information, including alleged HIPAA-related conduct.
That does not mean the same theory automatically applies to an ordinary consumer website.
The factual context matters enormously.
Some of the Added Claims Face Obvious Questions
The breadth of the letter may make it appear that the recipient is facing a dozen independent privacy claims.
That is not necessarily what a court would conclude.
For example, 15 U.S.C. §45 is the Federal Trade Commission Act’s prohibition against unfair or deceptive acts or practices. Enforcement authority generally rests with the FTC rather than providing an ordinary private damages action simply because a consumer alleges an unfair practice.
California Civil Code §1798.82 concerns notification following certain security breaches. A website intentionally configured to use analytics technology is not automatically experiencing a “breach of the security of the system.”
That distinction has already appeared in tracking litigation. In Tenet, the court dismissed the Section 1798.82 theory while addressing allegations involving third-party tracking technologies.
Trespass-to-chattels theories similarly tend to require more than simply showing that code operated in someone’s browser.
And common-law intrusion upon seclusion normally requires a plaintiff to establish an intrusion into a private matter that would be highly offensive to a reasonable person. A search for a sensitive medical condition may produce a different analysis from entering a surname into a retail site’s search bar.
So businesses should not read the number of statutes listed in a demand letter as equivalent to the number of viable causes of action.
Each claim still has elements.
The Pen-Register Claim Is Particularly Interesting
Hosseini also alleges four violations of California Penal Code Section 638.51, which generally prohibits installation or use of a pen register or trap-and-trace device without a court order unless an exception applies.
This theory has become one of the stranger fronts in California privacy litigation.
Historically, pen registers were associated with telephone systems. Plaintiffs have increasingly argued that the statutory definition is technologically neutral enough to encompass website tracking processes collecting routing, addressing or signaling information.
Federal courts in California have reached different conclusions about how far the statute extends.
In August 2026, for example, a Northern District of California judge examining Sections 638.50 and 638.51 tentatively reasoned that the statutes may be limited to processes capable of recording routing-type information but not the actual “contents” of communications.
Other courts have allowed web-based pen-register theories to proceed where plaintiffs sufficiently alleged collection of information such as IP addresses and user-agent data.
That creates an interesting tension inside Hosseini’s own demand.
For the Section 631 claim, the plaintiff wants the search term to qualify as communication “contents.”
For the Section 638.51 theory, the statutory definition of a pen register specifically focuses on dialing, routing, addressing or signaling information rather than communication contents.
A sophisticated defense analysis should separate those two theories rather than treating “tracking” as one undifferentiated activity.
The 29-Page Litigation Hold May Be the Most Aggressive Part
Perhaps the biggest departure from the ordinary Shah-style demand is what happens after the settlement request.
Hosseini includes an extensive litigation-hold notice.
The recipient is told to preserve web-server logs, application logs, CDN records, HAR files, packet captures, source code, JavaScript, tag-manager history, tracking configurations, vendor agreements, CMP records, consent receipts, GPC handling logs, privacy-policy versions and internal communications involving legal, privacy, marketing, engineering and compliance personnel.
The demand goes even further.
It asks for preservation of internal email, Slack, Microsoft Teams, SMS, Jira, Asana, Linear and similar communications concerning website tracking, CIPA, ECPA, cookie consent and opt-out handling.
It also instructs the recipient not to modify its tracking technologies in a way that would destroy evidence of the prior configuration without preserving a forensic snapshot.
That point deserves attention from privacy teams.
A company receiving a tracking demand frequently wants to immediately “fix the website.”
Technically, that may be exactly the right thing to do.
From a litigation perspective, however, the prior state should generally be preserved before material configurations are changed.
Screenshots are useful, but they are not necessarily enough. Tag-manager container versions, CMP logs, server-side configurations, consent records and network captures may ultimately be far more valuable.
Why Calling This “Another Vivek Shah” Is Fair — With One Important Caveat
Hosseini should not simply be labeled Vivek Shah 2.0 based on a single demand letter.
Shah developed a documented litigation history involving numerous similar cases, and a federal court eventually imposed a prefiling restriction on new CIPA and related digital-privacy actions in the Central District of California.
We do not yet have comparable evidence showing that Hosseini has launched a campaign of that scale.
But the methodology is unmistakably familiar.
The ingredients are all here:
browser DevTools;
a search box;
a deliberately entered search term;
screenshots of outbound network requests;
third-party analytics and advertising platforms;
CIPA statutory-damages theories;
damages multiplied by the number of alleged recipients;
and a settlement demand substantially below the claimed statutory exposure.
The innovation is the additional legal machinery surrounding it.
Instead of stopping at Section 631, the letter stacks ECPA, Section 638.51, CDAFA, privacy torts, consumer statutes and other theories around the same technical event.
And instead of attaching a handful of screenshots, it follows with an extensive litigation-hold demand designed to preserve nearly the company’s entire website tracking history.
That is what makes this one worth watching.
The Real Lesson for Businesses Is Technical, Not Procedural
Businesses should not wait until they receive a letter from Hosseini, Shah or the next claimant using this model.
The practical question is much simpler:
What happens on your website before the visitor makes a privacy choice?
Open the browser developer tools and find out.
Enter text into the search bar.
Use the contact form.
Open the chat widget.
Visit sensitive pages.
Reject cookies.
Send a Global Privacy Control signal.
Then inspect the network requests.
If advertising, analytics, session-replay or marketing technologies receive user-entered information before the appropriate consent state exists, the legal department should know about it before a claimant documents it for them.
A cookie banner that merely appears on the screen is not the same thing as technically controlling the scripts behind it.
That distinction is increasingly becoming the factual center of website privacy litigation.
And this latest demand suggests the next generation of claimants may not limit themselves to one statute when they find the configuration wrong.
They may try to turn one network request into an entire privacy case.