If you run an agency, you are sitting on both sides of the most aggressive privacy litigation campaign in the country right now. Your own website and every single one of your clients is a target. Every client website your team has ever tagged with Google Analytics, Meta Pixel, LinkedIn Insight, TikTok Pixel or a session replay tool is a target. And the person doing the targeting is not a class action firm with overhead and selectivity — it is one man, working alone, sending demand letters at industrial scale.
His name is Vivek Shah and we have covered this story in depth about Shah’s tactics sending out CIPA demand letters., and by conservative estimates he has sent thousands of demand letters to businesses and nonprofits across the country between Fall 2025 and June 2026, with no sign of slowing down. Manufacturers, schools, auto dealerships, mining companies, retailers, B2B firms with no consumer audience whatsoever the targeting is indiscriminate. Many recipients have no connection to California at all. That does not matter to the legal theory and it will not stop the letter from arriving.
What follows is the condensed briefing every agency principal and client-side marketer in this community should read before the next letter lands.
The Playbook: A Search Bar, DevTools and a $5,000-Per-Violation Statute
Shah’s method is remarkably consistent and understanding it tells you exactly where your agency’s exposure lives and is slightly different from the other online wiretapping claims that are being made specifically over retargeting.
He visits a website with his browser’s developer tools open and the network tab recording. He types something innocuous into the site’s search bar, typically his own first name in all caps, “VIVEK.” He then captures screenshots showing that search term being transmitted in real time to third-party endpoints: Google Analytics, Meta Pixel, HubSpot and whatever else the site’s tag manager fires on interaction. No cookie banner appeared first, or the banner appeared after the trackers had already fired or in most cases the banner just doesn’t even work and that causes the issue. That gap is the entire case and while it’s pretty baseless, it is working and we are warning agencies because once these demand letters get sent out, the clients almost always point the finger back to you. So an ounce of prevention is worth a pound of cure.
The packet that arrives at the business is engineered to look like a lawsuit that has already been drafted because it has but the catch is it has not been filed yet. It typically contains a short cover letter requesting “informal dispute resolution,” a draft complaint prepared for Los Angeles Superior Court that is nearly identical across recipients and an Exhibit A of network-capture screenshots. If the website’s terms of use contain an arbitration clause, Shah threatens arbitration instead and he has gone to court to compel arbitration against businesses that ignored him represented by an attorney when he does.
An example can be seen below:
The legal hook is the California Invasion of Privacy Act (CIPA), a 1967 wiretapping statute written for telephone surveillance. Two theories carry the weight:
Section 631(a) — the wiretap theory. The claim is that when a visitor types into a search bar or form and that content flows to a third-party vendor, the vendor has “intercepted” a communication in transit without all-party consent and the website owner aided and abetted the interception by installing the tags.
Section 638.51 — the pen register theory. This is where Shah pivoted in recent months, following the broader plaintiff bar. The claim is that tracking pixels and analytics tools collecting IP addresses, device identifiers and routing metadata are the digital equivalent of a pen register, a telephone surveillance device that requires a court order to deploy. Legislative estimates suggest pen register and trap-and-trace claims now account for roughly two-thirds of active California privacy litigation, with Section 638.51 filings growing from about 600 to more than 4,000 since remedial legislation was first introduced.
CIPA authorizes statutory damages of $5,000 per violation, or three times actual damages, whichever is greater with no requirement to prove any actual harm and no the claims are not asking for only $5,000 and we’ve seen some asking as much as $890,000 over CIPA violations and a class action lawsuit over a different privacy law called The Electronic Communications Privacy Act asking for $5,000,000. Plaintiffs argue every visit and in some framings every third-party recipient of the data, is a separate violation. That arithmetic is why class actions in this space routinely settle in the high six and seven figures and why Shah’s individual demands are calibrated to sit just below what it would cost you to make him go away in court and almost everybody is going away except for a real estate company called Lofty who is firing back with their own lawsuit to protect their 30,000 agents.
Why “We’re Not a California Company” Is Not a Defense
This is the point agencies most need to internalize on behalf of their clients: CIPA follows the California resident, not the business. When a Californian visits a publicly accessible website and a tracker captures data from that visit, the statute attaches to the California side of the communication regardless of where the business is headquartered, who it markets to, or what its privacy policy says about intended audience. Disclaiming California intent in your terms of service does nothing. If your website is reachable from California, you are reachable by Shah and similar to TCPA claims it doesn’t matter where you are it’s where the plaintiff is.
The Ground Is Shifting — In Both Directions
Here is what makes this moment genuinely strange: the same legal theory is simultaneously producing multimillion-dollar settlements and outright dismissals, sometimes weeks apart.
On the settlement side: On June 26, 2026, a federal judge in the Northern District of California granted final approval to a $3.85 million class settlement against the Los Angeles Times in Mirmalek v. Los Angeles Times Communications LLC, built on the pen register theory and targeting three ad-tech trackers TripleLift, GumGum and Audiencerate. The Times conceded no liability; it paid to exit uncertainty. Note what was targeted: not exotic spyware, but the ordinary programmatic ad stack this industry deploys every day.
On the dismissal side: California state courts have been increasingly hostile to the pen register theory. Rodriguez v. Ink America dismissed Section 638.51 claims without leave to amend, reasoning the statute was built for telephonic surveillance and that the plaintiff’s reading would criminalize conduct the CCPA expressly permits. Heiting v. Wildflower Brands and Blaker v. Netscout Systems reached similar results with prejudice.
And Shah himself took a direct hit. In Shah v. Talentbridge, Inc. (C.D. Cal. May 28, 2026), a federal court dismissed his CIPA claim for lack of Article III standing, holding that typing generic search terms into a public website does not implicate a protectable privacy interest and denied him leave to amend as futile. Shah has appealed to the Ninth Circuit, but for any business staring at one of his letters, Talentbridge is the single most important data point: the foundational theory behind thousands of his demands failed a standing challenge on the merits of its own facts. Reflexive settlement is not the obvious move it looked like a year ago but this also comes at a cost for Talentbridge to fight this.
Two more variables are in motion. The California Court of Appeal is poised to issue the first binding appellate rulings on whether a website pixel is a pen register at all Variety Media, LLC v. Superior Court in the Second District and Reuters News & Media v. Superior Court in the Sixth, with business groups including the Association of Corporate Counsel filing amicus briefs warning of “operational paralysis.” And in Sacramento, SB 690 has come back to life: as amended on July 1, 2026, it would eliminate the private right of action under the pen register provisions entirely, shift enforcement to the Attorney General and apply retroactively for two years which would extinguish most pending Shah-style claims. The Legislature reconvenes August 3 and must pass it by August 31 for enactment this year. It is not law yet and no one should build a compliance posture on a bill that stalled once before. But if you are weighing whether to pay a pen-register-only demand this summer, the calendar itself has become a strategic factor.
Why Agencies Carry Double Exposure
For this community specifically, the risk runs deeper than your own agency website though start there, because your site almost certainly runs the exact stack Shah screenshots given that you are a marketing agency.
The deeper problem is that agencies are the ones who installed the trackers on client sites. When a Shah letter or a class complaint lands on a client, the first question in-house counsel asks is who deployed the Meta Pixel, who configured the tag manager and whether the consent banner was set up to actually gate the tags or just decorate the page. If your MSAs and SOWs are silent on privacy compliance allocation and indemnification for tracking-related claims, that silence gets resolved in the least pleasant way possible after the demand letter arrives. Review those contracts now, not during a dispute.
There is also a delivery-quality issue hiding in plain sight: a consent banner that appears after trackers have fired is disclosure, not consent. That configuration banner present, tags firing on page load anyway and not respecting a users consent choice is precisely what Shah’s DevTools capture is designed to document and it is the recurring fact pattern in the adverse rulings that we are seeing in the courts. If your teams are shipping sites where the banner is decorative, you are shipping the evidence exhibit and the clients are going to point the finger back at you to pay out Shah.
If a Letter Arrives: Five Rules
- Do not respond directly and do not let marketing, IT or a client success rep respond. An informal reply can become an admission. Route it to experienced privacy litigation counsel who knows this claimant his history, his dismissals and his appeal before anyone says a word and of course we recommend connecting with the data privacy experts at Captain Compliance who have dealt with Shah and gotten numerous cases dismissed based on strategies they have seen work since there is constant communication with defense counsel and other industry experts.
- Do not ignore it either. Shah litigates. He files in state court and in arbitration and he has moved to compel arbitration against businesses that assumed a pro se plaintiff would fold. Templated does not mean toothless. Recently we saw a case where $5,000 was offered to settle and he just flat out said no. He was also declared a vexatious litigator recently by the Central California courts. Our coverage of this caught the ire of his team and they submitted a fake DMCA request to have the news piece removed.
- Preserve the website’s current state immediately. Capture HAR files, screenshot the cookie banner and privacy policy, export tag manager configurations and timestamp everything before making any changes. If you have good discovery and evidence this helps tremendously. You should remediate and document.
- 4. Do not pay before an investigation. Post-Talentbridge, a meaningful share of these demands rest on a theory that could not survive a standing challenge. Some claims present real exposure; others collapse the moment counsel compares the draft complaint against what the site actually transmits. Know which one you are holding before you decide. There is also potential for a 2-year backdating of all of these claims being dismissed but we don’t know if that relief is coming or not and it is just under CIPA not the other claims being made.
- Check your insurance now, not later. Confirm whether your cyber liability or E&O policy responds to CIPA claims or wrongful collection claims. As for your agency and, where you have contractual exposure, for tracking work performed for clients. Coverage gaps discovered mid-litigation are the expensive kind.
Closing the Gap Before the Letter Comes
The uncomfortable truth underneath this entire litigation wave is that it is almost entirely preventable and the fix is technical, not legal. Every one of these claims Shah’s letters, the class actions, the Mirmalek settlement is built on the same foundational fact: trackers transmitting data without providing proper consent and having a working cookie consent banner in place.
That means, for your own properties and every client property you touch: a complete inventory of every script, pixel and tag actually live on the site; a consent management platform configured to block trackers when the visitor affirmatively opts out, with server side tagging set up as an option to block access to seeing network traffic; a privacy policy that matches the real data flows rather than the ones someone described three redesigns ago; and ongoing monitoring, because tag stacks drift with every sprint and a banner that worked at launch can be silently bypassed by the next deployment. Test it the way Shah does incognito window, network tab open, watch what fires before anyone clicks anything. If analytics beacons appear before consent, the banner is decorative and the site is one DevTools session away from an Exhibit A.
Captain Compliance and my team have been tracking Shah’s campaign and the broader wave of website wiretapping litigation in depth. For the full profile of Shah, his tactics and the case law developing around him, see the dedicated Captain Compliance resource: Privacy Alert for Privacy Counsel Vivek Shah and his CIPA Demand Letters