The wave of California website privacy demand letters that has occupied privacy lawyers, insurers and businesses for much of the past two years has now drawn a direct warning from the Texas Attorney General. With him being called a “Vexatious Litigant” in Central California when attorney Kevin Cole fought back and now Vivek’s warnings have traveled to the great state of Texas where Attorney General Ken Paxton issued a consumer alert telling Texas businesses and nonprofit organizations to exercise caution when they receive demand letters accusing their websites of violating the California Invasion of Privacy Act, or CIPA.
The alert is notable for another reason.
Paxton’s office did not discuss the issue only in general terms.
It specifically identified serial CIPA plaintiff Vivek Shah, linked to an example of one of Shah’s demand letters and pointed to the July federal court order that declared Shah a vexatious litigant in the U.S. District Court for the Central District of California.
Captain Compliance has been following Shah’s demand-letter activity and the litigation surrounding it for months, including the lawsuits brought against businesses, defendants that decided to fight back, the July 20 vexatious-litigant ruling obtained by Crain Communications and its lawyers, and subsequent court developments.
The Texas Attorney General’s warning now puts a state enforcement office behind one of the central messages businesses have increasingly heard from defense lawyers: do not assume that receiving an official-looking CIPA demand means the allegations have been established, and do not rush to pay simply because litigation would be expensive.

What Ken Paxton’s Office Actually Said
The September 17 alert is titled:
“CONSUMER ALERT: Attorney General Ken Paxton Warns Texans of Scam Demand Letters Alleging Website Privacy Violations.”
The office said it was responding to a “recent surge” in letters being sent to Texas businesses and nonprofits alleging violations of California privacy law.
According to the Attorney General, the letters commonly focus on ordinary website technologies such as cookies, pixels, analytics tools and search bars. The sender may claim those technologies amount to illegal “wiretapping” under CIPA and demand money to avoid litigation. Some packages include website screenshots and a draft lawsuit.
Paxton said his office had “been made aware of suspicious letters demanding payment from Texas businesses.”
The state then gave businesses an unusually direct warning:
“Demand letters of this type may exaggerate or misrepresent a potential violation of law.”
That does not mean the Texas Attorney General has determined that every CIPA demand letter is fraudulent, that CIPA cannot apply to website technologies or that businesses can ignore legitimate privacy obligations.
Paxton’s office itself recommended that recipients review their websites’ use of cookies, pixels, analytics and similar technologies with qualified counsel.
What the warning does say is that the existence of a demand letter is not proof of liability.
Texas Specifically Named Vivek Shah
The most striking part of the announcement is the decision to identify Shah by name.
The Texas Attorney General who has been very aggressive going after large businesses described Shah as a “serial CIPA plaintiff” known to have sent CIPA demand letters and noted that he had been declared a vexatious litigant.
The alert explained that Shah cannot file a new CIPA or related digital-privacy lawsuit in the Central District of California without first obtaining permission from the court.
That is an extraordinary development for a demand-letter campaign that has become familiar to many businesses and privacy defense lawyers.
Shah’s name was previously appearing mostly in private correspondence, federal and state court dockets, defense-law-firm alerts and privacy-industry coverage.
It is now appearing in an official Texas Attorney General consumer warning.
The Texas Attorney General Published an Actual Shah Demand Letter
Paxton’s office went further and linked directly to an example of a demand letter signed by Vivek Shah.
The one-page letter is dated June 8, 2026 and labeled “Informal Dispute Resolution.”
It alleges that the recipient violated California Penal Code Section 638.51(a) by installing and using “multiple pen registers” on its website without consent.
The letter states:
“The attached Complaint is prepared and ready to be filed with the Los Angeles Superior Court should this matter remain unresolved.”
That short letter illustrates why these communications can create immediate pressure.
The recipient is not merely told that someone believes its website has a technical privacy problem.
It is told that litigation is already prepared.
And the asserted violation involves a California surveillance statute that can carry statutory damages and private enforcement rights.
Why Would a Texas Business Receive a California Privacy Demand?
This is one of the first questions businesses ask.
A company may be incorporated in Texas, operate its physical locations in Texas and have no obvious reason to think of itself as subject to a California wiretapping dispute.
But a website is available across state lines.
CIPA plaintiffs have argued that when a person in California visits an out-of-state company’s website and information from that session is allegedly intercepted or routed to a third party, California law can apply to the communication.
Whether that theory succeeds depends on the facts, jurisdiction, the particular CIPA provision being invoked and an increasingly complicated body of case law.
The Texas Attorney General did not attempt to resolve those legal questions in its alert.
Instead, it told Texas entities not to assume the demand is valid merely because California law is cited and to seek counsel before responding or paying.
Who Is Vivek Shah?
For purposes of the current privacy litigation story, Shah is a self-represented, or pro se, litigant who has repeatedly brought or threatened digital-privacy claims involving websites.
His recent cases have focused heavily on CIPA, a California surveillance statute enacted decades before modern websites, advertising pixels, analytics platforms and JavaScript tracking technologies existed.
Different CIPA theories have emerged in website litigation.
Section 631 claims generally allege unlawful interception or eavesdropping on electronic communications.
Section 638.51 litigation has attempted to characterize certain tracking technologies as prohibited pen-register or trap-and-trace devices.
Captain Compliance has covered both categories because the practical target is often the same: standard website functionality interacting with third-party technology.
The Shah Demand-Letter Playbook
Captain Compliance’s prior reporting has examined the recurring structure of Shah’s demands.
A business may receive a package through its registered agent or corporate office.
The package can include an informal dispute-resolution letter, technical screenshots or evidence, and a draft complaint.
The allegations often focus on activity such as:
- typing information into a website search bar;
- the presence of analytics scripts;
- third-party advertising or marketing pixels;
- network requests made by the browser;
- information allegedly transmitted to an outside technology provider; or
- technologies characterized as pen registers or interception mechanisms.
Captain Compliance has previously documented examples in which Shah allegedly tested websites by entering information into search functions and examining browser network traffic to determine whether information was transmitted to third-party systems.
This kind of testing is important to understand because it is different from an ordinary customer accidentally discovering a privacy issue.
In the Crain Communications litigation, Judge R. Gary Klausner considered Shah’s familiarity with website tracking and his repeated efforts to identify potential violations as part of the broader vexatious-litigant analysis.
The Crain Communications Case Changed the Story
The critical turning point came in Vivek Shah v. Crain Communications, Inc., Case No. 2:26-cv-03070-RGK-CTS.
Shah sued Crain Communications in the Central District of California on March 18, 2026.
Rather than treating the lawsuit simply as another CIPA case to defend or settle, Crain and its lawyers at KJC Law Group examined Shah’s broader litigation history.
Managing partner Kevin J. Cole and attorney W. Blair Castle represented Crain.
The defense then asked Judge Klausner to declare Shah a vexatious litigant.
That changed the case from a dispute over one website into an examination of Shah’s litigation conduct across multiple cases.
The Court Looked at More Than One Complaint
The record before the court included at least 29 proceedings Shah had initiated between 2021 and 2026.
Those cases were not all CIPA lawsuits, so the number should not be confused with 29 identical website-privacy claims.
Judge Klausner focused more closely on Shah’s recent privacy cases.
In the seven months preceding the court’s ruling, Shah had filed seven materially similar CIPA complaints against seven defendants.
According to the court’s analysis summarized in subsequent legal reporting, those cases did not progress beyond the pleading stage before being voluntarily dismissed or dismissed by a court.
The court also examined similarities among complaints, the timing of dismissals and what occurred when defendants filed substantive challenges.
That pattern mattered more than the raw number of lawsuits.
What “Vexatious Litigant” Actually Means
The phrase can sound as though a person has been banned from the courts.
That is not what happened.
Federal courts have to be careful when restricting a person’s access to the judicial system.
Under Ninth Circuit law, a prefiling order generally requires notice, an adequate record, substantive findings supporting restrictions and an order narrowly tailored to the problem the court has identified.
Judge Klausner concluded those requirements were satisfied.
On July 20, 2026, he entered an order that did two things particularly relevant here:
- declared Vivek Shah a vexatious litigant; and
- required Shah to obtain court permission before filing a new CIPA or related digital-privacy case in the U.S. District Court for the Central District of California.
The court denied Crain’s separate request for a security bond in the pending litigation, while noting that judges handling future cases covered by the prefiling order could consider requiring security.
The Court’s Concern Was the Pattern of Litigation
The ruling is more important when read for its reasoning than when reduced to the label “vexatious litigant.”
Judge Klausner did not hold that bringing a CIPA website case is itself improper.
Nor did he conclude that every lawsuit Shah had ever filed lacked merit.
The court examined a combination of factors: repeated filings, similarities among complaints, voluntary dismissals after defendants challenged the cases and Shah’s efforts to locate alleged CIPA violations.
Captain Compliance’s earlier analysis highlighted one of the most consequential phrases in the court’s reasoning: the pattern indicated an effort to “harass defendants into coercive settlements.”
That finding is especially relevant to the economics of privacy demand letters.
Why Demand-Letter Economics Matter
For many businesses, the settlement decision has little to do with whether executives or counsel believe the claim is legally correct.
The calculation can be brutally practical.
Suppose resolving a demand costs less than hiring litigation counsel, retaining technical experts, briefing standing and jurisdiction, litigating the meaning of a decades-old surveillance statute and possibly going through discovery.
A company might settle a weak claim simply because defending it costs more.
Kevin Cole described that dynamic after the Crain ruling. According to KJC Law Group’s account, Cole said many companies decide that fighting costs more than settlement, which is one reason the defense chose to examine Shah’s overall litigation pattern instead.
The vexatious-litigant procedure gave Crain a way to ask the court to consider that pattern rather than viewing each filing in complete isolation.
Shah Voluntarily Dismissed the Crain Case After the Order
Three days after Judge Klausner entered the vexatious-litigant order, Shah filed a voluntary dismissal of the Crain lawsuit with prejudice.
Crain’s pending motion to dismiss was then denied as moot because the underlying case was no longer proceeding.
Again, that procedural history should be described carefully.
The Crain case did not end with a judicial merits determination that Crain’s website complied with CIPA.
Shah dismissed his case.
The vexatious-litigant order concerns his filing practices and future access to that federal district for covered claims.
Shah Appealed
Shah has not simply accepted the order.
The public federal docket shows that he filed notices of appeal following the July ruling and later appealed an August order applying the vexatious-litigant restriction to another proposed filing.
A Ninth Circuit docket was opened in August, and Shah submitted an opening brief and a motion asking to expedite proceedings.
As of the current public docket information, the litigation over the scope and validity of the prefiling restriction remains part of the appellate process.
That means businesses should not describe the July district court order as though all appellate issues have been exhausted.
The Restriction Has Already Been Applied
The district court docket also shows why the prefiling order is more than symbolic.
On August 18, Judge Klausner issued an order concerning a proposed filing presented by Shah and directed that the complaint not be filed under the vexatious-litigant screening procedure. Shah then filed another appeal relating to that decision.
The practical effect is that new covered complaints in that district face judicial screening before they become ordinary lawsuits.
The Order Is Not a Nationwide Ban
This is probably the most important limitation for businesses to understand.
Shah was not prohibited from:
- sending demand letters;
- filing every type of lawsuit;
- bringing unrelated claims;
- automatically filing nowhere in California;
- filing in every other federal district; or
- pursuing every possible arbitration or state-court proceeding.
The restriction concerns new CIPA and related digital-privacy cases filed by Shah in the Central District of California.
Legal alerts from several firms following the ruling have emphasized the same limitation.
This is particularly important in light of Paxton’s alert.
The Texas Attorney General is not saying the federal order prevents Shah from sending a Texas company a demand letter.
It is pointing to that order as relevant context when a business evaluates such a demand.
Another Shah Case Was Dismissed for Lack of Standing
The Crain order is also not the only significant 2026 ruling involving Shah.
In Shah v. Drexel Chemical Company, another judge in the Central District of California dismissed Shah’s amended complaint after concluding he had not alleged a concrete injury sufficient to establish Article III standing.
Judge Hernan D. Vera granted Drexel’s motion to dismiss, denied leave to amend on futility grounds and entered judgment for the company on September 14, 2026.
Shah filed an appeal, and the Ninth Circuit opened case number 26-5894.
The standing ruling is legally distinct from Judge Klausner’s vexatious-litigant order.
But together they illustrate why recipients should not treat a demand letter as though a court has already accepted the underlying theory.
Captain Compliance Has Been Tracking This Story Before the Texas Warning
Captain Compliance’s coverage of Shah has developed alongside the litigation rather than beginning with Paxton’s September alert.
On July 17, Captain Compliance covered Lofty Inc.’s unusual decision to sue Shah first after receiving a demand letter. Instead of waiting to be sued, Lofty sought declaratory relief over the website-tracking theory being threatened against it.
After Judge Klausner issued the July 20 order, Captain Compliance published coverage explaining the vexatious-litigant designation, the prefiling restriction and its limitations.
Captain later published a more extensive examination of Shah’s demand-letter strategy and the CIPA theories being asserted against websites, including search-bar interception and third-party tracking claims.
On September 3, Captain Compliance published a detailed profile of Kevin Cole’s defense of Crain, focusing on the decision to examine Shah’s broader litigation history rather than simply settling the individual case.
Captain Compliance Chief Trust & Privacy Officer Alexander Proctor also presented an IAPP program published September 10 titled You’ve got mail: From a serial privacy plaintiff — A privacy pro’s CIPA playbook. The session used Shah’s campaign and the vexatious-litigant ruling to examine the larger serial demand-letter problem and how privacy teams should evaluate and respond to these claims. Thanks to our awareness campaign that has been so strong it even made an attorney think we were associated with Vivek Shah because we produced so many warnings and artifacts to protect business owners. Also thanks to this work we believe it’s led to Ken Paxton’s warning.
The September 17 Texas Attorney General alert therefore lands in the middle of an issue Captain Compliance has already been documenting in detail.
What Paxton Is Telling Texas Businesses to Do
The Attorney General’s recommended response is notable for what it does not include.
It does not tell companies to ignore the letter.
It does not say every tracking allegation is meritless.
It does not advise companies simply to call the sender’s bluff.
Instead, the Texas Attorney General recommends three practical steps:
- consult an attorney experienced in privacy and website-tracking litigation;
- review the website’s pixels, cookies, analytics tools and related technologies with counsel; and
- monitor the changing law surrounding website tracking.
Texas businesses that believe a demand is fraudulent, abusive or deceptive can also report it to the Attorney General’s Consumer Protection Division.
That Website Review Is Not Just Defensive Litigation Work
This part of the Paxton warning deserves more attention.
Even when a demand is exaggerated, technically incorrect or ultimately unsuccessful, the arrival of the letter can expose a separate issue: the company may not actually know what its website is transmitting.
A modern website can contain dozens of outside technologies.
Marketing teams add pixels.
Advertising agencies modify Google Tag Manager.
Chat providers inject scripts.
Session-replay products observe interactions.
Analytics platforms receive URLs, search values and event information.
An embedded service may introduce another vendor downstream.
The legal theory asserted in a particular demand may fail while the underlying technical configuration still deserves attention.
That is why remediation should not depend entirely on whether a company believes Shah, another claimant or a plaintiffs’ law firm will prevail.
The Core Question Is What Happens Before Consent
For many website-tracking allegations, one fact is especially important: what happens when a new visitor arrives before making a privacy choice?
A company may have a cookie banner and still transmit information before the visitor interacts with it.
The banner itself does not block a script.
The underlying website architecture has to do that.
A proper investigation should therefore examine:
- initial page-load network requests;
- cookies created before consent;
- analytics and advertising pixels;
- search-bar transmissions;
- chat and session-replay technologies;
- Google Tag Manager triggers;
- consent-mode settings;
- browser storage;
- third-party scripts; and
- what changes after Accept, Reject or another privacy choice.
That technical evidence can be considerably more useful than arguing from a screenshot of the cookie banner.
Why This Matters Beyond Vivek Shah
It would be a mistake to read Paxton’s alert as the end of website privacy demand litigation because one plaintiff received a prefiling restriction.
Shah is one person.
The underlying legal environment involves numerous plaintiffs, law firms, statutory theories and jurisdictions.
Website privacy demands have invoked CIPA, the Video Privacy Protection Act, federal and state wiretap statutes and other causes of action.
The theories are also evolving as courts reject some approaches and permit others to proceed.
The Texas Attorney General itself advises businesses to keep monitoring new decisions rather than treating the law as settled.
The value of the Shah story is that it demonstrates what can happen when courts begin looking not only at a privacy allegation but also at the litigation machinery surrounding it.
There Is a Difference Between Privacy Compliance and Paying a Demand
This distinction has been central to Captain Compliance’s coverage.
A business can believe a demand letter is legally weak and still decide that its website should be fixed.
Those positions are not inconsistent.
Consent implementation, script blocking, tracking inventories and evidence logs are valuable regardless of who sent the demand.
The objective should not be to configure a website specifically around one claimant.
It should be to make sure privacy choices correspond to actual website behavior.
That means knowing which technologies are operating, preventing technologies from loading when consent is required, documenting choices and maintaining records showing what the site did.
What a Business Should Preserve After Receiving a Demand
Before making substantial changes, counsel may also want to preserve evidence of the site’s existing configuration.
Depending on the matter, useful records can include:
- the complete demand package and envelope;
- the attached draft complaint;
- screenshots supplied by the claimant;
- the site’s cookie and tracker inventory;
- network captures;
- Google Tag Manager versions;
- CMP configurations;
- consent logs;
- privacy-policy versions;
- vendor documentation;
- deployment dates; and
- records showing when particular tracking technologies were introduced or removed.
Remediation and evidence preservation are separate tasks.
A company may want to fix a questionable configuration quickly without destroying the historical information its lawyers need to evaluate what actually occurred.
Paxton’s Warning Changes the Public Context
The September 17 announcement does not rewrite CIPA.
It does not resolve conflicting website-tracking cases.
It does not reverse any California precedent.
And it does not turn the Central District’s order against Shah into a nationwide prohibition.
What it does is put the office of the Texas Attorney General on record warning businesses that some CIPA demand letters may exaggerate or misrepresent potential legal violations and that companies should obtain legal advice before paying.
It also makes Vivek Shah part of that official warning.
For businesses that have received one of Shah’s letters, that context is difficult to ignore.
The federal court record now includes a vexatious-litigant order.
The Crain case ended with Shah voluntarily dismissing his claims with prejudice.
Another 2026 case against Drexel Chemical ended at the district court level with dismissal for lack of Article III standing, although Shah has appealed.
And Texas has now publicly advised its businesses to exercise caution when demands of this kind arrive.
The Larger Lesson From the Vivek Shah Story
The most important takeaway is not that companies should stop taking privacy litigation seriously.
It is almost the opposite.
Companies need enough technical and legal information to distinguish among three different things:
a real website configuration problem that should be fixed;
a contested legal theory that requires a defense;
and a demand whose economic pressure may be substantially stronger than its underlying merits.
Those categories can overlap.
A website can be poorly configured while the claimant’s legal theory still fails.
A demand can be aggressive while raising a legitimate compliance issue.
A company can remediate tracking without admitting that the claimant was entitled to money.
That is why the correct first response is investigation rather than panic.
Paxton’s office put it more simply: exercise caution and get counsel involved.
For companies following the Vivek Shah cases, the September 17 Texas alert also confirms something Captain Compliance has been documenting throughout 2026.
Website privacy litigation is no longer just a question of what a cookie banner says.
It is now an intersection of technical website architecture, old surveillance statutes, rapidly developing case law, high-volume demand practices and the economics of defending a lawsuit.
The companies in the strongest position are the ones that understand all of those layers before the demand letter arrives.