SF LAW LOGO SUITE_Cinzel Logo Set-4

Articles & Blogs

Rash of New Lawsuits Claim Violations of California Privacy Laws: How to Protect Your Business-SennFortis

Rash of New Lawsuits Claim Violations of California Privacy Laws: How to Protect Your Business

By Liz Hartsel 

In recent years, companies operating websites accessible to California consumers are increasingly encountering lawsuits and arbitration demands under the California Invasion of Privacy Act (CIPA), designed to protect Californians’ privacy. This law imposes potential statutory damages of $5,000 for each violation, which could pose a significant financial risk, especially if claims are filed on behalf of a class. One of the primary issues driving these claims is the use of website tracking technologies, such as cookies, which collect personal information from website visitors without their explicit consent. 

Understanding the Core Legal Risks 

The lawsuits hinge on the argument that cookies and similar tracking technologies “record” users’ interaction with a website without their explicit knowledge or consent. This, plaintiffs argue, violates CIPA. Given the broad reach of the internet, these lawsuits have the potential to affect any business with an online presence—even if the company is based outside of California. For instance, you could run a company based in Crested Butte and still face legal challenges because your website is accessible to California residents. 

At Fortis, we’ve already seen several of our Colorado clients receive demand letters alleging CIPA violations, with opposing attorneys arguing that the use of tracking technologies without user consent infringes on privacy rights. These cases represent an easy, predatory way for plaintiffs to claim thousands of dollars in damages and attorney fees.  

The Unclear Legal Landscape 

One complicating factor is that the law is unclear on whether visiting a website inherently implies user consent to tracking. So far, no cases have been fully litigated to a final judgment, leaving companies in a legal gray area. Some have opted to settle, hoping to avoid the risk and expense of prolonged litigation. However, this strategy does not necessarily offer long-term protection; in fact, settling may even encourage additional claims from other plaintiffs. 

Mitigating Risk: What Your Company Should Do Now 

There are several steps you can take now to protect your business from the growing wave of CIPA-related claims: 

  1. Comply with State Privacy Laws: Stay up to date on the privacy regulations in the states where your website operates. You need to understand California’s CIPA, but also other state laws that may have similar provisions. Consult with an attorney if needed.  
  1. Enhance Website Transparency: Evaluating whether your website is truly transparent about its use of tracking technologies is a crucial first step in building a compliant website. Does your website provide comprehensive information about cookies and other trackers? Can users easily understand which cookies are being used and how they can block or opt out of them? 
  1. Implement Opt-In Mechanisms: Consider deploying an opt-in consent mechanism, especially for California users. Most U.S. states have specific rules governing how companies must notify consumers about tracking technologies and how personal information is shared with third parties. Implementing an explicit opt-in mechanism helps ensure that your business is in compliance with state data protection laws and can offer protection against privacy-related lawsuits. 
  1. Tailor Your Approach for California: California is leading the charge in enforcing stricter privacy laws. An opt-in consent mechanism that asks for explicit consent before using any tracking technology will minimize risk under CIPA. 

Stay Vigilant 

With privacy laws continuing to evolve and expand, vigilance is vital. Taking the proactive steps mentioned above can help you avoid being a target of these parasitic lawsuits. You should also take this time to ensure that your website remains compliant with the Americans with Disabilities Act (a previous Fortis blog post discussing ADA website compliance is available here).  

If you have questions about website compliance or if you receive a CIPA demand letter, please reach out to a Fortis team member and we will help you address it.  

 

Share: