ConsentPixel – Privacy · Verified

⚖ CIPA & Legal Risk

CCPA Compliant, but Still Got a CIPA Letter? You're Not as Covered as You Think

You built the cookie banner. You added the "Do Not Sell or Share" link. You're CCPA compliant — so how did a CIPA demand letter still land on your desk? The uncomfortable answer: CCPA compliance and CIPA compliance are two different things, and the gap between them is exactly where the 2026 wave of website lawsuits lives. Here's the gap, in plain English, and how to close it.

ConsentPixel Team Published July 6, 2026 9 min read CIPA · CCPA · Compliance gap
$5,000
CIPA statutory damages per violation — and any individual can sue directly
Opt-out ≠ opt-in
CCPA lets tracking run by default; CIPA wants consent first — the whole gap
No safe harbor
SB 690 stalled — no relief expected before 2027 at the earliest

"But I'm CCPA compliant" — why the letter came anyway

If you've received a CIPA demand letter despite having a cookie banner and a compliant privacy policy, you're experiencing one of the most common and costly misconceptions in website privacy: the belief that being CCPA compliant means you're covered against California's other privacy law. It doesn't. This is the single most surprising thing privacy and legal teams discover in 2026 — and plaintiffs' firms have understood it for years, even while many businesses haven't.

Here's the blunt version: the California Invasion of Privacy Act (CIPA) and the California Consumer Privacy Act (CCPA) are independent statutes. They cover overlapping conduct — website tracking — but they're enforced by different parties, under different consent standards, with different remedies. Doing the CCPA work correctly, and even doing it well, leaves a specific, measurable CIPA gap wide open. That gap is not an oversight in the law. It's structural. And it's where the demand letters come from.

The one-sentence version. CCPA asks: "Did you disclose your tracking and offer an opt-out?" CIPA asks a completely different question: "Did you intercept the visitor's communication before you had their consent?" You can answer the first perfectly and still fail the second.

Two different laws, built to solve two different problems

To see the gap clearly, you have to see where each law came from — because they were built for genuinely different purposes.

CCPA (enacted 2018, amended by CPRA) is a modern consumer data-protection law. It governs what happens after data is collected: it gives California consumers the right to know what you collected, to delete it, and to opt out of its sale or sharing. Its consent model is opt-out — tracking is allowed to run by default, and the consumer's right is to say "stop." A cookie banner with a "Do Not Sell or Share My Personal Information" link is the classic CCPA control.

CIPA is a 1967 wiretapping statute. It was written to stop people from secretly tapping telephone lines, and California chose an unusually strict standard: all-party consent, meaning every participant in a communication must agree to its interception before it happens. Its consent model is effectively opt-in. Plaintiffs' lawyers have repurposed this decades-old language to argue that website trackers — pixels, session-replay tools, analytics scripts — "intercept" a visitor's communication the instant the page loads. (For the full story of how a phone law became a website-lawsuit machine, see our CIPA explainer.)

Put those two consent models next to each other and the gap becomes obvious: CCPA's consent is opt-out; CIPA's consent is opt-in. A business can satisfy CCPA's notice-and-choice obligations perfectly and still violate CIPA's prior-consent requirement — because the two laws want opposite defaults.

The gap: opt-out (CCPA) vs opt-in (CIPA) CCPA — opt-out 1. Visitor arrives 2. Trackers fire immediately ✗ 3. Banner offers "Do Not Sell" 4. Visitor may opt out later CIPA — opt-in 1. Visitor arrives 2. Trackers BLOCKED ✓ 3. Banner asks to opt in 4. Trackers fire only after consent THE GAP = step 2 A CCPA-compliant site fires trackers before consent. That's the CIPA violation.
Same banner, opposite defaults. A textbook CCPA setup lets trackers run on arrival and offers an opt-out. CIPA wants them blocked until opt-in. The difference at "step 2" is the entire lawsuit.

CCPA vs CIPA, side by side

Here's every dimension that matters, consolidated. The rows that create your exposure are the consent model and the enforcement mechanism.

DimensionCCPA / CPRACIPA
What it governsUse, sale & sharing of personal info after collectionInterception of a communication at the moment it happens
Consent modelOpt-out (tracking runs by default)All-party / opt-in (consent before tracking)
Who can sueRegulators (CPPA & Attorney General); private suits only for data breachesAny individual — broad private right of action
PenaltyUp to $2,500 (unintentional) / $7,500 (intentional) per violation, assessed by regulator$5,000 per violation (or 3× actual damages), no proof of harm required
What satisfies itNotice + opt-out link + honoring GPCBlocking trackers until affirmative consent

Find your gap before a plaintiff firm does

The gap is invisible from the front end — your banner looks fine. But a scanner sees which trackers fire before consent. Run the same scan a plaintiff firm would: see exactly what fires before consent on your site, in about 10 seconds.

Scan your site free →

No account needed · results in ~10 seconds

Why CIPA — not CCPA — is the weapon of choice

If both laws cover website tracking, why do virtually all the demand letters cite CIPA? The answer is enforcement mechanics, and it's the key to understanding the entire litigation industry.

CCPA has no general private right of action. A consumer can sue privately under CCPA only for a narrow category of data breaches. Every other CCPA obligation — including opt-out failures — is enforced by the California Privacy Protection Agency and the Attorney General, not by private plaintiffs. Regulators bring a limited number of cases each year. A demand-letter business simply cannot run on a statute it has no standing to sue under.

CIPA is the opposite. It provides a broad private right of action, a fixed $5,000-per-violation statutory figure, and a growing line of cases that don't require proving any actual harm. That combination is what makes the enterprise profitable: there's no regulator standing between the violation and the lawsuit. A small number of plaintiff firms use automated scanners to crawl thousands of sites, detect trackers firing before consent, and fire off templated letters at industrial scale. The math works precisely because CIPA hands private individuals a per-violation damages figure and the standing to collect it.

Why this matters for you

  • Your CCPA work protected you from the wrong threat. It addressed the law that regulators enforce slowly — not the one private plaintiffs can weaponize instantly.
  • "No proof of harm required" means the plaintiff doesn't need to show a breach, identity theft, or any loss — only that a tracker fired before consent.
  • The $5,000 multiplies. Across sessions or page loads and a class of visitors, the theoretical exposure climbs fast — which is exactly the leverage a demand letter is built on.

The timing gap: why a cookie banner isn't enough

Here's the technical heart of the problem, and the part that catches even careful teams. CCPA governs what happens after data is collected. CIPA targets whether a communication can be intercepted at all — and a CIPA violation occurs instantly, at the moment of interception, with no retroactive fix.

A standard cookie banner is built for the CCPA world. It loads, it offers choices, and — crucially — on most implementations the trackers have already fired by the time the banner appears. For CCPA, that can be fine: you disclosed, you offered an opt-out. For CIPA, it's the whole violation: the "interception" happened in the first few hundred milliseconds, before the visitor consented to anything. A banner that merely records a preference, rather than blocking trackers until consent, does nothing to prevent the CIPA claim.

The trap that catches good teams: a banner that looks compliant but lets tags fire on load is the worst of both worlds. It signals you knew consent was expected — while failing to actually get it before tracking. As one legal analysis put it, that combination signals you knew without protecting you.

The 2026 twist: even a working "Reject" can be turned against you

The litigation is evolving, and this is where being current matters — most explainers haven't caught up. In 2026, plaintiffs' firms have started repackaging opt-out failures as wiretap and deceptive-practices claims. The pattern: a visitor clicks "Reject All," the site represents that tracking will stop — but third-party tags keep transmitting data anyway. Plaintiffs then argue the business made a promise, the user relied on it, the business broke it, and that broken promise is itself a deceptive act or an unlawful interception.

Two things make this dangerous. First, it means even sites with a reject button are exposed if that button doesn't genuinely stop the trackers — a cosmetic "Reject All" becomes evidence against you. Second, courts have begun stretching CCPA's own narrow private right of action beyond data breaches: a May 2026 decision from the Northern District of California allowed a CCPA private claim to proceed over adtech tracking without any breach, joining a growing line of similar rulings. The walls between these theories are coming down, and the practical effect is more ways to sue, not fewer.

Meanwhile, the reform that might close the door — SB 690, which would create a safe harbor for commercial tracking already governed by CCPA — stalled in 2025, was designated a two-year bill, and even if it passes, relief wouldn't arrive until 2027 at the earliest. As of 2026, there is no safe harbor.

How to actually close the gap

The good news: closing the CIPA gap is a technical fix, and the same fix also strengthens your CCPA and GDPR posture. The principle is simple — move from "disclose and offer opt-out" to "block until opt-in." Concretely:

  • Block non-essential trackers before consent. No analytics, ad pixel, session-replay, or chat tool should fire on page load. Everything waits behind the consent choice. This is the step that directly neutralises the CIPA prior-consent theory.
  • Make "Reject" genuinely work. When a visitor declines, the trackers must actually not fire — test it, don't assume it. A cosmetic reject is now a liability, not a defense.
  • Honor Global Privacy Control signals in real time — increasingly an enforcement priority, and the next likely litigation trigger.
  • Keep a timestamped consent log. If a demand letter arrives, an auditable record of what was blocked, what the visitor chose, and when is your strongest single piece of evidence.

This is exactly what ConsentPixel — Privacy · Verified is built to do: a single pixel that blocks third-party trackers until a visitor opts in, makes "reject" actually stop tracking, honors GPC, and logs every decision. It closes the specific gap CCPA compliance leaves open — before a scanner finds it. And if a letter has already arrived, start with our guide to responding to a CIPA demand letter.

✅ Key takeaways

  • CCPA compliance does not equal CIPA compliance. They're independent laws with opposite consent defaults.
  • CIPA is the litigation weapon because it has a private right of action and $5,000-per-violation damages with no proof of harm required — CCPA opt-out failures are mostly regulator-enforced.
  • Timing is the gap: a cookie banner that lets trackers fire on load satisfies CCPA disclosure but fails CIPA's prior-consent standard.
  • 2026 makes it worse: cosmetic "Reject All" buttons and stretched CCPA private-right-of-action rulings create more ways to sue — and SB 690 offers no relief before 2027.
  • The fix is technical: block non-essential trackers until opt-in, make reject real, honor GPC, and keep a consent log.

Frequently asked questions

Does CCPA compliance protect me from CIPA lawsuits?
No. CCPA and CIPA are independent California laws with opposite consent models. CCPA is opt-out (tracking can run by default, with a right to opt out) and is mostly enforced by regulators. CIPA effectively requires opt-in (consent before tracking) and gives any individual a private right to sue for $5,000 per violation. You can be fully CCPA compliant and still violate CIPA if your trackers fire before a visitor consents.
I have a cookie banner. Why did I still get a CIPA demand letter?
Because most cookie banners let trackers fire on page load, before the visitor interacts with the banner. That satisfies CCPA's disclose-and-opt-out model but fails CIPA, which treats the interception as happening the instant a tracker fires without prior consent. If your banner records a preference but doesn't actually block trackers until consent, it doesn't prevent a CIPA claim.
Why do demand letters cite CIPA instead of CCPA?
Because CCPA has no general private right of action — outside narrow data-breach cases, only regulators can enforce it. CIPA gives any individual the right to sue directly, with $5,000 in statutory damages per violation and no requirement to prove harm. That combination is what makes high-volume demand-letter campaigns possible, so plaintiffs' firms build their claims on CIPA.
Will SB 690 fix this?
Not yet, and not soon. SB 690 would create a safe harbor for commercial tracking already governed by CCPA, but it stalled in the California Assembly in 2025 and was designated a two-year bill. Even if it eventually passes, relief would not arrive until 2027 at the earliest. As of 2026 there is no statutory safe harbor, and the litigation continues. This is general information, not legal advice.
What actually closes the CIPA gap?
A technical change: block non-essential third-party trackers until the visitor affirmatively consents, make sure clicking "reject" genuinely stops them, honor Global Privacy Control signals, and keep a timestamped consent log. Moving from "disclose and offer opt-out" (CCPA-style) to "block until opt-in" (CIPA-style) is what neutralises the prior-consent theory the lawsuits rely on.

The bottom line

If a CIPA letter arrived despite your CCPA work, nothing went wrong with your CCPA work — it just protected you from a different threat. CCPA governs what you do with data after you collect it. CIPA governs whether you were allowed to collect it in that moment at all. The gap between them is opt-out versus opt-in, and it's where the entire 2026 litigation wave operates.

You can't close it with a better privacy policy or a nicer banner. You close it by making sure nothing non-essential fires before consent — and by keeping the record that proves it.

See your CIPA gap in about 10 seconds

Run the same scan a plaintiff firm would: see exactly which third-party trackers fire on your site before a visitor consents — the gap your CCPA banner leaves open. Then close it automatically with ConsentPixel — Privacy · Verified.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

CP

ConsentPixel Team

Privacy & Website Compliance

ConsentPixel — Privacy · Verified helps website owners and agencies understand and reduce their exposure to CIPA, GDPR, and CCPA/CPRA risk. We translate fast-moving website-tracking litigation into practical, technical guidance. This article is educational and does not constitute legal advice; consult a qualified privacy attorney about your specific situation.

Scroll to Top