CCPA Compliant, but Still Got a CIPA Letter? You're Not as Covered as You Think
You built the cookie banner. You added the "Do Not Sell or Share" link. You're CCPA compliant — so how did a CIPA demand letter still land on your desk? The uncomfortable answer: CCPA compliance and CIPA compliance are two different things, and the gap between them is exactly where the 2026 wave of website lawsuits lives. Here's the gap, in plain English, and how to close it.
What this article covers
"But I'm CCPA compliant" — why the letter came anyway
If you've received a CIPA demand letter despite having a cookie banner and a compliant privacy policy, you're experiencing one of the most common and costly misconceptions in website privacy: the belief that being CCPA compliant means you're covered against California's other privacy law. It doesn't. This is the single most surprising thing privacy and legal teams discover in 2026 — and plaintiffs' firms have understood it for years, even while many businesses haven't.
Here's the blunt version: the California Invasion of Privacy Act (CIPA) and the California Consumer Privacy Act (CCPA) are independent statutes. They cover overlapping conduct — website tracking — but they're enforced by different parties, under different consent standards, with different remedies. Doing the CCPA work correctly, and even doing it well, leaves a specific, measurable CIPA gap wide open. That gap is not an oversight in the law. It's structural. And it's where the demand letters come from.
Two different laws, built to solve two different problems
To see the gap clearly, you have to see where each law came from — because they were built for genuinely different purposes.
CCPA (enacted 2018, amended by CPRA) is a modern consumer data-protection law. It governs what happens after data is collected: it gives California consumers the right to know what you collected, to delete it, and to opt out of its sale or sharing. Its consent model is opt-out — tracking is allowed to run by default, and the consumer's right is to say "stop." A cookie banner with a "Do Not Sell or Share My Personal Information" link is the classic CCPA control.
CIPA is a 1967 wiretapping statute. It was written to stop people from secretly tapping telephone lines, and California chose an unusually strict standard: all-party consent, meaning every participant in a communication must agree to its interception before it happens. Its consent model is effectively opt-in. Plaintiffs' lawyers have repurposed this decades-old language to argue that website trackers — pixels, session-replay tools, analytics scripts — "intercept" a visitor's communication the instant the page loads. (For the full story of how a phone law became a website-lawsuit machine, see our CIPA explainer.)
Put those two consent models next to each other and the gap becomes obvious: CCPA's consent is opt-out; CIPA's consent is opt-in. A business can satisfy CCPA's notice-and-choice obligations perfectly and still violate CIPA's prior-consent requirement — because the two laws want opposite defaults.
CCPA vs CIPA, side by side
Here's every dimension that matters, consolidated. The rows that create your exposure are the consent model and the enforcement mechanism.
| Dimension | CCPA / CPRA | CIPA |
|---|---|---|
| What it governs | Use, sale & sharing of personal info after collection | Interception of a communication at the moment it happens |
| Consent model | Opt-out (tracking runs by default) | All-party / opt-in (consent before tracking) |
| Who can sue | Regulators (CPPA & Attorney General); private suits only for data breaches | Any individual — broad private right of action |
| Penalty | Up to $2,500 (unintentional) / $7,500 (intentional) per violation, assessed by regulator | $5,000 per violation (or 3× actual damages), no proof of harm required |
| What satisfies it | Notice + opt-out link + honoring GPC | Blocking trackers until affirmative consent |
Find your gap before a plaintiff firm does
The gap is invisible from the front end — your banner looks fine. But a scanner sees which trackers fire before consent. Run the same scan a plaintiff firm would: see exactly what fires before consent on your site, in about 10 seconds.
Scan your site free →No account needed · results in ~10 seconds
Why CIPA — not CCPA — is the weapon of choice
If both laws cover website tracking, why do virtually all the demand letters cite CIPA? The answer is enforcement mechanics, and it's the key to understanding the entire litigation industry.
CCPA has no general private right of action. A consumer can sue privately under CCPA only for a narrow category of data breaches. Every other CCPA obligation — including opt-out failures — is enforced by the California Privacy Protection Agency and the Attorney General, not by private plaintiffs. Regulators bring a limited number of cases each year. A demand-letter business simply cannot run on a statute it has no standing to sue under.
CIPA is the opposite. It provides a broad private right of action, a fixed $5,000-per-violation statutory figure, and a growing line of cases that don't require proving any actual harm. That combination is what makes the enterprise profitable: there's no regulator standing between the violation and the lawsuit. A small number of plaintiff firms use automated scanners to crawl thousands of sites, detect trackers firing before consent, and fire off templated letters at industrial scale. The math works precisely because CIPA hands private individuals a per-violation damages figure and the standing to collect it.
Why this matters for you
- Your CCPA work protected you from the wrong threat. It addressed the law that regulators enforce slowly — not the one private plaintiffs can weaponize instantly.
- "No proof of harm required" means the plaintiff doesn't need to show a breach, identity theft, or any loss — only that a tracker fired before consent.
- The $5,000 multiplies. Across sessions or page loads and a class of visitors, the theoretical exposure climbs fast — which is exactly the leverage a demand letter is built on.
The timing gap: why a cookie banner isn't enough
Here's the technical heart of the problem, and the part that catches even careful teams. CCPA governs what happens after data is collected. CIPA targets whether a communication can be intercepted at all — and a CIPA violation occurs instantly, at the moment of interception, with no retroactive fix.
A standard cookie banner is built for the CCPA world. It loads, it offers choices, and — crucially — on most implementations the trackers have already fired by the time the banner appears. For CCPA, that can be fine: you disclosed, you offered an opt-out. For CIPA, it's the whole violation: the "interception" happened in the first few hundred milliseconds, before the visitor consented to anything. A banner that merely records a preference, rather than blocking trackers until consent, does nothing to prevent the CIPA claim.
The 2026 twist: even a working "Reject" can be turned against you
The litigation is evolving, and this is where being current matters — most explainers haven't caught up. In 2026, plaintiffs' firms have started repackaging opt-out failures as wiretap and deceptive-practices claims. The pattern: a visitor clicks "Reject All," the site represents that tracking will stop — but third-party tags keep transmitting data anyway. Plaintiffs then argue the business made a promise, the user relied on it, the business broke it, and that broken promise is itself a deceptive act or an unlawful interception.
Two things make this dangerous. First, it means even sites with a reject button are exposed if that button doesn't genuinely stop the trackers — a cosmetic "Reject All" becomes evidence against you. Second, courts have begun stretching CCPA's own narrow private right of action beyond data breaches: a May 2026 decision from the Northern District of California allowed a CCPA private claim to proceed over adtech tracking without any breach, joining a growing line of similar rulings. The walls between these theories are coming down, and the practical effect is more ways to sue, not fewer.
Meanwhile, the reform that might close the door — SB 690, which would create a safe harbor for commercial tracking already governed by CCPA — stalled in 2025, was designated a two-year bill, and even if it passes, relief wouldn't arrive until 2027 at the earliest. As of 2026, there is no safe harbor.
How to actually close the gap
The good news: closing the CIPA gap is a technical fix, and the same fix also strengthens your CCPA and GDPR posture. The principle is simple — move from "disclose and offer opt-out" to "block until opt-in." Concretely:
- Block non-essential trackers before consent. No analytics, ad pixel, session-replay, or chat tool should fire on page load. Everything waits behind the consent choice. This is the step that directly neutralises the CIPA prior-consent theory.
- Make "Reject" genuinely work. When a visitor declines, the trackers must actually not fire — test it, don't assume it. A cosmetic reject is now a liability, not a defense.
- Honor Global Privacy Control signals in real time — increasingly an enforcement priority, and the next likely litigation trigger.
- Keep a timestamped consent log. If a demand letter arrives, an auditable record of what was blocked, what the visitor chose, and when is your strongest single piece of evidence.
This is exactly what ConsentPixel — Privacy · Verified is built to do: a single pixel that blocks third-party trackers until a visitor opts in, makes "reject" actually stop tracking, honors GPC, and logs every decision. It closes the specific gap CCPA compliance leaves open — before a scanner finds it. And if a letter has already arrived, start with our guide to responding to a CIPA demand letter.
✅ Key takeaways
- CCPA compliance does not equal CIPA compliance. They're independent laws with opposite consent defaults.
- CIPA is the litigation weapon because it has a private right of action and $5,000-per-violation damages with no proof of harm required — CCPA opt-out failures are mostly regulator-enforced.
- Timing is the gap: a cookie banner that lets trackers fire on load satisfies CCPA disclosure but fails CIPA's prior-consent standard.
- 2026 makes it worse: cosmetic "Reject All" buttons and stretched CCPA private-right-of-action rulings create more ways to sue — and SB 690 offers no relief before 2027.
- The fix is technical: block non-essential trackers until opt-in, make reject real, honor GPC, and keep a consent log.
Frequently asked questions
Does CCPA compliance protect me from CIPA lawsuits?
I have a cookie banner. Why did I still get a CIPA demand letter?
Why do demand letters cite CIPA instead of CCPA?
Will SB 690 fix this?
What actually closes the CIPA gap?
The bottom line
If a CIPA letter arrived despite your CCPA work, nothing went wrong with your CCPA work — it just protected you from a different threat. CCPA governs what you do with data after you collect it. CIPA governs whether you were allowed to collect it in that moment at all. The gap between them is opt-out versus opt-in, and it's where the entire 2026 litigation wave operates.
You can't close it with a better privacy policy or a nicer banner. You close it by making sure nothing non-essential fires before consent — and by keeping the record that proves it.
See your CIPA gap in about 10 seconds
Run the same scan a plaintiff firm would: see exactly which third-party trackers fire on your site before a visitor consents — the gap your CCPA banner leaves open. Then close it automatically with ConsentPixel — Privacy · Verified.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo