Your Website Uses Cookies. (Whose Doesn't?) Here's Why That Could Suddenly Be a Problem.

TL;DR: Here’s What You Really Need to Know

  • If your website uses analytics, advertising pixels, UTM tracking, chat tools or other common marketing technology, cookies and tracking technologies are probably involved.
  • Businesses are receiving demand letters and lawsuits alleging that some of these technologies violate California privacy laws when they collect or transmit information before a visitor provides appropriate consent.
  • You don't have to be located in California to pay attention to this. California residents can visit your website from anywhere.
  • A simple “We Use Cookies” banner may not be enough. A true Consent Management Platform can identify cookies, give visitors choices and prevent certain non-essential tracking from firing before consent.
  • Adding cookie consent does NOT automatically make your business compliant. Your Privacy Policy also needs to accurately explain what information you collect and what you do with it and that's something you should review with your attorney.
  • Digital Division can help with the technology side: scanning your website, identifying and categorizing cookies, implementing consent management and continually monitoring for changes.

Bottom line: Don't panic, but don't ignore it either. Website privacy is becoming a much bigger issue in the U.S., and it's worth being proactive before a demand letter shows up.

Does your website use Google Analytics? A Meta Pixel? Google Ads tracking? A chat tool? Embedded third-party software?

Of course it does. Pretty much everyone's does.

These are normal tools that businesses use every day to understand who's visiting their website, measure whether their marketing is working, provide better customer service, and make smarter decisions.

But now those same everyday website tools are at the center of a growing number of privacy demand letters and lawsuits.

And yes, businesses outside of California need to pay attention too.

we value your privacy

What's Going On?

demand letter

There's been a wave of demand letters and lawsuits alleging that websites are violating a California privacy law by allowing certain tracking technologies to collect or transmit information before a website visitor has given consent.

One name that has come up repeatedly is Vivek Shah, who has reportedly sent thousands of demand letters to organizations across the country related to website tracking technologies.

And here's the part that may surprise you.

The law at the center of many of these claims wasn't written for websites.

It was written in 1967.

The California Invasion of Privacy Act, or CIPA, was originally created to protect people from things like wiretapping and the interception of private communications.

Obviously, nobody was sitting around in 1967 worrying about Google Analytics, Meta Pixels or website cookies.

But today, plaintiffs are arguing that when certain website technologies transmit information about a visitor's activity to a third party without that visitor's consent, it can amount to an unlawful interception under CIPA.

Welcome to the internet in 2026.

1967 to 2026 CIPA difference

Does This Sound a Little Like the ADA Website Lawsuits?

If you've been following the explosion of ADA website accessibility demand letters and lawsuits over the past several years, some of this may sound familiar.

The laws and legal issues are different, but from a business owner's perspective, there are some frustrating similarities.

With ADA website accessibility claims, businesses have found themselves facing demand letters or lawsuits because their websites allegedly aren't accessible to people with disabilities, even when the business had no idea there was an issue.

Now we're seeing another wave of website-related claims, this time involving privacy, cookies and tracking technology.

And once again, many businesses don't realize they may have exposure until a demand letter or lawsuit shows up.

To be clear, website accessibility and consumer privacy are both important. The ADA serves an important purpose in protecting people with disabilities, just as privacy laws serve an important purpose in protecting consumers' personal information.

The concern for businesses is how these laws are increasingly being used as the basis for large volumes of website-related demand letters and litigation.

We've seen the impact of these types of claims firsthand with our own clients. So when we see another website issue beginning to generate this kind of legal activity, we think it's important to tell our clients about it before they're the ones opening a demand letter.

That's why we're talking about cookie consent now.

Wait. What Exactly Are Cookies Again?

Cookies are small pieces of information that websites store on a visitor's device.

Some are necessary for a website to work correctly.

Others help businesses do things like:

  • See how many people visit their website
  • Understand which pages people visit
  • Measure advertising performance
  • Track conversions from Google Ads or social media
  • Track where website visitors came from (including campaigns using UTM codes)
  • Remember visitor preferences
  • Power chat and other website tools
  • Personalize the website experience

And here's one that surprises a lot of people: If you're using UTM codes on links to figure out whether someone came from an email, social media post, digital ad or another marketing campaign, that attribution is often recorded and connected to the visitor through analytics tools that use cookies or similar tracking technologies.

The UTM code itself isn't a cookie; it's simply information added to the URL. But tools like Google Analytics can use that information, along with cookies and other browser technologies, to understand where visitors came from and what they do after they arrive.

In other words, cookies are everywhere.

And a lot of the technology using them isn't something we'd consider unusual or invasive. It's the same basic marketing technology businesses have been using for years to answer questions like, "Did anyone actually click that email we sent?" or "Did that Google Ad generate any leads?"

Using cookies doesn't automatically mean your website is doing something wrong.

The issue is becoming what information is being collected, where it's going, and whether certain tracking tools are running before the visitor has had an opportunity to consent.

That's an important distinction.

"I'm Not in California. Why Do I Care?"

We can already hear this question.

Here's the problem:

Your website is.

Your website doesn't have to be located in California for someone in California to visit it.

Or, more accurately, your website can be visited by someone in California.

A business doesn't have to have an office in Los Angeles or San Francisco for a California resident to visit its website.

Whether a particular California law applies to your business is a legal question and one you should discuss with an attorney if you're concerned about your company's exposure.

But from a website and marketing standpoint, ignoring privacy simply because your business isn't located in California isn't a strategy we'd recommend.

Especially when businesses outside California are already receiving these types of demand letters.

Is This the California Consumer Privacy Act?

You may have heard of the California Consumer Privacy Act (CCPA). That's another important piece of California's privacy landscape, but it's not the same law driving many of these recent website tracking claims.

The CCPA gives qualifying California consumers certain rights regarding their personal information, including rights related to knowing how their information is used and opting out of certain sales or sharing of personal information.

The California Invasion of Privacy Act (CIPA) is different.

That's the 1967 law we just talked about.

The current controversy is that CIPA is being applied to modern website technologies that didn't exist (or even remotely resemble anything that existed)when the law was written.

That's why businesses that thought they had a fairly standard website setup are suddenly paying attention.

Europe Has Been Doing This for Years

You've probably visited a European website and immediately been asked:

Accept All Cookies? Reject? Manage Preferences?

There's a reason for that.

Europe has had much stricter requirements surrounding online privacy and tracking for years through laws and regulations including the General Data Protection Regulation (GDPR) and ePrivacy rules.

That's why cookie consent management has become standard practice on European websites.

The United States doesn't have one universal federal equivalent to GDPR. Instead, we have an increasingly complicated mix of state privacy laws, regulations and court cases.

And that means the way businesses manage cookies and tracking technology on their websites is becoming much more important here too.

"But I Already Have a Cookie Banner."

Great.

But there's an important question:

What does your cookie banner actually do?

There's a big difference between putting a message at the bottom of your website that says:

"We use cookies. By using this website, you agree..."

and actually giving someone control over which cookies they're allowing.

A true Consent Management Platform (CMP) can do much more.

It can scan your website to identify cookies and tracking technologies, categorize them, give visitors the ability to accept or reject certain cookies, and perhaps most importantly, prevent certain non-essential tracking technologies from firing until the visitor has provided the appropriate consent.

That's a lot different from putting a little box at the bottom of the website and calling it a day.

Your Website Has Probably Changed More Than You Think

Here's something else we see all the time.

A website launches with one set of technology.

Then someone adds Google Analytics.

Then Google Ads.

Then a Meta Pixel.

Then HubSpot.

Then a chat tool.

Then Calendly.

Then an embedded YouTube video.

Then a new CRM integration.

You get the idea.

Websites aren't static.

And every time another piece of technology gets added, there's the potential for additional cookies, scripts or third-party tracking.

That's why cookie management isn't necessarily something you should set up once and never think about again.

So What Should You Do?

First: don't panic.

Second: don't ignore it.

If your business has a website, and we're going to assume it does since you're reading a Digital Division blog, you should understand what tracking technology is running on it.

At a minimum, it's worth reviewing:

  • What cookies and tracking technologies your website currently uses
  • Which third parties may receive information from your website
  • Whether non-essential tracking is occurring before consent
  • Whether visitors can accept or reject different types of cookies
  • Whether you have an appropriate cookie policy
  • Whether your privacy policy accurately reflects the information you're collecting and how you're using it
  • Whether your cookie consent system continues to scan for changes
privacy policy on website

And Please Review Your Privacy Policy With Your Attorney

This is an important one.

Adding a cookie consent tool to your website doesn't automatically make your business compliant with every privacy law.

Adding a cookie consent tool to your website doesn't automatically make your business compliant with every privacy law.

Cookie consent is one piece of a much bigger privacy picture.

Your website's Privacy Policy should accurately explain what information your business collects, how you use it, and, when applicable, whether that information is shared with third parties.

And don't assume the Privacy Policy that's been sitting in your website footer for the last five years still covers everything you're doing today.

Think about how much technology may have been added to your business during that time: analytics platforms, advertising pixels, CRMs, email marketing systems, online forms, chat tools, scheduling software, payment processors and more.

analytics collage of pixels

Your Privacy Policy needs to reflect your actual business practices, not just check a box in the footer of your website.

That's why we recommend having your attorney periodically review your Privacy Policy and make sure it appropriately addresses the information your business collects and how that information is used.

Digital Division can help identify the cookies and tracking technologies operating on your website and implement tools to manage cookie consent. We can't tell you whether your Privacy Policy meets your company's legal obligations. That's a job for your attorney.

The two should work together.

Think of it this way:

Cookie consent helps manage what happens. Your Privacy Policy helps explain what happens.

You need to be thinking about both.

Yes, Digital Division Can Help With This.

Digital Division offers a website cookie consent management service that helps businesses take a more proactive approach to website privacy.

We can scan your website to identify the cookies and tracking technologies currently in use and implement a consent management system that gives your visitors more transparency and control.

Our service can include:

  • Website cookie scanning
  • Cookie identification and categorization
  • Cookie consent banner implementation
  • Accept and reject functionality
  • Cookie preference management
  • Blocking appropriate non-essential cookies until consent
  • Cookie policy information
  • Ongoing scanning as cookies and website technology change

And no, we're not going to tell you this guarantees you'll never receive a demand letter or get sued.

We're marketers and website developers. Not your attorneys.

Privacy laws vary by jurisdiction, and businesses with specific concerns about their legal obligations should absolutely talk with qualified legal counsel.

What we can do is help make sure you're not ignoring an increasingly important part of managing a modern website.

Website Privacy Isn't Just a European Thing Anymore

For years, a lot of American businesses saw those giant cookie consent boxes on European websites and thought:

"Glad we don't have to deal with that."

Well...

Here we are.

Whether or not you agree with how a law written nearly 60 years ago is being applied to modern website technology, businesses need to pay attention to what's happening.

You don't need to rip Google Analytics off your website.

You don't need to stop tracking whether your marketing works.

And you definitely don't need to panic every time you hear about another privacy lawsuit.

But you do need to be smarter about how your website handles cookies, tracking and visitor consent.

If you're not sure what cookies are running on your website, or whether your current cookie banner is actually doing anything, Digital Division can help.

Contact us to learn more about our website cookie consent management service or to have us take a look at your site.

This article is provided for general informational purposes and does not constitute legal advice. Digital Division is a digital marketing and website development company, not a law firm. Businesses should consult qualified legal counsel regarding their specific privacy and regulatory obligations.

DIGITAL MARKETING SOLUTIONS

 

Relax.
You've got a digital marketing partner.

 

Digital Division is a marketing agency with solutions that can help you generate leads and transform your business.