A 1967 wiretapping law is getting websites sued in 2026. Here's what's happening and how to fix it.

Businesses across the country are getting sued over their websites. Not over anything on the page, but over the tracking tools running behind it, the same analytics and pixels almost every site uses. The lawsuits claim those tools are illegal wiretapping under CIPA, the California Invasion of Privacy Act, a law written in 1967 for telephone calls that plaintiffs have retrofitted for the web.
Same idea as GDPR in Europe: block tracking until a visitor opts in. The difference is enforcement. GDPR brings government fines. CIPA lets private individuals sue you directly.
A good consent setup:
A lot of the exposure comes from one tool. Google Analytics uses cookies and collects data that can identify individuals, which is why it needs a consent banner at all.
Privacy-first analytics tools like Plausible measure traffic without cookies and without collecting personal data. No personal data means nothing to consent to, so no consent banner is required, and every visitor gets counted instead of just the ones who accept.
How it works: instead of planting a cookie to follow a person, Plausible counts visits using anonymous, aggregated data that resets daily. You still get visitors, page views, top pages, referral sources, countries, and devices on one dashboard. You give up individual tracking, cross-day retention, and deep Google Ads integration.
It also:
Switching analytics doesn't cover everything (ad pixels and chat widgets still need consent handling), but it removes one of the biggest risks and shrinks what your banner has to manage.
You can check this yourself in a few minutes. Open your site in a fresh browser session and open the network tab before the page loads.
If you're not comfortable in the network tab, that's fine, send it our way.
The law here is unsettled and recent rulings have gone both directions. Several 2025 decisions were dismissed on standing or merit when the plaintiff couldn't show real privacy harm, and one federal judge questioned whether the wiretapping provision even applies to internet communications at all. California's SB 690 could also narrow CIPA down the road. None of that makes the demand letters stop landing, and fixing your setup still costs far less than answering one.
If you're an SDH client, we'll audit your consent setup, tell you straight whether it's working, and either get you on a properly configured tool or move you to cookieless analytics. Reach out and we'll add it to the list.