Website Privacy Demand Letters

Website Privacy Demand Letters infograph

The wave of website privacy demand letters is real, and it is affecting businesses of all sizes—not just companies based in California. Most of these letters allege violations of the California Invasion of Privacy Act (CIPA) due to how websites use analytics, advertising pixels, chat widgets, session replay software, and other third-party tracking technologies. The Better Business Bureau has warned businesses about this growing trend because many demand letters target common website configurations rather than actual data breaches.

There is no single “magic fix”

The solution is a combination of legal compliance, technical changes, and ongoing monitoring.

1. Audit every third-party script on your website

Identify every script that collects visitor information, including:

  • Google Analytics 4
  • Google Tag Manager
  • Meta (Facebook) Pixel
  • Google Ads Conversion Tracking
  • Microsoft Clarity
  • Hotjar
  • TikTok Pixel
  • LinkedIn Insight Tag
  • Live chat widgets
  • CRM integrations
  • Form tracking tools

Many businesses don’t realize how many third-party services are installed. The first step is knowing exactly what is loading on every page.


2. Implement Consent Mode properly

This is probably the biggest technical change.

Tracking scripts should not load before the visitor gives consent for non-essential cookies.

For WordPress, this usually means:

  • CookieYes
  • Complianz
  • OneTrust
  • Cookiebot
  • Usercentrics

These platforms can:

  • Block tracking
  • Record consent
  • Allow visitors to withdraw consent
  • Keep consent logs

Simply displaying a cookie banner is not enough if scripts are already firing before consent.


3. Configure Google Tag Manager correctly

Many websites load:

Google Tag Manager

Google Analytics
Meta Pixel
Google Ads
LinkedIn
Hotjar

immediately on page load.

Instead:

Page loads

Consent banner appears

Visitor accepts marketing cookies

GTM triggers marketing tags

Modern GTM supports Google’s Consent Mode v2 for exactly this purpose.


4. Review Microsoft Clarity and Session Replay

Many lawsuits specifically mention:

  • Microsoft Clarity
  • Hotjar
  • FullStory
  • Lucky Orange
  • Mouseflow

These tools record visitor interactions.

If used:

  • disable sensitive field recording
  • mask personal information
  • obtain consent before recording

5. Update your Privacy Policy

A privacy policy should disclose:

  • what information is collected
  • which third parties receive it
  • cookies used
  • analytics platforms
  • advertising partners
  • visitor rights
  • opt-out instructions

Many demand letters point to incomplete or outdated privacy disclosures.


6. Review Forms

Contact forms should:

  • use HTTPS
  • not transmit unnecessary information
  • disclose how submitted information is used
  • identify any CRM integrations

7. Minimize unnecessary tracking

Ask:

Do you really need:

  • five advertising pixels?
  • multiple analytics platforms?
  • heat mapping?
  • session replay?

Every additional script increases risk.


8. Maintain records

If challenged, it helps to show:

  • consent logs
  • dates policies were updated
  • cookie settings
  • GTM configuration
  • vendor agreements
  • privacy audits

Documentation can strengthen your position if a demand letter arrives.


9. If you receive a demand letter

Do not:

  • ignore it
  • immediately pay
  • assume it is valid

Instead:

  1. Contact an attorney experienced in privacy law.
  2. Preserve your website configuration and logs.
  3. Determine exactly what technology is being challenged.
  4. Fix any legitimate compliance issues while your attorney evaluates the claim.

Many of these website privacy demand letters follow standardized templates, but that does not mean they should be ignored. Whether a particular claim is legally valid depends on the facts and evolving court decisions.

Best practices

AreaRecommendation
Cookie ConsentConsent Mode v2 with script blocking
Privacy PolicyAttorney-reviewed and updated annually
Google Tag ManagerConsent-aware triggers
AnalyticsGA4 configured with Consent Mode
Session ReplayDisabled until consent is granted
Cookie ScanningMonthly automated scan
Tracking AuditQuarterly review of all third-party scripts
SecurityHTTPS, CSP, and regular software updates
DocumentationMaintain consent and configuration records

Disclaimer

The information provided in this article is for general informational and educational purposes only and should not be construed as legal advice. Privacy laws, regulations, and legal interpretations vary by jurisdiction and continue to evolve. The suggested actions outlined in this article are general best practices intended to help organizations improve website privacy compliance and reduce potential risk, but they may not be appropriate for every business or situation.

Implementing the recommendations in this article does not guarantee compliance with applicable laws or protection from legal claims, regulatory actions, or demand letters. Businesses should consult with a qualified attorney experienced in privacy, technology, or internet law to evaluate their specific legal obligations and to obtain advice tailored to their circumstances.

If your business has received a website privacy demand letter or lawsuit, you should seek legal counsel promptly before responding, making changes to your website, or communicating with the requesting party.

Because privacy laws and enforcement practices are subject to change, businesses should periodically review their website, privacy policies, consent management practices, and third-party technologies to help maintain ongoing compliance.

Share The Wisdom: