
The wave of website privacy demand letters is real, and it is affecting businesses of all sizes—not just companies based in California. Most of these letters allege violations of the California Invasion of Privacy Act (CIPA) due to how websites use analytics, advertising pixels, chat widgets, session replay software, and other third-party tracking technologies. The Better Business Bureau has warned businesses about this growing trend because many demand letters target common website configurations rather than actual data breaches.
There is no single “magic fix”
The solution is a combination of legal compliance, technical changes, and ongoing monitoring.
1. Audit every third-party script on your website
Identify every script that collects visitor information, including:
- Google Analytics 4
- Google Tag Manager
- Meta (Facebook) Pixel
- Google Ads Conversion Tracking
- Microsoft Clarity
- Hotjar
- TikTok Pixel
- LinkedIn Insight Tag
- Live chat widgets
- CRM integrations
- Form tracking tools
Many businesses don’t realize how many third-party services are installed. The first step is knowing exactly what is loading on every page.
2. Implement Consent Mode properly
This is probably the biggest technical change.
Tracking scripts should not load before the visitor gives consent for non-essential cookies.
For WordPress, this usually means:
- CookieYes
- Complianz
- OneTrust
- Cookiebot
- Usercentrics
These platforms can:
- Block tracking
- Record consent
- Allow visitors to withdraw consent
- Keep consent logs
Simply displaying a cookie banner is not enough if scripts are already firing before consent.
3. Configure Google Tag Manager correctly
Many websites load:
Google Tag Manager
↓
Google Analytics
Meta Pixel
Google Ads
LinkedIn
Hotjar
immediately on page load.
Instead:
Page loads
↓
Consent banner appears
↓
Visitor accepts marketing cookies
↓
GTM triggers marketing tags
Modern GTM supports Google’s Consent Mode v2 for exactly this purpose.
4. Review Microsoft Clarity and Session Replay
Many lawsuits specifically mention:
- Microsoft Clarity
- Hotjar
- FullStory
- Lucky Orange
- Mouseflow
These tools record visitor interactions.
If used:
- disable sensitive field recording
- mask personal information
- obtain consent before recording
5. Update your Privacy Policy
A privacy policy should disclose:
- what information is collected
- which third parties receive it
- cookies used
- analytics platforms
- advertising partners
- visitor rights
- opt-out instructions
Many demand letters point to incomplete or outdated privacy disclosures.
6. Review Forms
Contact forms should:
- use HTTPS
- not transmit unnecessary information
- disclose how submitted information is used
- identify any CRM integrations
7. Minimize unnecessary tracking
Ask:
Do you really need:
- five advertising pixels?
- multiple analytics platforms?
- heat mapping?
- session replay?
Every additional script increases risk.
8. Maintain records
If challenged, it helps to show:
- consent logs
- dates policies were updated
- cookie settings
- GTM configuration
- vendor agreements
- privacy audits
Documentation can strengthen your position if a demand letter arrives.
9. If you receive a demand letter
Do not:
- ignore it
- immediately pay
- assume it is valid
Instead:
- Contact an attorney experienced in privacy law.
- Preserve your website configuration and logs.
- Determine exactly what technology is being challenged.
- Fix any legitimate compliance issues while your attorney evaluates the claim.
Many of these website privacy demand letters follow standardized templates, but that does not mean they should be ignored. Whether a particular claim is legally valid depends on the facts and evolving court decisions.
Best practices
| Area | Recommendation |
|---|---|
| Cookie Consent | Consent Mode v2 with script blocking |
| Privacy Policy | Attorney-reviewed and updated annually |
| Google Tag Manager | Consent-aware triggers |
| Analytics | GA4 configured with Consent Mode |
| Session Replay | Disabled until consent is granted |
| Cookie Scanning | Monthly automated scan |
| Tracking Audit | Quarterly review of all third-party scripts |
| Security | HTTPS, CSP, and regular software updates |
| Documentation | Maintain consent and configuration records |
Disclaimer
The information provided in this article is for general informational and educational purposes only and should not be construed as legal advice. Privacy laws, regulations, and legal interpretations vary by jurisdiction and continue to evolve. The suggested actions outlined in this article are general best practices intended to help organizations improve website privacy compliance and reduce potential risk, but they may not be appropriate for every business or situation.
Implementing the recommendations in this article does not guarantee compliance with applicable laws or protection from legal claims, regulatory actions, or demand letters. Businesses should consult with a qualified attorney experienced in privacy, technology, or internet law to evaluate their specific legal obligations and to obtain advice tailored to their circumstances.
If your business has received a website privacy demand letter or lawsuit, you should seek legal counsel promptly before responding, making changes to your website, or communicating with the requesting party.
Because privacy laws and enforcement practices are subject to change, businesses should periodically review their website, privacy policies, consent management practices, and third-party technologies to help maintain ongoing compliance.

