Learn

Protecting your clients from privacy lawsuits: a practical checklist

Cookie-related privacy claims against US businesses follow a pattern: an automated crawl finds a tracker firing without consent, a demand letter cites CIPA or CCPA/CPRA, and the target settles because litigating costs more. The defense is equally patterned — remove the trigger, verify the consent layer, and keep dated evidence of both.

This checklist walks counsel and compliance leads through that defense, item by item. It is practical guidance for the audit workflow, not legal advice for any specific matter.

Run a free scan

The claims landscape: CIPA, session recording, and demand letters

The dominant privacy claim against US websites right now is the CIPA theory: California's Invasion of Privacy Act (Penal Code sections 631 and 632) was written for wiretapping, and plaintiff firms argue that session-replay tools, live-chat widgets, and third-party pixels "intercept" a visitor's communications with the site. With statutory damages up to $5,000 per violation, most of these arrive as demand letters priced to settle, not to litigate.

Alongside CIPA sit CCPA/CPRA claims over undisclosed sharing of personal information with ad platforms, Video Privacy Protection Act claims where video pages carry tracking pixels, and — for clients with EU traffic — GDPR and ePrivacy exposure. Different statutes, same factual core: a tracker did something the visitor never agreed to.

Pre-consent tracking is the number-one trigger

Nearly every one of these claims starts the same way: an automated tool crawls the target site and finds a tracker firing before any consent was given. Session replay recording from the first pageview. A chat widget opening a websocket on load. A Meta or TikTok pixel firing on page one. If the tracker waits for consent, the core allegation — interception or sharing without agreement — loses its factual basis.

That makes pre-consent behavior the single highest-leverage thing to check. A pre-consent tracking scan shows you exactly what fires before the banner — the same view the plaintiff's tooling has.

Checklist part 1 — audit the high-risk trackers

For each client site, confirm the following, in order of claim frequency:

  • Session replay (Hotjar, FullStory, Microsoft Clarity, etc.): does recording start before consent? Does it capture form fields?
  • Chat widgets: does the widget load and connect to its vendor before the visitor opens it or consents?
  • Advertising pixels (Meta, TikTok, Google Ads, LinkedIn): do they fire on landing, and on pages with sensitive context (health, finance, video)?
  • Analytics: does it run pre-consent, and is IP or identifier collection configured beyond what the privacy policy discloses?

A single scan surfaces all four categories with the vendor domains named, so the checklist becomes a read-through of the report rather than a manual inspection.

Checklist part 2 — verify the consent layer actually works

A banner that displays but doesn't gate anything documents awareness without compliance. Verify:

  • Declining or ignoring the banner actually blocks the non-essential trackers.
  • Google Consent Mode signals (ad_storage, analytics_storage, ad_user_data, ad_personalization) start denied and update only after an affirmative choice.
  • The cookie policy names the trackers the scan actually found — not last year's list.
  • For CCPA/CPRA, the opt-out path ("Do Not Sell or Share") exists and functions.

CookieInspector checks banner behavior and Consent Mode state in the same pass as the tracker inventory, so parts 1 and 2 of this checklist come from one report.

Checklist part 3 — build the paper trail

Protection isn't only fixing issues — it's being able to prove when you looked and what you found. Keep the dated PDF report from the initial audit, the remediation record, and the re-scan showing the fix. If a demand letter arrives, that sequence shows prompt, documented diligence rather than indifference.

Then make the record continuous: put each site on a Compliance Monitor schedule so every re-scan extends the diligence trail automatically, and an email alert lands the moment a regression appears. The step-by-step version of this workflow is in the law firm cookie audit playbook.

What this checklist can and cannot do

Closing the gaps above removes the factual trigger behind the overwhelming majority of cookie-related claims. It does not make a client unsueable — plaintiff theories evolve, and disclosure, contract, and jurisdiction questions sit outside what any scanner can see. Treat the scan as the evidence layer and keep counsel's judgment on top of it; nothing here is legal advice.

For firms running this at scale, the law firm landing page covers reports and monitoring retainers; agencies protecting a client portfolio should start with the agency compliance page.

Related guides

More insights

Ready to prove your compliance?

Start with a scan so you can show regulators and stakeholders the evidence you followed cookie compliance checker best practices.

Run a free scan