The claims landscape: CIPA, session recording, and demand letters
The dominant privacy claim against US websites right now is the CIPA theory: California's Invasion of Privacy Act (Penal Code sections 631 and 632) was written for wiretapping, and plaintiff firms argue that session-replay tools, live-chat widgets, and third-party pixels "intercept" a visitor's communications with the site. With statutory damages up to $5,000 per violation, most of these arrive as demand letters priced to settle, not to litigate.
Alongside CIPA sit CCPA/CPRA claims over undisclosed sharing of personal information with ad platforms, Video Privacy Protection Act claims where video pages carry tracking pixels, and — for clients with EU traffic — GDPR and ePrivacy exposure. Different statutes, same factual core: a tracker did something the visitor never agreed to.
A parallel track has opened in the EU that has nothing to do with trackers. Under the European Accessibility Act, in force since 28 June 2025, a French court ordered Carrefour in June 2026 to make its site and app accessible within six months under a daily penalty, and Sweden's regulator opened cases after 124 complaints. The defensive posture is the one this checklist already argues for: a dated record showing the site was checked and fixed. What EAA compliance requires is a separate question from consent, but it lands on the same clients.