Companies all over the United States have been getting legal demand letters from a person named Vivek Shah saying they violated California CIPA law. The letters look intimidating, but they are actually a fear-based shakedown attempt to get companies to pay settlements.
The letter claims that standard tracking tags (Google Analytics 4, LinkedIn Insight Tag, Meta Tag, Google Ads, etc.) fire on a web page before a user can give affirmative consent. It says this violates the California Invasion of Privacy Act (CIPA). Specifically, it cites a provision called the “pen register” statute that was written in 1967 to regulate telephone wiretapping.
You read that right … telephone wiretapping.
It sounds absurd because it largely is, and courts have been saying so repeatedly. His most recent federal case based on CIPA, Shah v. Talentbridge, was dismissed “without leave to amend” in May 2026, but Shah has appealed. California state courts have been throwing out CIPA pen register claims against websites over the past 18 months. The Los Angeles Superior Court, where Shah typically threatens to file, has been particularly consistent about it.
So why is he still sending letters? Because it costs almost nothing to send a demand letter, and some percentage of recipients will pay to make it go away rather than deal with the hassle. That’s his business model.
What the Letters Claim
The demand letters argue that, based on CIPA, no website tracker should fire until a user gives explicit opt-in consent.
But the letters carefully avoid mentioning the established California privacy framework that actually and unambiguously applies to websites: CCPA (California Consumer Privacy Act) and CPRA (California Privacy Rights Act).
That’s not an accident. CCPA/CPRA is opt-out, not opt-in. Legally, website tags can fire by default without explicit prior permission. What you’re required to do is give users a way to opt out of the sale or sharing of their data, with proper disclosures after they’ve already visited your site.
The opt-in bar Shah’s letters demand is not what California’s actual web privacy laws require. Courts have said so explicitly and repeatedly.
What You Should Do
If you receive a demand letter from Shah, don’t ignore it. Get it to your attorney right away. The legal theory is weak, but the tactical decision on whether and how to respond should be made with counsel.
Your attorney can also confirm whether your business meets the CCPA/CPRA thresholds (100,000 California visitors annually or $25 million in annual revenue across your entire legal entity). Those thresholds apply at the business level, not per publication or per website.
Regardless of whether you’ve received a letter, this is a good reminder to check if your website has the proper legal compliance, and to update it at least once a year. Every time you add a tag or change your tech stack, your website compliance implementation needs to be revisited.
Laws change. Platforms change. And what was compliant 18 months ago may not be today.