Skip to Main Content
10/01/2026|2 minute read

Key Takeaways

  • CIPA demands are not staying in California.
  • A demand letter does not prove a privacy violation.
  • Questionable demands still require prompt attention.

On Sept. 17, Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofit organizations about a recent surge in demand letters alleging violations of the California Invasion of Privacy Act (CIPA). The alert cautions that some letters may exaggerate or misrepresent potential violations and advises recipients to consult legal counsel before responding or making a payment.

Why This California Law Matters in Texas

The subjects of these demands have not been limited to companies or organizations based in California. Businesses across industries have been targeted based on technologies such as cookies, pixels, analytics tools and search bars operating on their public-facing websites.

Demand letters may claim that these technologies unlawfully intercept website visitors’ electronic communications, constituting “wiretapping,” in violation of CIPA. They often also include screenshots of the organization’s website, a draft complaint threatening litigation and a demand for immediate payment.

As emphasized by the alert, however, receipt of the demand does not establish a violation of CIPA or other privacy laws because these demand letters may exaggerate or misrepresent potential violations. Whether the claim has merit may depend on a variety of factors, including the technology involved, the information transmitted, consent and disclosures and the relevant jurisdiction.

When a Demand Letter Deserves a Closer Look

Some demand letters come from serial plaintiffs or repeat claimants, which underscores the Attorney General’s concern about protecting Texans from fraudulent demands and scams. The alert identifies Vivek Shah as one example. Shah, a serial CIPA plaintiff known to have sent demand letters alleging website privacy violations, was declared a vexatious litigant by the U.S. District Court for the Central District of California and must obtain the court’s permission before filing new CIPA or related digital privacy actions in that district.

The order does not prevent Shah from pursuing claims in every forum or determine whether a particular organization’s website practices comply with CIPA. It does, however, illustrate why recipients should evaluate the sender and legal basis of a demand rather than taking it at face value.

Take It Seriously, Not at Face Value

Although the Attorney General warns that some demand letters may be fraudulent, abusive or deceptive, recipients should not assume that every demand lacks merit or can be safely ignored. Even a questionable demand may raise legal or compliance issues that warrant review.

Organizations receiving a CIPA demand should preserve the letter and its attachments, avoid making immediate admissions and promptly consult appropriate privacy counsel. Counsel can help assess the sender and allegations, coordinate a review of the website and determine the appropriate course of action.


Featured Insights