This story first broke around July 14, 2026.

If your website uses ordinary analytics or ad tracking pixels, and you have visitors in California, a state wiretapping law is being used to file real lawsuits over it.

What to Check

1. List every analytics tool, ad pixel, or chat widget running on your site.

2. Check whether your site shows a consent notice before those tools start tracking a visitor, not just a generic cookie banner.

3. If you’re not sure what’s actually running on your site, that’s worth finding out before assuming you’re covered.

An Old Law, a New Use

California’s Invasion of Privacy Act, originally written for wiretapping phone calls, is being applied to website tracking tools. Courts are still split on exactly where the line sits, but that hasn’t stopped a wave of lawsuits carrying statutory damages up to $5,000 per violation. A violation, in this context, can mean a single visitor whose activity was tracked without proper consent.

This isn’t limited to businesses based in California. Any site with California visitors is exposed, which covers most small business websites with any national reach at all. The legal picture is still unsettled, which means the pressure to settle rather than fight a suit remains real even without a final court answer.

Most sites run tracking tools without ever auditing what they collect or how. A straightforward review of what’s installed is the first step to knowing where the exposure actually is.

Source: Spencer Fane