Thousands of businesses are being sued despite their own cookie banners
Clym reports thousands of businesses face lawsuits under California's 1967 privacy law, stemming from cookie banners
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.


Aree_S // Shutterstock
A California law written in 1967 to stop wiretapping on telephone lines has become the basis for thousands of lawsuits arguing that everyday website tools, chat widgets, tracking pixels and analytics scripts amount to illegal interception of a visitor’s communications.
The suits aren’t limited to major technology companies. They’ve been filed against retailers, insurers, hospitals, media outlets and car dealerships, and most turn on the same gap: what a website’s cookie banner promises versus what the code running behind it actually does.
Clym reviewed litigation-tracking data, court filings and legal industry analysis to examine why this wave of lawsuits under California’s Invasion of Privacy Act, or CIPA, has accelerated in 2026 and which businesses are most exposed.
More than 4,300 digital wiretapping lawsuits have been filed nationwide since a pivotal 2022 appellate ruling opened the door to these claims, with more than 75% of them filed in California, according to Fisher Phillips’ Digital Wiretapping Litigation Map, a tracker maintained by the law firm’s privacy practice.
Cyber insurer Coalition separately found that privacy-related insurance claims it received roughly doubled in the first half of 2026 compared with 2025, and that nearly 75% of those web-privacy claims specifically cited CIPA, according to the insurer’s midyear claims analysis.
How a 1967 wiretapping law reached modern websites
CIPA was passed by the California Legislature in 1967, decades before the modern internet, and makes it illegal to intentionally intercept or record the contents of a communication without the consent of everyone involved, according to a legal history published by law firm Constangy, Brooks, Smith & Prophete. Unlike most privacy statutes, it lets a private citizen sue directly, with statutory damages of $5,000 per violation, or three times actual damages, and no requirement to prove real harm, according to law firm Spencer Fane.
The modern wave traces to a May 2022 ruling in Javier v. Assurance IQ, in which the Ninth Circuit found that session-replay software recording a visitor’s activity required consent before it started, not after. That opened the door for plaintiffs to argue that outside vendors whose code runs on a website, not just the site’s own operator, can be treated as eavesdroppers rather than participants in the conversation.
The consent timing problem
Legal analysts tracking this litigation point to three recurring patterns: tracking tags that fire the instant a page loads, before a visitor has any chance to interact with a cookie banner, a phenomenon an April 2026 alert from law firm Loeb & Loeb called the millisecond problem; tracking that continues after a visitor declines, because no one connected the banner’s setting to the tools actually collecting data; and sites with no consent mechanism at all.
One pending lawsuit against Toyota Motor Corporation, for example, alleges that tracking continued even after a visitor repeatedly selected “decline.” An April 2026 alert from law firm Fox Rothschild put it plainly: a cookie banner is a policy statement, not a guarantee, and whether a site’s behavior matches what the banner promises depends on how every individual script was configured.
Who’s being targeted?
Retail and e-commerce sites make up the largest single industry represented in Fisher Phillips’ litigation map, and law firms report a parallel wave of claims against auto dealerships, insurers, hospitality businesses, healthcare providers and media companies, according to law firm Barnes & Thornburg. Settlements have run into the millions: the Los Angeles Times agreed to pay $3.85 million in 2026 over third-party ad trackers, without admitting wrongdoing, and Forbes Media agreed to pay $10 million the same year to resolve similar claims.
Both cases were filed in the Northern District of California, which, along with Florida and Illinois, has become one of the most active venues for this kind of litigation.
The law is still unsettled
Courts remain divided on whether these claims hold up. In one 10-day stretch in April 2026, four different California courts issued rulings on nearly identical tracking claims and reached different conclusions. California lawmakers have also taken notice: Senate Bill 690, which would eliminate private lawsuits over one specific category of CIPA claim, passed the state Senate 35-0 in 2025 and advanced through an Assembly committee in July 2026.
If enacted, it would take effect Jan. 1, 2027, but would leave CIPA’s core wiretapping provisions, the ones underlying cases like the suit against Toyota, fully intact.
None of this means every business running a chat widget or an ad pixel is facing an imminent lawsuit. What the litigation wave does suggest is that a cookie banner is only as accurate as the technical work behind it, and businesses are increasingly being advised to check which third-party scripts run on their site, when those scripts start collecting data, and whether a visitor’s actual choice, including a decline, is honored by every tool connected to the site rather than just displayed on the banner.
This story was produced by Clym and reviewed and distributed by Stacker.
![]()

