The US has no federal privacy law like the GDPR, yet US businesses face more lawsuits over website tracking than almost anyone. The claims don't come from new privacy laws. They come from old laws about wiretaps and video rentals, applied to pixels and chat widgets.
Thousands of these claims have been filed. Many end in settlements or demand letters, which makes them a cost even for businesses that never go to court.
California's wiretapping law.
The California Invasion of Privacy Act, known as CIPA, was written in the 1960s for telephone calls. Plaintiffs argue that tools which pass what a visitor does on a website to a third party, while it happens, are a form of eavesdropping. The tools named most often are:
- session recording, which captures clicks, scrolling and typing
- chat widgets run by a third party
- advertising and analytics pixels, such as Meta, TikTok and Google
The law allows statutory damages of up to 5,000 dollars per violation, which is what makes class actions attractive.
A second wave used CIPA's "pen register" section, arguing that tracking tools which collect IP addresses and device details are like the devices that log the numbers a phone dials.
That changes soon. California's SB 690, signed on 30 September 2026, ends private lawsuits under that section for websites and apps from 1 January 2027, including some claims already filed. The wiretapping section isn't affected, and the state's Attorney General can still enforce both.
The video law.
The Video Privacy Protection Act is a federal law from 1988, passed after a newspaper published a list of a judge nominee's video rentals. It stops a "video tape service provider" from sharing which videos a person watched along with who they are.
Lawsuits argue that a site with video content does exactly that when the Meta pixel sends the address of a video page together with the visitor's Facebook ID. The law sets damages of 2,500 dollars per person.
Courts disagree on who counts as a "consumer" under the law: anyone who subscribes to anything from the business, such as a newsletter, or only people who pay for video. The Supreme Court hears that question in Salazar v. Paramount Global on 14 October 2026, and its answer will decide how far these claims can reach.
What the claims have in common.
Almost every claim depends on the same thing: data reaching a third party before the visitor agreed, or after they said no. Pixels that fire on page load, before the banner has been answered, and tags that ignore a "Reject" choice give plaintiffs their case. Sensitive pages make it worse: health, finance and video pages appear again and again.
What to check on your site.
- List every third-party tag, including session recording, chat and embedded video. Note what each one sends and when.
- Check what fires before any choice. Load the site in a fresh browser and watch the network requests before touching the banner.
- Check that "Reject" works. Decline, reload, and confirm advertising requests stop.
- Look at pages with video. If the Meta pixel runs there, the page address and the visitor's ID may travel together.
- Mask or remove session recording on forms, and on any page where people type personal details.
- Make sure your notices match reality. A privacy policy describing tracking the site doesn't do, or missing tracking it does, helps nobody.
The free tracking checker shows what a page loads before consent. The opt-out rules under state privacy laws are in US state privacy laws and your GA4 setup.
Whether a claim has merit, and what your notices should say, is for your lawyers. Marc Alexander makes sure the tags do what you've decided, for US businesses, and the GA4 mini audit starts with exactly these checks.