Clicky

The Cookie Lawsuit Wave

John McKusick

Founder & CEO of NextLeft

ChatGPT Image Jun 30, 2026, 08_40_54 PM

Why your website could be a cookie target, and tips on how to take it off the list. 

(For general informational purposes only. Laws and their interpretations vary by jurisdiction and circumstance, so please consult qualified legal counsel before implementing anything described below.) 

Most businesses do not think of Google Analytics, a chat widget, a remarketing pixel, or a tag manager as a legal issue. They are usually installed to answer practical marketing questions: Where is traffic coming from? Which campaigns are working? Where are visitors dropping off? How can we create a better customer experience?

But a growing body of lawsuits and demand letters suggests that website tracking deserves more attention than it has traditionally received.

Plaintiffs’ firms have brought claims under older state wiretapping and privacy statutes, arguing that certain website tools may collect or transmit visitor information without sufficient notice or consent. The technologies involved are often familiar parts of a standard marketing stack: Google Analytics, Google Tag Manager, advertising pixels, session-recording tools, chat platforms, and marketing automation software.

Healthcare organizations, large consumer brands, small businesses, and agencies have all been named in cases involving website tracking. From our perspective as a team that builds and audits websites every day, the takeaway is not that businesses should stop using marketing technology. It is that they may want to be more intentional about how those tools are deployed, what data they may collect, and whether consent controls are working the way they are supposed to.

The legal question: old statutes, modern websites

Much of this litigation involves state laws that were written well before anyone imagined cookies, pixels, or browser-based tracking.

Two statutes are frequently referenced in these cases.

Florida’s Security of Communications Act, or FSCA, was enacted in 1969 and includes restrictions involving “pen registers” and “trap and trace devices.” Historically, those terms referred to devices used to record information about telephone calls, such as the numbers dialed.

California’s Invasion of Privacy Act, or CIPA, includes similar language related to pen registers.

Plaintiffs’ attorneys have argued that certain web technologies may fit within those older definitions. Their theory is that when a visitor loads a website, third-party scripts can capture technical information, including IP addresses and other routing or signaling details. From there, they argue that a cookie, pixel, or tracking script may operate like a modern version of a pen register.

Courts are still working through how these laws may apply to website activity, and outcomes can depend on the specific facts of each case. In Greenley v. Kochava, 684 F. Supp. 3d 1024 (S.D. Cal. 2023), the court considered allegations involving software that identified consumers, gathered information, and correlated data through unique fingerprinting. The decision became an important reference point in later website-tracking cases.

Other cases, including Moody v. C2 Education Systems and W.W. v. Orlando Health, Inc., have added to the discussion around pixels, analytics tools, and third-party scripts. The legal landscape remains unsettled, which is one reason businesses may want to review their website setup before assuming a standard privacy policy or cookie banner fully addresses the issue.

How the demand-letter playbook may work

The cases we have reviewed often follow a similar pattern.

The first step may be a technical scan. A plaintiff’s firm or technology vendor can inspect a website and identify scripts, pixels, cookies, chat tools, and other third-party technologies that appear to load before a visitor has made a consent choice. That scan may later be attached to a demand letter or complaint.

The tools identified are often not unusual. Google Analytics 4, Google Tag Manager, Meta pixels, LinkedIn Insight Tags, HubSpot, heat-mapping tools, and live chat software may all appear in these types of scans. In many situations, the website owner may not even realize every tool that is running across the site, particularly when tags have been added over time by different agencies, departments, or vendors.

The second step is often about potential damages. Florida and California statutes may allow plaintiffs to seek statutory damages, attorney’s fees, costs, or other remedies. The amount requested in an initial demand may be influenced by those provisions, even when the underlying facts or legal theory are still open to debate.

Then comes the practical pressure point: defending a claim can be costly, even when a business believes it has a strong position. That dynamic may encourage companies to settle quickly rather than spend significantly more responding to litigation.

There is also ongoing disagreement around the legal theories themselves. A January 2026 Orange County Superior Court decision, for example, rejected the Greenley reasoning in a particular case involving an online business. But uncertainty does not necessarily prevent demand letters from being sent. In some ways, it may make early review and preparation more valuable.

Why some websites may attract more attention

Not every website presents the same set of privacy considerations. Consumer-facing websites with extensive tracking, sensitive content, or broad geographic reach may deserve additional review.

First, many businesses run more tracking technology than they realize. Analytics platforms, advertising pixels, remarketing tools, session-recording software, embedded forms, chat widgets, and CRM integrations can all be active at the same time. Each one may create a separate question about what information is being collected and when.

Second, the content a visitor views can sometimes reveal more personal context than a business intends to collect. Someone browsing health-related information, researching debt relief, reading about legal services, exploring insurance options, or using a financial calculator may be signaling something meaningful about their circumstances.

The Orlando Health line of cases has received particular attention because it involved allegations tied to sensitive health-related browsing behavior. That does not mean every website with informational content faces the same level of concern, but it may be worth considering whether sensitive pages need different tracking controls than general marketing pages.

Third, website visitors may come from virtually anywhere. A business does not necessarily need an office in Florida or California for people in those states to access its website. Companies with national reach, active search traffic, e-commerce activity, or broad digital campaigns may want to ask counsel how state-specific privacy laws could affect their online presence.

A more practical way to approach website tracking

The goal is not to remove every analytics tool or marketing platform from a website. Most businesses need data to make informed decisions, improve campaigns, and compete online.

The more useful question may be whether the business has visibility into what is running on the site and a process for managing it responsibly.

Here are a few steps businesses may want to consider.

Inventory every tag and third-party tool

Start with a full website scan and identify every analytics script, pixel, chat platform, embedded form, CRM integration, and session-recording tool.

This is often more revealing than expected. Many websites have legacy scripts from past campaigns, old vendors, or tools that were added through a tag manager and never revisited.

A clear inventory gives your team a starting point for deciding what is necessary, what may need further review, and what can potentially be removed.

Consider a consent management platform

A cookie banner by itself may not be enough if non-essential scripts begin loading before a visitor has the opportunity to make a choice.

A consent management platform can help businesses identify tracking technologies, categorize cookies, manage visitor choices, and retain consent records. We often recommend CookieYes because it can scan for cookies and scripts, help block non-essential technologies until consent is received, and provide documentation of those consent choices.

The configuration is important. A banner that appears on the screen while analytics and ad pixels continue firing in the background may not provide the protection a business expects. It may be worth testing the setup rather than assuming it is functioning correctly.

Review sensitive areas of the website first

Some pages may call for a more cautious approach than others.

Businesses may want to take a closer look at pages involving health information, financial hardship, debt, legal issues, account access, live chat, contact forms, appointment requests, calculators, and other situations where a visitor may be sharing or signaling personal information.

The question is not necessarily whether those pages should have no tracking at all. It is whether the tracking in place is appropriate for the content and whether the consent process reflects the sensitivity of the visitor’s interaction.

Include legal and insurance partners early

Privacy and website-tracking questions can involve technical, marketing, legal, and insurance considerations. Bringing the right people into the conversation early may make it easier to address gaps before they become urgent.

Businesses may want to ask counsel to review their consent language, privacy policy, state-specific obligations, and approach to third-party tracking. It may also be worthwhile to ask an insurance broker or carrier whether current cyber coverage addresses privacy, wiretap, or website-tracking claims.

If a demand letter or complaint arrives, legal counsel should be involved before responding. A prompt response may be important, but it is equally important to understand the facts and avoid making assumptions about the claim.

Revisit the setup regularly

Website tracking is not a one-time project.

Marketing teams add pixels. Developers install new tools. Vendors introduce integrations. A site that was reviewed six months ago may look very different today.

A quarterly review can help organizations spot new scripts, identify outdated technologies, and confirm that consent controls are still working as intended. It can also create a clearer record of the steps the business has taken to manage website privacy responsibly.

A better balance between visibility and privacy

The marketing technology on your website can still play an important role in helping you understand visitors, improve campaigns, and grow your business. The goal is not to choose between visibility and privacy.

It is to build a website strategy that treats both as connected responsibilities.

The recent litigation activity around cookies, pixels, and tracking scripts may be a reminder that a website is no longer just a digital brochure. It is a living system of data, technology, user behavior, and third-party tools. Businesses that understand what is happening behind the scenes may be in a stronger position to make thoughtful decisions before someone else starts asking questions.

At NextLeft, we increasingly encourage clients to take a consent-first approach to website tracking. That can include reviewing active scripts, identifying sensitive areas of the site, implementing appropriate consent controls, and working alongside legal or compliance teams when needed.

If you are unsure what is running on your website today, contact NextLeft to schedule a tracking review and identify areas that may be worth discussing with your legal and compliance partners.

Be Found with NextLeft