Website Privacy Litigation Trends

Agencies have seen this before: Overzealous plaintiff lawyers engaging in serial litigation to extract quick settlements. In past years, plaintiffs threatened to bring claims under the Americans with Disabilities Act (ADA) based on website accessibility, prompting evaluation of website design and outside vendor practices.

Today, the same tactic is repeated with website privacy litigation, which is beginning to expand from its initial focus on larger technology companies.

Any consumer-facing business with advanced website features, such as analytics, tracking cookies or chat features, could find itself subject to these types of claims. As a result, website privacy compliance is becoming another operational risk to consider as part of agencies’ broader risk management. Unlike traditional privacy lawsuits arising from data breaches, these cases typically allege that a business collected, recorded or shared information from website visitors without providing adequate notice or obtaining consent.

Although the legal theories vary, plaintiffs have relied on state privacy statutes, consumer protection laws and even anti-wiretapping laws, with the California Invasion of Privacy Act (CIPA) receiving the most recent attention.

In particular, a serial litigant named Vivek Shah has sent numerous demand letters and filed lawsuits alleging CIPA violations based on crawling business websites, even if the businesses do not operate in California. A federal court recently rejected one of Shah’s claims for lack of standing, but he has appealed the ruling.

Modern websites often include a variety of third-party technologies that improve customer experience and support marketing and business operations, including website analytics, tracking or advertising cookies, live chat platforms or artificial intelligence (AI) chatbots, customer portals and call recording systems. While these tools can serve important business purposes, they’re often implemented by third-party providers, which can make it easier to lose visibility into exactly what data is collected and how it is used or shared.

Regardless of whether required by applicable law, recent litigation serves as a useful reminder to review digital practices. Here are some questions agencies may wish to consider:

  • What tracking or analytics technologies are operating on our website?
  • What information do they collect?
  • Are our privacy notices current and accurate?
  • If we use a cookie consent tool, does it function as intended?
  • Are calls or chats recorded, and are appropriate disclosures provided where required?
  • Do we understand what our website vendors and marketing partners have implemented on our behalf?

As privacy laws continue to develop, agencies may benefit from viewing website privacy as another component of operational risk management. For many agencies, a periodic review of their website technologies, privacy notices and recording practices may be a worthwhile addition to overall compliance and governance efforts.

Like website accessibility issues, this does not necessarily require abandoning existing technologies or redesigning an entire website. Rather, both underscore the importance of conducting periodic reviews, understanding what vendors have implemented and ensuring that policies and practices evolve alongside evolving requirements and standards.

Finally, if your business receives a demand letter from a serial litigant, it may not be to your benefit to engage or respond right away. Instead, consider consulting with an experienced attorney who can provide specific advice and guidance. 

News Types

Big I Programs

Most Recent Big “I” News