Did Your Business Get a Website Privacy Demand Letter From Vivek Shah? Here’s What You Should Do Now
Many businesses nationwide are receiving demand letters from the same person seeking money for alleged privacy violations on their websites. Indeed, we estimate that from Fall 2025 through June 2026 Vivek Shah has already sent thousands of these letters to businesses and nonprofits throughout the country, claiming violations of California’s wiretapping law, and he doesn’t appear to be slowing down. Many targets are not consumer-facing and are wondering why a former actor and convicted felon from California would have any legitimate reason to access their website. Some of his targets appear to have no connection to California. Here’s what you should know and do if you receive one of these demands – and a five-step action plan to strengthen your data privacy compliance efforts.
What Is the Claim?
Specifically, Shah’s letters allege violations of the California Invasion of Privacy Act (CIPA), which has prohibited wiretapping for nearly six decades but has only recently been used to assert website privacy claims.
Under CIPA, wiretapping occurs when someone intentionally taps into, connects to, or tries to access a phone line or other communication device without permission. It also includes trying to read, hear, or understand the contents of a communication without the consent of all parties to the communication.
Many plaintiffs now allege that the commonplace use of cookies, pixels, and similar tech on websites without opt-in consent constitutes illegal wiretapping – and Shah appears to be the most prolific of such plaintiffs.
In Shah’s case, he typically sends a one-paragraph demand letter with a draft complaint for CIPA violations. His letters are often accompanied by website screenshots that allegedly support his claims. He usually threatens to file the complaint in state court or arbitration (if the website terms of use contain an arbitration clause) unless the business pays him to drop the claim. CIPA carries penalties of up to $5,000 per violation, and class actions routinely settle in the high six figures or even seven figures.
Since he began his campaign of asserting CIPA claims in Fall 2024, and through his wave of demand letters sent to companies in Fall 2025, Shah’s claims have been premised on his use of a website’s search bar, typing in some innocuous term like his first name in all caps (“VIVEK”), and then alleging the website transmitted his search terms to third parties like Google Analytics.
Shah asserts claims under CIPA Section 631, which prohibits wiretapping or aiding and abetting a third party in doing so. More recently in the last couple of months, Shah has pivoted to CIPA Section 638.51, which prohibits the use of a pen register or trap and trace device. Some courts have interpreted Section 638.51 to apply to website cookies while others have vehemently rejected such interpretation. You can read more about these claims here: In-House Counsel Asks California Appeals Court To Resolve CIPA Privacy Questions Amid Digital Wiretapping Litigation Flood
Who Has Been Targeted?
Vivek Shah has been indiscriminately targeting businesses across many industries, including manufacturers, schools, auto dealerships, mining companies, retailers, and B-to-B and B-to-C businesses. Essentially, if your website collects information from visitors, you are a target for privacy claims and a demand letter from Shah.
“The threat by Vivek Shah impacts businesses all over the country of every size and industry,” says Usama Kahf, FP Partner and Co-Chair of the firm’s Privacy and Cyber Practice Group. “Everyone is a potential target.”
When companies don’t agree to his settlement demands, Shah files lawsuits in arbitration or in court. In many of these lawsuits, Shah litigates these claims aggressively.
In a recent development, a federal court dismissed one of Shah’s claims for lack of standing (though he has appealed the ruling to the 9th US Circuit Court of Appeals).
When suing businesses for CIPA violations, Shah has been representing himself pro se without an attorney, but that doesn’t mean you should ignore his demand letter. Moreover, he has sued in court when businesses have ignored his arbitration demands, seeking to compel arbitration under the website’s terms of use. In those cases, Shah has been represented by an attorney.
What Should You Do If You Receive a Letter?
Don’t simply toss the letter aside – but also don’t engage or respond to him directly. “While Vivek Shah is pro se and his claims may feel like a meritless attack, working with an experienced attorney who knows this claimant and his history is important,” says Danielle Kays, FP Partner and litigator in the firm’s Privacy and Cyber Practice Group.
Your FP attorney can help you assess the risk and develop a game plan. At FP, we currently are handling 80+ matters against Vivek Shah, with that number increasing daily. Our team’s experience also includes defending over 250 privacy claims related to use of tracking technology in websites, apps, and marketing emails.
It’s also a good idea to be proactive. Document all relevant aspects of your website in real time, including third-party tracking technology, and your cookie banner, privacy policy, and terms of use. This is particularly important if you plan to make any changes, so you have documentation of your practices at the time of the demand letter. Additionally, follow our five-step action plan below to reduce your legal risk.
Your 5-Step Action Plan
Every business that operates a website should take a close look at what pixels, web beacons, cookies, and other tracking technologies you have on your website. Here are five specific steps you should consider taking now:
1. Review Your Website. Take a close look at your website to evaluate what pixels, web beacons, cookies, and other tracking tools are in use. Identify what data each tracking tool is disclosing and who is receiving it. Ascertain what third parties are doing with your data once they receive it. Audit every tracking tool currently running on your website. Know what cookies, pixels, analytics tools, and session replay software you’re using, who operates them, and when they start collecting data.
2. Display Appropriate Disclosures. Ensure your website includes disclosures that adequately describe the parties to the communication, to whom the data is disclosed, the further use (if any) of the data, and where your consumers can access your privacy practices – and all before the consumer enters or provides any information. For example, cookie banners should state that data is being disclosed to third parties for targeted ad purposes, if that is the case, instead of only stating that the website uses cookies to improve user experience.
3. Opt-In and Opt-Out Choices. Website visitors should have the option to choose whether they opt in or opt out of the use of data as described in the disclosures. Each of these options should be just as easy to accomplish as the other, known as symmetry of choice. This may involve turning off collection of data through cookies or pixels until a consumer opts in by clicking a button. Opt-in consent may not be required by applicable consumer privacy laws like the California Consumer Privacy Act (CCPA). But to avoid a wiretapping claim, your best bet may be installing an opt-in consent mechanism where no data is disclosed to third parties without a user’s click on a button.
4. Track Evolving Legal Developments. Website privacy litigation under CIPA, as well as other federal and state privacy laws, is rapidly evolving. For a fuller picture of digital wiretapping litigation trends nationwide, visit our Digital Wiretapping Litigation Map, which tracks related cases across all 50 states.
5. Consult with Counsel. Before responding to a demand letter from Vivek Shah or changing your website, reach out to an attorney with experience in digital wiretapping litigation to develop the best strategy.
Conclusion
To stay current on CIPA developments, legislative progress, and other California privacy litigation trends, subscribe to Fisher Phillips’ Insights. For guidance specific to your situation, contact your Fisher Phillips attorney, the author of this Insight, or any member of our Digital Wiretapping Litigation Team.





