Another Surge in Website Tracking Tool Claims Targets Auto Dealers

A Massive Increase in Claims and Demands Related to Website Tracking Tools

Auto dealerships across the country are once again seeing an uptick in demand letters and lawsuits alleging that their websites violate the California Invasion of Privacy Act (CIPA). These demands and suits are targeting dealerships in all 50 states. While website privacy litigation has been an active area for several years, the latest wave has been notable for its scale and consistency. Thousands of nearly identical demand letters have reportedly been sent to businesses across numerous industries by a single self-represented litigant, named Vivek Shah, with dealerships across the country among the latest targets.

The letters generally allege that common website technologies, including analytics tools, advertising pixels, cookies, website search functionality, chat features, and similar tracking technologies, unlawfully intercept or disclose communications without a visitor’s consent. More recently, the letters have expanded beyond traditional wiretapping allegations to assert that certain website technologies operate as unlawful “pen registers” or “trap and trace devices” under California law.

Like many demand campaigns, the letters typically seek a monetary settlement in exchange for avoiding litigation. Importantly, many dealers with no physical presence in California have received these demands simply because their websites can be accessed by California residents.

Why These Claims Matter

CIPA was enacted in the 1960s to combat unauthorized telephone wiretapping. In recent years, plaintiffs have increasingly argued that the statute also applies to ordinary internet technologies that collect or transmit information about website visitors.

The legal theories vary depending on the provision of CIPA being asserted, but many complaints allege that third-party analytics or advertising providers receive information about a visitor’s interactions with a website before the visitor has consented to that collection. Some complaints also challenge website search functions or session replay technologies under theories that were originally developed for telephone communications. Plaintiffs have met with mixed success in trying these claims, but because some courts have accepted these claims, some plaintiffs have been emboldened.

Because CIPA provides for statutory damages of $5,000 per violation, these cases can create significant litigation exposure even when there is no allegation that a consumer suffered any actual financial harm. The potential for substantial statutory damages has made these claims attractive to plaintiffs and has fueled a growing number of demand letters and lawsuits.

The Law Remains Unsettled

Although these claims continue to increase, the underlying law remains far from settled. Courts across California have reached differing conclusions on several fundamental issues, including whether CIPA applies to ordinary website communications, whether common tracking technologies constitute an unlawful interception of communications, or whether they constitute pen registers or trap-and-trace devices.

Some courts have dismissed these claims outright, while others have allowed them to proceed beyond the pleading stage. Several appeals currently working their way through the courts may provide greater clarity, but for now, the outcome often depends on the specific facts alleged, the technology at issue, and even the particular judge hearing the case.

Receiving a demand letter therefore should not be viewed as evidence that a dealership violated the law. At the same time, the letters should not be ignored, as they often precede litigation.

Recent Development: Shah Declared a Vexatious Litigant

One significant recent development may slow, but not stop, this particular wave of litigation. In July 2026, the U.S. District Court for the Central District of California declared Vivek Shah a vexatious litigant after finding that his extensive pattern of filing website privacy lawsuits imposed unnecessary burdens on defendants and the judicial system. The court entered a prefiling order requiring Shah to obtain judicial approval before filing additional CIPA and related website privacy lawsuits in that district.

The ruling represents an important procedural victory for businesses that have been targeted by Shah’s litigation campaign. However, its practical effect is limited. The order applies only to Shah, only to future filings, and only within the Central District of California. It does not prevent Shah from filing in other federal districts, in state court, or filing arbitration cases. It’s important to also note that Shah has been the most active recently, but he is far from the only plaintiff, or plaintiff’s firm sending these letters and filing these claims.  This does not prevent other plaintiffs from asserting similar claims, nor does it resolve the broader legal questions surrounding website privacy litigation.

Practical Steps for Dealerships

The recent increase in demand letters serves as another reminder that website privacy compliance deserves ongoing attention. Most importantly, dealers must have a cookie banner, and one that is designed to be compliant with the law, and critically – works as it should. Dealerships should understand what technologies are deployed on their websites, including analytics platforms, advertising pixels, chat tools, embedded videos, session replay software, and other third-party scripts. Cookie consent platforms should be periodically tested to confirm they are functioning as intended and blocking non-essential technologies before consent where applicable. Privacy policies should accurately describe the dealership’s data collection and sharing practices, and website vendors should be engaged to confirm that privacy settings have not changed following website updates or new feature implementations.

It is also worthwhile to periodically review the configuration of advertising and analytics platforms. Features such as Google’s Restricted Data Processing (RDP), IP anonymization, limiting data sharing between Google Analytics and Google Ads, Meta Limited Data Use (LDU), and executing available service provider or data processing addenda may help reduce privacy risk depending on how the technologies are being used.  

ComplyAuto just issued a detailed and comprehensive guide on analytics tools, including how to utilize features like RDP and LDU. It is the first and only guide of its kind available to dealers.  You can download that guide here.

Finally, dealers should remember that many of these demand letters rely on automated scanning tools or limited technical observations that may not fully reflect how a website actually operates. A careful technical review is often necessary before reaching conclusions about whether the allegations have merit.

Looking Ahead

Website privacy litigation continues to evolve at a rapid pace. While recent court decisions may make it more difficult for serial litigants such as Vivek Shah to continue filing large volumes of lawsuits, they do not eliminate the underlying legal risk. Other plaintiffs continue to pursue similar claims, regulators remain focused on website privacy practices, and appellate courts are still working through many of the unresolved legal questions.

In addition, cookie banners and consumer consent are also required under state privacy laws, state and federal UDAP standards, and a variety of other laws and regulations.  

Dealerships should continue to treat website privacy as an active compliance issue rather than a one-time project. Periodic website scans, regular reviews of tracking technologies, appropriate cookie consent configurations, and coordination with website providers remain some of the most effective ways to reduce both litigation and regulatory risk in this rapidly developing area of law.

How ComplyAuto Can Help

This is a complicated technical area where experience and expertise is critical, as is a keen awareness with ever changing legal requirements. Changing legal landscapes, along with website updates, new marketing tools, and third-party vendors can introduce new cookies and tracking technologies without a dealership realizing it.

ComplyAuto works with tens of thousands of dealers every day to manage this entire process for dealers. The ComplyAuto Privacy solution helps dealers manage this risk with a dealer-focused cookie consent platform and website scanning. Our Privacy platform includes a website scanner that identifies cookies, pixels, and scripts running on the site, including uncommon technologies that are analyzed and proposed for categorization using AI. This helps dealers understand what technologies are present and verify that they are being handled appropriately by their cookie consent settings. Moreover, it is the only solution of its kind that allows dealers to customize their cookie banner to align with their compliance and business strategy, including configuring which categories of technologies are blocked until consent is obtained. For dealers seeking additional protection, ComplyAuto also offers geofencing capabilities that allow a more conservative banner configuration to be shown to visitors from higher-risk states, while presenting a different configuration to users in other jurisdictions.

The bottom line is that this is complicated, but ComplyAuto can help. Rely on the experts at ComplyAuto to provide you with a configurable cookie consent solution, to help you more easily identify changes, address potential privacy risks, and reduce exposure to the growing number of website claims and regulatory requirements.

Scroll to Top