CIPA in 2026: 318 decisions, zero trial verdicts, and what a claim is really worth
By Karel Kubicek, Lead Privacy & AI Researcher, Vault JS | October 6, 2026
Since Javier v. Assurance IQ put the California Invasion of Privacy Act on the web in May 2022, courts have handed down 318 internet-tracking decisions under it. Our research team pulled every one, coded each for outcome, claim type and how it was decided, and analyzed the set as data.

The full report, CIPA in 2026: what a claim is really worth, is out today. Here is what the record shows.
The short version
- Not one of the 318 decisions is a trial verdict. These cases end on a motion or on a check.
- The defense wins 31.1% of the time. 266 different companies were sued, 238 of them exactly once.
- The median settlement a brand has disclosed is $3.7 million.
- A vendor’s business model doesn’t decide the case. The legal ground does.
- The one number a company controls is how many third parties load on its pages before consent.
Not one case has reached a trial verdict
The outcomes are almost all motion practice: 99 defense wins, 89 mixed rulings, 62 settlements, 42 rulings for the plaintiff and 26 still undecided. A handful reach summary judgment. None reach a jury. So the commercial question is not whether your tracking was lawful. It is what a claim costs and whether you can end it early.

This is not a wave that will pass. Internet-tracking decisions under CIPA went from 8 in 2022 to 103 in 2025. Defendants range from national retailers to single-site stores, and the only companies that appear more than four times are Meta and Google.
The docket moved from chat to pixels
In 2023, most CIPA decisions against brands were about live-chat widgets and session replay. In 2025 and 2026, the majority allege marketing pixels, with analytics and ad tags close behind. A compliance program built around the 2023 docket is defending the wrong thing.

A consent banner doesn't win the motion
The weakest position in the record is the one that looks compliant from the inside: a consent platform deployed, an opt-out recorded, and tags that keep firing anyway. The defense won 16.7% of those 18 decisions, about half the baseline. It is also the fastest-growing pattern: one such decision in 2024, seven in 2025 and ten in the first half of 2026.
Only one consent posture clearly beat the baseline: separate written consent that a user cannot skip, at 77.8% on nine decisions. A privacy-policy disclosure on its own did no better than average.
Sensitive data lowers the odds and raises the price
The defense wins 35.6% of decisions where no sensitive data is alleged and 22.4% where health data is. The same marketing pixel defends at 29.6% on an ordinary page and 17.5% where sensitive data is involved. Healthcare companies paid 29 of the 35 settlements brands have disclosed. Same pixel, same transmission, worse odds and a bigger check.

SB 690 helps less than the headlines suggest
Governor Newsom signed SB 690 on September 30. Starting January 1, 2027, it removes the private right of action for pen-register claims over websites and apps. It leaves Section 631 wiretap claims untouched, and the same fact patterns can still be pleaded there. In our reading of the record, SB 690 removes a pleading route and a damages count, not the likelihood of a demand letter.
Count the hosts before a claimant does
A demand letter’s first multiplier is the number of distinct third parties a claimant can list from a single visit to your site. You can measure that number yourself, and reduce it, before anyone else counts it.
The full report covers eight measures that reduce exposure, ordered by what each one actually changes; how to read a letter if one arrives; what 42 disclosed settlements tell us; and a 90-day measurement plan. It runs 40 pages and is written by Karel Kubicek and Julie Oberweis of Vault JS Research.
This article and the report describe a documented court record. Neither is legal advice.
Recent Posts
Four Takeaways From Our Conversation With CalPrivacy’s Tom Kemp
CalPrivacy Executive Director Tom Kemp on vendor validation, GPC enforcement sweeps, cross-device opt-outs, and reading settlements as guidance.
Read More
Show Your Work: Privacy’s Shift to Continuous Assurance
Regulators are shifting from "do the work" to "show your work." In a recap of our webinar with PwC's Jake Meek, this blog discusses the...
Read More
Configured Isn’t Compliant: Why Privacy Setup Alone Won’t Hold Up in 2026
In 2026, regulators test whether your privacy setup actually enforces consent. This blog recaps the webinar with Josh Manion and Richy Glassberg, CEO of Safeguard...
Read More