A demand letter shows up. It cites a law from 1967. It claims your website's chat widget, or maybe just Google Analytics, amounts to illegal wiretapping. It asks for up to $50,000.
That's not a scam email you can delete. It's a real legal theory, it's being filed by the hundreds against California businesses right now, and real estate websites are squarely in the crosshairs.
This isn't an obscure corner of privacy law anymore. It's an active, well-funded litigation strategy, and it's specifically found its way into an industry that's built its entire lead-generation model around exactly the tools now being targeted.

What CIPA Actually Is, and Why It's Suddenly Everywhere
The California Invasion of Privacy Act was written in 1967 to stop illegal phone tapping. Long before websites existed, the law's pen register and trap and trace provisions were designed to catch someone secretly recording a phone call or intercepting call routing data.
Plaintiff's attorneys have repurposed those same provisions to argue that common website technology, analytics scripts, chat widgets, session recording tools, amounts to the same kind of unauthorized interception. The argument is that a visitor's activity on your site, their clicks, their mouse movement, their chat messages, gets captured and shared with a third-party vendor without proper consent, which the plaintiff claims is legally equivalent to someone secretly listening in on a call.
Whether that theory should hold up is genuinely contested right now. As of August 2026, one tracker following documented CIPA website cases counts 46 lawsuits with more than $153 million in disclosed settlements. The legal ground underneath all of it is anything but settled.
What makes CIPA different from the privacy laws most agents already think about, like the California Consumer Privacy Act, is the penalty structure and the plaintiff's bar behind it. CCPA compliance is largely about disclosure and opt-out mechanisms, and enforcement runs primarily through the state attorney general. CIPA carries a private right of action with statutory damages attached, which means any individual, not a regulator, can file a claim and collect. That difference is exactly why CIPA has become the more aggressively litigated of the two, even though it predates the modern internet by decades.
The Real Estate-Specific Wake-Up Call
This stopped being an abstract industry risk in July 2026, when it hit real estate directly. Lofty, a proptech platform serving more than 91,000 real estate professionals and roughly 30,000 hosted websites, received a CIPA demand letter of its own over its standard analytics tools.
Rather than settle quietly, Lofty filed a lawsuit on July 8, 2026, against Vivek Shah, a self-represented litigant who has reportedly filed more than a thousand similar suits across California, asking a federal court to declare that Lofty's standard analytics implementation doesn't violate CIPA. The next day, Lofty launched a CIPA Defense Program, offering existing customers a free legal review and defense against demand letters tied to Lofty's standard platform tools.
That's a notable move. A vendor stepping in to fight a legal theory on behalf of its customers isn't common, and it tells you how seriously the proptech side of the industry is taking this. It also tells you the letters are real. Real estate brokerages nationwide, not just in California, have been receiving templated demand letters over tools as ordinary as Google Analytics 4 and HubSpot, tools that are effectively industry standard on agent and brokerage websites.
Real Estate News covered the Lofty situation directly, noting that Zillow and Redfin faced nearly identical CIPA suits from the same plaintiff back in 2024 over tracking pixels, both of which were eventually dismissed voluntarily. That history matters. It suggests these claims can be beaten, but only after real legal effort, not by ignoring the letter and hoping it goes away.

What Tools Are Actually Getting Targeted
The pattern across documented cases is consistent. Three categories of technology show up again and again: session-replay tools that record mouse movement, clicks, and form input for user experience analysis, advertising and analytics pixels like Meta Pixel and Google Analytics, and live chat widgets, especially ones that log or store conversation transcripts.
AI chatbots have become a newer target. If a chatbot vendor logs, stores, or trains on a visitor's conversation, plaintiffs are arguing the website operator "aided" an unconsented interception of that conversation. For real estate specifically, that's a direct hit. Chat widgets and AI-powered lead capture bots are common on IDX-powered agent websites precisely because they're effective at converting visitors into leads. The same feature driving your lead flow is the one drawing legal attention right now.
It's worth being precise about scope here. This isn't about whether these tools are illegal in some general sense. It's about whether they were deployed in a way that captured visitor activity before the visitor gave clear consent. The technical fix, in most cases, comes down to consent timing and disclosure, not ripping the tools out entirely.
Check your own site against this list honestly. If you're running any of the popular lead capture and marketing tools most agents use, there's a real chance at least one of them falls into a category that's already been named in a demand letter somewhere.
The Legal Ground Is Genuinely Unstable Right Now
Here's what makes this different from a straightforward compliance checklist. The courts themselves haven't settled the underlying question yet.
On June 26, 2026, a federal judge approved a $3.85 million class action settlement against the Los Angeles Times over tracking pixels. Three weeks earlier, a California state court dismissed a nearly identical claim with prejudice. Two courts, two opposite outcomes, on essentially the same legal theory. The Second and Sixth District Courts of Appeal are expected to issue the first appellate rulings on whether CIPA even reaches website tracking technology at all, and until that happens, the legal environment stays genuinely unpredictable.
There's also a legislative fix in motion. California SB 690 has been introduced specifically to close the loophole that's turned CIPA into what critics describe as a cottage industry of website litigation. Whether it passes, and when, is still an open question. Until it does, or until the appellate courts weigh in, the demand letters keep coming regardless of how the underlying legal theory eventually shakes out.

What Settlement Demands Actually Look Like
Demand letters in this category typically ask for up to $50,000. Actual settlements have tended to run lower, commonly between $5,000 and $15,000, according to reporting on the pattern across multiple cases. That's still a meaningful hit for a solo agent or small team, and it doesn't account for the time and legal fees involved in responding even when a claim eventually gets dismissed.
CIPA carries statutory damages of $5,000 per violation, which is part of what makes the threat credible enough that businesses settle rather than fight, even when they believe the underlying claim is weak. Nearly 2,000 CIPA cases were filed in California state courts between 2023 and 2026, with a small handful of law firms responsible for the majority of filings since 2024. This has the structure of a volume-based legal strategy, not isolated individual complaints. HousingWire's proptech coverage has been tracking how brokerage consolidation and shared technology platforms are reshaping legal exposure industry-wide, and CIPA is a clear example of a risk that scales with how many agents share the same underlying website infrastructure.
What to Actually Do If Your Website Runs These Tools
Start by knowing what's actually running on your site. If you're on a platform like Lofty, BoldTrail, or a similar all-in-one system, ask your provider directly whether they have any defense program or compliance guidance specific to CIPA. Some vendors are actively responding to this the way Lofty has. Others haven't said anything yet, which is worth knowing before you assume you're covered.
If you've built your own site or added third-party tools beyond what your platform provides, session replay software, a standalone chat widget, a custom AI chatbot, those additions typically fall outside any vendor's standard defense coverage. That's exactly the kind of gap worth auditing directly rather than assuming someone else's compliance program extends to cover it.
Review your cookie consent and disclosure setup. A lot of the legal exposure here traces back to timing, whether tracking tools fire before a visitor has given any indication of consent. If your site doesn't have a clear consent banner or if your tools load immediately on page visit regardless of consent status, that's the specific gap plaintiff's firms are built to find.
If you receive an actual demand letter, don't respond on your own and don't ignore it either. This sits in the same category as ADA website accessibility demand letters, a legal risk tied directly to your website's technical setup rather than anything about how you conduct business day to day, and it deserves the same seriousness. Loop in your broker or your errors and omissions coverage, and talk to an attorney who's actually handled a CIPA claim before deciding how to respond. The California DRE doesn't regulate CIPA directly, but a brokerage-wide legal exposure like this is exactly the kind of thing worth raising at your next office meeting rather than letting individual agents discover it one demand letter at a time.
The Broader Pattern Worth Watching
This is part of a wider trend of decades-old statutes getting reinterpreted for modern website technology, and real estate keeps showing up as a target because agent and brokerage sites are full of exactly the interactive features, chat, forms, IDX search, that these legal theories are built around. It's not that real estate is doing anything unusual. It's that the industry's websites are unusually feature-rich compared to a typical small business site, which means more potential surface area for a claim.
If your website has been sitting untouched for a year or more while you focus on transactions and leads, this is a good prompt to actually look at what's running on it. Not just for CIPA specifically, but as a general practice. A transaction coordinator catches deadline and disclosure gaps on the file side. Nobody's doing the equivalent audit on your website unless you're the one doing it, or paying someone to.
Pull up your website today and check what's actually loading before a visitor clicks anything. If you don't know the answer, that's the first thing to find out.


