CIPA Website-Tracking Claims: Defending the Demand Letter and Fixing the Website

James D. Snyder
James D. Snyder
Klinedinst PC

James D. Snyder is the Managing Shareholder of Klinedinst PC’s San Diego office, where he serves as Chair of the firm’s Transactional Practice Group and Co-Chair of its Artificial Intelligence (AI) Group. His practice centers on business transactions, mergers and acquisitions, and data privacy and security, and he is regularly engaged as an outside general counsel by emerging startups and established companies alike.

Lori S. Ross
Lori S. Ross
Outside General Counsel LLP

Lori S. Ross is a Partner with OGC with over 25 years of experience advising companies on data privacy, AI governance, and commercial contracts, including SaaS/IaaS agreements and licensing for clients ranging from startups to Fortune 100 companies giving her a practical, business-first approach to structuring deals that manage risk while enabling growth. She holds the AIGP, CIPP/U.S., CIPP/E, and CIPM and FIP designations from the IAPP and is admitted to practice in California, Colorado, and D.C.

Live Video-Broadcast: September 17, 2026

2 hour CLE

Tuition: $195.00
Subscribe to Federal Bar Association CLE Pass...
Co-Sponsored by myLawCLE
Get this course, plus over 1,000+ of live webinars.
Learn More
Training 5 or more people?

Sign-up for a law firm subscription plan and each attorney in the firm receives free access to all CLE Programs

Program Summary

A consent banner alone may not be enough — and a pre-load banner can destroy the defense

Plaintiffs’ firms are recasting the California Invasion of Privacy Act as a weapon against everyday website tools. Session-replay software, chat widgets, analytics tools, and advertising pixels now draw wiretap and pen register claims. Demand letters arrive before any lawsuit, and SB 690’s proposed fix remains unenacted.

The stakes compound quickly. Let a tracking tool transmit before opt-in, and the consent banner may not be enough. Deploy a pre-load banner, and it can destroy the defense rather than support it. Miss the Ninth Circuit’s party exception or § 638.51’s scope, and pleading-stage defenses slip away. Choose the wrong forum, and a removable case stays in state court.

This program is built around work product, not doctrine. Attendees leave with a concrete framework for evaluating CIPA exposure, demand letters, forum selection, and settlement strategy — plus a practical website tracking audit checklist and a remediation guide covering consent configuration, server-side tagging, and vendor contract protections. These are judgment-driven tools, applied client-by-client, that no automated summary can substitute for.

Key topics to be discussed:

  • Demand Letter Triage
    Separate a legally viable CIPA demand letter from a shakedown and evaluate the client’s consent banner and website tracking activities against the plaintiff’s allegations.
  • Defenses and Forum Strategy
    Decide when the Ninth Circuit’s party exception ends the wiretap claim, spot the pleading workarounds plaintiffs are using, and choose between removal to federal court and state court.
  • Settlement and SB 690
    Counsel clients on key settlement elements and on SB 690 while it remains unenacted — remediating under current law, never presenting proposed relief as an existing defense.
  • Risk-Tiering Tracking Tools
    Identify and risk-tier session replay, chat widgets, analytics tools, and advertising pixels using actual data flows, timing, recipient, and page context.
  • Consent Architecture
    Configure consent platforms so nonessential transmissions are blocked before opt-in, with server-side tagging and data minimization used where appropriate.
  • Sustaining Remediation
    Sustain remediation through vendor contracts, release controls, recurring testing, documented ownership, and legislative monitoring.

This course is co-sponsored with myLawCLE.

Date / Time: September 17, 2026

  • 1:00 pm – 3:10 pm Eastern
  • 12:00 pm – 2:10 pm Central
  • 11:00 am – 1:10 pm Mountain
  • 10:00 am – 12:10 pm Pacific

Closed-captioning available

Speakers

James D. Snyder, Managing Shareholder | Klinedinst PC

James D. Snyder is the Managing Shareholder of Klinedinst PC’s San Diego office, where he serves as Chair of the firm’s Transactional Practice Group and Co-Chair of its Artificial Intelligence (AI) Group. His practice centers on business transactions, mergers and acquisitions, and data privacy and security, and he is regularly engaged as an outside general counsel by emerging startups and established companies alike.

  • Education & Credentials

Mr. Snyder earned his J.D. from California Western School of Law and his B.A. from the University of California, Santa Barbara. He is admitted to practice in California and before the U.S. District Court for the Southern District of California.

  • Recognition & Leadership

Mr. Snyder is recognized in Legal 500’s City Elite Series for Corporate and M&A (2026) and received the John D. Klinedinst Entrepreneurial Spirit Award (2023). At Klinedinst, he leads as Managing Shareholder of the San Diego office, Chair of the Transactional Practice Group, and Co-Chair of the AI Group.

  • Professional Involvement

Appointed in 2020 to the USLAW NETWORK Data Privacy and Security Practice Group, Mr. Snyder serves as its Educational Coordinator. He is a member of the International Association of Privacy Professionals (IAPP) and the San Diego County Bar Association, and mentors through Ignite at the University of California, San Diego.

  • Experience

Mr. Snyder has counseled clients at the leading edge of data privacy, advising on the EU’s General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), negotiating data processing agreements with major auto manufacturers, and building GDPR-compliant processes for international connected and autonomous car connectivity providers. He previously served as Chief Legal and Compliance Executive of a software development testing company, where he helped grow annual revenue from $10 million to more than $100 million in approximately three years and led the company’s $375 million acquisition by a publicly held international technology company. His work spans commercial SaaS, financial services, licensing, and professional services contracts, along with export and open-source software compliance.

 

Lori S. Ross, Partner | Outside General Counsel LLP

Lori S. Ross is a Partner with OGC with over 25 years of experience advising companies on data privacy, AI governance, and commercial contracts, including SaaS/IaaS agreements and licensing for clients ranging from startups to Fortune 100 companies giving her a practical, business-first approach to structuring deals that manage risk while enabling growth. She holds the AIGP, CIPP/U.S., CIPP/E, and CIPM and FIP designations from the IAPP and is admitted to practice in California, Colorado, and D.C.

  • Education & Credentials

Ms. Ross earned her J.D. from UCLA Law School, an LL.M. from University College London, where she was a Bentham Scholar, and her B.A. from the University of California, Berkeley. She is admitted to the bars of California, Colorado, and the District of Columbia.

  • Recognition & Leadership

Ms. Ross was named a Bentham Scholar at University College London, and her career includes senior legal leadership posts as Vice President of Legal and Business Affairs at FanDragon Technologies and Chief Legal Officer of Global Mobile Vision in Dublin, Ireland.

  • Professional Involvement

She is a member of the International Association of Privacy Professionals (IAPP) and holds the AIGP, CIPP/US, CIPP/E, and CIPM designations.

  • Experience

Across more than 25 years of practice, Ms. Ross has advised new, emerging, and established technology, manufacturing, pharmaceutical, and media companies, with broad experience counseling SaaS and IaaS providers. Her prior roles include Vice President of Legal and Business Affairs at FanDragon Technologies, Chief Legal Officer of Global Mobile Vision in Dublin, Ireland, legal consultant through Lori S. Ross, LLC, and attorney with Paige & Co. in London, England. She speaks fluent French and has lived and worked on three continents.

Agenda

SESSION 1 – Defending CIPA Web-Tracking Demand Letters and Wiretap Lawsuits | 1:00pm – 2:00pm ET

This session equips defense counsel to respond to California Invasion of Privacy Act demand letters and defend wiretap and pen register lawsuits arising from website tracking technologies. Attorneys will learn how to evaluate your client’s potential exposure, the current circuit-level authority, strategies for defenses, forum selection strategies, key elements for settlements and the status of SB 690’s attempt to unwind CIPA issues for California businesses. Attendees leave with a concrete framework for evaluating client’s CIPA exposure, CIPA demand letters, forum selection, procedural defenses, as well as settlement and client triage strategies.

BREAK | 2:00pm – 2:10pm ET

SESSION 2 – Auditing and Fixing Website Tracking Before the Next CIPA Letter | 2:10pm – 3:10pm ET

In this session, I will walk attorneys through how to evaluate a client’s website for potential CIPA exposure before a demand letter arrives. I will explain how to identify the tracking technologies operating on a website, determine what information they collect and transmit, and prioritize the tools that present the greatest litigation risk. We will look closely at session-replay software, chat widgets, analytics tools, and advertising pixels, as well as why simply displaying a consent banner may not be enough if those technologies begin transmitting information before the user opts in. I will also discuss how consent platforms should be configured, how server-side tagging and data minimization can reduce exposure, and what protections should be included in vendor contracts. Finally, I will cover how attorneys should counsel clients regarding SB 690 while it remains unenacted and what ongoing testing and monitoring should occur after remediation. Attendees will leave with a practical audit checklist and remediation framework they can use with their own clients.

Credits

Alaska

Approved for CLE Credits
2 General

Our programs are CLE-eligible through Alaska’s recognition of multi-jurisdictional reciprocity.
Alabama

Pending CLE Approval
2 General

Arkansas

Approved for CLE Credits
2 General

Arizona

Approved for CLE Credits
2 General

California

Approved for CLE Credits
2 General

Colorado

Pending CLE Approval
2 General

Connecticut

Approved for CLE Credits
2 General

District of Columbia

No MCLE Required
2 CLE Hour(s)

Delaware

Pending CLE Approval
2 General

Florida

Approved via Attorney Submission
2 General Hours

Receive CLE credit in Florida via attorney submission.
Georgia

Pending CLE Approval
2 General

Hawaii

Approved for CLE Credits
2 General

Iowa

Pending CLE Approval
2 General

Idaho

Pending CLE Approval
2 General

Illinois

Pending CLE Approval
2 General

Indiana

Pending CLE Approval
2 General

Kansas

Pending CLE Approval
2 Substantive

Kentucky

Pending CLE Approval
2 General

Louisiana

Pending CLE Approval
2 General

Massachusetts

No MCLE Required
2 CLE Hour(s)

Maryland

No MCLE Required
2 CLE Hour(s)

Maine

Pending CLE Approval
2 General

Michigan

No MCLE Required
2 CLE Hour(s)

Minnesota

Pending CLE Approval
2 General

Missouri

Approved for CLE Credits
2.4 General

Mississippi

Pending CLE Approval
2 General

Montana

Pending CLE Approval
2 General

North Carolina

Pending CLE Approval
2 General

North Dakota

Approved for CLE Credits
2 General

Our programs are CLE-eligible through North Dakota’s recognition of multi-jurisdictional reciprocity. Section 1, Policy 1.14
Nebraska

Pending CLE Approval
2 General

myLawCLE reports attendance to Nebraska on each attorney’s behalf for all programs. Please do not self-report.
New Hampshire

Approved for CLE Credits
120 General minutes

As of July 1, 2014, the NHMCLE Board no longer provides pre- or post-approval of courses. Attendees must self-determine whether a program is eligible for credit, and self-report their attendance online at www.nhbar.org, based on qualification provisions of Rule 53.
New Jersey

Approved for CLE Credits
2.4 General

Our programs are CLE-eligible through New Jersey’s recognition of multi-jurisdictional reciprocity, except for the courses required under BCLE Reg. 201:2
New Mexico

Approved for CLE Credits
2 General

Nevada

Pending CLE Approval
2 General

New York

Approved for CLE Credits
2 General

Our programs are CLE-eligible through New York’s Approved Jurisdiction Group “B”.
Ohio

Pending CLE Approval
2 General

Oklahoma

Pending CLE Approval
2.5 General

Oregon

Pending CLE Approval
2 General

Pennsylvania

Approved for CLE Credits
2 General

Rhode Island

Pending CLE Approval
2.5 General

South Carolina

Pending CLE Approval
2 General

South Dakota

No MCLE Required
2 CLE Hour(s)

Tennessee

Pending CLE Approval
2 General

Texas

Approved for CLE Credits
2 General

Utah

Pending CLE Approval
2 General

Virginia

Not Eligible
2 General Hours

Vermont

Approved for CLE Credits
2 General

Washington

Approved via Attorney Submission
2 Law & Legal Hours

Receive CLE credit in Washington via attorney submission.
Wisconsin

Pending CLE Approval
2 General

West Virginia

Pending CLE Approval
2.4 General

Wyoming

Pending CLE Approval
2 General

More CLE Webinars
Upcoming CLE Webinars
iPad for Lawyers: The Complete Mobile Practice Toolkit
iPad for Lawyers: The Complete Mobile Practice Toolkit Thu, July 23, 2026
On-Demand
Live Replay
State National Security Law and Role Conflicts
State National Security Law and Role Conflicts Thu, July 23, 2026
Live Webcast
The AI Skills Every Attorney Needs: Think, Prompt, Win
The AI Skills Every Attorney Needs: Think, Prompt, Win Thu, July 30, 2026
On-Demand
Live Replay