A letter arrives at a small Texas company, a clinic, a church or a nonprofit. It says the organization’s own website — its cookie banner, its analytics tag, its chat widget, its search bar — broke a California wiretapping law. It attaches screenshots of the site and, sometimes, a draft lawsuit. It asks for money now. On September 17, 2026, the Office of the Texas Attorney General issued a consumer alert about a surge of exactly these letters landing on Texas businesses and nonprofit organizations. Here is what the alert says, what the California statute behind the letters actually is, where a pending California bill stands, and what a Texas lawyer can look at before anyone writes back or sends a payment.
Status as of September 18, 2026. Policy and litigation in this area change quickly; the linked official sources are the current word.
Get a Texas Business Lawyer — Now
A demand letter that arrives with a dollar figure, a deadline and a draft complaint attached is designed to feel urgent. A Texas business attorney can read the letter, look at what the sender is actually claiming, review what is running on the website, and explain what the options are before any money moves. Call or text 24/7. Get connected with an experienced business lawyer near you. If a lawyer in our network offers an initial consultation, it is free. Our referral service is free for the people we serve; the lawyer you hire sets their own fees.
What Changed, and When
On September 17, 2026, the Office of the Attorney General of Texas published a consumer alert advising Texas businesses and nonprofit organizations of what it describes as “a recent surge in demand letters alleging website privacy violations under California law that are being sent to Texas businesses and organizations.”
According to the alert, the letters allege violations of the California Invasion of Privacy Act, commonly shortened to CIPA, and they base those allegations on “common website technologies such as cookies, pixels, analytics tools, and search bars.” The alert states that senders “may claim that these tools constitute unlawful ‘wiretapping’ under California law and demand immediate payment to avoid litigation,” and that the letters “may include screenshots of the recipient entity’s website and a draft complaint.”
The alert also records that demand letters of this type “may exaggerate or misrepresent a potential violation of law,” and it names one example: a serial CIPA plaintiff who, the alert states, has been declared a vexatious litigant and is barred from filing any new action asserting CIPA or related digital privacy claims in the U.S. District Court for the Central District of California without first obtaining that court’s permission.
Nothing in the alert changes Texas law, and nothing in it creates a new obligation for a Texas business. It is a warning about mail that is already arriving.
Who in Texas This Reaches
The alert is addressed to businesses and nonprofit organizations in Texas. It does not limit itself by industry, by company size, or by whether the organization does business in California. In practice, the common thread in the letters described is simply operating a public website that uses ordinary measurement and convenience tools.
That is a very wide net in Texas. A two-person shop in Abilene, a family clinic in McAllen, a parish in Waco, a regional carrier in Lubbock and a nonprofit in Tyler all typically run some combination of an analytics tag, a cookie banner, a chat box, an advertising pixel or a site search field. Law-firm coverage of this wave of letters describes thousands of recipients nationwide since late 2025, across retailers, manufacturers, service providers and technology companies, including many with no obvious connection to California.
Nonprofit and faith organizations are worth naming separately, because the Texas alert names them and because a small nonprofit rarely has in-house counsel to hand a letter like this to.
What This Changes Legally
CIPA is a California statute, originally enacted in 1967 as a wiretapping and eavesdropping law. The letters described in the alert generally reach it through its “pen register and trap and trace” provision, California Penal Code section 638.51, on the theory that website tracking technology collects routing or addressing information about a visitor. Published law-firm analyses of this letter wave, such as the Tucker Ellis alert, note that senders often point to statutory damages of up to $5,000 per claimed violation, which is what produces the large numbers that appear in the letters.
Whether any particular letter states a real claim, and whether a California statute reaches a particular Texas organization at all, are legal questions that turn on the specific facts — the statute, the website, the visitors, and the forum. This page does not answer them, and a demand letter is not a court finding.
One development in California is worth knowing as a fact, because it is moving. On August 28, 2026, the California Legislature passed Senate Bill 690, which as passed would amend California Penal Code section 637.2 so that a claim against a private actor under section 638.51 arising from activity on a website or application could be brought only by the California Attorney General. Law-firm summaries, including Sidley’s and Fenwick’s, report that the Governor of California has until September 30, 2026 to act on the bill, that it would become operative January 1, 2027 if it becomes law, and that it is written to reach pending claims in actions commenced within two years before that operative date. As of the date on this page the bill has not been signed. It is reported here as pending legislation, with no position taken on it.
What Kind of Option Might Apply
The Attorney General’s alert sets out what it calls steps an entity receiving such a letter “should consider taking.” Quoted from the alert itself, those are: consulting “with legal counsel experienced in privacy and website-tracking litigation before taking action”; reviewing, “with the assistance of counsel,” the website’s use of “pixels, cookies, analytics tools, and similar technologies”; and monitoring “evolving state and federal privacy laws and court decisions regarding website-tracking technologies.” The alert adds that entities “should not respond directly to the sender or provide payment without first consulting qualified legal counsel, if possible.”
The alert also states that a Texas business or organization that receives a CIPA demand letter it believes to be fraudulent, abusive or deceptive may report it to the Attorney General’s Consumer Protection Division, and links its online consumer complaint form. Reporting a letter to the state is a separate matter from deciding how to handle the letter itself; a lawyer can advise on both for a specific organization.
Practically, the kinds of work a Texas business attorney can do here include reading the letter and the draft complaint attached to it, identifying who the sender is and what has happened in their other matters, reviewing what is actually deployed on the website and what consent the site collects, assessing whether a California claim plausibly reaches this organization, and handling any response that goes back. Where the letter itself looks deceptive, a consumer protection attorney can advise on reporting it. None of that can be decided from a web page — it depends on the letter and the site.
Why Acting Quickly Can Matter
Demand letters of this kind typically set their own response window, often a short one, and the Attorney General’s alert describes senders demanding “immediate payment to avoid litigation.” A deadline printed by the sender is not a legal deadline set by a court, but the practical consequence of letting it pass without advice is that the organization has given up the chance to shape what happens next.
There is a second reason timing matters, and it cuts the other way: the California bill described above has dates attached to it, and the legal landscape a letter relies on may not look the same in a few months as it does today. That is a reason to get the letter in front of a lawyer promptly rather than to act on the sender’s urgency.
Talking to a lawyer before responding, paying, or throwing the letter away is the step the Attorney General’s own alert points to, and it is the step that keeps every option open.
Get a Texas Business Lawyer — Now
If a website privacy demand letter has arrived at your business, church or nonprofit, an experienced Texas attorney can read it, check what the sender is claiming, look at what is running on your site, and explain the options before anything is signed or paid. Call or text 24/7. Get connected with an experienced business lawyer near you. Our referral service is free for the people we serve; the lawyer you hire sets their own fees.
Sources
- Office of the Attorney General of Texas, “CONSUMER ALERT: Attorney General Ken Paxton Warns Texans of Scam Demand Letters Alleging Website Privacy Violations” (September 17, 2026) — every quotation above. (Primary document.)
- TCPAWorld, coverage of the Texas alert (September 17, 2026) — independent same-day reporting on the alert.
- Tucker Ellis LLP, “The CIPA Demand Letter Tsunami” — the national scale of the letter wave and the statutory damages figure cited in the letters.
- Sidley Austin LLP, “California’s SB 690 Clears the Legislature” (September 2026) and Fenwick, “California Legislature Passes SB 690” — the August 28, 2026 passage, the September 30 action date, the January 1, 2027 operative date and the two-year reach-back.
- Texas Attorney General, Consumer Protection Division complaint form — the reporting channel named in the alert. (Primary source.)
Find the right Texas lawyer for this: Texas Business Lawyers · Texas Consumer Protection Attorneys · Texas Litigation Attorneys