Skip to content
TagSentry
Blog

Guide · Rules and enforcement

Got a cookie demand letter? Read this first

A calm checklist for the week a privacy demand letter arrives: what not to do, what to gather, how to see what your site actually sends, and what to fix.

The TagSentry team · September 25, 2026 · updated October 2, 2026 · 4 min read

The short answer

Don't reply in a hurry, and don't rip things off your site before you've recorded what was there. Forward the letter to a lawyer, capture what your site sends today, then fix what's actually wrong. Most letters rely on screenshots of trackers firing before anyone agreed, so that's what to look at first.

Why so many of these letters exist

In the US, a large share of these letters cite California's Invasion of Privacy Act. The argument is that a pixel or session recorder sending visitor data to a third party is a kind of wiretap unless the visitor agreed first. Law firms that track this report hundreds to thousands of claims filed in 2025, with statutory damages of up to $5,000 per violation cited in many of them.

In Europe the pressure comes from regulators instead. In September 2025, France's regulator fined Google €325 million and SHEIN €150 million for setting cookies before consent and not honouring "Reject all".

Either way, the evidence is usually the same: a screenshot of your site's network requests, taken on a first visit, showing trackers firing before any choice.

Week one: what to do, in order

1. Don't reply, and don't pay, yet

Letters often set short deadlines. That's pressure, not law. A lawyer can tell you whether the deadline means anything. Some letters are opportunistic, and some are phishing, so don't click links in them either.

2. Preserve what your site looks like today

Before anyone changes anything, capture the current state. Your lawyer may need it, and "we quietly changed it the next day" is a poor look.

  • Save the page source of your homepage and checkout.
  • Record a first visit in a private window with the browser's network panel open, and export it (a HAR file).
  • Export your Tag Manager container: Admin, Export Container.
  • Note which consent tool you use, if any, and its settings.

3. See what your site actually sends before anyone agrees

This is the heart of most claims, so find out for yourself. Open your site in a private window, don't click the banner, and list every third-party domain that receives a request. Look especially for:

  • facebook.com or connect.facebook.net (Meta Pixel)
  • analytics.tiktok.com
  • static.hotjar.com or other session recorders
  • googleads.g.doubleclick.net with consent granted
  • Chat widgets that load before consent

A free scan can do this for you: tools like ours open the site once as a new visitor, click nothing, and name every tracker it contacted.

4. Forward everything to a lawyer

Send the letter, your captures, and a short plain description of your setup: platform, consent tool, who manages Tag Manager. That's usually enough for a first conversation.

What to fix, once a lawyer has seen it

These are the usual gaps. Fixing them is sensible regardless of the letter.

GapFix
Pixels fire on page load before any choiceHold them until consent where the law asks first, and until opt-out elsewhere
No way for US visitors to opt outA visible "Your privacy choices" link that actually stops the tags
The browser privacy signal (GPC) is ignoredTreat it as an opt-out, before anything fires
Reject is hidden or harder than AcceptSame size, same colour, on the first screen
No record of what visitors choseKeep a record per visitor, with the wording they saw
Trackers pasted into your theme, not Tag ManagerFind them and hold them too; they are the easiest to miss

A good record doesn't make a claim go away, but it answers the questions that come next. What did this visitor see? What did they choose? When? Which version of the banner was live? A record that holds the wording, the choice, the time and the region, without storing the visitor's IP address, gives you and your lawyer facts instead of guesses.

After it's fixed: keep checking

The Todd Snyder case in California is a useful warning. The regulator fined the company partly because its opt-out tool was misconfigured for 40 days and nobody noticed. A banner that worked on launch day can break when a developer adds a new script or a plugin updates.

How TagSentry helps

TagSentry holds the trackers it finds until each visitor's rules allow them, including pixels pasted outside Tag Manager, honours GPC, and keeps a consent record for 24 months with no IP address or browser details. Our free scan shows what your site sends before anyone agrees, with no account needed.

Sources

  1. Shumaker: Your website may be a lawsuit waiting to happen
  2. Revision Legal: CIPA website tracking demand letters
  3. Loeb & Loeb: The millisecond problem, pre-consent tracking and CIPA
  4. Sidley: California's SB 690 clears the Legislature
  5. CNIL: SHEIN fined 150 million euros over cookies
  6. CPPA: Todd Snyder enforcement announcement