The short answer
Don't reply in a hurry, and don't rip things off your site before you've recorded what was there. Forward the letter to a lawyer, capture what your site sends today, then fix what's actually wrong. Most letters rely on screenshots of trackers firing before anyone agreed, so that's what to look at first.
Why so many of these letters exist
In the US, a large share of these letters cite California's Invasion of Privacy Act. The argument is that a pixel or session recorder sending visitor data to a third party is a kind of wiretap unless the visitor agreed first. Law firms that track this report hundreds to thousands of claims filed in 2025, with statutory damages of up to $5,000 per violation cited in many of them.
In Europe the pressure comes from regulators instead. In September 2025, France's regulator fined Google €325 million and SHEIN €150 million for setting cookies before consent and not honouring "Reject all".
Either way, the evidence is usually the same: a screenshot of your site's network requests, taken on a first visit, showing trackers firing before any choice.
Week one: what to do, in order
1. Don't reply, and don't pay, yet
Letters often set short deadlines. That's pressure, not law. A lawyer can tell you whether the deadline means anything. Some letters are opportunistic, and some are phishing, so don't click links in them either.
2. Preserve what your site looks like today
Before anyone changes anything, capture the current state. Your lawyer may need it, and "we quietly changed it the next day" is a poor look.
- Save the page source of your homepage and checkout.
- Record a first visit in a private window with the browser's network panel open, and export it (a HAR file).
- Export your Tag Manager container: Admin, Export Container.
- Note which consent tool you use, if any, and its settings.
3. See what your site actually sends before anyone agrees
This is the heart of most claims, so find out for yourself. Open your site in a private window, don't click the banner, and list every third-party domain that receives a request. Look especially for:
facebook.comorconnect.facebook.net(Meta Pixel)analytics.tiktok.comstatic.hotjar.comor other session recordersgoogleads.g.doubleclick.netwith consent granted- Chat widgets that load before consent
A free scan can do this for you: tools like ours open the site once as a new visitor, click nothing, and name every tracker it contacted.
4. Forward everything to a lawyer
Send the letter, your captures, and a short plain description of your setup: platform, consent tool, who manages Tag Manager. That's usually enough for a first conversation.
What to fix, once a lawyer has seen it
These are the usual gaps. Fixing them is sensible regardless of the letter.
| Gap | Fix |
|---|---|
| Pixels fire on page load before any choice | Hold them until consent where the law asks first, and until opt-out elsewhere |
| No way for US visitors to opt out | A visible "Your privacy choices" link that actually stops the tags |
| The browser privacy signal (GPC) is ignored | Treat it as an opt-out, before anything fires |
| Reject is hidden or harder than Accept | Same size, same colour, on the first screen |
| No record of what visitors chose | Keep a record per visitor, with the wording they saw |
| Trackers pasted into your theme, not Tag Manager | Find them and hold them too; they are the easiest to miss |
What a consent record helps with
A good record doesn't make a claim go away, but it answers the questions that come next. What did this visitor see? What did they choose? When? Which version of the banner was live? A record that holds the wording, the choice, the time and the region, without storing the visitor's IP address, gives you and your lawyer facts instead of guesses.
After it's fixed: keep checking
The Todd Snyder case in California is a useful warning. The regulator fined the company partly because its opt-out tool was misconfigured for 40 days and nobody noticed. A banner that worked on launch day can break when a developer adds a new script or a plugin updates.
How TagSentry helps
TagSentry holds the trackers it finds until each visitor's rules allow them, including pixels pasted outside Tag Manager, honours GPC, and keeps a consent record for 24 months with no IP address or browser details. Our free scan shows what your site sends before anyone agrees, with no account needed.
Sources
- Shumaker: Your website may be a lawsuit waiting to happen
- Revision Legal: CIPA website tracking demand letters
- Loeb & Loeb: The millisecond problem, pre-consent tracking and CIPA
- Sidley: California's SB 690 clears the Legislature
- CNIL: SHEIN fined 150 million euros over cookies
- CPPA: Todd Snyder enforcement announcement