# Got a cookie demand letter? Read this first

A checklist for the week a privacy demand letter arrives: what not to do, what to gather, how to see what your site really sends, and what to fix after.

_The TagSentry team · September 25, 2026 · https://tagsentry.ai/blog/got-a-cookie-demand-letter_

> **The short answer:** Don't reply in a hurry, and don't rip things off your site before you've recorded what was there. Forward the letter to a lawyer, capture what your site sends today, then fix what's wrong. Most letters rest on screenshots of trackers firing before anyone agreed, so look at that first.

> **Not legal advice** We build consent software. We aren't your lawyers. This is a checklist of what to gather and look at. Anything about your response, your liability or a settlement is a conversation for a lawyer who has read your letter.

## Why so many of these letters exist

In the US, a large share of these letters cite California's Invasion of Privacy Act. The argument is that a pixel or session recorder sending visitor data to a third party is a kind of wiretap unless the visitor agreed first.

Law firms that track this report hundreds to thousands of claims filed in 2025. Many of them cite statutory damages of up to $5,000 per violation.

In Europe the pressure comes from regulators instead. In September 2025, France's regulator fined Google €325 million and SHEIN €150 million for setting cookies before consent and not honouring "Reject all".

On both sides of the Atlantic the evidence tends to be the same: a screenshot of your site's network requests, taken on a first visit, with trackers firing before any choice.

## Week one: what to do, in order

### 1. Don't reply, and don't pay, yet

Letters often set short deadlines to push you. A lawyer can tell you whether the deadline means anything legally. Some letters are opportunistic and some are phishing, so don't click the links in them either.

### 2. Preserve what your site looks like today

Capture the current state before anyone changes anything. Your lawyer may need it, and "we quietly changed it the next day" doesn't look good.

- Save the page source of your homepage and checkout.
- Record a first visit in a private window with the browser's network panel open, and export it (a HAR file).
- Export your Tag Manager container: Admin, Export Container.
- Note which consent tool you use, if any, and its settings.

### 3. See what your site actually sends before anyone agrees

Most claims turn on this, so find out for yourself. Open your site in a private window, don't click the banner, and list every third-party domain that receives a request. Look especially for:

- `facebook.com` or `connect.facebook.net` (Meta Pixel)
- `analytics.tiktok.com`
- `static.hotjar.com` or other session recorders
- `googleads.g.doubleclick.net` with consent granted
- Chat widgets that load before consent

A free scan can do this for you: tools like ours open the site once as a new visitor, click nothing, and name every tracker it contacted.

### 4. Forward everything to a lawyer

Send the letter, your captures and a short plain description of your setup (platform, consent tool, who manages Tag Manager). That's usually enough for a first conversation.

## What to fix, once a lawyer has seen it

These are the usual gaps, and they're worth fixing whatever happens with the letter.

| Gap | Fix |
|---|---|
| Pixels fire on page load before any choice | Hold them until consent where the law asks first, and until opt-out elsewhere |
| [No way for US visitors to opt out](/blog/do-i-need-a-cookie-banner-us) | A visible "Your privacy choices" link that actually stops the tags |
| The [browser privacy signal (GPC)](/blog/global-privacy-control-explained) is ignored | Treat it as an opt-out, before anything fires |
| Reject is hidden or harder than Accept | Same size, same colour, on the first screen |
| No record of what visitors chose | Keep a record per visitor, with the wording they saw |
| Trackers pasted into your theme, not Tag Manager | Find them and hold them too. They're the easiest ones to miss |

## What a consent record helps with

A good record won't make a claim go away, but it answers the questions that come next. What did this visitor see, what did they choose and when, and which version of the banner was live?

If the record holds the wording, the choice, the time and the region, without the visitor's IP address, you and your lawyer have facts to work from instead of guesses.

## After it's fixed: keep checking

In the Todd Snyder case in California, the regulator fined the company partly because its opt-out tool was misconfigured for 40 days and nobody noticed. A banner that worked on launch day can break when a developer adds a new script or a plugin updates.

## How TagSentry helps

TagSentry [holds the trackers it finds](/consent) until each visitor's rules allow them, pixels pasted outside Tag Manager included. It honours GPC and keeps a [consent record](/trust) for 24 months with no IP address or browser details. Our free scan shows what your site sends before anyone agrees, and you don't need an account.

## Sources

- [Shumaker: Your website may be a lawsuit waiting to happen](https://www.shumaker.com/insight/client-alert-your-website-may-be-a-lawsuit-waiting-to-happen-the-cipa-demand-letters-flooding-businesses/)
- [Revision Legal: CIPA website tracking demand letters](https://revisionlegal.com/corporate/revision-legal/cipa-website-tracking-demand-letter/)
- [Loeb & Loeb: The millisecond problem, pre-consent tracking and CIPA](https://www.loeb.com/en/insights/publications/2026/04/the-millisecond-problem-how-pre-consent-tracking-is-driving-cipa-lawsuits-in-2026)
- [Sidley: California's SB 690 clears the Legislature](https://www.sidley.com/en/insights/newsupdates/2026/09/californias-sb-690-clears-the-legislature-what-it-means-for-cipa-website-tracking-claims)
- [CNIL: SHEIN fined 150 million euros over cookies](https://www.cnil.fr/en/cookies-placed-without-consent-shein-fined-150-million-euros-cnil)
- [CPPA: Todd Snyder enforcement announcement](https://cppa.ca.gov/announcements/2025/20250506.html)
