Over the past year, real estate agents across the country have been receiving demand letters claiming their websites violate a California privacy law written in 1967. If you have heard about this from a colleague, or a letter has landed in your own inbox, here is what is going on.
This post is for general education only. It is not legal advice, and it is not a guarantee about your website or your legal exposure. If you have received a demand letter or a lawsuit, please consult with your attorney.
What is CIPA, and why is it suddenly everywhere?
CIPA is the California Invasion of Privacy Act. California passed it in 1967 to stop wiretapping, back when wiretapping meant someone splicing into a telephone line to listen in on a call. The internet did not exist. Cookies, pixels, and web analytics were decades away. The lawmakers who wrote CIPA were worried about eavesdroppers on phone lines, not websites.
That history matters, because CIPA was never written to govern how a website works. What changed is not the law. What changed is a novel legal theory that a small group of plaintiffs' firms started pushing a few years ago, and that you now see going around everywhere. The theory recasts a 1967 wiretapping statute as a weapon against ordinary website technology. Plaintiffs argue that when a visitor uses a search bar or fills out a contact form, and information reaches a third-party service, that third party "intercepted" a private communication, the way a wiretap intercepts a phone call.
Courts have not agreed with that theory in most cases, which we will come back to below.
Why are real estate agents getting these letters?
Real estate websites are a common target because they tend to run the kinds of tools these claims focus on, like IDX search, contact forms, analytics, and chat widgets. And these are not carefully researched, individualized complaints. They are templated documents produced at scale by a small number of plaintiffs' firms and sent out in bulk to whoever is easy to find.
Zillow and Redfin have both been sued under CIPA over tracking pixels, and the same style of letter is increasingly landing on individual agent and brokerage websites.
The letters are built to feel urgent. They typically demand a settlement within about 30 days and cite $5,000 in statutory damages per violation. That urgency is a negotiating tactic. It is not a measure of how strong the claim is.
Where do the courts stand?
Here is the encouraging part. Courts have routinely dismissed these cases. Many judges who have looked at the theory that a cookie or a pixel is a 1967-style wiretap have thrown out near-identical claims, often at an early stage.
But routine is not the same as settled. There is no controlling appellate decision that closes the door on the theory for good, and some courts have let claims move forward past an initial motion to dismiss. So the law here remains unsettled, and that uncertainty is part of what the firms sending these letters rely on.
California lawmakers have been working on reform, too, though slowly. A bill known as SB 690 has been moving through the legislature. As of mid-2026 it advanced out of committee in an amended form, but the current version is narrower than first proposed, it has not become law, and it would not resolve every version of these claims. It is worth watching, but it is not something to count on today.
How does the Luxury Presence cookie banner help?
Luxury Presence websites include a cookie consent banner as a built-in feature. These demand letters generally center on the same idea: that tracking happened without the visitor's consent. A consent banner speaks to that idea directly, by presenting visitors with clear privacy choices and managing non-essential tracking scripts based on what the visitor chooses.
It is part of the platform, so there is nothing for you to buy, install, or configure. Here is what it does.
It gives visitors clear privacy choices. The banner lets visitors accept or decline non-essential tracking, and it manages non-essential analytics and advertising scripts based on that choice, where the law calls for it.
It adapts to where your visitor is. California visitors see the "Do Not Sell or Share My Personal Information" link that California law expects. Visitors elsewhere in the US see "Your Privacy Choices." International visitors see a consent-first experience aligned with the stricter rules abroad.
It respects browser privacy signals. If a visitor has Global Privacy Control turned on in their browser, the banner is designed to honor it.
It keeps a record. Consent decisions are logged, which can matter if you ever need to show that your site asked for and received consent.
It is maintained as part of the platform. Privacy law moves quickly. We update the banner over time as part of maintaining the platform.
The banner is on by default. If you already run your own consent tool, we aim to detect it and leave it in place, so your visitors do not see two banners. If you would rather manage privacy compliance yourself, you can opt out.
A word of realism: no consent banner, from us or anyone else, can guarantee that you will not receive a demand letter or promise a particular outcome if you do. What a banner can do is help you address the consent issue at the center of these claims.
What other privacy laws should I know about?
CIPA gets the headlines because of the demand letters, but it is not the only privacy law in play.
CCPA and CPRA. The California Consumer Privacy Act, expanded by the California Privacy Rights Act, gives California residents rights over their personal information, including the right to opt out of the sale or sharing of their data. That is where the "Do Not Sell or Share" link comes from. Worth knowing: CCPA compliance on its own does not shield you from CIPA claims. They are different laws with different requirements.
Other state laws. More than a dozen states now have their own consumer privacy laws, and several states have wiretapping statutes that plaintiffs' firms are testing against websites the same way they have tested CIPA.
Global Privacy Control. GPC is a browser setting that broadcasts a visitor's opt-out preference automatically. California treats it as a legally binding opt-out request, which is why honoring it matters.
Does GDPR apply to my real estate business?
It might, and the trigger is simpler than most people expect. GDPR is the European Union's privacy law, and it follows the person, not the business. It applies based on whose data you handle, not where your office sits.
Here is the practical test. Look at your contacts. If you have clients or leads reaching you from European email addresses, if you market to buyers abroad, or if European visitors are browsing your listings, GDPR can reach you. This is common for luxury agents with international clientele. GDPR generally requires consent before non-essential cookies run, which is why international visitors to your Luxury Presence website see the banner before that kind of tracking begins.
If you are not sure whether you have European contacts, it is worth checking. It is an easy thing to look into and an expensive thing to guess wrong about.
Do I need to do anything right now?
If you are a Luxury Presence client, the banner rolls out automatically. We will email you before it goes live on your site, so watch for that message. There is nothing for you to buy, install, or configure.
Beyond that, do the one thing only you can do. If you have questions, reach out. If a letter shows up, if you are not sure whether GDPR touches you, or if you just want to understand what is running on your site, contact us or your attorney. We would much rather hear from you early than after a deadline has passed.
Privacy law will keep changing. We will keep improving the privacy tools we build into the platform, and we are here when you need us.
Ready to grow?
Turn your content into your best lead source
See how Luxury Presence helps agents turn website visits into closed deals