Media Center

Threatened litigation letters hit Pennsylvania business owners: What businesses should know

August 12, 2026
Publications

A serial pro se litigant, Vivek Shah, has sent demand letters threatening litigation to thousands of businesses across the country, alleging violations of the California Invasion of Privacy Act (CIPA). If your business has received one of these letters, here is what you need to know.

Key takeaways:

  • CIPA, originally enacted to regulate wiretapping, is now being applied to website tracking technologies such as cookies and analytics tools.
  • Shah and other “privacy advocates” claim websites violate CIPA by collecting user data (such as IP addresses) without consent.
  • A federal judge declared Shah a vexatious litigant, limiting his ability to file CIPA lawsuits in the Central District of California.
  • Businesses receiving demand letters should not dismiss them outright and should contact legal counsel before responding.

Understanding CIPA and the demand letters

In this digital era, almost every business has an online presence. As a result, data privacy compliance is rapidly evolving, and new litigation trends require businesses to remain diligent in reviewing and revising their data privacy policies.

Shah’s letters claim an action under CIPA. Enacted in 1967, the law prohibits anyone without an approved court order from installing a pen register or a trap-and-trace device on a line of communication to record outgoing or incoming phone calls.

While CIPA was enacted in the era of landline phones and fax machines, plaintiffs like Shah now allege that websites that use tracking technologies (e.g., cookies, tags, analytics tools) have installed unlawful pen registers under the law. Shah specifically claims that websites collect user information, such as an IP address, via tracking technologies at the moment website visitors first access the website, without obtaining users’ informed consent, thus violating CIPA.

A court’s response to Vivek Shah’s pattern of repetitive filing

Recently, Shah’s filings caught the attention of Judge R. Gary Klausner of the U.S. District Court for the Central District of California. Since late 2021, Shah has filed at least 29 lawsuits against an array of companies. At first glance, these filings seemed commonplace, as hundreds of CIPA lawsuits have been filed over the last few years. However, Judge Klausner noticed a concerning pattern. Shah would file the complaint, the company would file a motion to dismiss, and right before the judge could rule on the merits, Shah would withdraw the case. In response to this repetitive pattern, the judge declared Vivek Shah a vexatious litigant. Meaning that, now, in the Central District of California, Shah cannot file a new CIPA or related data privacy lawsuit without a judge first approving the filing. Unsurprisingly, Shah has since appealed the order to challenge his vexatious status, and the appeal awaits review.

In the meantime, this ruling does not bar Shah from sending demand letters or filing in California state courts or other federal districts, nor does it provide an automatic ruling on the merits of CIPA claims. It only restricts Shah from making unauthorized repetitive filings of CIPA or other related digital privacy claims in the Central District of California.

What should my business do if it receives a letter?

Shah is not the only individual sending these demand letters. Other self-proclaimed “privacy advocates” have been filing similar claims across the U.S. However, if you have received a letter asserting CIPA violations, you should not automatically dismiss it as a scam. Depending on the circumstances, these claims may have viability as case law develops. Although receiving one of these letters can be concerning, taking proactive steps can help protect your business.

Before responding to the demands, your business should contact legal counsel to determine the best course of action. Legal counsel can provide your business with guidance, which may include updating external website policies or further litigation support. McNees’ Data Privacy and Security Group has the experience to assist your business in handling potential CIPA litigation at any stage.

McNees summer associate Alexis Jabara contributed to this article.