Member Login | Become a Member

America's Newspapers

  • Industry Research
    • Trust in Media
    • Ad Effectiveness
    • Resource Center
  • News Media D.C. Meeting
    • Senior Leadership Conference
    • Family Owners D.C.
  • Carmage Walls
    • Carmage Walls 2025
  • Election 2026
    • Election Editiorial Coverage
    • Election Advertising Strengths
  • Advocacy Center
    • Advisory on Privacy and CIPA
    • Editorials/Opinions
    • Public Notices
  • Marketing Campaigns
  • Solutions Directory
  • Back to newspapers.org
  • Resource Center
  • SignOn250
  • Industry Research
    • Trust in Media
    • Ad Effectiveness
    • Resource Center
  • News Media D.C. Meeting
    • Senior Leadership Conference
    • Family Owners D.C.
  • Carmage Walls
    • Carmage Walls 2025
  • Election 2026
    • Election Editiorial Coverage
    • Election Advertising Strengths
  • Advocacy Center
    • Advisory on Privacy and CIPA
    • Editorials/Opinions
    • Public Notices
  • Marketing Campaigns
  • Solutions Directory
  • Back to newspapers.org
  • Resource Center
  • SignOn250

Privacy Issues

Privacy Compliance Alert for Publishers


Website privacy compliance has moved from a background legal issue to an immediate operational risk for newspaper organizations.

In just the past week, several members of America’s Newspapers reported being served with notices alleging violations of the California Invasion of Privacy Act (CIPA), with claims seeking $25,000 or more. These actions are not tied to data breaches or misconduct. They are being driven by aggressive interpretations of privacy laws and a growing cottage industry of law firms targeting news organizations over how their websites collect and share user data.

While the current wave of claims is centered on CIPA, the broader concern is larger than California. Multiple states have enacted—or are actively enforcing—new and expanded privacy laws, and more are moving in that direction. Together, these laws are raising expectations around consent, disclosure, and data collection practices nationwide. CIPA is simply where enforcement pressure is showing up first.

The message is direct: this is a publisher responsibility, not an IT function—and no newspaper should assume it is compliant without confirming it.

If your website is accessible in California, you may be exposed regardless of where your business is located or where you market. Cookie banners, consent language, tracking technologies, privacy policies, and third-party tools are all being scrutinized. What was acceptable even a year ago may no longer meet current standards.

The following explains what CIPA is, why newspapers across the country are being targeted, and what steps publishers should take now to reduce risk.

What Every Publisher Should Do Now


​Every publisher should take the following steps promptly:

​
• Review your website’s cookie banner to ensure clear, affirmative consent before tracking begins

• Confirm that users can reject tracking—not just acknowledge it

• Audit third-party tools embedded on your site, including analytics, chat, advertising, and session replay software

• Ensure your privacy policy accurately reflects current data collection and sharing practices

• Verify that consent language and disclosures are consistent across banners, policies, and terms of use

• Do not assume vendor defaults equal compliance—confirm it

​• Involve legal counsel early, before a claim is filed
If you have been served with a suit or have questions about litigation or privacy requirements, contact Dean Ridings at [email protected]
​What Is CIPA—and Why Should I Be Concerned Even If I Don’t Do Business in California?
The California Invasion of Privacy Act (CIPA), codified at California Penal Code §§ 630–638, was originally enacted to protect individuals from the unauthorized interception or recording of confidential communications, such as phone calls, without the consent of all parties.
What has changed is how the law is being applied.

Courts have increasingly interpreted CIPA to apply to websites that track user behavior without proper notice and consent. Certain website technologies—such as session replay tools, chat features, and tracking scripts—are now being treated as potential “interceptions” of user communications. Unlike many earlier privacy frameworks, CIPA does not always require proof of actual harm, which makes it particularly attractive to plaintiffs.

This expanded interpretation is why newspaper websites are now being targeted.  In the past week alone, three members of America’s Newspapers have reported being served with notices of violation of CIPA laws, with claims for $25,000 or more. There is a growing cottage industry of law firms and individuals using CIPA laws to extract payments from news organizations.
 
What Is a CIPA Claim?
A CIPA claim refers to a legal claim brought under the California Invasion of Privacy Act alleging the unauthorized interception, recording, or monitoring of a confidential communication.
While the statute was once primarily associated with recorded phone calls, it is now being used to challenge how websites collect and transmit user data—often through technologies users never see.
 
Common Contexts for CIPA Claims—and Why They Matter
In recent years, CIPA claims have most frequently arisen in the following situations:
  •  Website technologies such as session replay tools, chat widgets, or tracking software alleged to capture user communications or keystrokes.
  •  Third-party vendors allegedly receiving user data without proper consent.

In the cases reported by America’s Newspapers members, all complaints have been based on newspaper websites containing alleged “hidden trackers” that obtained user information without the user’s consent.
 
 
Remedies and Exposure
CIPA is considered one of the most plaintiff-friendly privacy statutes in the United States. It allows for:
  • Statutory damages (often $5,000 per violation)
  • Injunctive relief
  • Attorneys’ fees
  • Potential class-action exposure, which can dramatically increase liability

Importantly, violations do not always require proof of actual harm. Even if your business is located outside California and you do not intentionally market to Californians, your website may still be found in violation of CIPA laws and you could be held liable.
 
How Do I Make My Newspaper’s Website Compliant With CIPA?
First, you must inform visitors to your website that you use cookies and other similar tracking devices and give them the option to accept or reject your collection of their data before they enter your website. There are several companies that can assist with this, including:
  • CookieYes
  • OneTrust
Additionally, if you have an arbitration provision, choice-of-law provision, or other terms in your Terms of Use, you should link those terms within the cookie banner.  You will also need a updated privacy policy. 
 
What Should I Do If I Receive a CIPA Claim?
First, seek counsel from an attorney experienced in CIPA litigation. These claims move quickly, and early decisions can materially affect outcomes.

If you have been served with a suit, have questions about litigation, do not have legal representation or have general questions about privacy issues related to your organization, contact America’s Newspapers for guidance. 

​The enforcement environment has changed. Waiting to address privacy compliance after a demand letter arrives is no longer a viable strategy.
 Copyright America's Newspapers.  All Rights Reserved.
America's Newspapers is incorporated in the District of Columbia and its staff works remotely.
Our mailing address for dues and memberships is 2615 Centennial Blvd., Suite 200, Tallahassee, FL 32308-0592
Phone: (847) 282-9850 | contact our staff | sitemap


Privacy Policy
Cookie Policy