Editor’s note: The “Vivek Shah” referenced in Dan Curry’s column below is not to be confused with the ZiffDavis publisher of a similar name. Searching the internet for the name “Vivek Shah” will return many results for the technology publisher and far fewer for the “former Hollywood actor and current convicted felon.”
Across the country, websites — including yours — often incorporate Google Analytics, ad tracking pixels, social sharing tools or an archive search bar. These can be standard offerings from a web designer or third-party host.
But a law called California’s Invasion of Privacy Act (CIPA) has been weaponized in a large-scale campaign to win quick settlements against website owners — even websites based in Missouri — for using these ubiquitous website features.
CIPA is a Cold War-Era law created in the 1960s that targets telephone wiretapping and the unauthorized use of what is known as pen registers — physical devices that were able to record outgoing telephone numbers for instance. People who violated the law were able to recover up to $5,000 per violation and other penalties.
Yet starting around 2020, California courts began to hold occasionally that CIPA could apply to internet communications, such as recorded chat sessions. Then in 2023, a California federal judge permitted CIPA cases to proceed under the theory that website tracking technologies, like cookies and pixels, could be construed as a kind of pen register.
Enter former Hollywood actor and current convicted felon Vivek Shah. Shah had a small role in “The Dark Knight” as a bank hostage. He is likely better known for a massive extortion scheme that targeted wealthy individuals, including Harvey Weintstein. He plead guilty in 2013 and was sentenced to seven years and three months in prison.
Shah was released in 2019, and he began to dabble in pro se litigation. He sued numerous media defendants, including The Atlantic and Fox News, for copyright infringement over running photographs of him taken from this Facebook page. The case was dismissed.
Now he has found CIPA. He has sent thousands of templated demand letters to website owners nationwide, including media companies; in far fewer cases, he has filed lawsuits. Shah, or someone else deciding to get in on this hustle, would simply visit a website and use some basic website developer tools to see what information the website captures. This becomes the basis of the demand letter.
But what kind of dark magic would allow a California state law to dictate how a Missouri business operates? People like Shah would argue that if a Missouri website is doing business in California by publishing there, and further, the Missouri website gathers data from the California resident, sufficient contacts have been made to establish personal jurisdiction.
There are legal defenses — people have successfully argued that website data collection is just too far afield from the Cold-War telephone technology that CIPA contemplated. People have also successfully argued that running a passive website is not sufficient to create out-of-state jurisdiction. But victory on these issues is not certain, and legal fees will mount even if you are vindicated.
You may have noticed, as I have, that banners have begun appearing on websites everywhere asking for your consent before you can interact with the site. Just another bit of added friction to your daily work.
However, until California fixes its law or perhaps a federal law is passed, it would likely be worth the effort to contact your web developer and see what simple changes can be made to your website to lessen your exposure.