Claims that do not need a breach
A large share of data privacy litigation now involves no hacking at all. Plaintiffs' firms test websites and apps for tracking tools, session replay, chat features, and embedded video, then bring claims under older wiretap and video privacy statutes, state consumer protection laws, and newer state statutes on biometric and health data. Some of these statutes provide set damages for each violation, which makes the claims economically attractive even where no one suffered a measurable loss. Courts are divided on how several of the older statutes apply to modern web technology, so outcomes vary by jurisdiction and by the specific tool involved.
Mass arbitration and demand letters
Many consumer terms require individual arbitration, which once discouraged privacy claims. Some firms now file thousands of individual arbitration demands at once, and the fees a company owes under its own arbitration terms can become the pressure point. Reviewing the arbitration clause, its fee provisions, and how users accepted the terms is now part of managing privacy risk. Pre-suit demand letters are common as well. How to respond depends on the strength of the claim, the size of the exposure, and whether others are likely to follow. Keep any demand letter and the communications around it, and route them to counsel rather than answering the sender directly.
Responding without making it worse
When a claim arrives, we start by documenting what the tool actually did and when, before anyone changes the website, since the configuration during the relevant period is the evidence. We then review the disclosures and consents in effect at the time, the vendor contracts governing the data flow, and any insurance that may respond. Quick technical changes can reduce future exposure, but they should be coordinated with counsel so they are not misread later. The response strategy, whether early resolution, motion practice, or a defense on the merits, follows from that review.