This is a technical scan report, not legal advice. It documents third-party network activity observed on your site and maps it to publicly-filed litigation patterns. It makes no compliance guarantee and no prediction about any legal outcome. Consult a qualified attorney for legal questions.
Demand letters / Vivek Shah
Demand-letter sender file · public record as of July 2026

Received a privacy demand letter from Vivek Shah?

What public court records and published commentary report about this sender, and the steps recipients typically take first. A demand letter is an allegation, not a finding of liability — and nothing on this page is legal advice.

Don’t ignore the deadline, don’t respond directly, and don’t change your site before preserving dated evidence of its current state. Then talk to a privacy or defense attorney. Everything below exists to make that conversation faster.
The sender, per the public record
Name
Vivek Shah
Type
Individual claimant (not a law firm)
Base
California
Who
An individual sending demand letters in his own name — not a law firm
Publicly reported scale
Thousands of letters reported from late 2025 through mid-2026; roughly 29 lawsuits ever filed (2021–2026) per published counts — a filing rate under 1%
Reported amounts
Demands around $50,000 have been reported, computed per third-party recipient
Key court ruling
Declared a vexatious litigant by the U.S. District Court for the Central District of California on July 20, 2026, requiring court permission before filing new suits

Fisher Phillips — which reports representing dozens of recipients — and other defense commentary document a high-volume demand-letter campaign with very few actual filings behind it. Courts have also dismissed Shah claims on standing grounds, and on July 20, 2026 the Central District of California declared Shah a vexatious litigant, a ruling that requires pre-filing court permission for future suits.

None of that decides any individual letter — a recipient’s facts are their own, and what a specific letter is worth is a question for the attorney you retain. But the public record above is exactly the kind of context defense counsel will want alongside dated technical evidence of what your site actually does.

Sources: Fisher Phillips: businesses fight back against the Shah letter spree · CIPAWorld: Shah declared a vexatious litigant (July 21, 2026).

What recipients typically do — none of it legal advice
  1. Talk to a privacy or defense attorney before responding or paying. Many letters settle below the ask, some claims get dismissed, and courts are split on the underlying theories — an attorney can evaluate which posture fits your facts.
  2. Don’t let the deadline pass unexamined. Published examples give 14–30 days; defense commentary treats silence past the deadline as the worst-documented option.
  3. Preserve everything, before changing anything. The letter itself, your tag-manager and consent-banner configuration, and dated evidence of what the site transmits today. If you carry cyber insurance, written carrier notice within the policy window is repeatedly described as coverage-critical.
  4. Find out what your site actually fires right now. The letter describes a scan from weeks or months ago. You and your attorney need the current picture — including whether the named trackers actually transmit anything.

Accuracy over fear: a tracker firing pre-consent is what demand letters allege — it is not, by itself, a finding of liability, and courts have gone both ways.

  • Courts are split on §638.51 (pen register). Plaintiff wins: Heiting v. IHOP, Price v. Entravision, Camplisson v. Adidas (Nov 2025). Defense wins: Sanchez v. Cars.com, Rodriguez v. Plivo (IP address alone insufficient), Licea v. Hickory Farms.
  • Session-replay §631 is split too. Torres v. Prudential granted summary judgment for the defense (replay readable only after transmission ≠ real-time interception); Licea v. Caraway Home survived dismissal.
  • A tracker firing pre-consent is what these letters allege — it is not, by itself, a finding of liability.

If the letter already arrived: preserve the evidence first

The Defense File is a one-time $299 capture of your site’s real network behavior — a fact-check of each tracker the letter names, timestamped HAR logs, screenshots, and a SHA-256 manifest, kept 365 days and packaged for your attorney and carrier.

Get the Defense File — $299 Technical evidence preservation, not legal advice. We never assess claims or advise on settlement.

Not sure what your site fires? Start with the free scan

A free scan runs the same fresh-session, pre-consent capture a claimant’s scanner runs — plus reject-flow and GPC tests — and shows you the timestamped request log for your own site.

Run a free scan Free scan, no signup to start. This is a technical scan report, not legal advice. Scan only sites you own or advise.
Related reading

CIPA Scanner is a technical scanning tool with no affiliation to Vivek Shah. This page summarizes publicly available court records and published commentary, linked above, for the benefit of letter recipients; it makes no statement about the merits of any particular claim, and nothing here is legal advice.