A plaintiff-firm scanner runs three checks: what fires before anyone touches the consent banner, what keeps firing after “Reject All,” and what a Global Privacy Control signal changes. We ran exactly that sequence against 252 prominent US e‑commerce, DTC, and consumer-health sites. This is what the bots that generate demand letters actually see.
There is a working industry built on exactly this measurement. Plaintiff law firms run automated scanners using a documented, disarmingly simple method: open a site in a fresh browser session, watch the network tab, and log every third-party request that fires before the consent banner is touched. That log becomes “Exhibit A” in a demand letter — alongside a cover letter alleging wiretapping under the California Invasion of Privacy Act (§631) and/or its pen-register provision (§638.51), a draft complaint, and a 14–30 day deadline. CIPA carries $5,000-per-violation statutory damages, no proof of harm required, no company-size threshold. Published redacted letters demand from $5,000 per violation up to $460,000 per claimant — arithmetic, not damages assessment: trackers × statutes × $5,000.
The volume is not hypothetical: by industry tallies, roughly 675 CIPA suits were filed in 2024 and over 800 in 2025 — and filings are the tip; counting unfiled demand letters, estimates run to 50,000–100,000 total claims since 2022. Pre-suit settlements are commonly reported at $10,000–$30,000, and small businesses settle because the math says to. We wanted to know: against the exact first test those scanners run, how do the biggest, best-resourced consumer sites in the country do? So we pointed our scanner — built to replicate that method — at 252 of them.
Each site got the same three-pass sequence our free scan runs, which mirrors the plaintiff-firm method:
Requests are classified against our database of 30 litigated trackers in 5 severity classes; each site gets a grade. Hard cap: 240 seconds per site.
| Checkpoint | Sites | Share |
|---|---|---|
| Measurable sites | 169 | — |
| Fired ≥1 named tracker pre-consent | 147 | 87% |
| Consent banner detected | 69 | 41% |
| — of those, fired before any interaction anyway | 58 of 69 | 84% |
| No banner detected, and fired | 89 | 53% of all measurable |
| Kept firing with GPC signalled | 139 | 82% |
| Reject button found and clicked | 19 | 11% |
| — of those, kept firing after “Reject All” | 16 of 19 | 84% |
The average measurable site fired 5.7 named trackers pre-consent (6.5 among sites that fired at all; median firing site: 7; worst: 13). Session-replay-class tools — the category behind roughly 65% of filed complaints — were firing pre-consent on 75 of 169 sites (44%). The failures were not concentrated in one corner of the market: apparel, beauty, health and wellness, and big retail all graded much the same.
Site counts are pre-consent firings among the 169 measurable sites, with our severity class (Class A = ad/identity pixels, the demand-letter headliners; Class B = session replay; Class D = identity resolution). Each tracker links to its litigation profile.
| Tracker | Sites | Class |
|---|---|---|
| Google Ads / DoubleClick | 126 | A — ad/identity |
| Google Analytics 4 | 101 | A — ad/identity |
| Microsoft UET / Bing Ads | 90 | A — ad/identity |
| Pinterest Tag | 80 | A — ad/identity |
| TikTok Pixel | 76 | A — §638.51 wave leader: 100+ class actions in a year |
| Meta Pixel | 67 | A — the most-named tracker in demand letters |
| Snap Pixel | 53 | A — named in the $5M European Wax Center pixel suit |
| The Trade Desk | 52 | A — ad/identity |
| Reddit Pixel | 47 | A — ad/identity |
| Microsoft Clarity | 39 | B — session replay |
| Klaviyo | 34 | D — identity resolution |
| LinkedIn Insight Tag | 24 | A — also named in the EWC pixel suit |
Full per-tracker litigation profiles: the tracker index.
A tracker firing pre-consent is a network observation, not a finding of liability, and courts are genuinely divided on whether it is even actionable. On the dominant §638.51 “pen register” theory, plaintiffs have survived early dismissal challenges in Heiting v. IHOP, Price v. Entravision, and Camplisson v. Adidas (pixels can be pen registers) — but defendants have won in Sanchez v. Cars.com, Rodriguez v. Plivo (an IP address alone held insufficient), and Licea v. Hickory Farms. Session-replay rulings diverge the same way: Torres v. Prudential ended in summary judgment for the defense (replay readable only after transmission is not real-time interception), while the Ninth Circuit in Mikulsky v. Bloomingdale’s (2025) revived a §631 session-replay claim, holding the “contents” of website communications were plausibly disclosed. And our numbers carry the limits stated above — one homepage pass, one vantage point, conservative detection, 51 bot-blocked sites about which we claim nothing. What the dataset shows is narrower: the network behavior demand letters are built on is the default state of prominent US consumer sites, and the mitigations that would change the log — banner gating, reject handling, GPC — mostly are not changing it.
Know what your own site sends before someone else logs it for you. The starting point is your current pre-consent log: which trackers fire before consent, whether they stop after “Reject,” and whether a GPC signal changes anything. You can do this manually with a fresh browser profile and the DevTools network tab, or run our free scan, which produces the same timestamped artifact a plaintiff-firm scanner produces, classified against the litigation record. Remove what you don’t need; gate what you do behind consent, verify the gate actually holds, and keep dated evidence of the change. None of this is legal advice: we report technical observations of network behavior, and what any of it means for your business is a question for a qualified attorney.
See what your site sends before consent
The same three-pass scan this study ran — pre-consent log, reject test, GPC test — free, on any site you own or advise.
Run a free scan Free scan, no signup to start. This is a technical scan report, not legal advice. Scan only sites you own or advise.Method: fresh-profile homepage scans of 252 US e-commerce/DTC/consumer-health sites, July 21–22, 2026, single US residential vantage point. Aggregates only; no site is named. Press and researchers: write to reports@cipascanner.com for questions about the method.