Now Available: Active Cyber Insurance for Enterprises
Cyber Incident? Get Help

Understanding Why Privacy Claims Doubled in H1 2026

Coalition Blog Privacy2026

When we published our report The State of Web Privacy last November, our central argument was that privacy risk behaves less like a static compliance checkbox and more like cyber risk. 

Just as security teams track attackers by their tradecraft, brokers now need to track the legal theories and law firms driving privacy claims so they can better advise their clients. The players change, the tactics evolve, and the potential exposure varies enormously from one actor to the next.

The frequency of privacy rights-related insurance claims in the first half of 2026 has doubled relative to 2025.* Beyond the headline number, there are several underlying trends and developments that may shape how brokers advise clients.

Blog Privacy-Chart

1. Nearly every business is exposed to CIPA

Our original report found that nearly three-quarters of web privacy claims cited the California Invasion of Privacy Act (CIPA), a 1967 wiretapping statute that plaintiffs are increasingly applying to common website tracking technologies like pixels, cookies, and analytics scripts.

CIPA remains a major claims driver in 2026, far out-numbering allegations related to modern privacy laws like the California Consumer Privacy Act (CCPA) or California Privacy Rights Act (CPRA), even though these laws were actually designed to address web tracking.

Any client with a consumer-facing website that uses common marketing or analytics tools has meaningful exposure, whether they are a Fortune 500 retailer or a regional non-profit.

When alleging CIPA violations, plaintiffs often argue that ordinary tracking technologies "intercept" website communications without all-party consent, with each alleged violation carrying $5,000 in statutory damages. These claims can be asserted even against websites that implemented opt-out mechanisms required by the more modern framework of CCPA.

These claims are also broader geographically than many businesses might expect. CIPA can apply when a California resident interacts with a website, regardless of where the business itself is located. To illustrate how far these lawsuits travel, we saw the first CIPA claims filed by Coalition policyholders in the UK and Australia this year.

Any client with a consumer-facing website that uses common marketing or analytics tools has meaningful exposure, whether they are a Fortune 500 retailer or a regional non-profit.

2. A prolific new (threat) actor: Vivek Shah

One of the clearest signs of how quickly the landscape has changed is the rise of Vivek Shah, a serial pro se litigant who is now the most prolific filer of website privacy complaints. 

When we analyzed privacy claims for our 2025 report, we had not received a single Shah-related claim. By mid-2026, Shah outpaced all law firms combined in demand-letter volume, with especially sharp spikes in November 2025 and June 2026.

Shah is scaling up the playbook already deployed by law firms like Tauler Smith and Swigart Law:

  • Scale: Shah typically sends a short demand letter accompanied by a draft complaint, framed as a request for "informal dispute resolution" of an alleged CIPA violation. The complaints typically follow the same template, changing only small details about the specific nature of the website.

  • Everyday website tools: Shah focuses on any third-party tool used by the website. A particularly absurd complaint alleged that the loading of a cookie compliance banner without consent was a violation of CIPA (We ask: how can a website collect consent without loading a consent banner?)

  • Settlement pressure: Shah threatens to file the complaint in state court or, where a website's terms include an arbitration clause, to compel arbitration. The strategy aims to make a quick, nuisance-value settlement look cheaper and less involved than a fight.

Shah’s tactics are worth noting because his campaign shows how quickly a single bad actor can industrialize privacy litigation by weaponizing laws. A business does not need to be reckless or high-profile to receive a demand letter. Operating a website with any third-party tool can make you a target. 

At the same time, Shah’s ambitious campaign has faced pushback. In one recent case, Shah entered generic terms like “felony-friendly jobs” into a website search bar, then argued that sharing those searches with third-party tools created a privacy violation under CIPA.  The court disagreed, and the judge ruled that generic website searches don't create a protectable privacy interest. 

In July 2026, a judge declared Shah a “vexatious litigant,” noting Shah’s record of complaints “strongly indicates that Plaintiff's purpose is to harass defendants into coercive settlements.” Shah now needs a judge’s approval to file a CIPA suit in the Central District of California.

These examples of pushback are useful context, especially in conversations with business owners who may feel (or have experienced) considerable anxiety upon receipt of a demand letter.

3. CIPA relief may be coming, but is not guaranteed

Last year, California Senate Bill 690 — legislation aimed at curbing abuse of CIPA — stalled in the Assembly and became a two-year bill. It moved again on July 1, when the Assembly Committee on Privacy and Consumer Protection passed an amended version. The bill still must clear the Assembly in August and be signed by the Governor before it can become law. 

Coalition has actively supported SB690 because the goal is straightforward: align California’s old wiretap law with the state’s modern privacy framework and curb the use of CIPA as a mass demand-letter tool.

But brokers should keep client expectations in check. The amended bill is much narrower than many had hoped. The broad commercial-business-purpose exemption supported in the Senate appears to be off the table in the Assembly. Instead, Assembly members have focused on limiting private enforcement of the pen-register and trap-and-trace provisions.

Businesses should not treat possible reform as a reason to delay reducing exposure or transferring risk.

That change could reduce some abusive claims, but it would leave other provisions, including claims under Sections 631 and 632, largely unchanged. So even if the bill passes, it may reduce only part of the exposure rather than meaningfully resolve the broader wave of website-tracking claims. Retroactivity for some claims is possible but also uncertain, which means the current backlog may not be cleared.

The takeaway is simple: relief may be coming, but will likely be limited. Businesses should not treat possible reform as a reason to delay reducing exposure or transferring risk.

4. Don't let volume distract from high-severity claims

In addition to drawing attention to the rise in templated demand letters, our original report recommended that “businesses should also be prepared for bespoke lawsuits and legal theories.”

Indeed, our data also shows a steady increase in the number of unique law firms focused on non-breach privacy. In fact, 72% of H1 2026 claims involved law firms we had not previously seen in privacy rights claims. Many of these “new” law firms market themselves as boutique consumer class action firms.

These law firms have the resources to formally file complaints, outline novel legal arguments, pursue discovery, seek class certification, and litigate to judgment. These matters are not typically settled within the retention and can escalate into six-, seven-, or even eight-figure exposure. 

In our experience, the segments most likely to see sophisticated litigation are:

  • Large healthcare firms with pixels and other common tracking technologies installed on their websites, often with privacy tools that may not have been configured properly.

  • Technology firms that sell data as part of their business model. This ranges from data brokers, AdTech firms, mobile apps that collect geolocation data, and digital platforms that process large volumes of data.

  • Media companies, sports teams, and universities that offer significant video content on their websites. These firms often face allegations that they violated the Video Privacy Protection Act.

The point to emphasize is that the headline rise in demand letters drives frequency, but the higher-severity risk comes from better-resourced law firms pursuing more sophisticated legal theories against businesses with larger data footprints across web and other platforms.

Practical steps for managing privacy risk

The good news is that web privacy risk can be manageable if treated with the same continuous focus as cyber risk rather than as a one-off compliance task.

Help clients gain visibility into their exposure. You can't fix what you can't see. Coalition's Active Privacy Protection, which includes individualized privacy risk insights available through Coalition Control®, helps surface the tracking technologies running on a client’s website, audit consent mechanisms, and evaluate certain disclosures. This helps give clients a clear picture of where their organization may be vulnerable before a regulator or plaintiff identifies an issue first.

Point clients to practical resources. Coalition has published a suite of advisory materials, including a checklist of privacy best practices for small and midsize businesses and an international privacy policy template. These resources can help clients strengthen disclosures and better align them with both US and European requirements.

Make sure clients understand the role of coverage. Even strong compliance programs can have gaps because websites change constantly, marketing stacks sprawl, and privacy rules vary across jurisdictions. A comprehensive cyber policy offering broad privacy coverage, plus access to an experienced claims team, can serve as a necessary backstop.

Privacy litigation is evolving quickly. Brokers who can explain the drivers behind these claims, identify which clients are most exposed, and point to practical risk-reduction steps will be better positioned to handle pushback and add value in client conversations.


UNPACK PRIVACY LIABILITY. PREVENT WRONGFUL COLLECTION CLAIMS.

Strengthen Your Privacy Risk Expertise

Take control of privacy risk >


*Data based on global Coalition claim trends for the period January 1, 2026 - June 30, 2026.
This blog post is designed to provide general information on the topic presented and is not intended to construe or render legal or other professional services of any kind. If legal or other professional advice is required, the services of a professional should be sought. Neither Coalition nor any of its employees make any warranty of any kind, express or implied, or assume any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, product, or process disclosed. Any action you take upon the information contained herein is strictly at your own risk. Coalition and its affiliates will not be liable for any losses and damages in connection with your use or reliance upon the information. The blog post may include links to other third-party websites. These links are provided as a convenience only. Coalition does not endorse, have control over, nor assumes responsibility or liability for the content, privacy policy, or practices of any such third-party websites.
Copyright © 2025. All rights reserved. Coalition, Coalition Control, and the Coalition logo are trademarks of Coalition, Inc.

Related blog posts

See all articles
Cyber Insurance

Blog

Making Active Cyber Insurance the Global Enterprise Standard

Cyber incidents remain the #1 global business concern. Coalition and Allianz are partnering to help enterprises manage cyber risk more confidently.
Shawn RamJuly 02, 2026
Cyber Insurance

Blog

Why Australian Businesses Need to Manage Web Privacy Risk

Businesses across Australia face growing privacy risk from domestic regulators and international litigation spilling over across borders warranting urgent action.
Daniel WoodsJune 30, 2026
Cyber Insurance

Blog

Why We Made Security Control Questions Optional for Australian SMEs

Coalition’s new shortened application makes it easier for brokers to quote cyber for Australian SMEs without attesting to existing cybersecurity controls.
Trent NihillJune 16, 2026