The Privacy Policy Is the Only Legal Document Nobody Fact-Checks

Room with Computer Showing Privacy Policy

Share This Post

A client forwards a CIPA demand letter. Their attorney does what the situation seems to call for: reads the privacy policy, finds it thin, and rewrites it properly. Fuller disclosure of analytics and advertising partners, a clear description of the categories collected, updated Do Not Sell language. Careful work, turned around quickly.

The website goes on sending the same data it sent before, at the same moment in the page load, to the same third parties. Nothing about the transmission changed. What changed was the description of the transmission, written by someone who never observed it.

That gap is worth sitting with, because it is where most CIPA remediation goes wrong.

An assertion of fact about a machine

Attorneys verify facts before asserting them. A representation in a purchase agreement gets diligence. A statement in a brief gets a citation. The privacy policy is the strange exception, often drafted from a client questionnaire, a vendor list assembled from memory, or the previous version of the same document.

Yet a privacy policy asserts facts about a machine. It says this website collects these categories of data and sends them to these recipients. Every clause in it is falsifiable, and falsifying it takes a few minutes with the developer tools that ship free with every browser.

That asymmetry is the problem. Opposing counsel can compare the disclosure against the actual network traffic whenever they like. If the client has never run that comparison, the first person to hold the document against the machine will be the one building a case.

Why nobody has the list

Tracking tools accumulate the way clutter does. Marketing adds a conversion pixel for a campaign. An agency installs a chat widget during a redesign. Someone turns on session recording for a usability study and never turns it off. An email platform drops in a tracking script as part of setup.

Each addition is defensible on its own. None of them generates a memo.

Three years on, no single person can name everything running on the site. The marketing director knows about the pixel. The developer knows about the tag manager. The inventory exists in pieces, held by people who each reasonably assume someone else is holding the whole picture.

This is why client questionnaires fall short as diligence. They capture what people remember, and memory is not the record here. The site itself is the record.

Consent has to arrive first

Sequence matters more than wording, and this is where otherwise careful remediation comes apart.

In Javier v. Assurance IQ, LLC, the Ninth Circuit concluded in 2022 that Section 631(a) requires prior consent and that retroactive consent through a privacy policy does not satisfy it. The disposition was unpublished, its scope was narrow, and the plaintiff’s own claims were later dismissed on remand, so it carries persuasive rather than binding weight. The reasoning still shapes how these disputes get argued, and plaintiffs cite it routinely.

The practical point survives the citation debate. A policy revised in August says nothing about a search query transmitted in June. A banner that appears after scripts have already fired is decorative.

What gets contested in these matters is when the data left, measured against when the visitor agreed. Both are technical facts about the page load. Neither is established by reading the policy.

The legislature is not coming to the rescue

Businesses have been waiting on SB 690 since early 2025. It cleared the California Senate 35 to 0 in June of that year, then stalled in the Assembly.

It moved again on July 1, 2026, and the version that moved is not the one businesses were hoping for. The broad commercial business purpose exemption is gone. As amended, the bill reaches only the pen register and trap-and-trace provisions, removing the private right of action there and routing enforcement to the Attorney General. Section 631, the wiretapping provision behind the search bar and pixel claims, is left alone.

Whatever happens to the bill before the August 31 deadline, the theory driving most of these demand letters survives it. Planning around legislative relief for Section 631 exposure is not a plan.

What an audit produces

CaliNetworks Logo

CaliNetworks begins a CIPA engagement by examining the site as it currently runs. The review inventories third-party scripts, identifies which ones transmit before consent is captured, evaluates the existing consent mechanism or documents its absence, and returns a remediation list ordered by exposure.

The cost logic follows from that order of operations. Remediation quoted before anyone has looked at the site is quoted against assumptions, which produces either padding for unknowns or a change order once the real picture emerges. A site running four third-party tools and a site running twenty-six are different jobs. Examining first turns an open-ended compliance question into a defined scope, and the client pays for the gaps actually present rather than a package built for the worst case.

The output does double duty for the drafting work. Instead of describing tracking in general terms and hoping the description survives scrutiny, you get a verified list of what the site collects, which parties receive it, and where in the load sequence each transmission occurs. That supports a privacy policy that matches reality, a cookie policy whose table reflects the cookies actually set, and terms written against the site as built. Alignment between disclosure and practice is itself part of a defensible position.

Including your own site

Law firm websites deserve the same review, and often more urgently. Intake forms and site search collect exactly the categories of information these claims are built around, and what a visitor types into a law firm’s search bar tends to be more sensitive than what they type into a retailer’s.

Where our work stops

CaliNetworks is not a law firm and does not provide legal advice. Response strategy and the merits of any claim belong with privacy counsel. Our work is technical: establishing what a site does, changing what it does, and documenting both so counsel can rely on the record.

No plugin and no configuration guarantees a legal outcome. What a well-built consent setup provides is the technical foundation and the documentation that support the position counsel decides to take.

If you are advising a client on privacy disclosures, the useful first step is finding out what the site actually transmits before anyone drafts language describing it. Call CaliNetworks at (805) 409-7700 or visit our CIPA compliance page.

Share This Post

More To Explore

ada website compliance on all electronic devices for desktop, tablet, mobile
ADA Compliance

What is ADA Website Compliance?

A Guide for explaining what ADA Compliance is in 2026 If your organization has a website (and let’s be honest, who doesn’t these days?),

legal business looking up at tall buildings
Content

2026 Compliance Checklist for California SB 37

Client Alert: 2026 Compliance Checklist for California SB 37 Practical Steps Law Firms and Legal Marketers Should Take Now California lawyers have always been

Local SEO for Businesses
Local

What Is Local SEO?

Why It’s Critical for Business Growth and How to Dominate Local Search Local SEO represents a critical digital marketing strategy for businesses serving specific

CaliNetworks
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.