Skip to Main Content
Publications

California Federal Court Declares Serial CIPA Plaintiff Vivek Shah a Vexatious Litigant: What You Need to Know

Judge R. Gary Klausner of the U.S. District Court for the Central District of California declared Vivek Shah – one of the nation's most prolific serial digital privacy litigants – a vexatious litigant on July 20, 2026, entering a prefiling order barring Shah from filing any new action asserting California Invasion of Privacy Act (CIPA) or related digital privacy claims in the district without first obtaining the court's permission. Shah v. Crain Commc'ns, Inc., No. 26 CV 3070 (C.D. Cal. July 20, 2026), Dkt. No. 34. The ruling is a noteworthy victory for the many companies – e-commerce and retail, technology and SaaS, healthcare, and financial services chief among them – with extortion-style demand letters and cookie cutter complaints alleging that routine website analytics tools violate CIPA and similar digital privacy laws.

The bottom line: Defendants now hold powerful, judicially endorsed leverage against Shah-style shakedown demands. But the decision does not resolve the merits of CIPA's application to website tracking, and the outsized liability exposure generated by digital privacy class actions remains, making comprehensive compliance and risk mitigation, guided by experienced outside privacy counsel, as essential as ever.

What Happened

Shah has sent hundreds – if not thousands – of templated demand letters to businesses across the country, asserting that standard website analytics tools such as Google Analytics and HubSpot constitute unlawful wiretapping and illegal "pen registers" under CIPA and, in some instances, the federal Wiretap Act. Leveraging CIPA's $5,000 per-violation statutory damages provision, the letters demand settlements untethered to the merits and attach draft complaints characterized as "ready to be filed" absent payment.

In March 2026, Shah sued Crain Communications, Inc. (Crain), alleging that its website intercepted the contents of his electronic communications in violation of CIPA § 631(a)'s wiretapping prohibition. Rather than pay, once Crain was sued, it moved under the California federal court's local rules to have Shah declared a vexatious litigant.

Applying the Ninth Circuit's four-factor framework under De Long v. Hennessey, 912 F.2d 1144 (9th Cir. 1990), the court compiled a striking record: from 2021 to 2026, Shah initiated at least 29 proceedings – including seven nearly identical complaints against seven different defendants in the past seven months alone – none of which progressed past the pleading stage.

On that record, the court made express findings of frivolousness and harassment, concluding that Shah's pattern of "seeking out CIPA violations," "voluntarily dismissing cases upon a defendant's motion to dismiss," and failing to try a single claim on the merits "strongly indicates that Plaintiff's purpose is to harass defendants into coercive settlements, rather than seek redress from the judiciary in good faith." As the court emphasized, "[a] party who repeatedly files baseless actions only to dismiss them when challenged is no less vexatious than the party who follows the actions through to an adverse completion." Even Shah's pro se status could not outweigh his "extensive record of harassment."

The court accordingly declared Shah a vexatious litigant and entered a prefiling order covering "any new case filed in the Central District of California that alleges any claims arising under [CIPA] or other related digital privacy claims." It declined to require a security bond in the Crain action itself, but noted that judges presiding over future related actions retain discretion to impose one.

Why It Matters

The decision lands amid an unprecedented wave of CIPA and "digital wiretapping" litigation. A small cadre of plaintiffs' firms and pro se litigants, filing at tremendous volume, has weaponized CIPA's per-violation statutory damages provision against the ordinary operation of commercial websites, targeting analytics tools, advertising pixels, session replay software, and chatbots. No sector has been left unscathed, with companies of all shapes and sizes facing outsized aggregate exposure from conduct as commonplace as deploying Google Analytics.

Crain gives targets of this litigation model immediately usable leverage: a federal court has now found, on a fully developed record, that the paradigmatic serial CIPA plaintiff's strategy is designed to extract coercive settlements rather than vindicate genuine privacy rights. That finding recalibrates the settlement calculus for any company holding a Shah-style demand.

The ruling also arrives as the defense bar increasingly goes on offense. On July 8, 2026, real estate technology company Lofty Inc. filed a preemptive declaratory judgment action against Shah in the same district, seeking declarations that Google Analytics and HubSpot do not violate CIPA's pen register provision and that Shah – a litigation "tester" with no reasonable expectation of privacy – lacks standing to sue. Lofty, Inc. v. Shah, No. 26 CV 7425 (C.D. Cal. July 8, 2026). Meanwhile, Los Angeles Superior Court judges have repeatedly sustained demurrers to pen register claims targeting standard web analytics, and California lawmakers continue to weigh pending CIPA reform legislation, SB 690 – which we analyze in detail here – aimed at curtailing such private suits.

With that said, important limits temper the victory. The prefiling order restricts only Shah's new filings in the Central District of California – it does not reach state courts or other districts, his pending cases, or other serial plaintiffs. Nor did the court decide whether analytics tools actually violate CIPA – an issue on which courts remain divided, with several federal courts declining to dismiss such claims at the pleading stage. CIPA litigation risk, in short, remains substantial.

Key Takeaways

In a nutshell, here are the key takeaways from Crain that readers should walk away with:

  • A California federal court has declared the nation's most notorious serial CIPA demand letter litigant vexatious, finding his litigation model was designed to "harass defendants into coercive settlements."
     
  • Shah must now obtain leave of court before filing any new CIPA or related digital privacy action in the Central District of California, and future judges may condition any permitted filing on the posting of security.
     
  • The order supplies immediate leverage in pre-suit negotiations with Shah – and persuasive support for aggressive responses to copycat serial litigants running the same high volume, quick exit strategy.
     
  • Crain, however, did not reach the merits: whether analytics, pixels, session replay, and chat tools violate CIPA remains unsettled, and the statute's exposure of $5,000 per misstep continues to fuel high-dollar class actions against a broad range of consumer-facing industries.

What Companies Should Do Now

  1. Reassess pending demands. If your company holds a Shah demand letter, or a similar serial litigant demand, revisit your settlement posture with counsel. The Crain order weakens the economics of the coercive settlement model and should be cited in any response.
     
  2. Leverage the decision in pending litigation. Defendants in active cases brought by serial digital privacy plaintiffs should evaluate vexatious litigant motions, security bond applications, and early dispositive motions attacking standing and statutory scope, building on the litigation history record that proved decisive in Crain.
     
  3. Consider going on offense. For companies facing repeated demands and threatened litigation, a targeted declaratory judgment action, like Lofty, can convert serial demand letter uncertainty into an adjudication on the merits in a favorable forum.
     
  4. Inventory your tracking technologies. Conduct a privileged audit of all analytics tools, advertising pixels, session replay software, chatbots, and software development kits (SDKs) deployed across your websites and mobile apps – especially those embedded by vendors.
     
  5. Close consent and disclosure gaps. Deploy or refine consent management tools so trackers fire only after appropriate notice and, where warranted, affirmative consent; update privacy policies to disclose all tracking; and review vendor contracts for data use and indemnification terms.
     
  6. Engage experienced privacy litigation counsel early. The companies best positioned to defeat – or avoid – CIPA claims work closely with seasoned privacy counsel before a demand letter arrives, not after.

How Baker Donelson Can Help

Baker Donelson's Privacy Litigation team has significant experience defending CIPA and similar digital privacy class actions, single plaintiff suits, and pre-suit demand letters involving Vivek Shah and the other repeat plaintiffs' firms and pro se litigants in this space, including Tauler Smith LLP, Swigert Law Group, Manning Law, and Joseph Sides. We have also advised hundreds of companies on website compliance, risk mitigation strategies, and litigation readiness. If you have received a demand letter or a complaint, or want to protectively get a step ahead of this risk, contact the authors – David Oberly and Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP – directly, or another member of Baker Donelson's Data Privacy & Cybersecurity, Digital Marketing, AdTech & Consumer Privacy Compliance, or Privacy Litigation teams.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept