A federal court just made it harder for one of the country’s most active website-privacy plaintiffs to continue operating the way he has been. But if your business has received one of his letters, the ruling does not make the issue go away.
What Happened
On July 20, 2026, the U.S. District Court for the Central District of California (Judge R. Gary Klausner) declared Vivek Shah a vexatious litigant in Vivek Shah v. Crain Communications, Inc.. Shah, a self-represented plaintiff, has filed at least 29 lawsuits since 2021, many of them under the California Invasion of Privacy Act (CIPA). He must now get court approval before filing any new CIPA or related digital-privacy suit in that district.
The court walked through all 29 of Shah’s prior cases and found a consistent pattern: seeking out potential violations, generating just enough activity against a target website to clear the federal amount-in-controversy threshold, voluntarily dismissing cases once they were challenged, and never once litigating a claim to the merits. Taken together, the court concluded this pattern pointed to an intent to pressure defendants into quick settlements rather than to pursue legitimate claims.
Why This Matters to Almost Any Business with a Website
Since late 2024, Shah has been one of the most prolific senders of CIPA demand letters in the country. His letters typically arrive addressed to a company’s registered agent, framed as a request for “Informal Dispute Resolution,” and allege that the business’s website secretly “intercepted” a visitor’s communications through everyday tracking tools: analytics platforms, chat widgets, session-replay scripts, and marketing pixels.
The legal theory barely changes from one letter to the next; usually only the company name and website are swapped out. Because these tracking tools are standard on most commercial websites, any business running them, regardless of industry, is a plausible target.
What the Ruling Does (and Doesn’t) Change
The order is narrow. Shah wasn’t barred from suing anyone, and the underlying case against Crain Communications wasn’t dismissed. The pre-filing restriction applies only to new federal CIPA or digital-privacy filings by Shah in the Central District of California. It carries no formal weight in other federal courts, in state court, or in arbitration.
This ruling is a meaningful development, but it isn’t a reason to set a letter aside, or to rush into settling one either. A few practical takeaways:
- This decision doesn’t automatically resolve or eliminate any letter or claim your business has already received.
- It’s a useful data point going forward. If Shah, or a similar plaintiff, targets your business, you can point to the court’s findings to challenge credibility and motive, even in venues where the order itself has no formal effect.
- Because this ruling (along with related trends in state courts) raises the cost of pursuing these claims in court, expect plaintiffs like Shah to lean more heavily on arbitration demands where a company’s terms allow for it.
- Any letter you receive, and your website’s privacy practices more broadly, are worth a legal review: consent and disclosure banners, how tracking tools are configured, and what your vendor agreements say. That review is the single best way to reduce exposure to the next letter, whoever sends it.
If your business has received a demand letter referencing CIPA or similar digital-privacy claims, please contact us to discuss your specific situation.