A privacy demand letter can feel urgent. Treat it seriously, but do not let urgency substitute for verification. A demand is a claim by a sender—not a court judgment, proof of liability, or guarantee that a lawsuit will follow.
What should I do first?
Preserve the letter, envelope, attachments, and the date and method of delivery. Record the response date stated in the letter, but do not assume it is a court deadline. A lawsuit generally begins when a complaint is filed and served; a demand letter by itself is not a filed civil case.
Identify one internal owner, such as your general counsel, outside counsel, or a senior leader, so that communications and documents are not lost or duplicated.
Do not destroy analytics, consent logs, tag-manager history, privacy-policy versions, vendor contracts, or deployment records. Preserve relevant information while counsel decides what must be retained.
How do I verify the sender and the claim?
Verify the organization, claimant, phone number, domain, and mailing address through sources you locate independently. Compare those details with the letter and the case portal before responding.
Ask whether the letter identifies:
- the person or organization making the claim;
- the website, dates, pages, and technologies at issue;
- the specific legal theory and jurisdiction;
- evidence supporting the allegation;
- the requested response and proposed terms; and
- a way for counsel to request clarification.
Missing detail does not prove a letter is false, and polished branding does not prove it is genuine. Independent verification is the safer test.
Should I change the website immediately?
Separate two workstreams: preserving evidence and reducing any ongoing risk. A developer or privacy professional can inventory tags, session-replay tools, pixels, consent behavior, network requests, and disclosures. Coordinate changes with counsel so the team records what changed, why, when, and by whom.
Removing or reconfiguring a technology may reduce future data collection. It does not, by itself, decide whether earlier conduct violated a law or resolve the sender's claim.
Should I notify an insurer or broker?
Check cyber, technology errors-and-omissions, media, and general-liability policies for notice requirements. Policies differ, and late notice can affect coverage. Ask the broker or insurer how to provide notice without characterizing disputed allegations as admitted facts.
Coverage, choice of counsel, deductibles, exclusions, and authority to settle depend on the policy. Do not rely on a generic estimate from a website.
What response options may exist?
The available options depend on the letter, facts, contract terms, insurance, jurisdiction, and counsel's assessment. They may include requesting evidence or more time, disputing some or all allegations, discussing remediation, negotiating terms, resolving the matter, or preparing to defend a filed case.
No option has a universal price, timeline, or outcome. Before agreeing to terms or paying, understand at least:
- who will sign and who will be released;
- which claims and time periods the release covers;
- whether liability is admitted or denied;
- confidentiality and permitted disclosures;
- remediation obligations and how completion is measured;
- payment amount, timing, method, and refund or failure handling;
- what happens if either side does not perform; and
- whether the agreement fully resolves the described matter.
What happens if I do not respond?
The sender may follow up, extend the stated date, end discussions, or consider other steps. A lawsuit is not automatic. If a complaint is actually filed and properly served, formal court deadlines can apply; those deadlines vary by court, claim, service method, and party.
That is why prompt review is useful: it preserves time to verify the notice, gather facts, notify an insurer, and obtain advice. It should not be framed as a reason to make an unverified payment.
What can I safely do today?
- Save the original letter and delivery information.
- Independently verify the sender and payment destination.
- Calendar the stated response date and any actual court dates separately.
- Preserve relevant technical and business records.
- Notify the appropriate internal owner, broker, or insurer as required.
- Ask qualified counsel to evaluate the law, evidence, jurisdiction, defenses, and response.
- Audit current tracking behavior and document any remediation without deleting historical evidence.
This sequence creates urgency around verification and informed action—not panic or a predetermined settlement.
Primary and official resources
- 18 U.S.C. § 2511: Federal Wiretap Act
- Cal. Penal Code § 631: California Invasion of Privacy Act
- U.S. Courts: Civil Cases
- U.S. Courts: Federal Rules of Civil Procedure