The Demand LetterEconomy.
An automated litigation pipeline is quietly suing tens of thousands of small business websites every year. What it costs. Who's behind it. And the only thing that prevents it.
CA · $4,000 / visit
No harm required
Plus punitives + fees
AG enforcement + cure periods
A field guide to statutory shakedowns.
The legal system has been quietly automated against your website. Four civil-rights and privacy statutes -- ADA, California's Unruh Act, California's Invasion of Privacy Act, and the federal Video Privacy Protection Act -- share a single feature that makes them irresistible to plaintiff firms: the plaintiff doesn't have to prove harm. The violation itself is the harm, by law. That feature, combined with cheap automated scanning, has produced an industrial pipeline of demand letters, settlements, and quiet payouts from businesses that mostly don't know what hit them.
This briefing is for the people on the receiving end -- small business owners, founders, marketing leads, and the lawyers who get the panicked phone call after the FedEx envelope arrives. It explains the four legal regimes in plain language, walks through the playbook used against businesses, and lays out the actual economics. It is informational, not legal advice.
How to read this
Each chapter opens with the statute, what plaintiffs must prove, and what the defense looks like in practice. Real cases are cited with primary sources. Margin notes flag the numbers and quotes worth remembering.
What a demand letter actually is.
A demand letter is a private settlement shakedown sent before a lawsuit is filed. A law firm scans your site with an automated tool, identifies a violation of a statute that carries statutory damages, and sends you a letter saying, in effect: 'We have a client who visited your site. We documented X violations. Each entitles our client to $Z. Multiplied by the affected class, your exposure is in the seven figures. We'll settle for $YY,YYY if you sign within 30 days. Otherwise, we file.'
The letter usually arrives by FedEx or certified mail, on real letterhead, with a real bar number, with screenshots and network captures attached. It is not spam. Ignoring it gets you sued.
Why it works as a business model
The mechanism is statutory damages. Under most consumer-protection statutes, plaintiffs must prove they were actually harmed in some way -- lost money, suffered emotional distress, missed an opportunity. Statutory damages skip that step entirely. The legislature has decided in advance that violating the statute is itself a compensable harm, and set a fixed dollar amount per violation. Multiply by the alleged class size and the exposure number on the demand letter routinely runs into seven figures.
The settlement number is always smaller than the projected exposure. That's the trade plaintiffs offer: pay a known five-figure sum now, or roll the dice on a seven-figure number later. Almost everyone pays.
Two flavors of sender.
The line between civil-rights advocacy and litigation factory is blurrier than the headlines suggest. From the receiving business's perspective, the legal effect is identical.
| Type | Who they are | Posture |
|---|---|---|
| Legitimate civil-rights firms | Real clients with real disabilities or real privacy concerns, often with a public-interest mission attached. | Want money and remediation. Settlements include compliance commitments. |
| Serial / troll firms | Industrial pipeline. One lead plaintiff files dozens to hundreds of complaints a year. Paralegal-driven. | Volume settlements at $5K-$25K. Speed over substance. Rarely litigate. |
Per Accessible.org's review of 3,948 ADA web cases, 33 plaintiffs accounted for over 50% of filings; Manning Law APC alone is responsible for roughly 14% of all ADA web filings nationally. The line between the two camps is blurrier than you'd think -- many "legitimate" suits use serial-plaintiff mechanics, and many serial plaintiffs do have qualifying disabilities.
Anatomy of a typical demand letter
The structure is almost always the same. If you've seen one, you've seen them all -- which is exactly the point. These are templates, filled in by paralegals, mailed by the dozen.
- Plaintiff identification. A named individual with a disability described in clinical detail, often with a screen-reader brand named (NVDA, JAWS, VoiceOver).
- Site visit narrative. Date, page URL, what the plaintiff was trying to do, what failed. Often phrased to track WCAG 2.1 AA criteria language exactly.
- Legal claims. ADA Title III as the federal hook, plus state-law analogs -- Unruh in California, NYC HRL §8-502 in New York -- for the damages multiplier.
- Itemized violations. A list of WCAG failures, almost always generated by an automated scanner (axe, WAVE, Lighthouse) and lightly edited by a paralegal.
- Damages calculation. Projected exposure, often in the six-to-seven-figure range. Designed to anchor the negotiation.
- Settlement demand. A specific number well below the projected exposure but still substantial -- typically $10,000-$25,000 for first-offense small businesses.
- 30-day clock. "Respond by [date] or we file." Almost no business takes the second option.
The accessibility wave.
A blind, deaf, or motor-impaired user -- or a 'tester' with a long history of suing -- cannot navigate your site with a screen reader, keyboard, or captioning. Their lawyer files. The plaintiff's burden is light: prove a qualifying disability, prove your business is a 'place of public accommodation' (in California state court, simply selling things online is enough), and prove they encountered a barrier -- an unlabeled button, a missing alt text, a keyboard trap, an uncaptioned video. They do not have to prove they intended to buy anything. They do not have to prove damages.
Under California's Unruh Act, every visit to an inaccessible page is a separate $4,000 violation. Multiply by twelve months of California traffic and the math gets ugly fast.
Why New York is the preferred venue
Plaintiff firms forum-shop into New York City for two reasons. First, NYC Administrative Code §8-502 allows public-accommodation plaintiffs to recover punitive damages plus attorney's fees, with a 3-year statute of limitations. NY State HRL does not allow punitives in public accommodation cases -- only NYC's law does. Second, NYC Admin. Code §8-126 sets civil penalties at $125,000 per violation, doubled to $250,000 for willful violations.
California's numbers look smaller in federal statistics not because there are fewer suits, but because Unruh suits go to state court and don't show up in federal filing counts.
The tester vector.
A "tester" is a plaintiff who visits sites specifically to find violations and sue, with no intent to be a customer. The Supreme Court was supposed to decide in Acheson Hotels v. Laufer (Dec 2023) whether testers have Article III standing -- and ducked the question on procedural grounds, leaving the existing circuit split intact and the tester industry humming.
Deborah Laufer alone filed over 600 ADA hotel-website lawsuits before her own attorney was suspended for misconduct, which is how Acheson got mooted in the first place. Her complaints were near-identical templates with the hotel name swapped in.
The circuit split, in plain English
The First, Fourth, and Fifth Circuits have held that testers without intent to use a service still have standing to sue. The Second, Fifth (in some opinions), and Tenth have held the opposite. SCOTUS could have settled it. Instead it dismissed Laufer's case as moot, kicked the issue, and the litigation pipeline kept running.
For a small business, this means the standing question is decided by where you get sued -- and plaintiff firms know exactly which circuits to file in.
If your site is sued in a tester-friendly circuit by a serial plaintiff, the standing question won't save you. The defense has to be technical -- the violations have to be fixed before the scan happens.
A 1967 wiretap law, weaponized for the pixel era.
California's Invasion of Privacy Act was written in 1967 for telephone wiretaps. Plaintiff firms argue that when your site loads a third-party tracking pixel (Meta, TikTok, Google), a session-replay tool (Hotjar, FullStory, Microsoft Clarity), or a chat widget that pipes conversations to a vendor, you're 'wiretapping' the visitor by routing their interactions through a third party without consent.
The plaintiff has to prove only three things: they visited from California, a third-party tracker fired during their session, and they didn't consent. All three are trivially documented in browser developer tools.
The damages: $5,000 per violation, no actual harm required, plus attorney's fees. This is the fastest-growing category of website litigation, and the one most small-business owners have never heard of.
The dominant troll firms
Pacific Trial Attorneys (Scott Ferrell) focuses on chat-widget wiretap claims; demands typically run $10,000-$75,000 depending on traffic and class size estimates. Bursor & Fisher brings broader pixel and tracking class actions, including Lesh v. CNN, which alleges CNN's site functions as an illegal "trap and trace" device merely by capturing visitor IP addresses.
What triggers a CIPA scan
Plaintiff firms run automated scanners much like the one Vitki Data's audit uses. Their scanners look for specific network signatures and consent-flow failures.
| Network signature | Service |
|---|---|
connect.facebook.net | Meta Pixel |
analytics.tiktok.com | TikTok Pixel |
bat.bing.com | Microsoft UET |
script.hotjar.com | Hotjar session replay |
cdn.fullstory.com | FullStory recording |
js.intercomcdn.com | Intercom chat widget |
The four detection axes
- Network requests to known third-party endpoints during the session.
- Whether those requests fire before consent -- meaning the cookie banner is decorative, not functional.
- Whether the privacy policy discloses each tracker by name. Most do not.
- Whether the chat or contact widget routes conversations through a vendor (LiveChat, Drift, Intercom, Zendesk).
Bork's revenge.
A 1988 federal law passed after a journalist published Robert Bork's video-rental records. Plaintiff firms revived it for the streaming and Meta-Pixel era. Any site that (a) shows pre-recorded video and (b) loads Meta Pixel on the page where the video plays is on the hook. The pixel transmits the user's Facebook ID along with the video URL, which plaintiffs argue is a knowing disclosure of 'video viewing records' to a third party.
To prevail, the plaintiff must prove three things: that the defendant is a "video tape service provider" (case law has stretched this to any site offering pre-recorded video), that the plaintiff was a "subscriber" (a newsletter signup is sufficient in most circuits), and that the defendant knowingly disclosed personally identifiable information plus what video the plaintiff watched, to a third party.
Liquidated damages: $2,500 per violation, plus punitives and attorney's fees.
Real settlements (2024-2025)
| Defendant | Settlement | Note |
|---|---|---|
| AARP | $12.5M | Largest known VPPA settlement to date |
| Christian Broadcasting Network | $4.0M | Religious broadcaster · newsletter signups |
| Limited Run Games | $2.72M | Indie game publisher · promotional videos |
| Springer Nature (Sci. American) | $0.9M | $200K to plaintiff's attorneys |
The target zone
Any site that hosts pre-recorded video alongside a tracking pixel -- product demos, tutorials, customer testimonials, sermons, news clips -- sits inside the VPPA target zone.
The other track: regulators.
GDPR and the U.S. state privacy laws (CalOPPA, CCPA, VCDPA, CPA, TDPSA) are the lower-acute, higher-regulatory track. Critically, the state privacy laws are attorney-general only with cure periods. They are not direct lawsuit risk like ADA, CIPA, and VPPA. The framing for prospects is different but the cost can still be steep.
GDPR (Europe)
Applies if your site has any EU visitors and you handle their personal data. Penalty ceiling: €20M or 4% of global annual turnover, whichever is higher. The "demand letter" analog is privacy NGOs -- most prominently NOYB, Max Schrems' organization -- filing complaints with EU data protection authorities.
CCPA private right of action
Only $750 per incident, and only for actual data breaches involving statutorily-defined personal information. Limited demand-letter risk. Unlike CIPA, there is no general private right of action under CCPA for tracking violations.
VCDPA / CPA / TDPSA
Virginia, Colorado, and Texas privacy laws all share the same basic structure: AG-only enforcement, with a cure period before penalties attach.
| Statute | Per violation | Cure period |
|---|---|---|
| Virginia VCDPA | $7,500 | 30 days |
| Colorado CPA | $20,000 | 60 days |
| Texas TDPSA | $7,500 | 30 days |
After the letter arrives.
Every step has a cost and a clock. This is the timeline a small business owner walks through, in compressed form.
FedEx envelope arrives
Owner Googles the law firm name, finds threads of similar businesses panicking. Realizes this is real.
Find a specialist lawyer
A general-business attorney usually doesn't know this area. ADA/CIPA defense specialists charge $3,000-$10,000 just for the initial retainer. The wrong lawyer is worse than no lawyer.
Don't touch the site
Counterintuitively, the worst thing the owner can do is start 'fixing' things. Spoliation risk: changes erase evidence the defense needs. Browser cache and Wayback Machine snapshots already capture the violation. A 'fix' can be cited as evidence of awareness.
Negotiation
Plaintiff's lawyer wants a number. Defense lawyer works to lower it. Typical first-offense settlement: $10,000-$25,000 plus a signed commitment to remediate to WCAG 2.1 AA within 6-12 months plus monitoring obligations.
Sign or fight
Fighting in court runs $30,000-$175,000 in defense fees before a verdict. Almost no small business fights -- the math doesn't work.
Remediation
Settlement requires actual WCAG conformance. Another $5,000-$50,000 depending on site complexity. Failure triggers a second lawsuit -- harder to defend because the defendant now had documented knowledge.
Monitoring & re-targeting
Plaintiff retains the right to rescan. The same firm or its referrals will. Many businesses get sued by a different plaintiff for the same site issues.
Plaintiffs vs. trolls.
It is tempting to villainize one side or the other -- the noble disabled plaintiff who was actually shut out of a service, or the cynical lawyer running a litigation factory. The reality is messier and, for the receiving business, irrelevant.
The legitimate end
A blind retiree in Brooklyn who can't book a hotel for her grandson's wedding because the booking page is unusable with a screen reader. She files suit, the hotel pays a settlement and fixes the site, and every blind user benefits. The mechanism Congress designed in 1990 is doing exactly what it was supposed to do.
The troll end
A law firm runs a script overnight against 50,000 small business websites. By morning it has 8,000 with WCAG violations. Paralegals draft near-identical demand letters with names swapped in. Settlements average $12,000 -- roughly $96M in annual revenue, with marginal cost approaching zero per case.
The blurry middle
Most cases sit between. The plaintiff is real and was really turned away by an inaccessible site -- and is on retainer with a firm that finds them new sites every week. Each case is colorable on its facts. Each case is part of a pipeline.
The mental model most owners are missing.
Most small business owners think: 'I haven't done anything wrong, so I can't be sued.' Two facts dismantle that assumption.
Statutory damages are the entire point. The plaintiff doesn't have to prove they tried to buy your product, were upset, or lost anything. The violation is the harm, by statute. This is fundamentally different from how most civil litigation works, and it is what makes the demand-letter pipeline economical at scale.
Plaintiff firms run scanners against tens of thousands of sites a month. There is no "I'm too small to notice." Small sites with obvious issues are preferred targets -- they settle faster, cheaper, and without the friction of corporate legal departments.
The legal system has been quietly automated against you. The only defense is to automate the inspection on your side first.
The audit doesn't make you "compliant" in any binding legal sense -- no automated scan can. What it does is give you the same list the plaintiff's scanner is going to produce, before they hit "send" on the demand letter. Once the list is in your hands, the issues are fixable. Once it's in their hands, it's a settlement.
Sources & primary references.
Statutes
- California Civil Code §52 (Unruh damages) -- leginfo.legislature.ca.gov
- California Penal Code §637.2 (CIPA damages) -- leginfo.legislature.ca.gov
- 18 U.S.C. §2710 (Video Privacy Protection Act) -- law.cornell.edu
- NYC Admin. Code §8-502 -- nyc.gov
- NYC Admin. Code §8-126 -- law.justia.com
- Virginia VCDPA §59.1-584 -- law.lis.virginia.gov
- Colorado CPA §6-1-1311 -- coag.gov
- Texas TDPSA §541.155 -- texasattorneygeneral.gov
- GDPR Article 83 -- gdpr-info.eu
Lawsuit data
- ADA Lawsuit Statistics 2025-2026, WCAGsafe -- wcagsafe.com
- Serial ADA Web Litigation, Accessible.org -- accessible.org
- 40 ADA Web Plaintiffs' Law Firms -- accessible.org
- Settlement Amounts, Accessible.org -- accessible.org
- 2025 Mid-Year Report, EcomBack -- ecomback.com
- Tracking Litigation 2025, Byte Back Law -- bytebacklaw.com
- CIPA / VPPA / SB 690, Coblentz Law -- coblentzlaw.com
- VPPA Pixel Class Action Wave, ABA -- americanbar.org
Cases & defense guides
- Acheson Hotels v. Laufer (SCOTUS 2023) -- supremecourt.gov
- Tester Standing Post-Laufer, Berenzweig -- berenzweiglaw.com
- $12.5M AARP VPPA Settlement -- topclassactions.com
- $4M CBN VPPA Settlement -- usesparrow.com
- $2.72M Limited Run Games VPPA -- natlawreview.com
- $900K Springer Nature VPPA -- cipaworld.com
- Inclusive Web 2026 Defense Guide -- inclusiveweb.co
- TestParty 2026 Defense Guide -- testparty.ai
- Anatomy of an ADA Demand Letter, TestParty -- testparty.ai
- Pacific Trial Attorneys CIPA, Klein Moynihan -- kleinmoynihan.com
- Bursor & Fisher Class Actions, Captain Compliance -- captaincompliance.com
See what the plaintiff's scanner is about to find.
Vitki Data's Website Legal Risk Audit uses the same engine, the same network-trace methodology, and the same statutory framework that plaintiff firms use to build their cases.
Disclaimer. This briefing is informational and is not legal advice. Statutory damage amounts, case citations, and lawsuit counts cited herein are accurate as of publication and may change. For questions about specific legal exposure, consult counsel licensed in the relevant jurisdiction. Vitki Data is not a law firm and does not provide legal services.