Just the Facts · Article
When the Court Reins One In: the Vivek Shah Vexatious-Litigant Ruling
A prolific CIPA website-privacy filer was just declared a vexatious litigant. Here's what that does — and, just as important, what it doesn't — for the demand-letter wave.
On July 20, 2026, a federal judge declared Vivek Shah — one of the most prolific CIPA / website-privacy filers — a "vexatious litigant." It is a real and welcome check on an abusive filer. It is not the end of the CIPA demand-letter business, and it does not make the underlying issue go away.
What the court actually did
In Shah v. Crain Communications (Central District of California, Judge R. Gary Klausner), the court found Shah had filed 29 lawsuits in under five years — including "seven nearly identical complaints in seven months" — and then abandoned each case the moment a defendant pushed back, a pattern the court read as trying to "extract a quick settlement without ever testing whether the claim actually held up." Several complaints appeared copied from unrelated class actions with the class-action parts simply cut out. Applying the Ninth Circuit's De Long test, the judge ordered that Shah must now get a judge's pre-approval before filing new CIPA or related digital-privacy suits.
What it does NOT do (read this part)
- It is narrow. The pre-filing screen covers only CIPA / digital-privacy claims, only in that one district (the Central District of California). Shah can still file in other courts or on other theories, and every other filer is completely unaffected.
- It did not rule CIPA meritless. The court sanctioned Shah's behavior — serial filing and abandonment — not the legal validity of the wiretap / pen-register theory. Analytics-before-consent was not blessed as lawful.
- The wave continues. As the coverage put it, for every filer a court reins in, others are “still filing the same template complaint this week.” The demand-letter economy doesn't depend on any one person.
The useful lessons for a business
- If a letter comes, the filer's whole history matters. Courts respond to the pattern, not just the one case in front of them — compiling a plaintiff's full litigation record is what turned the tide here.
- Going on offense can work. One defendant answered a Shah letter by filing its own declaratory-judgment action asking a court to confirm that standard analytics don't violate CIPA — choosing its own timing, forum, and framing instead of settling.
- But the cheapest defense is still not being a target. A block-first consent model — no third-party tracker fires until the visitor opts in — means an automated scan captures nothing pre-consent, so there is no violation to allege, regardless of which filer is active or how the courts eventually rule.
The honest read: this ruling is a good sign that courts will punish the worst actors, not a reason to relax. The underlying exposure is unchanged, and so is the smart move — remove the evidence, and you're off the menu.
Background information, not legal advice. This describes one 2026 ruling and its narrow scope; if you've received a demand letter, talk to a qualified attorney.
Sources
- National Law Review — ‘A Very Bitter Pill to Swallow: Vivek Shah Declared Vexatious Litigant’ (2026)
- Shah v. Crain Communications, Inc., No. 2:26-cv-03070-RGK-CTS (C.D. Cal. July 20, 2026)
- De Long v. Hennessey, 912 F.2d 1144 (9th Cir. 1990)
More from Just the Facts
- Is Any of This Actually Real?
- How Real Is the Threat? A By-the-Numbers Risk Assessment
- Who's Really Suing — CIPA Website-Wiretap Filers
- The Demand-Letter Economy
- Verifying Licensed Images, Fonts & Video
- Copied Content: Plagiarism, Copyright & the Hidden SEO Risk
- Passwords, Backups & VPNs: the security that decides whether a breach sinks you
- Website accessibility is the most-sued thing on the internet
- Your cookie banner probably isn't doing anything
- The instructions your website isn't giving the browser
- Three real demand letters, eighteen years apart
- The privacy signal your site is ignoring
- Code you didn't write, running on your site tonight
- Three documents nearly every site gets wrong
- What an accessibility statement is actually for
- Cookies without locks
- Anyone can send email as you