client advisory
California Privacy Law: Your Risk and How to Fix It
Why we are sharing this
Businesses across the country — including businesses like yours — are being sued over how their websites handle visitor data under California privacy laws. Several lawsuits have recently been filed against companies with no California locations. Because your website can be visited by California residents, your club may have exposure even though you operate entirely outside the state. This advisory explains the risk in plain terms and lists the steps that close the gap.
The Law in Brief:
The California Consumer Privacy Act (CCPA), as strengthened by the CPRA, gives California residents rights over their personal information: the right to know what is collected, to have it deleted or corrected, and to opt out of its “sale” or “sharing.” Critically, “sharing” includes sending visitor data to advertising platforms through tracking pixels — something most business websites do.
A physical presence in California is not required. The law follows the consumer, not the company’s address. The CCPA applies to for-profit businesses that do business in California and meet any one of these thresholds:
- Annual gross revenue over roughly $26.6 million (this is worldwide revenue, not California revenue);
- Buying, selling, or sharing the personal information of 100,000 or more California residents or households per year; or
- Earning 50% or more of revenue from selling or sharing personal information.
Why an Out-of-State Fitness Club Can Still Be Sued
Most independent fitness clubs fall below the CCPA thresholds — but that is not the end of the analysis, for two reasons:
- Pixel and “wiretapping” lawsuits do not depend on those thresholds. Plaintiffs’ firms are filing hundreds of claims per year (over 800 in 2025 alone) under the California Invasion of Privacy Act (CIPA) and related theories against websites whose tracking tools — Meta Pixel, Google Analytics, chat widgets, session-recording software — capture data from California visitors without consent. Any Californian who visits your site is a potential plaintiff. Recent settlements have ranged from $1.2 million to $10 million
- Fitness data raises the stakes. Class schedules, health questionnaires, injury histories, and body metrics are health-adjacent information. Cases involving health data have drawn the largest settlements, including a $3 million hospital-system settlement over Meta Pixel use.
Quick Self-Assessment
Answer each question honestly — a “yes” means the item on the right applies to you.
What a “Yes” Means
Question
Does your website use Meta (Facebook) Pixel, Google Analytics, TikTok Pixel, or similar ad/analytics trackers?
High — this is the #1 source of current lawsuits, regardless of where your club is located.
Do trackers load before a visitor accepts a cookie banner (or is there no banner at all)?
High — firing pixels before consent is the most common allegation in pixel litigation.
Does your site use live chat, session-recording tools (e.g., Hotjar), or embedded video?
Elevated — these tools are frequent targets of wiretapping-style claims.
Do online forms collect health-related info (fitness goals, injuries, health questionnaires, body metrics)?
Elevated — health-adjacent data draws extra scrutiny and larger settlements.
Is your annual gross revenue (all locations, worldwide) over ~$26.6 million?
If yes, the CCPA itself likely applies to you in full.
Could your website plausibly reach 100,000+ California residents per year?
If yes, the CCPA itself likely applies to you in full.
Compliance Action Checklist
These steps address both CCPA obligations and the pixel-litigation risk. Most can be handled through your website vendor or by us.
- 1. Audit every tracker on your site. Inventory all pixels, cookies, analytics tags, chat widgets, and session-recording tools, and document what data each one sends and to whom.
- 2. Install a consent banner that actually blocks trackers. The banner must technically prevent pixels from firing until the visitor consents. The most common lawsuit allegation is a banner that displays a choice but does not enforce it.
- 3. Honor Global Privacy Control (GPC) signals. Browsers can send an automatic opt- out signal; California requires businesses to treat it as a valid opt-out request.
- 4. Add a “Do Not Sell or Share My Personal Information” link on your homepage if the CCPA applies to you, and process opt-outs within 15 business days.
- 5. Update your privacy policy to accurately disclose what is collected, which third parties receive it, and how visitors can exercise their rights.
- 6. Set up a consumer-request process. Provide at least two methods (e.g., email and web form) for access, deletion, and correction requests, and keep records of responses.
- 7. Review your forms for health-related data. Collect only what you need, and never let tracking pixels fire on pages where health questionnaires or booking details are submitted.
- 8. Recheck annually. Thresholds adjust for inflation, regulations change, and new marketing tags creep onto sites over time.
How we can help:
As your marketing agency, we manage many of the tools involved. We can run the tracker audit, implement a compliant consent-management platform, configure GPC support, and update your site’s privacy disclosures. Contact us to schedule a compliance review of your website.
Important Disclaimer
This advisory is provided for general informational purposes only and does not constitute legal advice. Whether the CCPA or related laws apply to your business depends on your specific facts. Please consult a qualified attorney before making compliance decisions.For more information about the California Consumer Privacy Act (CCPA), visit the official California Privacy Protection Agency