The Facebook ad is built around a real problem.
Gytahnna Loffgren, the small-business owner featured in the Reform CIPA campaign, really does co-own Element Electric. Her company really was sued under California’s Invasion of Privacy Act over technology connected to its website. Independent reporting from CapRadio and ABC10 corroborates the lawsuit, and Loffgren has described facing potentially enormous legal costs simply to defend the business.
California also appears to have a genuine problem with highly scalable CIPA claims in which businesses are targeted over common website analytics, advertising pixels, chat tools and similar technology. The economics can strongly favor settlement even when a defendant believes the claim is weak.
That deserves reform.
But that is only half of what the Facebook ad is selling.
Reform CIPA is not merely asking lawmakers to protect businesses like Element Electric from one controversial type of website lawsuit. Its current lobbying page explicitly says the narrowed version of SB 690 does not go far enough and calls for additional changes involving CIPA’s wiretapping and eavesdropping provisions. The coalition advocating those broader changes includes not only small businesses such as Element Electric, but Meta.
That does not prove Meta paid for this particular Facebook ad, controls Reform CIPA or recruited Loffgren. The evidence reviewed by SHERAFY does not establish any of those things.
It does establish something more important: a legitimate small-business problem is being used to build public support for a privacy-law campaign whose consequences extend far beyond small businesses.
And Californians should separate those two questions.
Being pro-consumer does not require being pro-lawsuit.
But being against abusive lawsuits does not require giving large data companies a wider shield from consumers.
What the Reform CIPA Facebook Ad Gets Right
The ad says lawsuit abuse could shut down Loffgren’s small business and that thousands of organizations face similar threats.
The underlying small-business story is credible.
CapRadio reported that Loffgren and her husband have operated Element Electric for roughly two decades. She said the lawsuit arrived at their home in May 2026 and that the first attorney they consulted warned that lawyers handling a case of that magnitude could require a deposit around $30,000. She also said the same plaintiff had sued three other Sonoma County businesses over similar CIPA allegations.
ABC10 subsequently reported that Mou Law PC was suing Element Electric and that the complaint involved multiple alleged CIPA violations associated with website technology, including a connection to Meta.
Element Electric is not an isolated anecdote. CapRadio interviewed another small-business owner, Tami Goldsmith of Folsom Lake Heating & Air, whose company had also been sued over website technology. A defense attorney interviewed for the story said his firm had represented more than 500 CIPA defendants.
There is therefore enough independent evidence to conclude that the basic phenomenon is real.
But one word in the advertisement should still be treated carefully: “frivolous.”
That is Reform CIPA’s characterization of Loffgren’s lawsuit. Nothing reviewed by SHERAFY establishes that a court has ruled Element Electric’s case frivolous.
That distinction matters. A lawsuit can be opportunistic, economically coercive, legally questionable or eventually unsuccessful without already having been judicially determined to be frivolous.
The People Being Hurt Are Not Just “Businesses”
There is a mistake privacy advocates should avoid here too.
Small businesses are not abstract corporations floating above society. They are often a few people trying to make payroll, support families and keep an operation alive.
If a legal system allows someone to identify a commonly used website script, generate a standardized demand, threaten statutory damages and extract a settlement because defending the case costs more than paying it, that can itself become an abuse of ordinary people.
California Penal Code §637.2 currently allows $5,000 per violation or three times actual damages, whichever is greater. The statute expressly says actual damages are not a prerequisite to an action.
That structure makes sense when the underlying conduct is a serious invasion of privacy. Privacy injuries often cannot be reduced to a hospital bill or a lost paycheck.
But the same statutory structure can produce extraordinary leverage when applied repeatedly to automated website interactions whose privacy consequences are disputed.
Consumer protection should not become a business model in which the principal winners are serial litigants and attorneys while neither website users nor small businesses end up meaningfully safer.
The answer, however, is to fix that problem specifically.
The Current SB 690 Is Much Narrower Than the Bill California Originally Considered
This is one of the most important facts missing from the campaign.
Earlier versions of SB 690 contemplated much broader exemptions for information processing performed for a “commercial business purpose.” Those proposals would have affected multiple CIPA provisions, including Sections 631 and 632.
They are no longer in the bill.
The July 2, 2026 version strikes that language and now proposes changing only Penal Code §637.2.
Under the current bill, when a private defendant is accused of violating §638.51 through conduct occurring on a website, online application or mobile application, a civil action under §637.2 could be brought only by the California Attorney General.
It would also apply that limitation retroactively to certain pending claims filed within the preceding two years.
That is a substantial change, but it is nowhere near the blanket “commercial business purpose” immunity contemplated by earlier versions.
Crucially, the present bill does not remove consumers’ private remedies under CIPA’s broader wiretapping and confidential-communication provisions, including Sections 631 and 632.
As of August 22, SB 690 remains active in the Assembly. It was advanced by the Assembly Appropriations Committee 15–0 on August 13, ordered to third reading and placed on the Assembly’s August 24 third-reading file.
So this advertising campaign is appearing at a particularly important moment.
Reform CIPA Wants Lawmakers to Go Further
Reform CIPA’s action page does not simply ask Californians to support the bill currently moving through Sacramento.
It says lawmakers should “finish the job.”
Specifically, the campaign calls for reforms covering CIPA’s wiretapping, eavesdropping and pen-register/trap-and-trace provisions and seeks broader retroactive protection.
That is where the consumer implications become much larger.
There is a meaningful difference between saying:
“A statute governing pen registers should not produce $5,000 website claims whenever a local HVAC company uses ordinary analytics.”
and saying:
“We should broadly restructure the provisions Californians use when companies intercept confidential communications.”
The first proposition may be a sensible correction to an unintended litigation market.
The second could affect genuine surveillance cases.
Reform CIPA has not provided, on the campaign page reviewed for this article, the precise statutory language it wants inserted into Sections 631 or 632. Therefore it would be premature to claim that its preferred reform would eliminate a particular consumer lawsuit.
But that uncertainty is itself a reason lawmakers should not agree to a vague demand for “comprehensive reform.”
The exact language matters enormously.
There Is Also a Problem With the Campaign’s Description of the Current Bill
Reform CIPA says SB 690 currently addresses only “the pen register piece” of the pen-register/trap-and-trace provision and claims the trap-and-trace theory remains available to serial litigants.
The actual July 2 bill text is harder to reconcile with that description.
SB 690 says that an action against a private actor “for a violation of Section 638.51” arising from website or app conduct may be brought under §637.2 only by the Attorney General.
Section 638.51 is the provision prohibiting the installation or use of either a pen register or a trap-and-trace device without the required order, subject to statutory exceptions.
On the face of the statutory language, therefore, the restriction is not written merely around one half of §638.51.
There may be a more technical litigation theory behind Reform CIPA’s wording, but its public action page does not explain it.
At minimum, telling voters that trap-and-trace claims under the same provision simply remain untouched gives an incomplete picture of the legislation actually moving through the Assembly.
The “1967 Telephone Law” Argument Is Also Only Half the Story
Another centerpiece of Reform CIPA’s campaign is that CIPA was written in 1967 for telephone wiretapping and was never designed for websites.
The first half is true.
California enacted CIPA in 1967, decades before the modern web.
But the specific pen-register and trap-and-trace provisions at the center of the current website controversy were not enacted in 1967.
California added Sections 638.50 and 638.51 in 2015 through AB 929.
The Legislature expressly defined a pen register as a “device or process” capturing dialing, routing, addressing or signaling information associated with a wire or electronic communication. It similarly defined trap-and-trace devices using electronic-routing concepts.
That does not prove lawmakers intended those provisions to regulate Meta Pixel, Google Analytics or every IP-address collection tool.
There are strong textual and historical arguments going the other direction, including the law’s surrounding procedures and its origins in traditional telecommunications surveillance.
But this is precisely why saying, as a settled fact, that lawmakers were accidentally applying an untouched 1967 telephone statute to the internet is misleading.
The controversial provision was written in the internet era.
The real dispute is what the 2015 Legislature meant by “device or process,” “electronic communication,” and routing or addressing information.
And California’s appellate courts are currently confronting that question.
A Major Court Decision May Narrow These Claims Anyway
The timing gets even more interesting.
On August 21, one day before this article was written, Bloomberg Law reported that a California Court of Appeal panel had issued a tentative opinion in Variety Media v. Superior Court indicating that certain website trackers did not satisfy CIPA’s definition of a pen register because they collected addressing information associated with the source, rather than the destination, of a communication.
The opinion is tentative, not final.
The official appellate docket schedules oral argument for August 25, 2026.
The case has become important enough that other courts are already pausing CIPA cases while awaiting guidance from Variety Media.
That means California is simultaneously approaching a legislative vote and an appellate decision that could significantly clarify the very claims being cited as justification for reform.
Broad permanent exemptions should not be rushed through merely because the current law is unsettled when the courts are days away from addressing part of that uncertainty.
Why Consumers Still Need the Ability to Sue
There is another side of CIPA that disappears almost entirely from the Reform CIPA advertisement.
Sometimes the tracking is not trivial.
Sometimes private information really does end up somewhere consumers had no reason to expect.
Consider Flo Health.
The Federal Trade Commission alleged that the popular period and fertility app shared sensitive health information with third-party analytics and marketing companies, including Facebook and Google, despite making privacy promises to users. The FTC ultimately entered an order requiring Flo to obtain affirmative consent before sharing health information and to notify affected users.
Consumers also sued.
In 2025, after Google and Flurry settled before trial and Flo settled during trial, a federal jury considered the remaining CIPA §632 claim against Meta.
The jury found Meta liable.
The federal judge’s post-trial order confirms that the certified California class involved people who entered menstruation or pregnancy information into the Flo app and that the remaining claim against Meta was brought under CIPA §632.
That is not a hypothetical privacy concern.
And it is especially relevant here because Meta is publicly listed as a member of the Reform CIPA coalition.
Again, that does not mean Meta controls the coalition.
But lawmakers deciding how far to rewrite CIPA should remember that the statute is not used exclusively by serial plaintiffs targeting local contractors.
It has also been used against one of the largest data companies on Earth in a case involving deeply personal reproductive information.
The Current SB 690 Would Not Erase the Flo Case
This distinction is essential.
The Flo verdict involved §632.
The current SB 690 is focused on private website/app actions arising under §638.51.
So citing Flo does not demonstrate that the current narrow version of SB 690 would eliminate that kind of case.
It wouldn’t.
In fact, that is one reason the narrowed bill is considerably more defensible from a consumer perspective than its earlier versions.
The concern arises when Reform CIPA says lawmakers should expand the legislation again to address eavesdropping and wiretapping claims too.
Before lawmakers touch those provisions, Californians deserve exact statutory language showing that genuine cases involving sensitive communications will remain viable.
Don’t Assume the CCPA Will Let Consumers Sue Instead
One common response is that modern online privacy should simply be handled through California’s newer Consumer Privacy Act.
That sounds cleaner than it actually is.
The CCPA gives Californians significant rights and imposes important obligations on businesses. But its private civil cause of action is narrowly focused on specified unauthorized access, theft or disclosure resulting from failures to maintain reasonable data security.
California Civil Code §1798.150 expressly states that its private cause of action applies only to the violations specified there and not to other provisions of the CCPA.
For many ordinary privacy violations, therefore, the individual consumer cannot simply replace a lost CIPA claim with a CCPA lawsuit.
Enforcement falls largely to regulators.
Government enforcement is important, but it is not a substitute for every private right.
An Attorney General’s office has enforcement priorities, limited resources and institutional discretion. A person whose privacy was invaded should not automatically lose the ability to seek relief simply because the state could theoretically pursue the same conduct.
A consumer-first legal system needs both sensible regulation and meaningful individual remedies.
The Coalition Includes the Small Business in the Ad — and Meta
Reform CIPA publicly identifies its members.
The list is genuinely broad. It contains local businesses, nonprofits, chambers of commerce, health organizations and community groups.
Element Electric appears on it.
So does Folsom Lake Heating & Air.
And so does Meta.
That context should have accompanied the small-business-centered political pitch.
It is completely possible for Meta and a two-person local business to have a legitimate shared interest in eliminating meritless claims.
But they do not necessarily have the same interest in where lawmakers draw the line afterward.
A small contractor may reasonably want protection from a $5,000-per-visit claim over an advertising pixel it barely understands.
A global data company has an obvious interest in the rules governing third-party tracking, interception, consent and liability at enormous scale.
Those interests overlap until they don’t.
That is exactly why the Legislature should solve the small-business problem without automatically granting the same breadth of protection to companies whose business models revolve around collecting and monetizing information.
The Campaign’s Biggest Numbers Need Better Evidence
Reform CIPA says as many as 100,000 California businesses and nonprofits have received CIPA demand letters and that those demands have imposed more than $1 billion in costs.
It attributes those figures to an Oxford Economics study and says an average demand costs approximately $30,000 to resolve.
Those are striking numbers.
They should not currently be repeated as independently verified facts.
The Reform CIPA action page reviewed by SHERAFY does not provide the underlying methodology alongside those claims, and a public Oxford Economics report documenting those figures was not located in the sources reviewed for this article.
That does not prove the estimates are wrong.
Demand letters are often private, making them much harder to count than filed lawsuits.
But there is an enormous difference between “the campaign estimates 100,000 targets” and “100,000 targets have been independently documented.”
The first is supportable.
The second is not, based on the evidence currently available.
Meanwhile, independent reporting and statements from attorneys involved in the litigation support the narrower conclusion that the CIPA website-litigation phenomenon is substantial and involves thousands of disputes.
That is enough to justify examining reform without inflating the evidence.
Reform CIPA’s Own Website Demonstrates Why This Is Not a Simple Question
There is a particularly revealing detail on Reform CIPA’s own website.
Its privacy policy says the site may collect IP addresses, browser information, page views, button clicks, form activity, device information and location-related information.
It also says Reform CIPA may use cookies, pixels, beacons and other technologies to share information — including personal information — with third-party vendors such as Google, Yahoo and Meta for analytics, advertising and personalized advertising.
That does not mean Reform CIPA is violating CIPA.
There is no basis in the evidence reviewed to make that accusation.
Instead, it demonstrates why the policy question is harder than “old law versus ordinary website tools.”
A Californian can click on a political advertisement about limiting website-tracking lawsuits, visit the campaign’s site and encounter a privacy policy explaining that information about that visit may itself be shared through pixels with major advertising companies.
That is the modern internet.
The relevant questions are therefore not simply whether a website uses a “pixel” or “analytics.”
They are:
What information is transmitted?
To whom?
For what purpose?
Was the person clearly informed?
Did the person consent?
Is the data necessary to provide the service, or is it being used to build advertising profiles?
Is sensitive information involved?
Can the user actually stop the tracking?
Those distinctions should drive privacy law — not whether a defendant happens to call a technology “ordinary.”
What a People-First CIPA Reform Should Actually Do
California does not have to choose between serial demand-letter litigation and unlimited corporate tracking.
A better reform could protect both consumers and genuinely small organizations:
-
Give small businesses and nonprofits a meaningful safe harbor and opportunity to cure technical website violations before statutory-damages litigation begins, particularly when they are using off-the-shelf technology supplied by larger vendors.
-
Distinguish first-party functionality and basic analytics from third-party behavioral tracking. Measuring whether a page loads is not the same thing as transmitting a person’s activity across companies for profiling or advertising.
-
Preserve private lawsuits for serious privacy invasions, especially those involving health information, precise location, intimate communications, intentional interception, deceptive privacy promises or companies that continue tracking after a consumer has opted out.
-
Make statutory damages proportional without requiring consumers to prove financial loss. Privacy itself has value. Courts can be given more discretion over aggregate damages for technical or inadvertent violations while preserving substantial remedies for knowing or repeated conduct.
-
Put responsibility on technology vendors as well as unsophisticated website owners. A local electrician should not bear the entire legal risk for data flows engineered by a multinational advertising platform or software vendor.
-
Preserve a meaningful private right of action. Pre-suit notice, cure opportunities and reasonable small-business thresholds are preferable to simply transferring all enforcement power to government agencies.
That approach asks the obvious question policymakers should have asked from the beginning:
Who actually caused the privacy harm, who benefited from the data collection, and who had the power to prevent it?
The answer will not always be the small business whose WordPress plugin happened to contain a tracking script.
But it will not always be “nobody” either.
Quick Fact Check of the Reform CIPA Ad
| Claim or implication | What the evidence shows |
|---|---|
| Gytahnna Loffgren’s business is facing a CIPA lawsuit | Supported. Multiple independent reports corroborate the Element Electric lawsuit. |
| The lawsuit is “frivolous” | Not established. That is the campaign’s description; no court ruling reviewed by SHERAFY establishes it as frivolous. |
| Small businesses are facing a real wave of CIPA website claims | Supported. Independent reporting documents repeated lawsuits, defendants and mass-demand concerns. |
| 100,000 organizations have been targeted and demand letters cost more than $1 billion | Campaign estimate, not independently verified here. Reform CIPA attributes the figures to Oxford Economics, but the underlying public methodology was not located. |
| CIPA is simply a 1967 telephone law being applied to websites | Incomplete. CIPA began in 1967, but the pen-register/trap-and-trace provisions at the center of current litigation were added in 2015 and expressly reference electronic communications. |
| Current SB 690 deals only with the “pen register piece,” leaving trap-and-trace claims untouched | Difficult to reconcile with the current statutory text. SB 690 restricts private actions alleging violations of §638.51, and §638.51 covers both pen registers and trap-and-trace devices. |
| SB 690 is a broad corporate immunity bill | Not in its current form. Earlier versions were much broader. The July 2026 bill is substantially narrower. |
| Reform CIPA is simply a small-business campaign | Incomplete. Small businesses are genuine coalition members, but so is Meta. |
| Broader CIPA reform has no consumer downside | Unsupported. CIPA provisions outside the current SB 690 have been used in substantial consumer privacy cases, including the Flo Health litigation against Meta. |
The Bottom Line
The small-business owners in these ads should not be dismissed as props simply because larger companies share their policy goal.
Their problem appears real.
California should fix it.
If a local electrician, HVAC contractor, church or nonprofit can be dragged into expensive litigation over a commonplace website component installed with little understanding of the underlying data flow, the law is failing to distinguish between technical noncompliance and meaningful privacy abuse.
But lawmakers should solve that problem at its source.
They should not use injured small businesses as the emotional justification for quietly removing rights from the very people privacy law is supposed to protect.
The current, narrowed SB 690 is much closer to a targeted solution than the broad version California considered earlier. Even it deserves scrutiny because it removes private enforcement of website/app §638.51 claims and places that authority with the Attorney General.
What deserves considerably more skepticism is the push to broaden the bill again into CIPA’s wiretapping and eavesdropping provisions before the public has even been shown the exact language.
The clearest evidence for why is sitting inside the same story.
A small California business can plausibly be victimized by an opportunistic CIPA lawsuit.
And California consumers can plausibly be victimized when their intimate information is quietly transmitted to enormous data companies.
Both things can be true.
A law written for people should protect both groups.
It should not force Californians to choose between plaintiffs’ lawyers extracting settlements from small businesses and corporations extracting data from everyone else.
References and Further Reading
Primary Law and Court Records
California Legislature — Current Text of SB 690: Crimes: Invasion of Privacy — The controlling July 2, 2026 legislative text. Shows the removal of earlier broad commercial-purpose language and the current restriction on private §638.51 website/app actions.
California Legislature — Current Status of SB 690 — Official legislative history and floor status, including the August 13 committee action and August 24 third-reading file.
California Legislature — AB 929 and the 2015 Pen-Register/Trap-and-Trace Provisions — Primary legislative record showing that §§638.50–638.51 were added in 2015 and expressly cover wire and electronic communications.
California Civil Code §1798.150 — CCPA Private Right of Action — Shows the limited circumstances in which California consumers can bring private CCPA actions, principally specified data-security breaches.
California Court of Appeal — Variety Media v. Superior Court Docket, B350578 — Official appellate docket for the pending case addressing CIPA’s application to website tracking; oral argument is scheduled for August 25, 2026.
Frasco v. Flo Health — Amended Federal Post-Trial Order — Primary federal court record detailing the §632 claim against Meta and the jury proceedings involving California Flo users.
Government Consumer-Protection Evidence
Federal Trade Commission — Flo Health Settlement Over Sharing Sensitive Health Data — FTC account of allegations that Flo shared sensitive health information with Facebook, Google and others despite representations made to users.
Federal Trade Commission — Complaint Against Flo Health — Primary complaint describing the categories of reproductive and health information collected and the third-party analytics relationships at issue.
Independent Reporting
CapRadio — Waves of Lawsuits and Internet Tracking: CIPA in the Digital Age — Detailed independent reporting on Element Electric, Folsom Lake Heating & Air, the growth of CIPA litigation and proposals to protect small firms without broadly eliminating consumer remedies.
ABC10 — Thousands of Businesses Hit With Lawsuits Over California Privacy Law — Additional reporting on Element Electric’s lawsuit and the debate over the narrowed version of SB 690.
Bloomberg Law — Variety Poised for Narrow Win in Web Tracker Pen Register Suit — August 21, 2026 reporting on the appellate court’s tentative interpretation ahead of oral argument. The tentative opinion is not yet a final decision.
Reform CIPA Campaign Materials
The following are interested-party sources and are included to document what the campaign itself is claiming, not as independent verification.
Reform CIPA — Tell Your Legislator: Finish the Job on CIPA Reform — The landing page promoted by the advertisement. Contains the coalition’s estimates and its explicit request to broaden reform beyond the current SB 690.
Reform CIPA — Coalition Members — Public membership list showing both Element Electric and Meta among the coalition’s members.
Reform CIPA — Privacy Policy — Describes the campaign site’s own use of cookies, pixels, beacons and third-party technologies for analytics and advertising, including potential information sharing with Meta, Google and Yahoo.
Editorial currency note: SB 690 is active legislation and Variety Media is a pending appellate case. Legislative language, vote status and the court’s tentative position may change after August 22, 2026. This article should be updated if SB 690 is amended or voted on, or when the Court of Appeal issues its final Variety Media opinion.



