Anonymous small-business accountability report - Reviewed regularly
Johnson Dalal PLLC reviews: what small businesses should know
A website-privacy claim can turn ordinary analytics or marketing tools into an urgent legal threat. This independent report examines Johnson | Dalal, PLLC's publicly reported role in that litigation wave, the settlement pressure it creates, and the questions every small-business owner should ask.
This is not a review of legal services received as a client. It is anonymous public-interest commentary written from a small-business perspective and grounded in public sources.
Why this page exists
The letter arrives before the owner understands the theory
For many small businesses, the first warning is a lawsuit or demand alleging that familiar website tools acted like illegal surveillance devices. The deadline is short. The statute sounds criminal. The cost of hiring counsel can quickly compete with the amount needed to make the matter disappear.
This site intentionally excludes every private name, business identifier, case detail, settlement term, consultation, and communication that could identify anyone. The purpose is not to relitigate one dispute. It is to give the next owner useful context before answering a demand under pressure.
Published legal and compliance commentary has specifically described Johnson | Dalal as pursuing Florida website-privacy claims against businesses. Read that characterization in its original context at Captain Compliance. This site independently evaluates the legal theory and economics using statutes, court reporting, and government records.
Who this report is about
Johnson | Dalal, PLLC
The information below is published by the firm and corroborated by the Florida Bar. It is included so readers can distinguish this firm from similarly named businesses and verify the subject for themselves.
- Primary listing name
- Johnson | Dalal, PLLC
- Also known as
- Johnson | Dalal, The Intellectual Property Law Firm, PLLC; Johnson Dalal PLLC
- Primary office
- 111 N. Pine Island Road, Suite 105
Plantation, Florida 33324 - Phone
- (954) 507-4500
- Website
- patentandtrademarklaw.com
- Verification
- Firm contact page and Florida Bar directory
What this Johnson Dalal PLLC review covers
Litigation conduct, not the firm's client services
People searching for a Johnson Dalal review or Johnson Dalal reviews will mostly find commentary about patent and trademark work by clients of the firm. Those reviews address a different relationship. This Johnson Dalal PLLC review is about the experience of small businesses placed on the opposing side of website-privacy claims and about the public legal framework behind those claims.
For balance, readers can inspect a public review aggregator such as Birdeye, which displays third-party client reviews. We do not reproduce, endorse, or dispute those reviewers' personal experiences. A positive trademark-service review does not answer the questions examined here, and this report does not answer whether the firm provides good trademark service.
How the pressure works
Four steps can turn a disputed theory into an expensive deadline
The public record does not require a reader to accept anyone's rhetoric. The statute, procedural setting, and court split explain the leverage.
- 01
An ordinary website tool becomes the alleged device
Common website services are characterized as pen-register or interception technology under Florida's communications statute.
Read Fla. Stat. 934.31 - 02
The right to bring a private suit is contested
Florida's civil-remedy section lists Sections 934.03 through 934.09. It does not list the pen-register provision in Section 934.31.
Read Fla. Stat. 934.10 - 03
The courts have not spoken with one voice
Published legal analysis describes decisions allowing some website theories to proceed and other decisions requiring a closer examination of the underlying technology.
Sidley analysis IAPP analysis - 04
Defense cost can overwhelm the practical dispute
Small-claims procedure limits the damages demand, while the civil-remedy section separately provides attorney fees and costs. That changes the settlement calculation.
Florida small-claims rule
The settlement equation
Paying can cost less than proving you are right
That does not establish that any particular claim is invalid. It explains why merits and outcomes can separate: a business may rationally pay for certainty even when it has substantial defenses.
Johnson Dalal scam searches
Is Johnson Dalal a scam?
What the current record does not establish
- A verified total count of website-privacy cases filed by the firm.
- That every claim brought by the firm is legally invalid.
- That client reviews about unrelated patent or trademark work are false.
- That any lawyer associated with the firm committed a crime.
If your business receives a claim
Slow the panic. Preserve your options.
This is general information, not legal advice. Deadlines and insurance rights are fact-specific, so qualified counsel should evaluate your matter.
- 1Preserve everything.
Keep the complaint, envelope, emails, website configuration, consent settings, tag history, and vendor records.
- 2Calendar every deadline.
Do not assume an informal conversation pauses a court response date.
- 3Notify every possible insurer.
Late notice or voluntary payment can damage coverage that might otherwise fund a defense.
- 4Get a scoped legal assessment.
Ask for the cost of a focused review of service, venue, standing, the private right of action, consent, and the technology alleged.
- 5Do not destroy or quietly rewrite evidence.
Prospective compliance changes may be wise, but preserve the historical state first.
Do not take our word for it
Verify the record yourself
Strong criticism should be easy to check. These starting points let a reader separate statutory text, public filings, commentary, and opinion.
Common questions
Johnson Dalal PLLC review FAQ
Is this site affiliated with Johnson | Dalal, PLLC?
No. It is an independent, anonymous public-information resource.
Is this a review from a Johnson | Dalal, PLLC client?
No. It examines the firm's publicly reported role in website-privacy litigation from the small-business side of that process.
Does this site claim Johnson | Dalal, PLLC committed a crime?
No. Moral criticism and the word scam appear only as clearly labeled opinion about the litigation model. No criminal conduct is asserted as fact.
Why are the operators anonymous?
To keep attention on the public record and protect private people and businesses from further exposure. No private case details are published.
Complete resource
Detailed guides
Everything formerly spread across separate pages now lives below.
- What These Lawsuits Are The statute, the theory, and the current split in the courts, including the rulings that have gone against businesses.
- Why These Cases Settle The math that drives the outcome. Why a defense quote routinely exceeds the worst realistic result on the merits.
- First Steps After a Claim The practical checklist. What to preserve, who to notify, and the sequencing mistake that can forfeit your best defense.
- Consent Setup, Opt-in Versus Opt-out The technical heart of it. Why a working consent platform can still fail the scan, and how to check your own site.
- Insurance The tender you probably have not made yet. Which policies may respond, the deadlines that void coverage, and a letter template.
- Other States The parallel statutes in California, Pennsylvania, and beyond, for readers sued outside Florida.
- About and Disclaimers Who publishes this and what it is not.
- Privacy No cookies, visitor analytics, tracking pixels, or automatic third-party resources; submissions are privately moderated.
Detailed guide
What These Lawsuits Are
If you have been served, you are probably looking at a claim under a Florida statute that was written for something else entirely. This page explains what that statute is, how it came to be pointed at ordinary website tools, and how courts have actually ruled so far, including the rulings that have gone against businesses like yours.
The statute
Florida’s Security of Communications Act is Chapter 934 of the Florida Statutes. It is Florida’s wiretap law, an all-party consent statute modeled on the federal Wiretap Act, and it generally prohibits intercepting, disclosing, or using someone’s communications without the consent of all parties (Fisher Phillips).
The specific provision driving the current wave is Section 934.31, the pen register and trap and trace section. A pen register historically recorded the numbers dialed from a phone. The statute says no person may install or use a pen register or a trap and trace device without first getting a court order, subject to exceptions including where the user has consented (Fla. Stat. 934.31, official text).
The theory
Plaintiffs’ counsel argue that ordinary website services work like a pen register or trap and trace device when they capture a visitor’s identifiers or activity and transmit them to a third party. On that reading, a business using common website services without prior consent has installed a tracking device without the required authorization (Hunton Andrews Kurth, Sidley).
There is a serious textual problem with applying the statute this way, and it is worth knowing. The civil right to sue under Chapter 934 is created by a different section, 934.10, and by its own terms that section grants a private cause of action for violations of Sections 934.03 through 934.09. Section 934.31, the pen register provision, is not in that list (Fla. Stat. 934.10). Whether a private plaintiff can sue at all under 934.31 is therefore contested, and a Florida appellate court has not squarely settled it. Ask your lawyer about this. It is a live defense grounded in the plain text of the statute.
The history
This is not the first time the wiretap theory has been aimed at websites. An earlier wave targeted tools that record how visitors interact with webpages. In Jacome v. Spirit Airlines, a Florida circuit court dismissed such a claim. The court reasoned, among other grounds, that capturing website interactions did not intercept the contents of a communication and that the software was not a device under the act (Jacome order, later federal order citing Jacome). Federal courts in Florida followed that reasoning to dismiss similar session-replay cases. The pen register theory is in part an attempt to get around those dismissals with a different section of the same statute.
Where the courts stand now
The honest answer is that the law is unsettled and the rulings cut both ways. A guide that told you the theory is doomed would be misleading you.
On the plaintiffs’ side, a federal court in the Middle District of Florida declined to dismiss FSCA claims in W.W. v. Orlando Health, distinguishing the earlier session-replay dismissals because the pixels there allegedly shared the substance of a communication, sensitive health information, with a third party (Sidley, National Law Review). That ruling is widely credited with triggering the surge of demand letters that followed.
On the defense side, courts have pushed back on the underlying pen register idea. In a California case applying the parallel state statute, Gabrielli v. Insider, a federal court dismissed a pen register claim and urged courts to actually analyze the underlying technology rather than assume it fits the statute (IAPP). A Florida firm summarizing the landscape put it plainly: no court has ruled definitively on whether website tracking fits an FSCA claim, and some of these cases are surviving early motions (Gunster).
What a plaintiff typically pleads
Described generically, a complaint of this kind alleges that a website service captured a visitor’s identifiers or activity, transmitted information to a third party, and operated without prior consent. Supporting material may include a technical scan that characterizes the site’s behavior. How a scan like that can be misleading, and why a business with a properly configured consent platform can still show up as having none, is explained in the consent setup section.
Detailed guide
Why These Cases Settle
This is the page most likely to change what you decide to do, so it is worth reading slowly. The reason these cases settle has very little to do with whether the legal theory is strong. It has to do with math.
The damages are small and capped
These suits are typically filed in Florida county court under the small claims rules. Those rules place a limited monetary threshold on the principal claim, while treating costs, interest, and attorney fees separately (Florida Bar). The damages themselves come from the Florida Security of Communications Act, which provides a statutory damages formula (Fla. Stat. 934.10, official text). As a general matter, a judgment cannot exceed what the complaint actually demands. So the number in the demand is usually a modest, bounded figure.
The attorney fees are not capped, and they sit on top
Here is the part that catches almost everyone. The same statute that sets those small damages also awards the winning plaintiff a reasonable attorney fee and litigation costs, separately from the damages (Fla. Stat. 934.10). That fee award sits outside the threshold for the principal demand. The statute and procedural rules treat costs, interest, and attorney fees separately (Gunster).
That is the whole mechanism. Your maximum exposure is not the damages figure you see in the complaint. It is that figure plus a fee award that grows every hour the case stays alive, and the fee award can dwarf the damages. This is the single most commonly misunderstood point in these matters, and it is the reason a defense lawyer’s quote to fight the case can be larger than the worst realistic outcome on the merits.
The asymmetry
A complaint of this kind is cheap to produce and can be filed in volume. Much of the text is reused from one case to the next. Defending a single case, by contrast, means paying a lawyer by the hour to answer, to raise the right defenses in the right order, and possibly to argue a motion. One side is running a low-cost, repeatable process. The other side is paying retail, one case at a time. That imbalance, not the strength of the claim, is what sets the price of peace.
Running your own numbers
Lay it out plainly for your own situation:
- The settlement number being asked for, in writing.
- A defense lawyer’s estimate to take the case through a motion to dismiss.
- Your best estimate of the fee exposure if you fight and lose, remembering it is uncapped.
- The strength of your specific defenses, above all personal jurisdiction if you are based outside Florida (see your first 72 hours).
Weigh those against each other. For many small businesses the settlement number is set, deliberately, just below what a competent defense would cost. That is not an accident of the numbers. It is the point of them.
Detailed guide
First Steps After a Claim
This is a checklist, not an essay. Work it in order. The steps are ordered on purpose, because at least one of them can be forfeited by doing a later step first.
1. Preserve everything before you change anything
Before you touch the website, preserve a complete copy of the site, its relevant configuration, and related third-party records. Export or screenshot the current state so it is fixed in time.
Fixing the website going forward is fine and expected. Destroying the record of what it looked like before is not. Deleting emails, internal messages, or configuration history after you have been served can be treated as spoliation of evidence, and courts can sanction it. That duty reaches your internal chat tools too, not just your email. It also does you no practical good: the third-party vendors whose tools are at issue keep their own copies regardless of what you delete on your side.
2. Docket every date
Find the response deadline and the date of any pretrial or case-management conference, and put both on a calendar the day you are served. Confirm whether the assigned division allows a remote appearance so you are not forced to travel for a short hearing. Many of these are filed in county court under Florida’s small claims rules, which move on their own schedule.
3. Give written notice to every insurance carrier immediately
Notify each carrier that could conceivably cover this, in writing, right away. Do not wait until you have decided what to do about the case. Notice deadlines are often short, and late notice can void coverage that you paid for. Which policies might respond, and what to put in the notice, is covered on the insurance section.
4. Do not contact the other side until steps 1 through 3 are done
It is natural to want to call and get it over with. Preserve, docket, and tender to your carriers first. A carrier that agrees to defend may take the conversation off your plate entirely, and anything you say or pay before that can complicate coverage.
5. Understand the personal jurisdiction sequencing trap
If your business is based outside Florida, whether a Florida court can exercise personal jurisdiction over you is often your strongest single argument. It is also the easiest one to throw away by accident.
Under Florida law, a defendant can waive a personal jurisdiction challenge by first asking the court for other relief that is inconsistent with the position that the court has no power over you. In plain terms: raise the jurisdiction question in the right order, at the start, before you seek other things from the court. This is the highest-value place to spend a small amount of paid attorney time, because getting the order wrong can forfeit the defense before it is ever argued.
6. Consider limited-scope representation
You do not have to choose between representing yourself and hiring a lawyer for a full-blown defense. Many lawyers will take a defined, limited task, for example reviewing the complaint, drafting a specific motion, or advising on the jurisdiction sequencing above, for a fixed fee. That is called limited-scope or unbundled representation. When you call, ask directly whether the lawyer offers it and what a single defined task would cost.
7. Look up the plaintiff and the filing firm in the public record
Court filings are public. Search the county clerk’s public case index for the plaintiff’s name and the filing firm’s name, and you can see how many similar cases they have filed and how those cases resolved. For cases filed in Broward County, use the Broward County Clerk public case search. Each Florida county clerk runs its own search, so check the clerk for the county where your case was filed. Reading the pattern of filings tells you a great deal about what you are actually dealing with, and it is all on the record.
Detailed guide
Consent Setup, Opt-in Versus Opt-out
This is the most technical page on the site, and also the one that resolves the confusion most business owners feel when they get one of these letters: my site has a cookie banner, so how can it be tracking without consent? The answer is that there are two different models of consent, and a scan can be measuring you against the one you did not build for.
Two different models
Privacy frameworks use different consent models. In an opt-out setup, website services load by default and the visitor can decline afterward. In an opt-in setup, nonessential services wait for affirmative consent. The distinction, not the identity of any particular provider, is what matters here.
These lawsuits allege something different. They are built on an opt-in model, in which affirmative consent must be obtained before any tracking tool is installed or any data is transmitted. That is pre-consent tag blocking: nothing fires until the visitor says yes. It is the model that European law requires, and it is not how most US consent platforms are configured out of the box.
Why a working platform scans as none
Here is the reconciliation, and it is worth saying slowly because it is the single most useful technical point on this site. A business can have a functioning, correctly configured, fully paid-for consent platform, and still appear in a plaintiff’s scan report as having no consent management at all. Both statements are true at the same time, because they are measuring different things. Your platform is doing exactly what an opt-out configuration does: letting tags load and offering a way to opt out. The scan is looking for the opt-in behavior, tags blocked until consent, and correctly reporting that it is not there. The scan is not necessarily lying. It is answering a different question than the one your platform was set up to answer.
Why scanners miss privacy centers
There is a second technical wrinkle. Many consent interfaces and privacy centers are rendered in the browser, drawn by script after the page loads. Automated scanners and crawlers that read the initial page often do not execute or wait for that, so a privacy control that a human visitor plainly sees can be invisible to the tool generating the scan. That gap can make a site look less compliant in a report than it is in a browser.
How to test your own site honestly
You can see what your site actually does, and you should, before you accept anyone’s characterization of it. A straightforward, honest test:
- Open a fresh browser profile with no history or stored consent, or a private window.
- If the claim concerns a specific state, use a VPN endpoint in that state, since behavior can vary by region.
- Open the browser developer tools and watch the network activity as the page first loads, before you interact with any banner.
- Identify which tags and third-party requests fire before any consent interaction. Those, if any, are what the opt-in theory is about.
That test tells you the truth about your own site, which is a better footing than either the plaintiff’s scan or a vendor’s reassurance.
Remediation and its tradeoffs
If you decide to move toward pre-consent blocking, understand the cost as well as the benefit. Blocking tags until consent is the configuration these suits are built around, and it reduces that exposure. It also means you lose analytics and advertising data for every visitor who does not affirmatively consent, which is often a large share of them. Marketing measurement, remarketing audiences, and conversion tracking all degrade. This is a real business tradeoff, not a pure compliance upgrade, and it is worth deciding deliberately rather than flipping a switch in a panic.
Detailed guide
Insurance
Before you pay a settlement out of your own pocket, find out whether you already bought insurance that covers this. Many businesses have, and do not realize it. This page is written for a non-lawyer and walks through how to tender the claim and the mistakes that can quietly forfeit coverage.
Your general liability policy may already cover it
A standard commercial general liability policy has two main coverage parts. Coverage B, called Personal and Advertising Injury, lists specific offenses it covers, and one of them is the oral or written publication of material that violates a person’s right of privacy (IRMI). A lawsuit alleging that your website published or transmitted a visitor’s private information plausibly falls inside that enumerated offense. It is not guaranteed, and carriers argue about it, but it is a real and common basis for coverage that is easy to overlook because people assume a wiretap claim is not an insurance matter.
The duty to defend is broader than the duty to indemnify
This is the single most important insurance concept for you to hold onto. An insurer has two separate obligations: a duty to defend the lawsuit, and a duty to indemnify, meaning to pay a judgment or settlement. The duty to defend is broader, and it is triggered by what the complaint alleges, not by whether the claim ultimately succeeds (National Law Review). In many states, if even one allegation in the complaint is potentially covered, the insurer must defend the entire suit (IRMI). The exact rule depends on the law of the state governing your policy, so have your lawyer confirm it, but the practical upshot is that a carrier may owe you a defense even if it thinks the case is weak. A defense funded by your insurer changes the economics in the why they settle section entirely.
Two traps that void coverage
The second trap is the voluntary payments provision. Most policies say that if you settle or pay a claim without the carrier’s consent, the carrier does not have to reimburse that payment. In plain terms: if you settle first and tell your insurer later, you may have given up coverage for the money you paid. That is why notice and tender go out before any settlement discussion, not after.
What to put in a tender
A tender is simply a written request that the carrier defend and cover the claim. Include:
- A copy of the complaint or demand letter.
- Your policy number.
- A short statement of which coverage part you are relying on, for example Coverage B, Personal and Advertising Injury, for publication of material that violates a right of privacy.
- A request for the claim number, the name of the assigned adjuster, and a written coverage position by a specific date.
If the carrier reserves rights or denies, ask it to state, in writing, the specific policy provisions it is relying on. That preserves the record and forces the carrier to commit to a position you and your lawyer can then evaluate.
Also tender to E and O and cyber policies
If you carry errors and omissions or a cyber liability policy, tender to those as well. A common feature of these policies is a self-insured retention, an amount you pay before coverage kicks in, and that retention can be larger than the whole value of a small claim. Even when the retention means the policy will not pay anything on a small matter, making the tender is a formality worth completing, so the claim is on record with every carrier that could conceivably respond.
A plain-language tender letter template
Fill in the bracketed parts. Send it in writing, keep a copy, and note the date.
[Date]
[Carrier name and claims address]
Re: Notice of claim and tender of defense and indemnity Policyholder: [Your business legal name] Policy number: [Number] Claimant: [Plaintiff name from the complaint]
To the claims department:
[Your business] has been served with the enclosed [complaint / demand letter], dated [date]. We are providing notice of this claim and tendering it to [carrier] for defense and indemnity.
We believe this claim is potentially covered under Coverage B, Personal and Advertising Injury, including the offense of oral or written publication of material that violates a person’s right of privacy, and under any other applicable coverage part of the above policy.
Please confirm within [for example, 14] days: the claim number, the adjuster assigned, and [carrier]‘s written coverage position, including your agreement to defend. If [carrier] reserves rights or denies coverage in whole or in part, please identify in writing the specific policy provisions relied upon.
We have not authorized any payment or settlement and will not do so without the carrier’s consent, consistent with the policy.
[Name, title] [Contact information]
Detailed guide
Other States
Florida is one front in a larger, multi-state trend. If you were sued somewhere else, or you operate in several states, this is a short orientation to the parallel laws and where the filings are concentrated.
California
California is the origin and the largest source of these filings. The California Invasion of Privacy Act, Penal Code Section 630 and following, includes a wiretapping section (631), an eavesdropping section (632), and a pen register and trap and trace section (638.51) that mirrors the theory now used in Florida. CIPA carries a private right of action with statutory damages that may be available without proof of actual harm (California Penal Code 637.2, Spencer Fane, Hunton). As in Florida, the courts are split, and the reach of the pen register section remains unsettled (Holland and Knight).
Pennsylvania
Pennsylvania’s Wiretapping and Electronic Surveillance Control Act, 18 Pa.C.S. Section 5701 and following, is an all-party consent statute with statutory civil damages and potential fees. What opened the door to website claims there was Popa v. Harriet Carter Gifts, in which the Third Circuit held that a third-party marketing vendor receiving a visitor’s site interactions could be intercepting them, and that the interception occurs at the visitor’s browser (Morgan Lewis). Later Pennsylvania rulings have also favored defendants, so the picture there, too, is mixed (Fisher Phillips).
Where the volume is
California remains the center of gravity, and legal commentators now describe Florida as the most important second front, with filing volume rising fast (Barnes and Thornburg, Privacy Daily). Claims also appear under the federal Wiretap Act and under statutes in other all-party consent states. The through-line is the same everywhere: an older surveillance statute, a private right of action with fixed statutory damages and fee shifting, and common website tools recast as interception.
Detailed guide
About and Disclaimers
Who publishes this
This site is published anonymously as an independent small-business information project. It is written in the plural because it presents a shared public-record analysis, not an identifiable person’s story. No private case, business, client, settlement, or consultation is described here. There is no product or service behind the site, and there is nothing to buy.
What this site is not
This site is not legal advice. Reading it does not create an attorney-client relationship, and nothing here is a substitute for advice from a lawyer licensed in the state where your case is filed. The people who publish this are not attorneys and cannot give legal advice. We will not respond to requests for legal advice, because we are not able to give it and it would be wrong to pretend otherwise.
The facts on this site are drawn from public sources, statutes, court records, government sites, and named reporting, and each is linked so you can read the original. Where we offer an opinion, we label it as our view and base it on the sourced facts shown alongside it.
Non-affiliation
Detailed guide
Privacy
It would be strange for a site about tracking to track you, so it does not.
This site sets no cookies and runs no visitor analytics, tracking pixels, or server-side page counting. It loads no automatic third-party fonts, scripts, videos, embedded social content, or widgets. Its Content-Security-Policy blocks third-party origins. There is no public contact email.
The Small Business Experiences form collects only the information a person chooses to submit. A private contact email is optional, used only for editorial verification, and never published. Submissions remain private until an editor approves a redacted version. The application does not store submitter IP addresses. It may hold a one-way, short-lived IP-derived value in memory to limit automated abuse; that value is lost when the application restarts.
The origin web server keeps its visitor access log turned off. The site is delivered through Cloudflare, which necessarily receives network information, including an IP address, to proxy and protect each request. Cloudflare may process or retain operational and security data under its own policies. Its browser analytics injection is disabled for this site, so no Cloudflare analytics script runs in your browser.
Firsthand accounts
Small-business experiences
This moderated section is for firsthand experiences involving Johnson | Dalal, PLLC. Published accounts are edited for privacy and clarity. They are personal accounts, not findings by this site, unless an editor's note links supporting public records.
No experiences have been published yet. Submissions are reviewed before appearing here.