The California Legislature recently passed Senate Bill 690 (SB 690), legislation that would curtail the torrent of demand letters and litigation alleging violations of the California Invasion of Privacy Act's (CIPA) pen register and trap and trace device provision. The bill is now with Governor Gavin Newsom, who has until September 30 to sign or veto the legislation. If signed, or if no action is taken by Governor Newsom, the bill would take effect on January 1, 2027.
The bottom line: For companies defending CIPA website tracking demand letters and class actions, SB 690 is the most consequential development in this space since the pen register theory took hold, but it is far narrower than earlier drafts, leaving half of the CIPA playbook intact.
What Happened: From Broad Exemption to Narrow Carve-Out
Earlier versions of SB 690, which was originally introduced in February 2025, would have exempted from CIPA any processing of personal information undertaken for a defined "commercial business purpose," removing routine online business activity from the ambit of the statute altogether. Assembly amendments adopted July 2, 2026, abandoned that approach.
As we explained in our previous post, the enrolled bill makes a much narrower substantive change to CIPA: It amends Penal Code § 637.2, CIPA's civil remedy provision, which authorizes damages of the greater of $5,000 per violation or treble actual damages, with no injury required, to add subdivision (d)(1): "An action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General." Subdivision (d)(2) provides that the amendment applies "retroactively to any pending claim in an action commenced within two years before the operative date of that legislation." The Assembly Floor Analysis identifies that operative date as January 1, 2027. The bill is severable; it does not amend CIPA § 638.51 itself and does not make the underlying conduct lawful.
Why It Matters: What the Enrolled Bill Actually Does
The pen register theory has been the workhorse of the CIPA website tracking wave. The Assembly Appropriations Committee assumed roughly 4,000 pending CIPA actions, "the bulk of which assert pen register claims based on website tracking software."
Three features define relief:
- Only CIPA § 638.51 is affected: Claims under § 631 (wiretapping) and §§ 632 and 632.7 (eavesdropping) remain fully available to plaintiffs in class action litigation at the same $5,000-per-violation exposure. The Reform CIPA coalition told the Legislature the bill would fully relieve only 27 percent of organizations now facing CIPA litigation, leaving 61 percent unprotected.
- Enforcement shifts, rather than disappears: The California Attorney General (AG) becomes the exclusive civil enforcer for the specified § 638.51 claims arising from conduct occurring on an internet website, online application, or mobile application, and the California Department of Justice (DOJ) is projected to add six positions and approximately $1.5 million in funding beginning January 1, 2027, though the bill imposes no enforcement mandate.
- The retroactivity provision is bounded, reaching pending claims in actions commenced on or after January 1, 2025. Read literally, it would leave the oldest pending cases standing while barring newer ones.
Key Takeaways
Five aspects of SB 690 deserve particular attention:
- SB 690 is a carve-out, not complete CIPA relief: CIPA § 631 exposure is untouched; expect pen register claims to be replaced with wiretapping claims, and demands reframed accordingly.
- Retroactivity reaches filed claims, not demands: The provision bars "any pending claim in an action." An outstanding demand letter is not a pending claim; the bar removes its leverage without extinguishing anything. Expect the provision to be contested on due process and vested rights grounds; the bill's severability clause signals the Legislature anticipated that fight.
- The conduct is not legalized: CIPA § 638.51 still prohibits use of a pen register or trap and trace device without a court order or consent; the bill changes only who may enforce noncompliance.
- The courts moved first, and not cleanly: The Second District's late August 2026 tentative ruling in Variety Media, LLC v. Super. Ct., No. B350578, adopted a technology-neutral reading of the pen register definition, rejecting the telephone-only construction many demurrers rely on, while sustaining the demurrer in that case on the facts because an IP address identifies a communication's source, rather than its destination. No final opinion has issued.
- The relief is California-only: Exposure under the federal Wiretap Act/Electronic Communications Privacy Act (ECPA), Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), Florida Security of Communications Act (FSCA), Video Privacy Protection Act (VPPA), and state consumer health data privacy statutes, such as the Washington My Health My Data Act (MHMDA), also continues unaffected.
What to Do Now: Practical Compliance Tips & Strategies
While the CIPA landscape remains in flux, companies with any digital presence should work with experienced privacy counsel to take the following proactive steps:
- Triage pending matters by statutory theory and commencement date: Separate CIPA § 638.51-only matters from those asserting §§ 631 or 632 claims; the retroactivity window turns on when the action was commenced, not when the conduct occurred.
- Revisit settlement posture on pen register-only matters: Where a matter falls within the window, the calculus changes materially if the bill is signed. Coordinate with privacy counsel before agreeing to terms that would foreclose the defense.
- Harden § 631 wiretapping defenses now: Audit consent management sequencing so disclosure and consent precede tag firing, confirm banners actually gate the technologies they purport to gate, and paper vendor relationships to support service provider and party-to-the-communication defenses.
- Complete a tracking technology inventory: Catalog every pixel, tag, software development kit (SDK), session replay tool, chatbot, and analytics script across web and mobile properties, with the data elements each transmits and each recipient, then reconcile privacy notices and California Consumer Privacy Act (CCPA) opt-out mechanics against it.
- Prepare for regulator scrutiny: Assume California AG and California Privacy Protection Agency (CalPrivacy) inquiries, not private demand letters, become the principal online tracking enforcement risk beginning in 2027.
The Final Word
SB 690 would remove the single most-used claim in the California website tracking wave, but it is a carve-out rather than a reset; its retroactivity provision will be litigated, and Variety Media already signals that the underlying theory survives on better-pleaded facts. The organizations that fare best will be those that treat SB 690 as an opportunity to build the compliance and documentation record they will need under CIPA § 631, out-of-state wiretap statutes, and in front of regulators, not as a reason to stand down. Companies should engage experienced outside privacy counsel now, while the posture of pending matters can still be shaped, rather than after a demand letter or putative class action complaint arrives.
How Baker Donelson Can Help
Baker Donelson's Privacy and Cybersecurity Litigation Team has significant experience defending CIPA and similar digital privacy class actions, single-plaintiff suits, and pre-suit demand letters involving repeat plaintiff's firms and pro se litigants in this space, including Tauler Smith LLP, Vivek Shah, Swigert Law Group, Manning Law, and Joseph Sides. We have also advised hundreds of companies on website compliance, risk mitigation strategies, and litigation readiness. If you have received a demand letter or a complaint, or want to get a step ahead of this risk, contact the authors, David Oberly, Alex Koskey, CIPP/US, CIPP/E, PCIP, Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP, and MJ McMahan, directly, or another member of Baker Donelson's Data Privacy & Cybersecurity, Digital Marketing, AdTech, and Consumer Privacy Compliance, or Privacy and Cybersecurity Litigation Teams.