Skip to Main Content
Publications

SB 690 Signed Into Law - What It Means For CIPA/Web Tracking Litigation

California Governor Gavin Newsom signed into law Senate Bill 690 (SB 690) on September 30, 2026, eliminating the private right of action for the California Invasion of Privacy Act (CIPA) "pen register" and "trap and trace" claims arising from conduct on an internet website, online application, or mobile application. Only the California attorney general (AG) may now bring such an action. The law takes effect January 1, 2027, and applies retroactively to pending claims in actions commenced on or after January 1, 2025.

The bottom line: For companies defending CIPA web tracking class actions or negotiating demand letters, this is the most consequential development in the litigation since the pen register theory took hold, and it is narrower than its billing, as the Governor said in signing it.

What Happened: From Broad Exemption to Narrow Carve-Out

The enacted law makes a single substantive change. It amends Penal Code § 637.2, CIPA's civil remedy provision, which authorizes the greater of $5,000 per violation or treble actual damages with no injury required, to add subdivision (d)(1): "An action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General." New subdivision (d)(2) makes that limitation retroactive to pending claims in actions commenced within two years before the operative date. The amendment is severable; it does not amend CIPA § 638.51 itself, and it does not make the underlying conduct lawful.

That is far less than the bill once promised. Earlier versions would have exempted from CIPA any processing of personal information undertaken for a defined "commercial business purpose"; amendments adopted on July 2, 2026, abandoned that approach. The bill then cleared the California legislature on August 28 without a dissenting vote in either chamber.

Why It Matters: What SB 690 Actually Does

The pen register theory has been the workhorse of the CIPA web tracking wave; the Assembly Appropriations Committee assumed roughly 4,000 pending CIPA actions, "the bulk of which assert pen register claims based on website tracking software."

Three features define relief:

  • Only CIPA § 638.51 is affected. Claims under § 631 (wiretapping) and §§ 632 and 632.7 (eavesdropping) remain fully available to plaintiffs in class action litigation at the same $5,000 per-violation exposure. The Reform CIPA coalition told the legislature the bill would fully relieve only 27 percent of organizations now facing CIPA litigation, leaving 61 percent unprotected.
     
  • Enforcement shifts, rather than disappears. The California AG becomes the exclusive civil enforcer, and the California Department of Justice (DOJ) is projected to add six positions and approximately $1.5 million in funding beginning January 1, 2027, though the bill imposes no enforcement mandate.
     
  • The retroactivity provision is bounded. It reaches pending claims in actions commenced on or after January 1, 2025. Read literally, it would leave the oldest pending cases standing, while barring newer ones.

The governor's signing message matters as much as the statute. It describes the measure as addressing "the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses," also adding that "additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants," and urged "the Legislature to take this on next year." CIPA § 631 reform is now a live prospect for the 2027 session, and this year's relief is understood by its signer to be partial.

Key Takeaways

Five aspects of SB 690 deserve particular attention:

  • SB 690 is a carve-out, not complete CIPA relief. CIPA § 631 exposure is untouched; expect pen register claims to be replaced with wiretapping claims, and demands reframed accordingly.
     
  • Retroactivity reaches filed claims, not demands. The provision bars "any pending claim in an action." An outstanding demand letter is not a pending claim; the bar removes its leverage without extinguishing anything. Expect the provision to be contested on due process and vested rights grounds; the bill's severability clause signals the legislature anticipated that fight.
     
  • The conduct is not legalized. CIPA § 638.51 still prohibits use of a pen register or trap and trace device without a court order or consent; the bill changes only who may enforce non-compliance.
     
  • The courts have not resolved the underlying question. The Second District's late August 2026 tentative ruling in Variety Media, LLC v. Super. Ct., No. B350578, adopted a technology-neutral reading of the pen register definition, rejecting the telephone-only construction many demurrers rely on, while sustaining the demurrer in that case on the facts because an IP address identifies a communication's source, rather than its destination. No final opinion has been issued.
     
  • The relief is California-only. Exposure under the federal Wiretap Act/Electronic Communications Privacy Act (ECPA), Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), Florida Security of Communications Act (FSCA), Video Privacy Protection Act (VPPA), and state consumer health data privacy statutes, such as the Washington My Health My Data Act (MHMDA), also continues unaffected.

What To Do Now: Practical Compliance Tips and Strategies

While the CIPA landscape remains in flux, companies with any digital presence should work with experienced privacy counsel to take the following proactive steps:

  1. Triage pending matters by statutory theory and commencement date. Separate CIPA § 638.51-only matters from those asserting §§ 631 or 632 claims; the retroactivity window turns on when the action was commenced, not when the conduct occurred;
     
  2. Revisit settlement posture on pen register-only matters. Where a matter falls within the window, the calculus changes materially now that SB 690 has been signed into law. Coordinate with privacy counsel before agreeing to terms that would foreclose the defense;
     
  3. Harden § 631 wiretapping defenses now. Audit consent management sequencing so disclosure and consent precede tag firing, confirm banners actually gate the technologies they purport to gate, and paper vendor relationships to support service provider and party-to-the-communication defenses;
     
  4. Complete a tracking technology inventory. Catalog every pixel, tag, software development kit (SDK), session replay tool, chatbot, and analytics script across web and mobile properties, with the data elements each transmits and each recipient, then reconcile privacy notices and California Consumer Privacy Act (CCPA) opt-out mechanics against it; and
     
  5. Prepare for regulator scrutiny. Assume California AG and California Privacy Protection Agency (CalPrivacy) inquiries, not private demand letters, become the principal online tracking enforcement risk beginning in 2027.

The Final Word

SB 690 removes the single most asserted claim in the California website tracking wave, but it is a carve-out, rather than a reset. Its retroactivity provision will be litigated, and Variety Media already signals the underlying theory survives on better-pleaded facts. The organizations that fare best will be those that treat SB 690 as an opportunity to build the compliance and documentation record they will need under CIPA § 631, out-of-state wiretap statutes, and in front of regulators, not as a reason to stand down. Companies should engage experienced outside privacy counsel now, while the posture of pending matters can still be shaped, rather than after a demand letter or putative class action complaint arrives.

How Baker Donelson Can Help

Baker Donelson's Privacy and Cybersecurity Litigation team has significant experience defending CIPA and similar digital privacy class actions, single plaintiff suits, and pre-suit demand letters involving repeat plaintiff firms and pro se litigants in this space, including Tauler Smith LLP, Vivek Shah, Swigert Law Group, Manning Law, and Joseph Sides. We have also advised hundreds of companies on website compliance, risk mitigation strategies, and litigation readiness. If you have received a demand letter or a complaint, or want to proactively get a step ahead of this risk, contact the authors David Oberly, Alex Koskey, CIPP/US, CIPP/E, PCIP, Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP, MJ McMahan, or another member of Baker Donelson's Data Privacy and Cybersecurity, Digital Marketing, AdTech and Consumer Privacy Compliance, or Privacy and Cybersecurity Litigation teams.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept