If your company operates a website or mobile app that uses digital tracking tools, California plaintiffs' lawyers may already have you in their sights. Since early 2025, California Invasion of Privacy Act (CIPA) lawsuits have exploded from roughly 600 to nearly 4,000, with tens of thousands more pre-suit demand letters flooding corporate inboxes. The potential payout? $5,000 per violation, with no actual harm required, multiplied across millions of website visits. Now, after months of legislative wrangling, a narrowed reform bill is gaining traction in California – but even if it passes, companies will still face substantial litigation risk. Here's what you need to know.
Recently, the California Assembly Committee on Privacy and Consumer Protection voted to advance Senate Bill 690 (SB 690), legislation that would amend CIPA to curb the litany of class action litigation targeting companies' use of cookies, pixels, and similar online tracking technologies. The vote marks the most significant progress on CIPA reform since an earlier version of the bill stalled last year.
However, as amended, SB 690 reaches only one of several CIPA theories of liability currently advanced by the plaintiffs' bar – "pen register" and "trap and trace" claims under CIPA § 638.51 – leaving the remainder of the statute intact, including CIPA's § 631 wiretapping provision, which continues to fuel a substantial share of digital tracking suits.
The bottom line: If enacted, SB 690 would provide meaningful – and retroactive – relief from the predominant category of CIPA litigation claims. It would not, however, eliminate the outsized liability exposure companies face for using everyday digital analytics and advertising tools. A comprehensive compliance and risk management strategy remains essential.
How a 1967 California Wiretapping Law Became a Weapon Against the Modern Internet
California enacted CIPA in 1967 to combat telephone wiretapping and eavesdropping. The plaintiffs' class action bar has since repurposed the statute to challenge the routine operation of commercial websites and mobile apps. The theory: Common tracking technologies operate as illegal "wiretaps" under CIPA § 631 or as unauthorized "pen registers" or "trap and trace devices" under § 638.51 – a provision added in 2015 to regulate law enforcement surveillance orders, with no evident consideration of online activity.
The economics are simple. CIPA's private right of action (§ 637.2) authorizes statutory damages of $5,000 per violation or treble actual damages, whichever is greater – and actual damages are not required for recovery. Aggregated across thousands or millions of website visits, exposure can quickly reach bet-the-company levels, and defendants often settle accordingly, regardless of the merits.
The numbers also explain why lawmakers are reacting. According to the Alliance for Legal Fairness – a member of the Reform CIPA Coalition, which recently launched the "Stop CIPA Shakedowns" campaign (stopcipashakedowns.com) – roughly 600 CIPA suits had been filed against California businesses as of early 2025. Eighteen months later, that figure had skyrocketed to approximately 4,000, alongside tens of thousands of pre-suit demand letters. For many businesses, these demand letters feel less like legitimate legal claims and more like legalized extortion – pay up or face ruinous litigation costs defending against claims brought under a statute never designed for the digital age.
Courts remain deeply divided. Federal district courts, following Greenley v. Kochava, Inc., 684 F. Supp. 3d 1024 (S.D. Cal. 2023), and Shah v. Fandom, Inc., 754 F. Supp. 3d 924 (N.D. Cal. 2024), have largely allowed pen register claims to proceed past the motion-to-dismiss stage. California trial courts have been more willing to dismiss such claims. Licea v. Hickory Farms LLC, No. 23STCV26148 (Cal. Super. Ct. L.A. Cnty. Mar. 13, 2024), is the leading example, although several courts have recently begun following their federal counterparts. As one federal judge observed in Doe v. Eating Recovery Ctr. LLC, "[t]he language of CIPA is a total mess." 806 F. Supp. 3d 1109 (N.D. Cal. 2025).
What the Amended SB 690 Would Do
The current bill would amend CIPA § 637.2 so that an action against a private actor for a violation of § 638.51 "alleged to arise from conduct occurring on an internet website, online application, or mobile application" could be brought exclusively by the California Attorney General (AG). In practical terms, the bill would:
- end the private right of action – and the $5,000 per-violation statutory damages engine – for pen register and trap and trace claims based on website and mobile app activity, shifting enforcement exclusively to the California AG;
- apply retroactively to any pending claim in an action commenced within two years before the bill's operative date of January 1, 2027, providing relief to defendants in pending litigation while leaving final judgments undisturbed; and
- add a severability clause, anticipating constitutional challenges to the retroactivity provision.
What SB 690 Would Not Fix
Even if enacted, SB 690 leaves substantial exposure in place:
- wiretapping claims under § 631 – the theory driving session replay, chatbot, and pixel "content interception" suits – would remain exactly the same, private right of action and $5,000 statutory damages included;
- eavesdropping claims under § 632 and common law privacy theories likewise remain untouched;
- plaintiffs are already pivoting to adjacent statutes, including the California Comprehensive Computer Data Access and Fraud Act (CDAFA), the federal Wiretap Act (enacted as Title III of the Electronic Communications Privacy Act), and the Video Privacy Protection Act (VPPA) to fill the gap; and
- CIPA's imprecise, 1967-era language – and its unsettled relationship with the California Consumer Privacy Act (CCPA) – will continue to produce divergent judicial outcomes and settlement pressure.
The Road Ahead
SB 690 has now moved to the Assembly Appropriations Committee, with a hearing expected in August after the Legislature's summer recess. The bill would then require an Assembly floor vote, Senate concurrence in the Assembly's amendments, and Governor Gavin Newsom's signature. Given its unanimous Senate support, broad business coalition, and narrowed scope, SB 690 has a realistic – though far from guaranteed – path to enactment this session.
Companies that want to weigh in have a narrow window of opportunity: The Reform CIPA Coalition is soliciting business support letters and impacted-company testimony ahead of the August hearing.
Key Takeaways
SB 690 is targeted litigation relief, not wholesale CIPA reform. It would defuse the most abused CIPA theory – retroactively, for pending cases – but leave the broader CIPA minefield in place. If the bill becomes law, expect § 631 and adjacent theories to absorb much of the displaced claim volume. Either way, aggressive litigation testing CIPA's outer boundaries will continue.
Six Steps to Shrink Your Liability Footprint Now
While SB 690 remains pending – and with no relief in sight for non-§ 638.51 CIPA claims – companies should take proactive steps now to shrink their liability footprint. Here's how:
- Inventory and map all tracking technologies: Audit every cookie, pixel, software development kit (SDK), session replay tool, chatbot, and analytics script across all websites and mobile apps, documenting what each collects, when it fires, and which third parties receive the data. Automated scans frequently surface "shadow" tags deployed without legal review. Because marketing teams add tags continuously, inventories should be refreshed regularly.
- Configure consent management to actually block trackers: The core allegation in most CIPA suits is that trackers transmitted data before the visitor consented. A cookie banner alone is insufficient if non-essential trackers fire on page load; a properly configured consent management platform must block them until the visitor affirmatively opts in, with auditable consent logs. Under Shah, the operative question is "whether the user agreed to the specific use or collection," so consent language should specifically identify third-party disclosures, not merely first-party collection.
- Align privacy disclosures with actual practices: Privacy policies and cookie notices should accurately describe the tracking technologies in use, the data collected, and the third-party recipients. Gaps between disclosures and real-world data flows are a central liability theory in class actions. More importantly, these missteps can independently create liability under California's Unfair Competition Law (UCL) and similar state consumer protection statutes.
- Scrutinize high-risk tools: Session replay tools, chat features, and pixels on sensitive pages carry the greatest CIPA § 631 exposure because they can capture the substance, i.e., "content," of user communications. Suppress keystroke and form-field capture, redact free-text inputs, and keep third-party trackers off pages where users submit sensitive information – the lesson of recent health care pixel litigation, including In re Meta Pixel Healthcare Litig., 647 F. Supp. 3d 778 (N.D. Cal. 2023).
- Practice data minimization: Configure analytics and advertising tools to collect only the data the business actually uses by enabling IP truncation, restricted data processing modes, and limited retention where available. Data that is never collected cannot support a claim, and data minimization simultaneously advances compliance with the CCPA and many other consumer privacy laws that now make data minimization a mandatory legal obligation.
- Monitor the landscape and calendar recurring audits: Track SB 690's progress, evolving CIPA case law, and the plaintiff's bar's ongoing pivot to CDAFA, federal Wiretap Act, and VPPA theories. Compliance validated against last year's case law may not withstand this year's rulings.
How We Can Help
Baker Donelson's privacy team regularly advises companies on CIPA compliance, risk mitigation, and litigation readiness, and the Firm's deep bench of privacy litigators have extensive experience defending CIPA and similar types of digital privacy class actions. For questions about SB 690, help with reform advocacy, or an audit of your tracking technology compliance program, contact the authors – David Oberly, Matt White, AIGP, CIPP/US, CIPP/E, CIPT, CIPM, PCIP, and MJ McMahan – or another member of Baker Donelson's Data Privacy and Cybersecurity, Digital Marketing, AdTech, and Consumer Privacy Compliance, or Privacy Litigation teams.