If your company runs a website, app, or chat tool that uses cookies, tracking pixels, session-replay software, or similar analytics or tracking technology, you’ve likely felt the effects of California’s pen-register lawsuit wave. The state’s legislature just took its first real swing at that problem, and Senate Bill 690 has passed both the Senate and the Assembly and now sits on Governor Newsom’s desk awaiting signature.
What the bill does, however, is narrower than a lot of early chatter suggested. This isn’t a business exemption. It’s a targeted fix limiting who gets to sue, and it comes with a retroactivity provision that matters a great deal if your company is already defending one of these claims.
The Lawsuit Wave SB 690 Was Built to Address
The California Invasion of Privacy Act (CIPA) originally dates to 1967 and was written to police telephone wiretapping and eavesdropping. In recent years, plaintiffs’ attorneys have applied two of its lesser-known provisions, the “pen register” and “trap and trace device” rules in Penal Code section 638.51, to ordinary website technology. The theory: a tracking pixel, cookie, or chat widget that captures a visitor’s IP address, browser type, or device identifiers is functioning like a pen register or trap and trace device to capture dialing, routing, addressing, or signaling information and requires consent.
Combine that theory with Penal Code section 637.2, which lets a private plaintiff recover $5,000 per violation without proving actual harm, and you get exactly what California has seen: a steady stream of demand letters and lawsuits against website operators, many resolved through quick settlements rather than court fights over the merits.
From a Broad Business Exemption to a Narrow AG-Only Fix
SB 690 didn’t arrive in its final form overnight. As introduced, the bill proposed a much broader fix in the form of an exemption from CIPA liability for data processing conducted for a “commercial business purpose,” borrowed from California Consumer Privacy Act definitions. That version would have shielded a wide range of ordinary business analytics and advertising practices from CIPA exposure altogether. It stalled in the Assembly amid pushback from consumer privacy advocates concerned it went too far.
The version that just passed the Legislature is a different, more surgical bill. Rather than declaring certain data practices exempt from liability, it changes who is allowed to bring the claim in the first place.
The Final Fix: AG-Only Enforcement, Not a Liability Shield
As passed, SB 690 amends Penal Code section 637.2 to remove private plaintiffs from one specific category of claim: pen-register and trap-and-trace claims under section 638.51 arising from conduct on an internet website, online application, or mobile application. Once SB 690 takes effect, only the California Attorney General will be able to bring that particular claim.
That’s a meaningful change, and a narrow one. It leaves section 631 (wiretapping) and section 632 (eavesdropping on confidential communications) completely untouched, and those provisions remain fully available to private plaintiffs. Although additional defensive theories are available under those provisions as compared to 638.51 claims, we expect the plaintiffs’ bar to lean harder on those theories, particularly section 631(a), as the pen-register avenue for private suits narrows.
What SB 690 Doesn’t Do
It’s worth being precise about the limits here, because “CIPA relief is coming” is not the same thing as “CIPA exposure is gone.” Specifically, SB 690:
- Does not legalize website tracking technology or create a safe harbor for how it’s used.
- Does not touch sections 631, 632, or 632.7, all of which remain privately enforceable.
- Does not eliminate enforcement of section 638.51 — it simply channels those website/app-based claims to the Attorney General instead of private plaintiffs.
- Does not, on its own, answer open questions about what consent or disclosure practices keep a company clear of the CIPA provisions that remain privately enforceable.
The Retroactivity Wrinkle
Here’s the detail that matters most if your company is currently facing a CIPA pen-register or trap and trace device demand letter or lawsuit: SB 690’s restriction on private enforcement is retroactive. It applies to pending actions commenced within two years before the bill’s operative date, not just claims filed after SB 690 takes effect. If the Governor signs the bill, that retroactive reach could cut off currently pending private suits against website operators. That is a live issue for any company presently in litigation over this theory, and it’s worth flagging with counsel now rather than waiting.
What Happens Next
SB 690 passed both houses of the Legislature and, as of this writing, the bill awaits Governor Newsom’s action. If signed, the amendments become operative January 1, 2027. You can track the bill’s status directly, and see the Governor’s action once it’s posted, through the Legislature’s official bill page and the Governor’s official newsroom.
What Website and App Operators Should Do Now
- Don’t treat this as a compliance green light. SB 690 changes who can sue over pen-register theories; it doesn’t declare tracking technology risk-free. Your cookie, pixel, session-replay, and chat-widget practices should still be evaluated against the CIPA provisions that remain in force.
- Watch your section 631(a) exposure. As the pen-register avenue narrows for private plaintiffs, expect wiretapping and eavesdropping theories to become the plaintiffs’ bar’s next move.
- If you’re currently defending a CIPA pen-register suit, raise the retroactivity provision with counsel now. Depending on when the case was filed and when SB 690 becomes operative, the private right of action underlying that claim may no longer exist.
- Track the Governor’s action and the January 1, 2027 operative date, and revisit your risk assessment once the bill is signed or vetoed.
- Keep reviewing your consent and disclosure practices independent of SB 690. The underlying question of what notice California law requires for website tracking technology hasn’t gone away; it’s just being asked under different CIPA provisions and under the CCPA. Additionally, we are seeing increased attempts by plaintiffs in other states to use creative theories to pursue similar claims under those states’ laws.
If you’d like help assessing your company’s CIPA exposure, reviewing your website’s tracking practices, or understanding how SB 690’s retroactivity provision might affect a pending case, we can help.