California Governor Gavin Newsom signed Senate Bill 690 (SB 690) into law on September 30, 2026, delivering meaningful relief to businesses facing a wave of claims under the California Invasion of Privacy Act (CIPA). It is scheduled to become operative on January 1, 2027.
As discussed in our prior client alert, Who, Me? A Wiretapper? Common Website Activities May Subject Your Business to Demands Under the California Invasion of Privacy Act, plaintiffs have increasingly relied on CIPA to challenge the use of common website marketing technologies, including pixels, web beacons, analytics tools, session replay software, and other third-party tools. Those claims have alleged that such technologies function as unlawful pen registers, trap-and-trace devices, or wiretaps when they collect and transmit information about website visitors without sufficient notice or consent.
SB 690 addresses one significant piece of that litigation landscape: The new law restricts private lawsuits alleging that website or application technologies constitute unlawful pen registers or trap-and-trace devices under CIPA Section 638.51.
But SB 690 is not a complete fix. Private plaintiffs may still pursue other CIPA theories, including claims alleging unlawful wiretapping or interception under Section 631 and eavesdropping on confidential communications under Section 632. Governor Newsom himself acknowledged this continuing risk in his signing message, urging lawmakers to do additional work on CIPA because other provisions of the decades-old statute remain susceptible to litigation abuse against businesses across the country.
For website operators, the takeaway is therefore mixed: SB 690 closes one of the most heavily used avenues for recent CIPA claims, but it does not create a general safe harbor for website tracking technologies or fully mitigate a company’s risk.
What SB 690 Changes
SB 690 directly targets the theory that has driven many recent CIPA pen-register and trap-and-trace lawsuits against website operators.
Under Section 638.51, a person generally may not install or use a pen register or trap-and-trace device without obtaining a court order. Historically, those terms referred to technologies associated with telephone communications. A pen register captures outgoing dialing, routing, addressing, or signaling information, while a trap-and-trace device captures similar information identifying the source of an incoming communication.
In recent website-tracking lawsuits, however, the plaintiffs argued that those definitions were broad enough to encompass modern internet tracking technologies. Their theory? When a website operator embeds a tracker, such as an advertising pixel, analytics tool, or similar script, it automatically collects information such as the visitor’s IP address, cookie identifiers, and other routing, addressing, or signaling information when the visitor communicates with the website. Plaintiffs therefore alleged that the tracker itself functions as a digital pen register or trap-and-trace device and that the website operator violates Section 638.51 by causing that technology to be installed or used without a court order or the visitor’s prior express consent.
SB 690 shuts the door on this tortured interpretation of CIPA. The legislation amends California Penal Code Section 637.2 so that only the California attorney general may enforce, eliminating the private right of action that fueled the recent wave of website-based pen-register litigation. In practical terms, an individual website visitor can no longer sue a business under Section 638.51 on the theory that a pixel, cookie, analytics script, or other website technology operated as an unlawful pen register or trap-and-trace device.
Importantly, the prohibition against private lawsuits applies retroactively to pending claims in actions commenced in the two years before the law’s operative date. For businesses currently defending pen-register or trap-and-trace claims or in receipt of demand letters premised on Section 638.51, SB 690 represents a significant victory.
But the amendment is targeted. While it will prohibit private lawsuits for specific CIPA claims, it will not broadly exempt websites or online tracking technologies from CIPA’s scope.
The Door Remains Open to Wiretapping Claims
Perhaps the most important limitation of SB 690 is what it does not do. CIPA Section 631 generally prohibits certain unauthorized interceptions of communications in transit, as well as specified conduct involving the use of information obtained through an interception. Plaintiffs have increasingly relied on Section 631 to argue that when a business embeds third-party technologies into its website, it intercepts a visitor’s communications with the website in real time.
These claims differ conceptually from the pen-register theory addressed by SB 690. A pen-register claim generally focuses on routing, addressing, or signaling information associated with a communication. By contrast, a Section 631 claim focuses on whether a third party obtained the contents or substance of the communication itself in real time. The risk is particularly significant where a technology transmits information beyond basic technical identifiers and instead relays information about what the visitor is doing or communicating, such as URLs visited, search terms, products viewed or placed in a shopping cart, buttons clicked, information entered in forms, or communications through chat features. Courts considering Section 631 claims have focused on whether such information constitutes the “contents” of a communication and whether a third party received those contents while the communication was still in transit.
As a result, eliminating private pen-register and trap-and-trace claims does not necessarily eliminate the underlying litigation risk associated with technologies such as advertising pixels, session replay, chat tools, or analytics scripts.
Defendants may have important defenses, including visitor consent and whether the website operator is itself a party to the communication, whether the challenged information constitutes the contents of a communication, whether an interception occurred contemporaneously with transmission, and whether the technology provider was acting merely as a service provider rather than as an independent third-party interceptor. But SB 690 does not resolve those issues.
Eavesdropping Claims Also Remain
CIPA Section 632 creates another potential theory of liability via its general prohibition of intentional eavesdropping on or recording of a confidential communication without the consent of all parties.
In website-tracking litigation, plaintiffs may attempt to characterize interactions with a website—particularly communications through chat functions, forms, account portals, or other interactive features—as confidential communications that were improperly recorded or transmitted to third parties.
These claims present their own legal hurdles. Among other things, plaintiffs must establish that the communication was actually confidential, which can depend on the nature of the interaction, the information disclosed, the circumstances surrounding the communication, and the disclosures provided to the user. Nevertheless, SB 690 leaves Section 632 untouched.
What Website Owners Should Do Now
Website owners therefore should not interpret SB 690 as a reason to scale back their website-tracking compliance programs; instead, businesses should continue to understand precisely what technologies operate on their websites and what information those technologies receive.
Companies should consider conducting or updating a website tracking audit that inventories pixels, cookies, analytics tools, advertising technologies, session-replay software, chat tools, and other third-party scripts. That review should go beyond identifying the vendor. Businesses should determine:
- What information is collected or transmitted
- Why that information is needed and how it will be used
- Whether the technology receives only technical identifiers or also receives substantive user interactions
- Whether information is transmitted in real time
- Whether tracking begins before a visitor receives disclosures or provides consent
- Whether technologies operate on sensitive pages, such as login portals, health-related pages, financial pages, checkout flows, or web forms
- Whether vendors are permitted to use collected information for their own advertising, profiling, analytics, or other purposes
- Whether the website’s privacy policy, cookie disclosures, and consent-management platform accurately reflect actual practices
Website operators should pay particular attention to form fields, search bars, chat functions, account portals, and other interactive website features because those technologies may create different risks than a tracker that receives only a basic IP address or device identifier.
Businesses should also evaluate whether their consent mechanisms function as intended. Consent can be an important defense to CIPA claims, but that defense is only as strong as the disclosures and technical controls supporting it.
If you have questions about assessing your CIPA risk, contact the authors of this alert or the McCarter attorney with whom you work.
