Subhead: California's biggest swing at fixing the CIPA litigation wave finally passed the Legislature, in a much smaller form than the one first proposed. Here's the honest answer on what that means for your website.
Updated September 20, 2026: SB 690 passed both houses on August 28, 2026 and is awaiting the Governor's action. This post has been revised to reflect the final bill. For a closer look at what the narrowed bill changes, see SB 690 Won't End CIPA Lawsuits. It Will Change Which Ones You Get.
If you've been watching California's Senate Bill 690 with one eye and your demand-letter inbox with the other, here's the short version: SB 690↗ passed the Legislature on August 28, 2026, but only after it was cut down to a single change. It takes pen register and trap-and-trace claims under Penal Code § 638.51 away from private plaintiffs. It does nothing to wiretap claims under § 631. For most websites, the largest share of CIPA liability is exactly where it was last summer — $5,000 per violation, every California-facing website still exposed.
Book a 10-minute demo↗ to see exactly which scripts on your site are firing before consent — the question every CIPA demand letter is built on.
What SB 690 was supposed to do
CIPA — the California Invasion of Privacy Act, originally a 1967 wiretapping statute — has been the legal foundation for over a thousand class actions and tens of thousands of demand letters against website operators in the last two years. The theory: cookies, pixels, chatbots, and session replay tools that fire before a California visitor consents constitute "interception" of a private communication, which triggers $5,000 in statutory damages per violation. No actual harm required.
SB 690 was the legislative attempt to draw a line between "actual eavesdropping" and "running a website." As introduced, the bill would have added a commercial business purpose exception to four CIPA sections (§§ 631, 632, 632.7, and 638.50). In practical terms, if a company processes personal information either to further a legitimate business purpose or in a way that is already subject to a consumer's CCPA opt-out rights, the activity wouldn't have been wiretapping or trap-and-trace.
In plain English: SB 690 would have meant cookies, pixels, chatbots, and session replay — used the way most companies use them — stop being a CIPA problem.
That is not the bill that passed. The commercial business purpose exception was removed by amendment on July 2, 2026↗.
Where SB 690 actually stands
Four things matter about the bill's current status:
- The broad version stalled. The Senate passed the original bill 35-0 on June 3, 2025, but Senator Caballero, the sponsor, paused it before an Assembly floor vote, citing "outstanding concerns around consumer privacy" raised by consumer-protection groups. It carried into 2026 as a two-year bill.
- It was rewritten on July 2, 2026. The amended bill drops the commercial business purpose exception and changes one thing: for conduct on a website, online application, or mobile app, only the California Attorney General may bring a pen register or trap-and-trace claim under § 638.51. Private plaintiffs cannot.
- Both houses passed the narrowed bill on August 28, 2026. The Assembly vote was 66-0↗. The Governor has until September 30 to sign or veto. If signed, the law takes effect January 1, 2027.
- Retroactivity is back, in a limited form. A retroactivity provision was removed from the original bill on May 29, 2025. The version that passed applies to any pending claim in an action commenced within two years before its operative date, which reaches pen register suits filed on or after January 1, 2025. For those cases, the pen register count should be dispositive↗ once the law is operative.
Will the Governor sign it?
Most observers expect a signature. The bill cleared both houses without a single no vote, and the narrowing was the compromise that brought consumer-privacy groups and the plaintiffs' bar along.
The cost of that compromise is what the bill leaves out. Sections 631, 632, and 632.7 are untouched, and those are the provisions behind most website wiretapping suits involving chatbots, session replay, and pixels that capture what a visitor types or views. The federal Wiretap Act, the Video Privacy Protection Act, and wiretap statutes in other states are untouched as well.
What that means for your website right now
Through the end of 2026, CIPA exposure is unchanged. After January 1, 2027, if the bill is signed, only the pen register piece changes. The wiretapping sections remain the same. The plaintiff firms remain active. Demand letters are being sent today. Verdicts are being entered — the Frasco v. Flo Health jury found Meta liable for billions in potential CIPA damages↗ in August 2025, and a federal court refused to set the verdict aside in September.
Three implications:
1. Waiting for SB 690 is not a compliance strategy. The bill only reaches private pen register claims. Any § 631 exposure you accumulate, before or after the effective date, is yours to keep.
2. The "commercial business purpose" defense isn't a defense at all. Some defense filings argued it informally, but the exception was cut from the bill in July 2026 and has no force in California law. Don't let a vendor tell you otherwise.
3. The Javier rule still controls chatbots and session replay. The Ninth Circuit's holding that retroactive consent doesn't cure a CIPA violation means consent must be obtained before any third-party tracking technology fires. SB 690 doesn't change that. It limits who can sue under § 638.51, and the prior-consent rule for wiretap claims remains.
A four-question CIPA exposure check
Run your website through these four questions today. Each "yes" is potential exposure.
- Does any third-party script — Meta Pixel, Google Analytics, TikTok Pixel, LinkedIn Insight Tag, a chatbot, session replay tool — fire on page load before a California visitor accepts a consent banner?
- Does your consent banner default to "all on" or otherwise count silence or scrolling as consent?
- Is your consent record per-user, time-stamped, and retrievable for at least three years?
- Are GPC (Global Privacy Control) signals from California visitors honored as opt-outs, including for advertising and analytics?
If you can't answer all four with confidence, the next step is a scan.
Run a free PieEye scan↗ to see exactly which scripts are firing pre-consent, whether your banner is doing what it claims, and where your consent records stand.
What "compliant" looks like in 2026 — regardless of SB 690
The compliance posture that satisfies CIPA today is also the posture that holds up after SB 690. There's no version of this where investing in real consent infrastructure was the wrong call.
Block tracking scripts in California until consent. Geo-fence by IP or by precise location and suppress all non-essential scripts for California visitors until they actively accept. Opt-out mode — where tags fire on page load and users can decline later — does not satisfy CIPA's prior-consent rule.
Run a Consent Management Platform that gates tags at the source. Whether that's a CMP firing through Google Tag Manager, a server-side gate, or both, the rule is the same: no PII or routing information leaves the page before the user agrees.
Keep server-side consent records for at least three years. CIPA claims have a one-year statute of limitations, but plaintiff firms often plead to extend that with related claims. Three years of queryable, per-user consent records is the defensible posture.
Honor GPC signals as a confirmed opt-out. California regulators have been clear: a GPC signal is a valid opt-out under CCPA, and ignoring it is evidence of bad faith that bleeds directly into CIPA cases.
Audit your tag manager configuration quarterly. Tags get added by marketing teams. Vendors push updates that change firing rules. The configuration you signed off on six months ago may not be the configuration running today.
How PieEye fits
PieEye was built specifically for the CIPA problem. Three things make us different from the general-purpose CMPs:
- Pre-consent script suppression for California visitors is on by default. Not a setting to find. Not a paid upgrade.
- Per-user server-side consent records are retained for three years, queryable by date range without engineering.
- A free pre-consent scan that tells you specifically whether your Meta Pixel, Google Analytics, or other named tracker is firing before consent — the exact question every CIPA demand letter is built on.
We compare ourselves head-to-head against OneTrust in PieEye vs OneTrust: CIPA Compliance Compared↗. The short version: if you're an ecommerce or DTC brand with a California-facing site, you don't need an enterprise platform. You need pre-consent gating that works on day one.
Book a 10-minute demo↗ and we'll walk through your stack on screen — what's firing, what isn't, and what we'd change.
Quick links to deeper reading
- SB 690 Won't End CIPA Lawsuits. It Will Change Which Ones You Get.↗ — what the final bill changes
- What Is CIPA?↗ — the foundational overview
- CIPA vs. CCPA↗ — why CCPA compliance doesn't cover you
- CIPA Demand Letter Guide↗ — what to do if one lands
- Trap and Trace: Respond the Right Way↗
- Meta Pixel and CIPA↗
- Google Tag Manager and CIPA↗
- Frasco v. Flo Health: The CIPA Jury Verdict↗
