CIPA in 2026: Will SB 690 Save You?

EU
Eddy Udegbe
•
A tiny life preserver around a microphone — will SB 690 rescue businesses from CIPA?
SB 690 passed the California Legislature in a much narrower form. Here's what it changes for CIPA exposure, what it leaves alone, and what to do now.

Subhead: California's biggest swing at fixing the CIPA litigation wave finally passed the Legislature, in a much smaller form than the one first proposed. Here's the honest answer on what that means for your website.

Updated September 20, 2026: SB 690 passed both houses on August 28, 2026 and is awaiting the Governor's action. This post has been revised to reflect the final bill. For a closer look at what the narrowed bill changes, see SB 690 Won't End CIPA Lawsuits. It Will Change Which Ones You Get.

If you've been watching California's Senate Bill 690 with one eye and your demand-letter inbox with the other, here's the short version: SB 690↗ passed the Legislature on August 28, 2026, but only after it was cut down to a single change. It takes pen register and trap-and-trace claims under Penal Code § 638.51 away from private plaintiffs. It does nothing to wiretap claims under § 631. For most websites, the largest share of CIPA liability is exactly where it was last summer — $5,000 per violation, every California-facing website still exposed.

Book a 10-minute demo↗ to see exactly which scripts on your site are firing before consent — the question every CIPA demand letter is built on.

What SB 690 was supposed to do

CIPA — the California Invasion of Privacy Act, originally a 1967 wiretapping statute — has been the legal foundation for over a thousand class actions and tens of thousands of demand letters against website operators in the last two years. The theory: cookies, pixels, chatbots, and session replay tools that fire before a California visitor consents constitute "interception" of a private communication, which triggers $5,000 in statutory damages per violation. No actual harm required.

SB 690 was the legislative attempt to draw a line between "actual eavesdropping" and "running a website." As introduced, the bill would have added a commercial business purpose exception to four CIPA sections (§§ 631, 632, 632.7, and 638.50). In practical terms, if a company processes personal information either to further a legitimate business purpose or in a way that is already subject to a consumer's CCPA opt-out rights, the activity wouldn't have been wiretapping or trap-and-trace.

In plain English: SB 690 would have meant cookies, pixels, chatbots, and session replay — used the way most companies use them — stop being a CIPA problem.

That is not the bill that passed. The commercial business purpose exception was removed by amendment on July 2, 2026↗.

Where SB 690 actually stands

Four things matter about the bill's current status:

  1. The broad version stalled. The Senate passed the original bill 35-0 on June 3, 2025, but Senator Caballero, the sponsor, paused it before an Assembly floor vote, citing "outstanding concerns around consumer privacy" raised by consumer-protection groups. It carried into 2026 as a two-year bill.
  2. It was rewritten on July 2, 2026. The amended bill drops the commercial business purpose exception and changes one thing: for conduct on a website, online application, or mobile app, only the California Attorney General may bring a pen register or trap-and-trace claim under § 638.51. Private plaintiffs cannot.
  3. Both houses passed the narrowed bill on August 28, 2026. The Assembly vote was 66-0↗. The Governor has until September 30 to sign or veto. If signed, the law takes effect January 1, 2027.
  4. Retroactivity is back, in a limited form. A retroactivity provision was removed from the original bill on May 29, 2025. The version that passed applies to any pending claim in an action commenced within two years before its operative date, which reaches pen register suits filed on or after January 1, 2025. For those cases, the pen register count should be dispositive↗ once the law is operative.

Will the Governor sign it?

Most observers expect a signature. The bill cleared both houses without a single no vote, and the narrowing was the compromise that brought consumer-privacy groups and the plaintiffs' bar along.

The cost of that compromise is what the bill leaves out. Sections 631, 632, and 632.7 are untouched, and those are the provisions behind most website wiretapping suits involving chatbots, session replay, and pixels that capture what a visitor types or views. The federal Wiretap Act, the Video Privacy Protection Act, and wiretap statutes in other states are untouched as well.

What that means for your website right now

Through the end of 2026, CIPA exposure is unchanged. After January 1, 2027, if the bill is signed, only the pen register piece changes. The wiretapping sections remain the same. The plaintiff firms remain active. Demand letters are being sent today. Verdicts are being entered — the Frasco v. Flo Health jury found Meta liable for billions in potential CIPA damages↗ in August 2025, and a federal court refused to set the verdict aside in September.

Three implications:

1. Waiting for SB 690 is not a compliance strategy. The bill only reaches private pen register claims. Any § 631 exposure you accumulate, before or after the effective date, is yours to keep.

2. The "commercial business purpose" defense isn't a defense at all. Some defense filings argued it informally, but the exception was cut from the bill in July 2026 and has no force in California law. Don't let a vendor tell you otherwise.

3. The Javier rule still controls chatbots and session replay. The Ninth Circuit's holding that retroactive consent doesn't cure a CIPA violation means consent must be obtained before any third-party tracking technology fires. SB 690 doesn't change that. It limits who can sue under § 638.51, and the prior-consent rule for wiretap claims remains.

A four-question CIPA exposure check

Run your website through these four questions today. Each "yes" is potential exposure.

  1. Does any third-party script — Meta Pixel, Google Analytics, TikTok Pixel, LinkedIn Insight Tag, a chatbot, session replay tool — fire on page load before a California visitor accepts a consent banner?
  2. Does your consent banner default to "all on" or otherwise count silence or scrolling as consent?
  3. Is your consent record per-user, time-stamped, and retrievable for at least three years?
  4. Are GPC (Global Privacy Control) signals from California visitors honored as opt-outs, including for advertising and analytics?

If you can't answer all four with confidence, the next step is a scan.

Run a free PieEye scan↗ to see exactly which scripts are firing pre-consent, whether your banner is doing what it claims, and where your consent records stand.

What "compliant" looks like in 2026 — regardless of SB 690

The compliance posture that satisfies CIPA today is also the posture that holds up after SB 690. There's no version of this where investing in real consent infrastructure was the wrong call.

Block tracking scripts in California until consent. Geo-fence by IP or by precise location and suppress all non-essential scripts for California visitors until they actively accept. Opt-out mode — where tags fire on page load and users can decline later — does not satisfy CIPA's prior-consent rule.

Run a Consent Management Platform that gates tags at the source. Whether that's a CMP firing through Google Tag Manager, a server-side gate, or both, the rule is the same: no PII or routing information leaves the page before the user agrees.

Keep server-side consent records for at least three years. CIPA claims have a one-year statute of limitations, but plaintiff firms often plead to extend that with related claims. Three years of queryable, per-user consent records is the defensible posture.

Honor GPC signals as a confirmed opt-out. California regulators have been clear: a GPC signal is a valid opt-out under CCPA, and ignoring it is evidence of bad faith that bleeds directly into CIPA cases.

Audit your tag manager configuration quarterly. Tags get added by marketing teams. Vendors push updates that change firing rules. The configuration you signed off on six months ago may not be the configuration running today.

How PieEye fits

PieEye was built specifically for the CIPA problem. Three things make us different from the general-purpose CMPs:

  • Pre-consent script suppression for California visitors is on by default. Not a setting to find. Not a paid upgrade.
  • Per-user server-side consent records are retained for three years, queryable by date range without engineering.
  • A free pre-consent scan that tells you specifically whether your Meta Pixel, Google Analytics, or other named tracker is firing before consent — the exact question every CIPA demand letter is built on.

We compare ourselves head-to-head against OneTrust in PieEye vs OneTrust: CIPA Compliance Compared↗. The short version: if you're an ecommerce or DTC brand with a California-facing site, you don't need an enterprise platform. You need pre-consent gating that works on day one.

Book a 10-minute demo↗ and we'll walk through your stack on screen — what's firing, what isn't, and what we'd change.

Quick links to deeper reading

Is your site exposed to CIPA claims?

Run a free 60-second scan to see which trackers fire before your visitors consent — the same thing a plaintiffs' firm would check.

Scan your site for CIPA violations →

For a walkthrough of how PieEye handles CIPA compliance, book a demo.

Related Posts

CIPA § 632.7 and Mobile Communications

Most CIPA coverage focuses on website tracking. Section 632.7 targets a different attack surface — SMS marketing, AI phone agents, and cloud contact centers. Here is what the provision covers, what the 2025 cases established, and what businesses with California customers need to do now.

4/19/2026Read More →

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.