If you run a website with California visitors, you have probably spent the last two years hearing about CIPA demand letters, or answering one. On August 28, the California Legislature passed SB 690↗, a bill many businesses hoped would make those letters stop. The Assembly vote was 66-0↗. Governor Newsom has until September 30 to act, and most observers expect a signature. If he signs, the law takes effect January 1, 2027.
The relief is real, but it is much smaller than the headlines suggest. SB 690 closes one door. The plaintiffs' bar has several others, and the ones left open demand a different kind of preparation than most privacy programs have done.
What the bill does
The California Invasion of Privacy Act is a 1967 wiretapping law. Over the past few years, plaintiffs have stretched one of its provisions, Penal Code Section 638.51, to cover ordinary web technology. That section prohibits installing a "pen register" or "trap and trace device" without a court order. The terms were written for devices that record the numbers dialed on a phone line. The litigation theory is that a cookie, pixel, or analytics script does the same thing when it records a visitor's IP address and device details.
SB 690 takes that claim away from private plaintiffs. For conduct on a website, online application, or mobile app, only the California Attorney General could bring a Section 638.51 claim.
The bill also reaches backward. It applies to any pending claim in an action filed within two years before its operative date, which means lawsuits filed on or after January 1, 2025. For defendants in those cases, the pen register count should be dispositive↗ once the law is in effect.
What the bill does not do
This is where the final version departs from the one many people remember. When SB 690 was introduced in 2025, it proposed a broad "commercial business purpose" exemption that would have shut down private suits across CIPA's wiretapping and eavesdropping provisions too. That version stalled. The bill that passed was rewritten in July 2026↗ and touches exactly one provision.
Everything else stands:
- Section 631, CIPA's wiretapping provision, is untouched. So are Sections 632 and 632.7.
- The federal Wiretap Act and the Video Privacy Protection Act are untouched.
- Wiretap statutes in other states, including Florida, Pennsylvania, Arizona, and Washington, are untouched.
- Common-law privacy claims and California's Unfair Competition Law remain available, and a complaint that pleads several theories can survive the loss of its pen register count.
- The CCPA is unchanged. Opt-out rights, Global Privacy Control, and downstream obligations all still apply. CCPA compliance was never a defense to a CIPA claim, and it is not one now.
The bill also does not declare any technology lawful. It does not say a pixel is not a pen register, and it does not bless session replay or chat transcription. It changes who can sue under one section.
Demand letters deserve a separate note. A demand letter is not a lawsuit, so nothing in SB 690 invalidates one sitting in your inbox today. What changes is the leverage behind it. A letter threatening a Section 638.51 suit loses most of its force once the claim can no longer be filed privately. A letter threatening a Section 631 suit loses none.
The claim that survives is a harder one, for both sides
Pen register claims became popular because they were cheap to bring. A plaintiff's firm could scan a site automatically, list the third-party tags that fired, and allege that each one captured routing and signaling data such as an IP address. No one had to look at what the tags actually sent.
Section 631 is a different claim. The plaintiff has to allege that a third party read or learned the contents of a communication while it was in transit, without consent. That means pointing to actual payloads: the search term typed into a site's search box, the text of a chat message, the URL of a page that reveals a health condition, the fields of a half-completed form.
That is a higher bar for plaintiffs. It is also a harder question for defendants to answer about their own sites. Most privacy programs were built around the tag inventory. They can say which vendors are present. Far fewer can say what each vendor receives on each page, and whether it was sent before or after the visitor consented.
Expect the volume of filings to move rather than disappear. Firms that built a practice on Section 638.51 will repurpose it toward Section 631, the federal ECPA, and out-of-state statutes, and they will concentrate on sites where the payload evidence is strongest: search, chat, forms, video, and anything health or finance related.
What about the Attorney General?
Two facts point in different directions here.
The Attorney General has had authority to enforce Section 638.51 for more than a decade and has never used it against a website. Inheriting exclusive jurisdiction does not guarantee a wave of pen register cases.
On the other hand, the office has become a serious privacy enforcer under the CCPA. In February 2026 it announced a $2.75 million settlement with Disney↗, the largest CCPA settlement to date, over opt-outs that did not carry across devices and services and Global Privacy Control signals that were honored only on the device that sent them. The settlement requires opt-out methods that fully stop the sale and sharing of a consumer's data.
The practical reading: the state's enforcement energy is going into whether opt-outs and consent signals work as promised. That is the same technical question Section 631 plaintiffs are asking from the other direction.
What to do before January 1
If you are a defendant in a pending case filed since January 1, 2025, talk to counsel now about the retroactivity provision and how it affects any pen register count.
If you have an open demand letter, do not ignore it on the theory that SB 690 will make it go away. Read which sections it cites. If it cites Section 631, nothing has changed.
For everyone else, shift the audit from "what tags do we have" to "what does each tag receive, and when":
- Capture real network traffic on your highest-risk pages: site search, chat widgets, forms, login and checkout flows, and video players. Look at the request payloads, not just the list of domains.
- Test the pre-consent state. Load the site as a first-time California visitor and record what fires before any banner interaction. Then reject everything and check again.
- Test Global Privacy Control. Send the signal and confirm that third-party sharing actually stops, across every property and logged-in surface.
- Review session replay and chat vendors closely. These tools capture content by design, which makes them the natural center of a Section 631 complaint. Confirm masking is configured and that the vendor's contract limits it to acting on your behalf.
- Keep the evidence. A dated record showing what was transmitted and what consent state applied is the most useful thing you can hand counsel when a letter arrives.
The Takeaway
SB 690 removes the cheapest claim in the CIPA playbook. It leaves in place the claims that turn on what your site actually transmits, and it hands the remaining pen register authority to a regulator that is already testing whether opt-outs work. A site that can show, with evidence, what leaves the browser and under what consent is in a good position on all three fronts. A site that can only produce a vendor list is not.
This post is for general information and is not legal advice. SB 690 has not been signed as of publication, and CIPA case law continues to change quickly. Talk to counsel about your specific situation.
