Takeaways

SB 690 eliminates private actions for website- and app-based pen-register and trap-and-trace claims under the California Invasion of Privacy Act (CIPA) while leaving other CIPA claims available to private plaintiffs and applying retroactively to certain pending cases.
The bill also applies retroactively to certain pending claims filed before the law’s effective date.
Private website, online-application or mobile-application § 638.51 claims in actions filed within the two-year lookback period should be barred when SB 690 takes effect.

On September 30, 2026, Governor Newsom signed SB 690. Effective January 1, 2027, it eliminates private actions for website- and app-based pen-register and trap-and-trace claims under the California Invasion of Privacy Act (CIPA) while leaving other CIPA claims available to private plaintiffs and applying retroactively to certain pending cases. It also applies retroactively to certain pending claims filed before the law’s effective date.

Overview and Legislative Background
Plaintiffs’ firms and serial pro se litigants have sent tens of thousands of demand letters to businesses threatening class-action suits under the CIPA’s pen-register and trap-and-trace provisions for using everyday website tools like cookies, analytics software and pixels. For every lawsuit filed, an estimated 10 to 15 additional demand letters or arbitration claims never reach the public record, and California businesses have already paid more than half-a-billion dollars in settlements, according to testimony before the California Assembly Privacy Committee.

The California Assembly Privacy Committee called these pen-register suits a “poster child for abusive lawsuits,” finding that staggering liability “encourag[es] vexatious litigants to continue blasting out demand letters.” Sen. Anna Caballero, the bill’s author, said SB 690’s goal is to “protect California businesses from a new wave of abusive lawsuits” driven by a handful of firms and serial plaintiffs. According to the Assembly Committee on Privacy and Consumer Protection’s analysis of SB 690, about 600 lawsuits had been filed against California businesses when this effort began in early 2025; just 18 months later, that number had exploded to 4,000.

Gov. Newsom signed the bill on September 30, 2026.

Key Provisions/Statutes Affected
SB 690 amends only Penal Code § 637.2, CIPA’s civil remedy provision. It does not amend § 638.51, which prohibits installing or using a pen-register or trap-and-trace device without a court order and provides specified exceptions for communications service providers and where the user has consented. Under the new § 637.2(d)(1), only the California attorney general may bring an action against a private actor for a § 638.51 violation arising from conduct on a website or app. Under § 637.2(d)(2), that limitation applies retroactively to pending claims in actions filed within two years before the January 1, 2027, operative date.

Implications for Pending Lawsuits and Future Claims
Private website, online-application or mobile-application § 638.51 claims in actions filed within the two-year lookback period should be barred when SB 690 takes effect. However, cases combining § 638.51 with § 631 or another CIPA claim may continue on the other claim; older cases may fall outside retroactivity.

Because the California attorney general has sole enforcement authority of § 638.51, plaintiffs may attempt to seek leave to amend and re-plead their claims as § 631 wiretapping or §§ 632/632.7 eavesdropping claims. Such laws carry $5,000-per-violation exposure.

Next Steps for Businesses Using Website and App-Tracking Technologies

  • Inventory pending § 638.51 claims and filing dates; actions filed on or after January 1, 2025, fall within the bill’s two-year retroactivity window and should be subject to dismissal once SB 690 takes effect on January 1, 2027.
  • Consider motions to stay or dismiss for the January 1, 2027, operative date and reassess settlements and demand letters.
  • Anticipate re-pleading under §§ 631, 632, and 632.7 and prepare defenses.
  • While the law remains unsettled as to whether ordinary website tracking technologies, such as cookies, constitute pen-registers or trap-and-trace devices under § 638.51, businesses should maintain consent and cookie-banner practices, tag governance, vendor review and privacy disclosures. SB 690 does not resolve that underlying question or otherwise change the substantive requirements of § 638.51 or other CIPA and privacy provisions, and enforcement by the California AG remains available for covered § 638.51 claims.
  • Review insurance coverage for existing or threatened CIPA claims and notify carriers as appropriate.
  • Continue monitoring related California privacy legislation that may affect website-tracking practices.
These and any accompanying materials are not legal advice, are not a complete summary of the subject matter, and are subject to the terms of use found at: https://www.pillsburylaw.com/en/terms-of-use.html. We recommend that you obtain separate legal advice.