On September 30, 2026, Governor Gavin Newsom signed SB 690. Starting January 1, 2027, private plaintiffs can no longer sue a business under the California Invasion of Privacy Act (CIPA) pen register provision for tracking that happens on a website or app. Only the California Attorney General can bring those claims.
That removes the legal theory behind most of the CIPA demand letters small businesses have received. It does not end CIPA risk. Wiretap claims under Section 631, which target chat widgets, session replay tools and pixels that capture what visitors type, are untouched. Business owners should keep doing CIPA work, but aim it at different problems.
SB 690 signing: what the Governor approved
SB 690, authored by Senator Anna Caballero, passed both houses on August 28, 2026 without a single no vote. Newsom signed it on September 30.
In his signing message, the Governor said the bill targets the “vexatious use of CIPA lawsuits and demand letters” against small businesses. He also said the job is unfinished and asked the Legislature to address other parts of CIPA in 2027.
The signed version is much narrower than the bill first introduced in 2025. Earlier drafts would have exempted any data processing done for a “commercial business purpose” across several CIPA sections. Amendments on July 2, 2026 dropped that approach.
What SB 690 does for website owners
SB 690 changes who can sue, not what is legal. It amends one section, Penal Code 637.2, which sets CIPA’s civil damages: $5,000 per violation or three times actual damages, with no proof of harm required.
- Pen register claims over websites and apps go to the Attorney General. A suit against a private business under Section 638.51, based on conduct on a website, online app or mobile app, can now be brought only by the Attorney General.
- The effective date is January 1, 2027. The bill has no urgency clause.
- It reaches back to recent lawsuits. It applies to pending claims in actions filed on or after January 1, 2025.
- Enforcement shifts to the state. The California Department of Justice is projected to add six positions and about $1.5 million in funding starting in 2027.
This matters because the pen register theory drove the recent wave. Plaintiffs argued that a cookie or pixel recording a visitor’s IP address or device ID works like a phone-line pen register. The Assembly Appropriations Committee assumed roughly 4,000 pending CIPA actions, mostly built on that theory.
What SB 690 does not do
SB 690 is a carve-out, not a repeal. The Reform CIPA coalition told lawmakers the final version would fully relieve only 27 percent of organizations facing CIPA litigation and leave 61 percent unprotected.
| Issue | Status after SB 690 |
| Section 631 wiretapping claims | Private suits continue at $5,000 per violation |
| Sections 632 and 632.7 eavesdropping claims | Private suits continue |
| Tracking without consent under Section 638.51 | Still prohibited; only the enforcer changed |
| Demand letters already received | Not wiped out; pen-register-only letters lose leverage |
| Lawsuits filed before January 1, 2025 | Outside the retroactivity window, read literally |
| Federal Wiretap Act, Pennsylvania, Florida, VPPA, Washington health data law | Unaffected; SB 690 is California-only |
| Whether a pixel is a pen register | Still unresolved in the courts |
Only the pen register claim changes hands; wiretap and eavesdropping claims stay open to private plaintiffs.
Two limits deserve a plain warning. First, defense firms expect plaintiffs to replead pen register cases as wiretap cases. Second, the retroactivity clause will likely be challenged in court, so it is not a guaranteed exit for pending suits.
Should business owners still do CIPA work after SB 690?
Yes. The reason to do it has shifted from pen register claims to wiretap claims, regulators and other states.
- Wiretap claims follow content, not identifiers. Section 631 asks whether a third party captured what a visitor said or typed. Chat widgets, session replay, form analytics and site search tracking sit on that side of the line.
- The conduct is still unlawful. Tracking without consent still violates Section 638.51. The Attorney General and the California Privacy Protection Agency become the main enforcement risk from 2027.
- Your visitors are not only in California. Similar wiretap laws in Pennsylvania, Florida and other states are untouched.
- More CIPA reform may come, in either direction. The Governor asked for 2027 legislation on other CIPA sections. That outcome is not known yet.
Who benefits most from SB 690? A site that runs only first-party analytics, with no chat, replay or ad pixels, saw its private-lawsuit exposure fall more than most. That still needs to be confirmed by testing, not assumed.
CIPA findings from our own website reviews
In our CIPA reviews of client sites this year, the most serious problems were consent setups that did not do what the site owner believed. We load each site as a first-time California visitor, export the browser’s network traffic as a HAR file from Chrome, and record every request sent before a consent choice.
- A banner that never appeared for California visitors. On one professional services site, the consent tool was configured to skip California. Google Tag Manager’s consent mode pre-granted tracking, so tags fired on the first page load.
- No consent tool at all. On another site, Tag Manager, a stats plugin, reCAPTCHA, an accessibility widget and a contact form plugin all loaded with no consent management platform in place.
SB 690 changes which legal theory these setups invite, not whether they are problems. A tag that loads before consent and sends form entries or chat text to a third party is the fact pattern Section 631 claims are built on.
CIPA checklist for your website after SB 690
The first five steps can be started in a browser; the last two need your vendors and your attorney.
- ☐ List every tag, pixel, chat widget, session replay tool and form plugin on the site, with what each sends and to whom.
- ☐ Open the site in a private window as a new visitor and check whether anything non-essential loads before you make a consent choice.
- ☐ Confirm the consent banner blocks the tools it claims to block, using the browser’s network panel.
- ☐ Review tools that capture content first: chat, session replay, form analytics and site search tracking.
- ☐ Match your privacy policy and CCPA opt-out link to the tool list.
- ☐ Check vendor contracts for service provider terms that limit how they use visitor data.
- ☐ If you have a pending lawsuit or demand letter, give your attorney its filing date and the claims listed so they can assess SB 690’s retroactivity.
CaliNetworks is a digital marketing agency, not a law firm. This post is general information, not legal advice. Talk to privacy counsel about your specific site and any claims against you.
Sources
- Governor’s signing message for SB 690
- Baker Donelson: SB 690 Signed Into Law
- Kilpatrick Townsend: What SB 690 Means for Pending Pen Register Claims
- Butler Snow: Governor Signs Legislation Curtailing CIPA Website Claims
- Clark Hill: SB 690 Limits CIPA Website Tracking Claims
- Procopio: Governor Signs SB 690
- Captain Compliance: California Closes the CIPA Pen Register Loophole
- TrueVault: SB 690 Is Now Law