SB 690 Signed: What It Means for CIPA and Your Website

Website on a monitor with a cookie consent banner in focus, offering "Accept All" and "Manage Preferences" options.

Share This Post

On September 30, 2026, Governor Gavin Newsom signed SB 690. Starting January 1, 2027, private plaintiffs can no longer sue a business under the California Invasion of Privacy Act (CIPA) pen register provision for tracking that happens on a website or app. Only the California Attorney General can bring those claims.

That removes the legal theory behind most of the CIPA demand letters small businesses have received. It does not end CIPA risk. Wiretap claims under Section 631, which target chat widgets, session replay tools and pixels that capture what visitors type, are untouched. Business owners should keep doing CIPA work, but aim it at different problems.

SB 690 signing: what the Governor approved

SB 690, authored by Senator Anna Caballero, passed both houses on August 28, 2026 without a single no vote. Newsom signed it on September 30.

In his signing message, the Governor said the bill targets the “vexatious use of CIPA lawsuits and demand letters” against small businesses. He also said the job is unfinished and asked the Legislature to address other parts of CIPA in 2027.

The signed version is much narrower than the bill first introduced in 2025. Earlier drafts would have exempted any data processing done for a “commercial business purpose” across several CIPA sections. Amendments on July 2, 2026 dropped that approach.

What SB 690 does for website owners

SB 690 changes who can sue, not what is legal. It amends one section, Penal Code 637.2, which sets CIPA’s civil damages: $5,000 per violation or three times actual damages, with no proof of harm required.

  • Pen register claims over websites and apps go to the Attorney General. A suit against a private business under Section 638.51, based on conduct on a website, online app or mobile app, can now be brought only by the Attorney General.
  • The effective date is January 1, 2027. The bill has no urgency clause.
  • It reaches back to recent lawsuits. It applies to pending claims in actions filed on or after January 1, 2025.
  • Enforcement shifts to the state. The California Department of Justice is projected to add six positions and about $1.5 million in funding starting in 2027.

This matters because the pen register theory drove the recent wave. Plaintiffs argued that a cookie or pixel recording a visitor’s IP address or device ID works like a phone-line pen register. The Assembly Appropriations Committee assumed roughly 4,000 pending CIPA actions, mostly built on that theory.

What SB 690 does not do

SB 690 is a carve-out, not a repeal. The Reform CIPA coalition told lawmakers the final version would fully relieve only 27 percent of organizations facing CIPA litigation and leave 61 percent unprotected.

IssueStatus after SB 690
Section 631 wiretapping claimsPrivate suits continue at $5,000 per violation
Sections 632 and 632.7 eavesdropping claimsPrivate suits continue
Tracking without consent under Section 638.51Still prohibited; only the enforcer changed
Demand letters already receivedNot wiped out; pen-register-only letters lose leverage
Lawsuits filed before January 1, 2025Outside the retroactivity window, read literally
Federal Wiretap Act, Pennsylvania, Florida, VPPA, Washington health data lawUnaffected; SB 690 is California-only
Whether a pixel is a pen registerStill unresolved in the courts

Only the pen register claim changes hands; wiretap and eavesdropping claims stay open to private plaintiffs.

Two limits deserve a plain warning. First, defense firms expect plaintiffs to replead pen register cases as wiretap cases. Second, the retroactivity clause will likely be challenged in court, so it is not a guaranteed exit for pending suits.

Should business owners still do CIPA work after SB 690?

Yes. The reason to do it has shifted from pen register claims to wiretap claims, regulators and other states.

  1. Wiretap claims follow content, not identifiers. Section 631 asks whether a third party captured what a visitor said or typed. Chat widgets, session replay, form analytics and site search tracking sit on that side of the line.
  2. The conduct is still unlawful. Tracking without consent still violates Section 638.51. The Attorney General and the California Privacy Protection Agency become the main enforcement risk from 2027.
  3. Your visitors are not only in California. Similar wiretap laws in Pennsylvania, Florida and other states are untouched.
  4. More CIPA reform may come, in either direction. The Governor asked for 2027 legislation on other CIPA sections. That outcome is not known yet.

Who benefits most from SB 690? A site that runs only first-party analytics, with no chat, replay or ad pixels, saw its private-lawsuit exposure fall more than most. That still needs to be confirmed by testing, not assumed.

CIPA findings from our own website reviews

In our CIPA reviews of client sites this year, the most serious problems were consent setups that did not do what the site owner believed. We load each site as a first-time California visitor, export the browser’s network traffic as a HAR file from Chrome, and record every request sent before a consent choice.

  • A banner that never appeared for California visitors. On one professional services site, the consent tool was configured to skip California. Google Tag Manager’s consent mode pre-granted tracking, so tags fired on the first page load.
  • No consent tool at all. On another site, Tag Manager, a stats plugin, reCAPTCHA, an accessibility widget and a contact form plugin all loaded with no consent management platform in place.

SB 690 changes which legal theory these setups invite, not whether they are problems. A tag that loads before consent and sends form entries or chat text to a third party is the fact pattern Section 631 claims are built on.

CIPA checklist for your website after SB 690

The first five steps can be started in a browser; the last two need your vendors and your attorney.

  • ☐ List every tag, pixel, chat widget, session replay tool and form plugin on the site, with what each sends and to whom.
  • ☐ Open the site in a private window as a new visitor and check whether anything non-essential loads before you make a consent choice.
  • ☐ Confirm the consent banner blocks the tools it claims to block, using the browser’s network panel.
  • ☐ Review tools that capture content first: chat, session replay, form analytics and site search tracking.
  • ☐ Match your privacy policy and CCPA opt-out link to the tool list.
  • ☐ Check vendor contracts for service provider terms that limit how they use visitor data.
  • ☐ If you have a pending lawsuit or demand letter, give your attorney its filing date and the claims listed so they can assess SB 690’s retroactivity.

CaliNetworks is a digital marketing agency, not a law firm. This post is general information, not legal advice. Talk to privacy counsel about your specific site and any claims against you.

Sources

Share This Post

More To Explore

ada website compliance on all electronic devices for desktop, tablet, mobile
ADA Compliance

What is ADA Website Compliance?

A Guide for explaining what ADA Compliance is in 2026 If your organization has a website (and let’s be honest, who doesn’t these days?),