SB 690 would end lawsuits over website tracking under one CIPA provision
California's SB 690, awaiting the governor's signature, would eliminate private lawsuits over website tracking under one CIPA provision while leaving other privacy claims intact.

California's SB 690, heading to Governor Gavin Newsom for signature by September 30, would end private lawsuits under one provision of the California Invasion of Privacy Act targeting website and mobile app tracking. The bill would eliminate the private right of action under CIPA's pen register provision, added to the 1967 law in 2015, while leaving other privacy theories available to plaintiffs. For tech companies, the change narrows exposure to one type of claim even as other CIPA provisions and federal laws remain.
The bill addresses a surge in litigation triggered by a single court ruling. According to the bill's sponsors, filings under the pen register provision climbed from roughly 600 to about 4,000 in the roughly eighteen months after lawmakers introduced the measure in early 2025, as plaintiff firms sent demand letters targeting cookies, pixels, analytics software, software development kits, and session replay tools. SB 690 passed the Assembly 66-0 and received unanimous Senate concurrence. But the final outcome still depends on the governor's decision in the next week.
How pen register provisions were meant to work
CIPA Section 638.51, added to the Penal Code in 2015 to harmonize California law with the federal pen register statute, prohibits the installation or use of a pen register or trap-and-trace device without a court order. CIPA itself was enacted in 1967 to address telephone eavesdropping. A pen register records the numbers dialed from a telephone line—"dialing, routing, addressing, or signaling information"—without capturing the content of the conversation itself. A trap-and-trace device works in reverse, identifying numbers calling into a line. The statute carried a per-violation penalty of $5,000.
What made the pen register theory appealing to plaintiffs' attorneys was that it required no proof of actual injury. The statute only required showing that recording of routing data occurred, not that anyone listened to actual communications or suffered harm. This lower evidentiary bar later made the theory straightforward to litigate once plaintiffs applied it to websites.
The legal breakthrough that opened website tracking claims
The application of pen register law to websites remained dormant until a critical court ruling changed the analysis. In *Greenley v. Kochava*, a court determined that "a process can take many forms," opening the door to treating cookies, tracking pixels, analytics software, and other web technologies as pen registers. The ruling suggested that if a tracking tool collects routing information—IP addresses, URLs, device identifiers, or similar data—it could violate the 1960s statute.
Plaintiff attorneys seized on this interpretation. They argued that when a website deploys cookies, pixels, SDKs (software development kits), or session replay tools, it functions as a pen register by capturing addressing and routing data without court authorization. Under this theory, each website visitor could count as a separate violation carrying $5,000 in potential liability, making theoretical exposure staggering for any popular website.
The litigation wave and demand letter business model
After *Greenley*, plaintiff firms began targeting websites systematically. They sent demand letters in volume from templates, identifying websites using common tracking technologies and threatening litigation unless companies paid settlements. The effort required per letter was minimal, creating a scalable business model. Each visitor counted as a potential violation, so even small websites faced claims alleging thousands of violations with millions in potential damages.
According to the bill's supporters, filings escalated from roughly 600 cases in early 2025 to about 4,000 roughly eighteen months later. Law firms characterized the pen register provision as a low-friction way to extract settlements without proving interception of actual message content or demonstrating real privacy harm. The statute originally meant for telephone surveillance suddenly became a template for mass-scale website litigation. The Assembly Committee on Privacy and Consumer Protection called the provision "a poster child for abusive lawsuits." Companies generally settled hastily because potential liability was staggering.
What SB 690 eliminates and how it applies
SB 690 would end private rights of action under California Penal Code § 638.51 for claims arising from website, online application, or mobile application conduct. The provision would shift enforcement authority exclusively to the California Attorney General. Once the law takes effect on January 1, 2027, plaintiffs would no longer be able to bring pen register or trap-and-trace claims against private businesses over website tracking.
Critically, the law would apply retroactively to cases filed on or after January 1, 2025—meaning pending lawsuits brought within two years before the operative date could potentially be dismissed under the new rule. This retroactive application could resolve many cases currently in litigation without going to trial, providing relief to companies facing pending claims from the litigation wave.
“Law firms sent demand letters in volume from templates, identifying websites using common tracking technologies and threatening litigation unless companies paid settlements.”
What lawsuits remain available to plaintiffs
SB 690 would leave multiple avenues open for website tracking claims, though each requires a higher evidentiary bar. CIPA's traditional wiretapping provision, Section 631 (California's Wiretap Act), remains fully available to private plaintiffs. Section 631 requires showing that tracking captured the "contents" of communications and occurred "in transit," with potential defenses when a party consents. Section 632 (recording confidential communications) focuses instead on whether there was a "reasonable expectation that the communication was not being overheard or recorded."
Federal law provides additional claims. The federal Electronic Communications Privacy Act (ECPA) and the Video Privacy Protection Act impose similar requirements to show contents interception and allow third-party defenses. State wiretap analogues in Florida, Pennsylvania, Arizona, and Washington remain available. Plaintiffs also retain common law privacy claims and state consumer protection statutes. Legal experts characterize the remaining theories as "the more expensive ones," noting that they leave defendants with more built-in defenses than pen register claims and require more factual development.
Why timing matters before September 30
Governor Newsom is expected to have until September 30, 2026, to act on SB 690. He can sign the bill, veto it, or allow it to become law without his signature. The legislature's unanimous passage—66-0 in the Assembly with unanimous Senate concurrence—signals strong support. Observers generally expect him to sign, though a veto remains possible.
The governor's decision determines whether private pen register lawsuits stop being filed on January 1, 2027, or continue under current law. If he signs, pending lawsuits could face dismissal under retroactive application. If he vetoes, the pen register provision remains available to plaintiffs through 2027 and beyond.
What this means for California tech companies
If enacted, SB 690 removes one significant source of litigation risk. The pen register theory's ease of pleading made it especially expensive to defend even for companies with sound legal positions. Shifting enforcement to the attorney general alone narrows the field of potential plaintiffs and curtails the demand-letter business model built on pen register claims.
However, companies cannot treat this as a complete resolution of tracking liability. Traditional CIPA wiretapping claims require more factual development, but the private right of action survives. Section 632 claims focusing on expectation of privacy in communications may prove more difficult for defendants to defeat. The shift to these alternative theories means privacy policies, consent mechanisms, and transparency about tracking methods become even more important. Tech companies that operate websites or apps serving California users still face substantial CIPA exposure under provisions SB 690 does not touch. The legislation reflects a deliberate narrowing rather than comprehensive privacy deregulation—California simultaneously expanded protections under the CCPA.
Related coverage: What the CCPA and CPRA actually require of a business; What your California privacy rights actually let you do.



