California just closed the door on one legal theory driving thousands of CIPA website-tracking claims, but businesses still face real exposure under the statute’s other provisions.
For three years, businesses have faced a particular brand of privacy suit: claims that ordinary website cookies, pixels, and chat tools are illegal “pen registers” under California Penal Code Section 638.51. On September 30, Gov. Gavin Newsom signed Senate Bill 690, cutting off the private right of action behind the pen register theory for conduct on websites and apps. That relief is certainly welcomed, but it does not end California Invasion of Privacy Act (CIPA) exposure.
Why Section 638.51 Became a Lawsuit Magnet
Section 638.51 was originally intended to target physical devices that captured telephone routing information, not website code. Plaintiffs’ firms argued that IP addresses, device identifiers, and similar metadata collected by routine web tools satisfy that same definition, and trial courts split on the question. The volume of these suits became difficult to ignore: Legislative staff estimated close to 4,000 Section 638.51 actions were pending statewide, the great majority built on a website-tracking pen-register theory, and each violation could expose a company to the greater of $5,000 or treble actual damages without any need to show actual harm. Facing that math, many defendants chose to settle early rather than test the statutory theory in court.
Weeks before SB 690 passed, the California Court of Appeal tentatively addressed the same question in Variety Media, LLC v. Superior Court, No. B350578 (Cal. Ct. App. 2d Dist. tentative ruling Aug. 21, 2026). The court indicated that Section 638.51 can reach internet activity in principle, but the court concluded that an IP address alone — without data showing where that traffic was routed — does not state a claim. Notably, the panel rejected the argument that the pen-register provision is confined to telephone networks. Instead, the panel adopted a technology-neutral reading of the statute, even as it found the particular pleading before it wanting because an IP address shows where a communication came from, not where it was sent. While the ruling is not final, it signals that courts are willing to apply the statute’s language to modern technology, and that better-pleaded cases describing actual routing destinations may well survive where this one did not. SB 690 moots most of that fight for private plaintiffs.
What SB 690 Actually Shuts Down
The bill does not touch the underlying prohibition in Section 638.51 itself — installing a pen register or trap-and-trace device without a court order or the user’s consent remains unlawful. Instead, it adds a new enforcement limitation to Penal Code Section 637.2, CIPA’s civil remedy statute, specifying that a private-actor claim under Section 638.51 arising from conduct on a website, online application, or mobile application may be brought only by the California attorney general. Effective January 1, 2027, that change leaves the attorney general as the sole civil enforcer of these website and app claims, and the state’s Department of Justice is expected to add staff and funding to take on that role.
The statute also reaches back: It bars continuation of qualifying claims in actions already pending, provided those actions were commenced on or after January 1, 2025, which means the very oldest filed cases may fall outside the retroactive bar even as more recent ones are cut off. That retroactivity language is also written to reach pending claims in a filed action, not outstanding demand letters, so a demand that has not yet ripened into a lawsuit loses negotiating leverage without being formally extinguished.
It is also worth noting how much this final version was narrowed from where it started. The bill was first introduced in 2025 as a broad exemption for data processing undertaken for a “commercial business purpose,” which would have pulled routine online business activity outside CIPA altogether, before opposition forced lawmakers to pare it back to this narrower carve-out limited to Section 638.51 enforcement.
Where CIPA Risk Remains
SB 690 reaches only Section 638.51. Sections 631 (wiretapping) and 632 (eavesdropping) are untouched, and both target the contents of a communication rather than routing data — a theory well suited to chat widgets, session-replay tools, and any feature that records what a customer typed into an account portal. These claims carry the same statutory damages exposure as Section 638.51 claims, and one industry coalition estimated that the bill as enacted would fully resolve the exposure of roughly a quarter of companies currently facing CIPA suits, leaving the majority still exposed under these surviving theories. Plaintiffs’ counsel previously pleaded claims under Section 631 and Section 632, and where available, plaintiffs will likely replead narrowed claims under these surviving theories. Section 631 claims do, however, carry a heavier pleading burden; a plaintiff must show that the intercepted material was the actual “contents of a communication” and that a third party read or tried to read it while it was still in transit.
Finally, Newsom acknowledged in his signing statement that CIPA still contains other decades-old provisions susceptible to the same kind of litigation abuse and called on the Legislature to revisit the statute again in 2027 to strike a better balance between protecting personal information and curbing opportunistic suits. So although future additional relief may be on the way, CIPA risk remains for now.
Next Steps
- Reassess pending Section 638.51 matters for a retroactivity defense under SB 690.
- Separate currently pending CIPA matters by statutory theory and by the date the action was filed, since the retroactive bar turns on when the suit was commenced rather than when the challenged tracking occurred.
- Revisit settlement strategy on suits that assert only a Section 638.51 theory, since the calculus for resolving those matters may change once the retroactive bar applies.
- Review pixels, chatbots, SDKs, and session-replay tools on consumer-facing sites and apps, flagging anything that captures form content rather than routing data alone.
- Move to opt-in consent before trackers fire on any page collecting account, application, or transaction information.
- Update vendor and data-processing agreements with analytics and chat providers to confirm how customer data is used, stored, and shared.
- Build CIPA review into the product-launch process for new digital features, since litigation theories keep shifting.
- Prepare for a shift in enforcement focus toward the California attorney general and the California Privacy Protection Agency rather than private plaintiffs’ counsel, and treat regulatory-readiness documentation as a priority alongside litigation defense.
Conclusion
SB 690 narrows the playing field, but it does not foreclose CIPA liability. If anything, it shifts the center of gravity: Private pen-register suits should recede, while attorney general inquiries and Section 631/632 claims become the theories to watch. Businesses that treat this as a reason to pause their compliance efforts, rather than a prompt to redirect them, may find themselves back in the same position under a different statutory heading. Additionally, relief under SB 690 is specific to California; exposure under the federal Wiretap Act and under comparable statutes in other states, such as Pennsylvania’s Wiretapping and Electronic Surveillance Control Act and Florida’s Security of Communications Act, along with state health-data privacy laws like Washington’s My Health My Data Act, is untouched by SB 690. For businesses collecting consumer data, these distinctions are worth considering when building a compliance plan.









