Overview
When we wrote in April that California's Senate Bill 690 had stalled and that a statutory safe harbor from California Invasion of Privacy Act (“CIPA”) website tracking suits "would not take effect before 2027 at the earliest," we did not expect the Legislature to revive the bill, strip it down to a single provision, and pass it without a dissenting vote in either chamber. But that’s what happened on August 28, 2026, and the enrolled bill has been with Governor Gavin Newsom since September 4, where he has until September 30 to sign it, veto it, or let it become law without his signature. Here is what the bill would do to the "pen register" theory at the center of the current wave of CIPA website tracking claims, what it would leave untouched, and how a business holding a demand letter should read the next two weeks.
Where the Bill Stands
On August 28, 2026, the California Legislature passed Senate Bill 690 (SB 690), a measure aimed at one of the most active theories in the recent wave of website tracking litigation. The Assembly approved the bill 66–0, and the Senate unanimously concurred in the Assembly's amendments by a vote of 40–0, sending it to the Governor. The bill was enrolled on August 31, 2026, and presented to the Governor on September 4. The bill cleared both chambers without a dissenting vote, but the Governor has taken no public position and could sign it, veto it, or allow the bill to become law without his signature. Under article IV, section 10(b)(2) of the California Constitution, the deadline for that decision is September 30, 2026. The enrolled bill carries no urgency clause, so if it becomes law this year it would take effect January 1, 2027. Its express retroactivity provision would then reach qualifying claims that remain pending on that date in actions commenced on or after January 1, 2025.
In short, the amended SB 690 would eliminate the private right of action for alleged violations of California's pen register and trap-and-trace restrictions when the challenged conduct occurs on a website, online application, or mobile application. For qualifying website and app conduct, only the California Attorney General could bring a civil action under Section 637.2 against a private actor for an alleged Section 638.51 violation. The limitation would apply retroactively to qualifying claims that remain pending on the operative date in actions commenced during the preceding two years.
How the Litigation Got Here
CIPA, Cal. Penal Code sections 630 et seq., enacted in 1967 to address illicit telephone wiretapping, was rarely invoked for decades until plaintiffs' firms applied Section 631 (wiretapping), to consumer-facing web technologies such as chat features, session replay tools, and analytics pixels, a history we traced in Part 1 of our Chatbot on the Witness Stand series.
As Section 631 theories met defense resistance, plaintiffs turned to a less tested provision: Penal Code Section 638.51, which bars installing or using a pen register or a trap and trace device without a court order. A pen register is a device or process that records dialing, routing, addressing, or signaling information of an outbound communication, such as an IP address, domain, or other destination information, whereas a trap and trace device captures the corresponding incoming information, identifying the source of a communication. Neither process captures the contents of a communication, and neither contemplated commercial web analytics. Plaintiffs nonetheless argue that routine tools, such as cookies, pixels, tags, and analytics scripts that collect IP addresses, URLs, and device identifiers, function as unlawful pen registers or trap-and-trace devices.
Because these claims carried the prospect of statutory damages of $5,000 per violation, or three times actual damages, under Section 637.2(a), without proof of actual damages, they became a favored litigation and demand letter tool; federal plaintiffs must still show concrete injury for Article III standing. Testimony before the Assembly Privacy and Consumer Protection Committee describes pen register and trap-and-trace cases growing from roughly 600 when the CIPA amendments were proposed in early 2025, to more than 4,000 eighteen months later, with tens of thousands more businesses receiving demand letters, including small business owners, nonprofits, businesses with no California operations and companies whose only alleged conduct was deploying a common Meta Pixel or LinkedIn tag.
The case law never settled. Trial courts split over whether common website technologies and the information they collect satisfy Section 638.51, producing a forum- and fact-dependent landscape with no controlling California appellate decision. As of this writing, no California appellate court has construed the provision, although a pending writ proceeding may change that. In Variety Media, LLC v. Superior Court, No. B350578, the Second District issued a tentative ruling on August 21, 2026, heard argument on August 25; no opinion has issued. The tentative ruling would reject the argument that internet communications fall categorically outside the statute but hold that the complaint failed because a pen register must capture information identifying where a communication is headed, whereas an IP address identifies the visitor's own device. Because SB 690 does not amend Section 638.50 or Section 638.51, a published opinion would remain significant, including for the Attorney General's enforcement authority and for claim outside the retroactivity window. A tentative ruling is not a filed opinion and may change before issuance.
What SB 690 Would Change
SB 690 arrived at the Governor's desk in a form significantly narrower than the CIPA reform measure it was in 2025. As introduced, SB 690 proposed to exempt technology used consistently with a "commercial business purpose," a term drawn from the California Consumer Privacy Act, from several CIPA provisions, and would have narrowed the definitions of a pen register and a trap and trace device. The Senate passed it 35–0 on June 3, 2025, but the Assembly held it as a two-year bill over the breadth of the exemption. On July 1, 2026, the Assembly Privacy and Consumer Protection Committee amended the measure into its present form and removed the exemption entirely, a turn our August 28 AI Litigation Roundup flagged on the day the floor votes were taken.
The enrolled version makes one focused change: it amends CIPA's civil remedies provision, Cal. Penal Code Section 637.2, by adding a new subdivision (d) providing that an action against a private actor for a Section 638.51 violation "alleged to arise from conduct occurring on an internet website, online application, or mobile application" may be brought only by the Attorney General. Two features of that change matter in practice:
What This Means for a Business Facing a Demand or Suit
Three Key Takeaways
A Section 638.51 demand arising from website or app activity should be evaluated in light of the bill’s potential elimination of the claimant’s private remedy. That may materially reduce settlement leverage, particularly where the demand does not assert a developed alternative theory. The bill remains unsigned, however, and its practical value depends on the claims, filing date, procedural posture, and ultimate treatment of retroactivity.
Defendants in pending cases should preserve arguments based on the enrolled bill’s text, anticipated operative date, filing window, and proposed retroactive application while continuing to litigate the underlying statutory merits. Until the bill becomes law and courts apply it, dismissal should not be assumed.
SB 690 would not eliminate Section 631 or other website privacy theories. Businesses should continue to identify active tags, test consent states, evaluate transmitted data, confirm vendor roles and contractual restrictions, preserve relevant configurations, and address Global Privacy Control and other applicable opt-out signals.
For questions about CIPA compliance and website tracking litigation, please contact the Jones Walker Privacy, Data Strategy and Artificial Intelligence team. Stay tuned and subscribe for continued insights from the AI Law and Policy Navigator.
