September 02, 2026

Trapped and Traced No More - SB 690 Will Stem Tidal Wave of California Invasion of Privacy Claims

Empower
Your Business:

Subscribe to our News & Updates for Practical Solutions

Trapped and Traced No More - SB 690 Will Stem Tidal Wave of California Invasion of Privacy Claims

The flood of California Invasion of Privacy Act (CIPA) lawsuits targeting cookies, pixels and other tracking tools under antiquated laws that did not contemplate the internet is on its way to an end. For years, plaintiffs’ lawyers and individuals have used CIPA to send demand letters, commence arbitrations and class action lawsuits against companies of every size alleging that website tracking was illegal eavesdropping. On August 28, 2026, California legislature passed SB 690 eliminating a private right of action under CIPA for one of the most heavily used theories behind the website-tracking claims. The bill also applies retroactively to claims accrued within the past two years.

SB 690 still needs to be signed by Governor Newsom before it becomes law. If enacted, the bill will provide meaningful relief, but it is not a “cure-all,” as it leaves open other avenues for plaintiffs to bring website related claims and businesses must continue to monitor their website tracking practices for compliance.

What SB 690 Does:

Many CIPA claims rely on CIPA § 638.51 governing "pen registers" and "trap and trace" devices. In plain terms, those are surveillance tools — historically used by law enforcement — that capture the routing and dialing information of outgoing communications, such as a list of the phone numbers a person dials. Plaintiffs' attorneys argue that everyday cookies and pixels on business websites function the same way, secretly logging visitors' activity in violation of the law.

SB 690 will amend the law so that such claims may only be brought by the California Attorney General, not private individuals or the plaintiff’s lawyers.

Planning Ahead:

  • Effective: If signed into law by Governor Newsom, this bill will go into effect January 1, 2027.
  • Retroactivity: The bill is written to apply retroactively to claims that accrued within the past two years — meaning it may affect matters already in the pipeline, not just future ones, something that we expect to see attacked by future litigation.
  • Cautions:
    • The bill does not eliminate all privacy claims under CIPA § 631, for alleged wiretapping.
    • It is not known how aggressive the Attorney General’s office via that California Privacy Protection Agency (CPPA) will be.
    • There is no general “commercial business purpose” carve-out as requested by many businesses.
    • Plaintiffs’ lawyers will pivot to other privacy or digital laws.

What To Do Now:

  1. Treat website compliance as an ongoing and regular task. Make a continuous effort to review and update your website’s cookies, pixels, tracking tools, and privacy disclosures and consents, especially as your marketing stack changes. Disclosure and consent may be the best deterrent.
  2. Leverage 690 for pending matters. SB 690 is a bargaining chip to efficiently resolve pending matters.
  3. Consult with counsel and stay updated in the evolving ere of privacy laws and litigation.

We Are Here To Help:

CDF’s Privacy Practice Group will continue to monitor developments related to privacy issues, CIPA, California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA) and the California Privacy Protection Agency’s enforcement actions. Please contact Dan M. Forman or Linda Wang) to discuss compliance with privacy laws, any investigation by the California Privacy Protection Agency or with any questions about CIPA, CCPA, CPRA & CPPA. Our Privacy Practice Group is available to assist with policies, notices, general compliance for employers and the defense of claims and lawsuits.

Empower

Empower Your Business:

Subscribe to our News & Updates for Practical Solutions