California businesses received some welcome relief when Governor Gavin Newsom signed SB 690 into law on September 30, 2026.
As CDF previously blogged, the new law eliminates a private right of action under CIPA Section 638.51, which governs pen-register and trap-and-trace devices and has been the basis for one of the most heavily used theories behind recent website-tracking claims. Typically, these claims allege that website tracking tools, including cookies and pixels, constitute third-party surveillance under CIPA because they collect information about users’ interactions with websites without their consent. The law also applies retroactively to claims that accrued within the past two years.
While businesses may welcome this significant development, SB 690 does not eliminate all potential exposure arising from website tracking. Businesses should continue to remain vigilant about how their websites are configured and how tracking technologies are used.
What SB 690 Does Not Do
The new law does not:
- Eliminate all privacy claims under CIPA Section 631, including claims alleging unlawful wiretapping.
- Eliminate the possibility of enforcement by the California Attorney General or the California Privacy Protection Agency (CPPA), and it remains to be seen how aggressively these agencies will pursue website-tracking practices.
- Create a general “commercial business purpose” carve-out, an exemption that many businesses had advocated for during the legislative process.
- Prevent plaintiffs’ attorneys from pursuing other theories under California or federal privacy and digital laws, including the Electronic Communications Privacy Act (ECPA).
Planning Ahead
SB 690 represents a meaningful change in the landscape for businesses facing CIPA website-tracking claims, particularly those based on Section 638.51. However, businesses should not view the new law as a blanket exemption from potential privacy liability.
Businesses should continue to regularly review their website cookies, pixels, analytics tools, advertising technologies, and other tracking mechanisms, particularly as their marketing and technology stacks evolve. Privacy disclosures and, where appropriate, consent mechanisms remain important components of a comprehensive compliance strategy.
For businesses with pending CIPA matters, the enactment of SB 690 may also provide an additional consideration in evaluating how to efficiently resolve existing claims.
CDF’s Privacy Practice Group will continue to monitor developments related to privacy issues, CIPA, California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA) and the California Privacy Protection Agency’s enforcement actions. Please contact Dan M. Forman or Linda Wang to discuss compliance with privacy laws, any investigation by the California Privacy Protection Agency or with any questions about CIPA, CCPA, CPRA & CPPA. Our Privacy Practice Group is available to assist with policies, notices, general compliance for employers and the defense of claims and lawsuits.