Skip to content

California Legislature Passes Bill Curtailing CIPA Website-Tracking Lawsuits

September 1, 2026

The California Legislature has passed legislation that, once signed into law, significantly reduces the most active basis of website-tracking litigation in the state. On August 28, 2026, lawmakers approved Senate Bill 690 (“SB 690”), which eliminates private lawsuits under the pen-register and trap-and-trace provisions of the California Invasion of Privacy Act (“CIPA”) for alleged violations due to website-tracking technologies. The bill now heads to Governor Gavin Newsom to be signed into law.

SB 690 was introduced in response to a growing wave of demand letters and lawsuits alleging that common website technologies—including cookies, pixels, analytics software, and similar tools—constitute unlawful “pen registers” or “trap-and-trace devices” under California Penal Code section 638.51.

What SB 690 Would Change

CIPA generally prohibits the installation or use of a pen register or trap-and-trace device without a court order, subject to specified exceptions. In recent years, Plaintiffs have applied those provisions, originally directed toward telephone surveillance technologies, to website tracking tools that routinely collect information such as IP addresses, URLs, device identifiers, and other routing or addressing information.

SB 690 takes direct aim at that theory. Rather than rewriting the substantive prohibition in section 638.51, the bill, as amended, curtails CIPA’s civil-remedies provision to prevent a private plaintiff from filing litigation based on a violation of section 638.51. After its introduction in 2025 and further amendments, the legislation passed the Assembly 66-0 and received unanimous concurrence in the Senate.

Notable is the bill’s retrospective applicability to certain pending claims in actions commenced during the two years preceding the legislation’s operative date. This may not only affect future demand letters and lawsuits, but potentially also pending litigation.

What SB 690 Does Not Do

Businesses should not interpret SB 690 as altogether eliminating website-tracking litigation. The legislation addresses private actions based on the pen-register and trap-and-trace provisions of section 638.51. It does not eliminate claims under CIPA section 631, which prohibits certain unauthorized interception or use of communications and has separately been invoked against website pixels, session-replay software, chat tools, and other third-party tracking technologies.

Plaintiffs may also continue pursuing claims under other state and federal privacy statutes and common-law privacy theories depending upon the technology and information involved. Businesses, therefore, should not view passage of SB 690 as a reason to discontinue website privacy reviews or automatically restore tracking technologies that previously presented heightened risk.

This distinction is particularly important for healthcare organizations and other businesses whose websites may reveal sensitive information. Even if SB 690 becomes law, transmitting information concerning medical conditions, appointment activity, treatment interests, or other sensitive interactions to advertising or analytics vendors may implicate laws and regulatory requirements well beyond CIPA’s pen-register provision.

California Is Expanding Privacy Rights Elsewhere

At the same time that lawmakers moved to restrict this particular form of CIPA litigation, the Legislature approved two bills that would expand substantive protections under the California Consumer Privacy Act (“CCPA”).

SB 923, the Expanding Privacy Rights Act, would broaden the CCPA’s deletion right so that consumers may request deletion of covered personal information a business has collected about them and has obtained from third parties, such as data brokers. The legislation would also require certain online-only businesses to provide an online mechanism, such as a webform or portal, for consumers to submit privacy requests.

AB 1542 prohibits businesses, service providers, and contractors from selling or sharing sensitive personal information with third parties, subject to applicable statutory exceptions. Sensitive personal information under the CCPA includes categories such as Social Security numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, and certain information concerning health, sex life, or sexual orientation. The Legislature completed action on the bill at the end of August, sending it to the Governor.

Taken together, the bills reflect an important distinction in California’s evolving privacy landscape: Lawmakers appear willing to curb attempts to use an older surveillance statute against ordinary website technologies while simultaneously strengthening the state’s modern consumer-privacy framework.

What Businesses Should Do Now

As a matter of best practice, businesses should continue treating website tracking as a material privacy and litigation risk. SB 690 has not yet become law, and even if signed, its principal protection is directed at one particular CIPA theory.

Organizations should inventory and evaluate their use of website technology based on operational needs. Organizations should also carefully align their use of technologies with policies and procedures and, moreover, privacy notices. Both technologies and policies should be reviewed and updated periodically to ensure their continued accuracy over time.

Businesses currently facing CIPA section 638.51 demand letters or litigation should also evaluate SB 690 carefully. If Governor Newsom signs the bill, its application to certain pending claims could materially affect the viability and settlement value of existing pen-register cases.

Bottom Line

Once signed into law, SB 690 provides meaningful relief from the recent proliferation of CIPA pen-register lawsuits directed at ordinary website-tracking technologies. It does not, however, create a general safe harbor for pixels, cookies, analytics tools, or other tracking technologies.

Organizations should, therefore, view the legislation as a significant narrowing of one litigation theory based on one state law and not the end of website privacy risk overall.

This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual author(s) only and are not necessarily the views of Clark Hill PLC or Clark Hill Solicitors LLP. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.

Subscribe for the latest

Subscribe