Executive Summary
California’s new law significantly narrows website privacy litigation risks under the California Invasion of Privacy Act (CIPA). Our Privacy, Cyber & Data Strategy Team explains how businesses still face exposure under other privacy claims and enforcement avenues.
- Private lawsuits targeting website tracking technologies under CIPA’s pen register and trap-and-trace provision will be barred, leaving enforcement to the state attorney general
- Retroactive application could affect cases, arbitrations, and demand letters filed on or after January 1, 2025
- Companies should continue reviewing tracking tools, consent practices, disclosures, and vendors
The landscape of website privacy litigation in California shifted materially with the enactment of a landmark statutory reform. SB 690 was signed into law by Governor Gavin Newsom on September 30, 2026, marking the first substantial legislative amendment to the California Invasion of Privacy Act (CIPA) prompted by the proliferation of website privacy lawsuits and pre-suit demand letters.
The legislation targets California Penal Code § 638.51, CIPA’s pen register and trap-and-trace provision, which plaintiffs have increasingly invoked to challenge the deployment of routine website technologies such as cookies, pixels, analytics tools, and analogous tracking mechanisms. SB 690 will go into effect on January 1, 2027.
SB 690 eliminates the private right of action for claims arising under p 638.51 if the alleged conduct occurs on an internet website, online application, or mobile application, reserving enforcement authority exclusively to the California attorney general. The legislation further incorporates a retroactivity provision that applies to claims in actions commenced on or after January 1, 2025, a measure that may affect a substantial number of pending lawsuits, arbitration proceedings, and pre-suit demands. Proponents of the reform contended that plaintiffs had progressively extended a statute originally conceived to regulate telephone surveillance to encompass ordinary website functionality, generating thousands of claims against businesses across a broad range of industries.
Although SB 690 is poised to reshape the website privacy litigation landscape, businesses should not regard the legislation as a comprehensive resolution of their CIPA exposure. The statute leaves intact other frequently asserted causes of action—notably wiretapping claims under California Penal Code § 631—and does not address other privacy statutes and theories that plaintiffs continue to invoke in website tracking cases.
There are portents of greater legislative reform. In his signing message, Governor Newsom “urge[d] the Legislature” to take on additional work next year to reform CIPA, which is “susceptible to abuse by overly aggressive litigants” and hurts California's small-business community. This is a bipartisan issue. Texas Attorney General Ken Paxton similarly warned Texas businesses and nonprofits about website privacy demand letters from California.
Businesses with pending CIPA lawsuits, mass arbitration demands, or pre-suit demand letters should consult with counsel to evaluate the implications of SB 690 for their litigation and settlement strategy. Companies should likewise continue to assess their website tracking technologies, consent management platforms, cookie disclosures, and vendor integrations. Risk may remain under alternative statutory theories or from regulatory agencies.
While broader reform efforts should continue in Sacramento and elsewhere, SB 690 represents a meaningful step toward curtailing one of the most aggressively and often frivolously litigated theories in the current wave of California website privacy litigation.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.
[View Source]