On September 30, 2026, Governor Gavin Newsom officially signed S.B. 690, a long-awaited bipartisan amendment intended to reform the California Invasion of Privacy Act (“CIPA”) by removing the private right of action for one of its most-litigated provisions: CIPA’s prohibition against the private installation of pen registers and trap-and-trap devices.
What is CIPA And What Is a Pen Register or a Trap-and-Trace Device?
As Kelley Drye has covered previously on this blog, CIPA is a 1960s wiretapping statute designed to prevent the secret interception or recording of private communications. It contains several substantive provisions, including the prohibition against eavesdropping (Cal. Penal Code 631) and the prohibition against recording confidential communications (Cal. Penal Code 632). Notably, CIPA carries significant statutory damages for any violations: any person “damaged” by any violation of CIPA may recover $5,000 per violation.
While CIPA as a whole was enacted in the 1960s, the pen register provision was only added into the statute in 2015 (Cal. Penal Code 638.51). As explained by its author at the time, the bill was intended to close a loophole and codify a state-law mechanism through which law enforcement officers could apply for a court order permitting “the capture of incoming and outgoing phone numbers” through pen registers and trap-and-trace devices, providing that installation of these devices without first obtaining a court order violates CIPA. To ensure the effectiveness of the bill, the legislature defined both terms broadly, defining pen register and trap-and-trace devices as “a device or process” that captures “dialing, routing, addressing, or signaling information,” but not the contents, of any outgoing or incoming communication, respectively.
What Led the California Legislature to Amend CIPA?
As Courts began grappling with whether CIPA a whole applies to the Internet in the early 2020s, plaintiffs turned their focus to the pen register provision. Under this new theory, plaintiffs alleged that common website features, such as tracking pixels, cookies, and session replay tools operate as illegal pen registers or trap-and-trace devices (often used interchangeably), injuring website visitors. And at the outset, courts agreed: early motions to dismiss were denied, with courts finding that when plaintiffs alleged that third-party tools had the ability to record non-substantive metadata, they fit under CIPA’s broad definitions of pen registers and trap-and-trace devices.
Fueled by CIPA’s broad statutory definitions and high statutory damages, the theory of liability soon gave way to a litigation tidal wave. According to the California Legislature, “as many of 100,000 California businesses” have received near-identical demand letters alleging CIPA violations, with at least 1,800 resulting in filed lawsuits. The legislature further cited an Oxford Economics study from June 2026, which estimated that the “average CIPA demand letter [costs] roughly $30,000 to resolve,” without even including attorneys’ fees. Most of this volume was driven by a handful of plaintiffs’ firms using pleading templates that have been described by at least one federal judge as generating “cookie-cutter” lawsuits. And this tactic worked: faced with the cost of litigation and exposure from fees, most businesses quietly resolved demand letters and lawsuits on an individual basis, costing businesses millions of dollars in the aggregate without providing consumers any privacy protections.
What Is S.B. 690?
After complaints from the small businesses targeted by these suits, S.B. 690 was the Legislature’s response. When first introduced in 2025, the bill cast a wide net, broadly shielding businesses from liability all CIPA provisions so long as the information is used for a “commercial business purpose” as defined by the CCPA. But after passing in the California Senate, debate over the legislation’s scope and whether the bill overcorrected the issue caused its progress to stall in the California Assembly, where it was placed on the suspense file so the bill’s sponsor, Senator Anna Caballero, could work with opponents on a compromise measure that could pass the legislature.
In July 2026, the Assembly Committee on Privacy and Consumer Protection published the Amended S.B. 690. Instead of a broad exception, the bill was now narrowly focused on the pen register provision, which Senator Caballero explained at the Committee’s July 1, 2026 hearing was the main driver of the litigation abuse. But while the bill no longer covered the other CIPA sections, it provided two key provisions:
- First, S.B. 690 amends the CIPA right of action to state that any action for violation of the pen register section “may be brought under this section only by the Attorney General.”
- Second, S.B. 690 provides that the bill is retroactive for any claims commenced on or after January 1, 2025, which is two years before the bill’s operative date.
The compromise measure worked: the bill unanimously passed the California Assembly on August 28, 2026, with the California Senate concurring on the amended version that same day. And while Governor Newsom’s signing message urged the California Legislature to continue its work on CIPA reform next term, he highlighted the bill’s “goal of protecting small businesses from overzealous lawsuits based on a statute written without today’s complex technological landscape in mind.”
How Does S.B. 690 Affect Businesses and Websites Moving Forward?
While S.B. 690 is not the all-encompassing fix that businesses were envisioning when it was first unveiled, it still goes a long way toward reining in abusive CIPA litigations that have taken hold. Upon the bill’s effective date on January 1, 2027, private individuals will no longer be able to bring claims for illegal installation of pen registers or trap-and-trace devices, and many pending claims will be subject to dismissal.
Despite this needed CIPA reform, however, businesses should still remain vigilant that they are complying with applicable data practices, including the CCPA and the GDPR. And while private suits under for installation of pen registers or trap-and-trace devices are no longer actionable, plaintiffs’ firms may revert back to other CIPA sections that were untouched by the legislature, such as the wiretapping provisions, which still allow for the same statutory damages. Therefore, strategies such as strengthening privacy disclosures and implementing consent management solutions remain critical for businesses to protect themselves from Section 631 eavesdropping claims or any other wiretapping or website-based claims. And, as always, please reach out if you have any concerns specific to your business.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.
[View Source]