ARTICLE
7 October 2026

Still Tracking, Still Suing: Website Privacy Litigation After SB 690

BB
Bass, Berry & Sims

Contributor

Bass, Berry & Sims is a national law firm with nearly 350 attorneys dedicated to delivering exceptional service to numerous publicly traded companies and Fortune 500 businesses in significant litigation and investigations, complex business transactions, and international regulatory matters. For more than 100 years, our people have served as true partners to clients, working seamlessly across substantive practice disciplines, industries and geographies to deliver highly-effective legal advice and innovative, business-focused solutions. For more information, visit www.bassberry.com.
California's SB 690 eliminates private lawsuits under CIPA for pen register and trap-and-trace device theories, but website tracking litigation continues under federal wiretapping statutes, ECPA's crime-tort exception, and sector-specific claims. Businesses face ongoing risk from cookies, pixels, and tracking technologies that may unlawfully intercept visitor communications or collect routing data without proper consent.
United States California Privacy

Key Takeaways

  • California SB 690, passed August 28, 2026, eliminates private lawsuits under the California Invasion of Privacy Act (CIPA) based on pen register and trap-and-trace device theories, including claims filed on or after January 1, 2025, but does not affect wiretapping claims, ECPA theories, or claims in other states.
  • Plaintiffs will continue to pursue website tracking litigation under federal and state wiretapping statutes, the ECPA’s crime-tort exception, and sector-specific theories targeting healthcare, financial services, and consent mismatch scenarios.
  • Businesses can reduce litigation risk by mapping all tracking technologies, aligning privacy disclosures with actual data flows, configuring consent tools to enforce user choices, and testing regularly to confirm that cookie banners, tag managers, and CMPs function as intended.

A company’s website cookies may be generating more than just marketing data—they may also be generating lawsuits. Over the past several years, plaintiffs have sent thousands of demand letters and filed hundreds of putative class actions claiming that cookies, pixels, session-replay tools, chat widgets, and mobile software development kits (SDKs) (commonly called “tracking technologies”) unlawfully intercept visitor communications or collect routing data. Most demands rely on wiretapping statutes, chiefly the California Invasion of Privacy Act, but plaintiffs increasingly add federal and other state theories.

A bill passed by the California Legislature on August 28 – SB 690 – cuts off one common private claim involving pen registers and trap-and-trace devices, including some pending cases, but it does not eliminate broader tracking-technology litigation risk. A business does not have to sell to California residents, or even operate there, to face this risk.

Below we examine the technology behind tracking tools and summarize the legal theories plaintiffs assert, identify the key players driving litigation, and outline how to respond to a demand and reduce risk going forward.

How Website Tracking Tools Work and Where They Appear

Tracking technologies support analytics, advertising, and basic website or app functions. Cookies, for example, store or retrieve browser data to maintain a login, remember a preference, measure traffic, or support advertising. Pixels, web beacons, tags, and scripts work differently: they run when a page loads or a user acts, sending page views, searches, clicks, form submissions, or purchases to a technology provider.

Other tools collect richer interaction data. Session-replay and heatmap tools can record clicks, scrolling, navigation, and form activity throughout a visit. Chat widgets and artificial intelligence (AI) chatbots send a user’s message directly to the vendor that runs the service. Mobile apps, streaming apps, and connected televisions carry their own tracking layers too: SDKs assist in analytics, ads, attribution, and crash reports, and viewing or device events for streaming and connected hardware.

Where Do Cookies, Pixels, and SDKs Appear on Websites?

These tools appear across digital properties. Common page locations for tracking technology include search results, product pages, shopping carts, checkout flows, contact forms, job applications, and embedded videos. Healthcare sites may use them on appointment schedulers, provider searches, symptom pages, and patient portals. Financial sites may use them on calculators, applications, quote tools, login pages, and account dashboards. They also appear outside of website and mobile apps, including marketing emails, streaming services, and connected devices.

Depending on the tool, they can capture uniform resource locators (URLs), Internet Protocol (IP) addresses, device identifiers, geolocation, search terms, form entries, video-viewing events, or account activity, much of which are considered “personal information” and identifiers under privacy laws.

Legal Theories Behind Tracking Claims

Potential plaintiffs use a variety of theories for alleging that tracking technology is illegal and that they should be awarded damages. Here are the most common claims:

State Wiretapping, Pen Register, and Trap-and-Trace Claims, Including California Claims

A dozen states require every person in a conversation to give permission before it can be recorded or legally intercepted. These include California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. Plaintiffs in these states, and particularly in California under the California Invasion of Privacy Act (CIPA), claim that when a website uses third-party tracking technology, it allows a vendor to receive a user’s communication illegally unless it has obtained prior consent, or that these technologies are “pen registers” or “trap and trace devices.” These claims treat searches, form entries, clicks, URLs, identifiers, or routing data as a communication. These statutes can offer private remedies with thousands of dollars in statutory damages per violation, which can accumulate rapidly.

SB 690, passed by the California Legislature on August 28, eliminates the statutory basis plaintiffs use for private demand letters, individual lawsuits, and class actions under CIPA related to the pen register and trap-and-trace device theory, instead leaving enforcement authority with the California Attorney General. The bill, if signed into law as expected, applies retroactively to pending claims in actions filed within two years before its operative date. If it takes effect on January 1, 2027, that retroactivity may support dismissal of claims filed on or after January 1, 2025. While SB 690 is a meaningful development, the bill does not affect California wiretapping theories, change the definitions of “pen register” or “trap and trace device,” or affect any claims in other states. Therefore, we expect plaintiffs are likely to shift litigation strategies rather than end website privacy litigation altogether.

Electronic Communications Privacy Act (ECPA) Claims

The ECPA bans the real-time interception of electronic communications via hidden devices or wiretaps, as well as pen registers that track routing information. The statute, however, allows an interception when one party consents, and a website operator consents to the tools it installs. Plaintiffs therefore invoke the law’s crime-tort exception, which says that consent does not shield a defendant if the interception was made to further a separate crime or tort. Plaintiffs argue that a false privacy statement, undisclosed data use, or broken consent tool supplies the separate wrong needed to trigger the exception. Civil plaintiffs can recover statutory damages of the greater of $10,000 or $100 per day of violation, plus punitive damages and attorney’s fees. This theory has moved tracking litigation beyond California and makes accurate notices and working consent controls more important everywhere.

Healthcare and Health-Privacy Claims

Healthcare plaintiffs often add a sector-specific theory: claiming that pixels or other tools disclosed health information from appointment pages, symptom searches, prescription pages, forms, URLs, or patient portals. HIPAA offers no private right of action, so plaintiffs instead use an alleged HIPAA or state medical-privacy violation as the predicate wrong that triggers ECPA’s crime-tort exception. Courts have reached mixed results. Some have dismissed claims because the disclosed data did not qualify as protected health information. Others have let claims proceed where the data arguably revealed a treatment relationship or health condition.

Financial-Services and Gramm-Leach-Bliley Act (GLBA) Claims

Potential plaintiffs will likewise target businesses in the financial-services space using a similar theory: trackers allegedly received financial information from applications, quote tools, account pages, or eligibility forms. Some plaintiffs argue that this disclosure violated GLBA and use that alleged violation to support ECPA’s crime-tort exception. Some courts have disagreed and rejected the alleged GLBA predicate outright. The same facts, however, may still support wiretapping, consumer-protection, privacy, or misrepresentation claims.

Consent Mismatch Claims

A significant issue can arise when a website operator believes that it is obtaining consent but the mechanism for collecting consent does not work or is poorly installed. This happens far more than many realize. For, example a consent notice may tell a visitor that “Rejecting All” cookies stops the data flow for non-essential tracking technologies, but the technology loads even after selecting “Reject All.” In this case, the vendor has intercepted a communication without consent, which plaintiffs allege as a violation of ECPA, CIPA, or other wiretap laws as well as fraud. Plaintiffs also assert that failing to honor choices provided to users is a deceptive trade practice or a misrepresentation under state consumer protection laws.

Other Claims

Plaintiffs also reach for theories tailored to the data at issue. A plaintiff whose viewing history is disclosed through a pixel may sue under the Video Privacy Protection Act (VPPA). Others fall back on state consumer-protection law, common-law fraud, or an intrusion-upon-seclusion claim for conduct a reasonable person would find offensive.

Who Is Bringing Website Tracking Claims?

Plaintiffs’ Counsel

A small group of plaintiffs’ firms drives most tracking litigation. These generally file near-identical, templated complaints against many defendants through named plaintiffs, alleging state invasion of privacy, ECPA or related privacy claims based on publicly visible third-party tools or visitor data transfers. SB 690 bill may weaken demands and lawsuits built only on the pen register or trap-and-trace theory, including claims filed within the bill’s retroactive window, but plaintiffs are likely to continue to assert other website privacy theories.

Vivek Shah

Shah, a self-represented litigant, has sent thousands of pre-suit demand letters and has pursued both arbitration and litigation. His recurring theory targets search bars and forms: he alleges that they transmit user-entered text to analytics or advertising vendors before notice or consent. A demand typically attaches screenshots or browser network records showing the search term and the destination domains. On July 20, 2026, a federal court in the Central District of California declared Shah a vexatious litigant and barred him from filing new CIPA or related privacy actions there without the court’s permission. The order does not reach arbitration, state courts, or other federal districts, and Shah is continuing to send demands.

What Should a Business Do When It Receives a Website Tracking Demand Letter?

If a business receives a demand letter claiming that its website has violated privacy laws through the use of tracking technologies, start by assessing the specific claims asserted and the technology allegedly at issue. Claims asserting a violation of CIPA based solely on a pen register or trap-and-trace theory are likely no longer viable if SB 690 takes effect as expected. However, plaintiffs may still attempt to assert claims under other laws discussed above, and it is key to parse out each allegation, especially in such a rapidly evolving legal landscape.

Before deciding whether to respond, litigate, or settle, evaluate the website’s compliance posture. Start by assessing the demand, evaluating litigation and settlement risk, and identifying practical steps to reduce tracking-technology risk going forward.

How to Reduce Website Tracking and Cookie Compliance Risks

Tracking technology is more than an isolated marketing tool and must be addressed as a compliance and litigation risk like other data systems. To reduce risk, a sound compliance program must track the technology itself, disclosures, user choices, and controls and then audit/monitor the technology and its uses. Here are five steps that will help reduce risk from using tracking technologies:

Step 1: Find and Map the Tools

Businesses must understand their own use of data, and this can be more difficult than it would appear. Often, management will be unaware of cookies and other tracking technologies on their own websites, as well as use cases for personal data. As such, companies should begin by scanning their own websites, apps, logged-in areas, and other digital properties for cookies, pixels, tags, SDKs, chat tools, session replay, and embedded content. For each tool and use case, the company should utilize a spreadsheet or digital tool to record the owner, purpose, data, recipients, timing, retention, vendor rights, sensitive-page use, and contract. This documentation must be based on observed behavior, not vendor descriptions or staff memory. For example, companies should test a representative number of webpages and user paths and remove tools that no longer serve a business need.

Step 2: Match Disclosures to Actual Practice

Compare the technology map described above with the company’s privacy notice, cookie notice, terms and in-product messages, and any other public disclosures. For example, does the Privacy Policy accurately describe the data collected, purposes, recipients, and covered properties accurately? Remove any broad claims that conflict with actual data flows such as, “we do not share data” or “we use only essential cookies.” Review statements about identifiable data and user control with care. There is particular danger if a notice says that individuals can choose whether or not to share information or must give consent but the technology acts in a way that is inconsistent.

Step 3: Set the Right User Choices

Depending on the type of data received, the user’s location, and the uses of the data, different rules may apply to whether, and what sort of, consent is required. Once the legal requirements are understood, the business will almost certainly still have decisions to make, e.g., whether to have a single type of consent regardless of jurisdiction and what type of consent to collect, and some risk may remain. For example, an opt-out link that works under the California Consumer Privacy Act (CCPA) may not remove potential risk under federal or state wiretapping theories or consumer-protection laws. The new California bill may narrow one private claim category, but it does not make consent design irrelevant. For higher-risk contexts, such as health or financial pages and connected devices, businesses may want to consider blocking nonessential scripts by default and requiring an affirmative opt-in before any third party receives data. The business will want to record why the business chose opt-in, opt-out, or notice for each tool and data type and in some cases may need to complete a data risk assessment under state law.

Step 4: Enforce and Test the Choices

Once the business has determined what sort of consent to implement, it must configure tag managers, consent-management platforms (CMPs), apps, and vendor tools to enforce the chosen consent model. Configuration will include blocking or delaying nonessential tools when required and limiting data sent to vendors and restricting their reuse. The business must also test all of the potential responses of users, i.e., acceptance, rejection, no action, and custom choices across common browsers and devices. It should also check network requests before the banner loads and after each choice and confirm that blocking does not break required site functions.

Step 5: Review Changes and Keep Records

Once appropriate consent tools are in place, the business must recognize that use cases will change and sites will be updated. The business must therefore create a cadence for regularly scanning each property on a schedule that matches its risk and pace of change. Additional scans should occur after major releases, campaigns, vendor updates, SDK changes, or CMP changes to confirm that key functions still work, find new or unapproved tools, and retest consent flows. Documentation should include keeping dated copies of settings, notices, contracts, and test results.

Conclusion

Recent California legislation may reduce one important category of private claims, especially pending pen register and trap-and-trace claims within the bill’s retroactive window. It will not end website tracking litigation. Courts still disagree about several tracking theories, and businesses can take clear steps now. Before a demand arrives, map the tools, match disclosures to practice, set user choices, enforce those choices, and test often. These steps cannot prevent every claim, but they can reduce common gaps and help the business respond with evidence rather than assumptions.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More