Publication
California Legislature Passes Bill to Curb Certain Website-Tracking Lawsuits Under CIPA
By Patricia Brum, Tony Caldwell, CJ Utter, and Emily Statham
On August 28, 2026, the California Legislature (Legislature) unanimously passed Senate Bill 690 (SB 690). California Governor Newsom has until September 9, 2026, to sign or veto the bill. The expectation is that SB 690 will be enacted and provide a direct response to the recent wave of website-tracking litigation under the California Invasion of Privacy Act (CIPA) by removing private enforcement of certain claims under CIPA’s pen register and trap and trace provision and assigning enforcement of those claims to the California Attorney General. The bill is expected to also provide for retroactive application to certain pending claims. However, SB 690 does NOT appear to eliminate other CIPA theories or alter businesses’ obligations under California’s broader privacy framework. In sum, SB 690 could materially affect the current litigation landscape, but it will not end website-privacy litigation altogether.
California’s Evolving Privacy Framework and CIPA’s Distinct Provisions
California has spent the last decade building one of the nation’s most comprehensive privacy frameworks. The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) address the collection, use, disclosure, and sharing of personal information. They also impose requirements concerning, among other things, online tracking, and targeted advertising. These modern statutes, however, do not displace CIPA — an older statute that businesses may also want to consider when evaluating digital data practices.
CIPA was enacted in 1967 to prohibit wiretapping, eavesdropping, and other forms of electronic surveillance. Although it predates the Internet, its provisions have taken on renewed significance as plaintiffs have sought to apply them to website and mobile-application technologies. As relevant to SB 690, there are three distinct CIPA provisions.
California Penal Code Section 631 (Section 631) is CIPA’s wiretapping provision. Plaintiffs invoking Section 631 generally allege that website technologies improperly intercept or disclose communications.
California Penal Code Section 632 (Section 632) is CIPA’s eavesdropping and recording of confidential communications. Plaintiffs invoking Section 632 generally allege the website technologies improperly record and transmit keystrokes, mouse movements, chatbot, and screen content without consent.
California Penal Code Section 638.51 (Section 638.51) addresses different conduct: it prohibits installing a pen register or trap and trace device without a court order. A pen register generally captures dialing, routing, addressing, or signaling information associated with an outgoing communication, while a trap and trace device captures comparable information associated with an incoming communication. Historically, these devices were used in telephone networks to identify the origin or destination of communications without capturing their substantive contents. The distinction matters because SB 690 targets private enforcement of certain Section 638.51 claims, not Section 631 or Section 632 claims.
The Rise of Website-Tracking Litigation Under CIPA
Plaintiffs have increasingly turned to CIPA to challenge website and mobile application technologies, even as California’s modern privacy framework has expanded. The difference in available remedies may help explain that shift: the CCPA and CPRA are principally enforced by the regulators (such as the Attorney General’s Office and the California Privacy Protection Agency), while CIPA’s civil-remedies provision permits private plaintiffs to seek statutory damages for certain violations. That difference has likely made CIPA an attractive vehicle for plaintiffs to challenge online data-collection practices.
Recent suits have invoked CIPA against commonplace website and mobile application technologies, including cookies, tracking pixels, analytics tools, chat features, session replay software, and software development kits (SDKs). Section 638.51 plaintiffs have argued that these technologies operate as digital pen registers or trap and trace devices because they collect IP addresses, device identifiers, referral URLs, and other information associated with a user’s online activity. By contrast, Section 631 and Section 632 plaintiffs generally allege the same or similar technologies intercept and/or disclose communications to third parties. These are distinct statutory theories, even when they arise from the same underlying technology or conduct.
These theories have generated a substantial volume of demand letters and lawsuits across various industries, exposing businesses to potentially significant statutory damages based on routine website and mobile application functionality. Courts, however, have reached differing conclusions about whether statutory provisions enacted for telephone-era surveillance technologies apply to internet-based communications.
Overview of SB 690
Against that backdrop, businesses have questioned whether website-tracking practices addressed by California’s modern privacy framework should also support private damages claims under a statute enacted decades before the Internet. The Legislature’s passage of SB 690 appears to respond to those concerns, although the bill’s text addresses only one defined category of CIPA claims.
If enacted in its current form, SB 690 would make two principal changes for certain CIPA claims based on conduct occurring on an internet website, online application, or mobile application: (1) it would remove the private right of action for claims alleging violations of Section 638.51 and assign enforcement authority for those claims exclusively to the California Attorney General; and (2) it would apply retroactively to pending claims asserted in actions commenced within two years before the statute’s operative date.
Removing the Private Right of Action and Assigning Enforcement Authority to the California Attorney General
SB 690 would amend CIPA’s civil remedies provision to eliminate private lawsuits alleging a violation of Section 638.51. If enacted, private plaintiffs would likely no longer be able to pursue the specified claims under CIPA’s civil remedy provision. Enforcement would instead be reserved for the California Attorney General. In practical terms, the bill would likely limit private plaintiffs from pursuing the Section 638.51 pen register and trap and trace theories that have driven a significant portion of recent website-tracking litigation.
Retroactivity
SB 690 also contains a retroactivity provision. As passed, the bill would provide that the relevant amendments apply retroactively to pending claims asserted in actions commenced within two years before the statute’s operative date. If enacted, that language could reach beyond future lawsuits and affect cases already pending in California state and federal courts. The precise universe of affected claims would depend on the bill’s operative language and judicial interpretation. Defendants facing private Section 638.51 claims could potentially argue that those claims can no longer be maintained and should be dismissed, but courts would ultimately decide whether and how the retroactivity provision applies in particular cases.
That potential retroactivity has immediate practical implications. Businesses defending Section 638.51 claims may want to consider whether the proposed law supports dismissal arguments or other changes in litigation strategy, while parties considering demand letters or settlements may want to account for the possibility that the claims’ viability and value could change if the bill becomes law. The bill’s operative date, the scope of its retroactive language, and the treatment of particular claims may require close attention.
SB 690’s Limited Scope
SB 690’s effect is significant but narrow. If enacted, it would likely remove private enforcement for the specified Section 638.51 claims arising from website, online-application, or mobile application conduct. It would likely not eliminate website privacy litigation in California, repeal other CIPA provisions, or alter business’ broader privacy-compliance obligations.
Most importantly, SB 690 does not appear to amend Sections 631 or 632 — CIPA’s wiretapping and eavesdropping provisions. Consequently, claims under those provisions would likely remain available to private litigants under current law. Businesses should not necessarily assume that SB 690 would eliminate exposure associated with website analytics, chat, session replay, cookies, pixels, or similar technologies. Plaintiffs may continue to assert Sections 631, 632, and other claims based on the same underlying conduct.
The bill likewise would not change obligations under California’s broader privacy framework, including the CCPA and CPRA. Organizations would remain responsible for applicable requirements concerning privacy disclosures, consumer rights, data-sharing practices, and cookies and other tracking technologies. Nor would SB 690, by its terms, limit the California Attorney General’s or other regulators’ authority to investigate and enforce applicable privacy laws. Businesses may therefore want to continue reviewing their digital-data practices, vendor relationships, consent mechanisms, and privacy disclosures.
Practical Takeaways
If enacted, SB 690 could materially reduce litigation risk associated with private Section 638.51 claims and could affect pending cases through its retroactivity provision. It would likely not, however, eliminate website-tracking litigation or address Section 631 or 632 claims. It also would not necessarily change the CCPA, CPRA, or other applicable privacy obligations. The key practical distinction is between the affected enforcement mechanism and the underlying practices: private Section 638.51 claims in the specified context may be curtailed, while other CIPA and privacy theories would likely remain available.
Accordingly, organizations may want to consider (1) reviewing pending Section 635.81 claims, demand letters, and settlement discussions in light of the bill’s proposed scope and retroactivity language; (2) continue assessing whether website and mobile application practices support Sections 631, 632, or other evolving claims; and (3) maintaining reviews of privacy disclosures, consent mechanisms, and relationships with analytics and advertising vendors. Until the bill is enacted and its application is clarified, businesses may want to treat it as a potential change to litigation exposure — not as a substitute for ongoing privacy compliance.
About Snell & Wilmer
Founded in 1938, Snell & Wilmer is a full-service business law firm with more than 500 attorneys practicing in 17 locations throughout the United States and in Mexico, including Phoenix and Tucson, Arizona; Los Angeles, Orange County, Palo Alto and San Diego, California; Denver, Colorado; Washington, D.C.; Boise, Idaho; Las Vegas and Reno-Tahoe, Nevada; Albuquerque, New Mexico; Portland, Oregon; Dallas, Texas; Salt Lake City, Utah; Seattle, Washington; and Los Cabos, Mexico. The firm represents clients ranging from large, publicly traded corporations to small businesses, individuals and entrepreneurs. For more information, visit swlaw.com.