Key point: SB 690 passes the California legislatures and eliminates the private right of action for website-based pen register and trap-and-trace claims and reaches back two years, but it leaves CIPA §§ 631 and 632 and the federal Wiretap Act entirely intact.
On August 28, Senate Bill 690 (SB 690) passed both the California Assembly and the California Senate, potentially closing one of the several doors plaintiffs have used to bring website tracking claims. The bill is a major victory for companies of all sizes who faced demand letters and lawsuits ranging from pro se plaintiffs to putative class actions in what had become essentially a strict liability statute. If Governor Gavin Newsom signs SB 690 into law, it will entirely remove the private right of action from California’s pen register and trap and trace law, Cal. Penal Code §§ 638.50–638.51.
The more interesting question is not what the bill fixes but rather what happens to the several hundred pending and threatened claims that no longer have a home, and whether the theories that absorb them are any easier for website owners to defend.
Link to What the Bill Does What the Bill Does
SB 690 arrives at the governor’s desk in a form barely recognizable from the version introduced in February 2025. As drafted, the bill would have amended §§ 631, 632, 632.7, and 638.50/638.51 to preclude liability whenever the challenged technology was deployed consistent with a “commercial business purpose.” That version passed the Senate 35-0 in June 2025 and then stalled in the Assembly, where opposition centered on the breadth of the commercial business purpose carve-out.
As we have covered previously, the Assembly Privacy and Consumer Protection Committee amended the bill on July 1, 2026. The resulting bill applies only to §§ 638.50 and 638.51, California’s pen register and trap-and-trace provisions, and only to claims arising from conduct on a website, online application, or mobile application. For those claims, it removes the private right of action and vests enforcement exclusively in the attorney general (AG). And it applies retroactively to any pending claim in an action commenced within two years before the operative date. That means if the governor signs the bill, actions filed on or after January 1, 2025, are subject to SB 690’s reach.
Two features of that structure matter for defense strategy. First, this is a standing fix rather than a substantive one. The bill does not declare that pixels, session replay tools, or analytics scripts fall outside the definition of a pen register; it says that private plaintiffs may no longer be the ones to make that argument. The underlying conduct is exactly as lawful or unlawful as it was, and the AG retains full authority to test the theory. Second, the retroactivity provision is the operative relief for anyone currently defending a pen register claim. Companies with § 638.51 counts in actions filed in 2025 or 2026 should be evaluating now whether to hold those claims in abeyance, seek a stay, or tee up a dispositive motion timed to the January 1 operative date.
Link to What the Bill Does Not Do What the Bill Does Not Do
Everything else survives. Section 631, which carries the same $5,000 per violation exposure, is untouched. So is § 632, which prohibits recording of confidential communications. So are the federal Wiretap Act, the VPPA, and the state wiretap analogues in Florida, Pennsylvania, Arizona, and Washington that plaintiffs’ firms have been developing in parallel for the last 18 months.
While the California legislature may in future years take aim at other provisions of the CIPA including §§ 631 and 632, SB 690’s legislative history suggests this may be an uphill battle. The §§ 631 and 632 amendments were the first thing sacrificed when the bill needed votes, and the sponsor’s own framing of the July amendments, as well as statements in the Assembly on August 28, acknowledged these other claims presented tougher questions to balance California consumers’ rights to privacy with how these statutes had been weaponized. Indeed, the only “tracking tech” case to go to jury verdict involved a claim under § 632 and resulted in a jury verdict in favor of the plaintiffs. In short, businesses waiting on a legislative solution to wiretapping claims should not read this session as a first installment. Additional relief, if any, will not come this year.
Link to What’s Next What’s Next
The pen register theory was attractive precisely because it let plaintiffs skip the elements that make § 631 and ECPA claims harder to plead and maintain. A § 638.51 claim required no showing that the intercepted material constituted “contents,” no allegation that interception occurred “in transit” or simultaneously with transmission, and no opportunity for the defendant to argue they were exempted by the party exception. Plaintiffs also typically argued website consent banners were not effective because the violation occurred immediately when a user visited the website. Because many websites employ tracking technologies automatically, this essentially created strict liability whenever a user simply visited the website regardless of what action (if any) they took.
SB 690 pushes these claims back onto § 631 and the federal Wiretap Act, where defendants have additional defenses, including whether the data captured is content or record information, whether the third party intercepted in transit or received a duplicate after the fact, and whether the vendor acted as an extension of the website operator or as an independent eavesdropper. Courts continue to disagree on each of these, and recent decisions have made it easier for plaintiffs to survive arguments at the pleading stage.
Section 632 claims have also become increasingly common. The provision reaches the intentional recording of a “confidential communication,” and it does not require the contents-versus-record-information analysis or the in-transit timing analysis that § 631 does. Plaintiffs must instead allege an objectively reasonable expectation that the communication was not being overheard or recorded. Several courts have found this to be a fact-bound question that resists resolution at the pleading stage. As plaintiffs press chat widgets, in-app messaging, and session replay of authenticated user sessions, § 632 supplies a theory with real damages exposure, no third-party structural requirement, and a standard that turns on what the user reasonably believed.
Link to The Defense That Works Against CIPA Claims and Beyond The Defense That Works Against CIPA Claims and Beyond
Consent defeats every one of these theories. It defeats § 631 and the Wiretap Act through the party-consent rule, subject to the crime-tort exception that courts have applied inconsistently. It defeats § 632 by eliminating the reasonable expectation on which the claim depends.
As these cases shift from pen register and trap and trace claims to wiretapping and beyond, expect more decisions to focus on whether website owners can establish consent at the motion to dismiss stage. The decisions to date establish that any method used to obtain user consent must be reasonably conspicuous and require the user to take some action to demonstrate assent. A hyperlink to a website’s privacy policy buried at the bottom of the website will not be enough. Website owners must also ensure that any consent obtained matches what actually happens on the website. Consent banners can quickly transform from a tool to defend against a claim into a liability that exposes the company to higher liability under the federal wiretapping law. A company that can prove what a visitor was shown, when the visitor was shown it, and what fired before and after the visitor responded is in a different posture from one that cannot, regardless of which claim is asserted.
Post-SB 690, companies are encouraged to A-C-T to avoid additional website privacy litigation: Audit-Correct-Track.
Audit. Identify every tag, pixel, script, and SDK deployed on the site and in the app, what each transmits, to whom, and under what conditions it fires. Verify that any consent mechanism, such as a banner that allows users to opt out of nonessential technologies, operates as represented. Run the site in each consent state (e.g., no action, accept, reject) and confirm that outbound requests match the represented behavior, including in response to a Global Privacy Control signal. Also use this as an opportunity to evaluate risk of website litigation under other statutes such as the ECPA, TCPA, and compliance with state privacy laws such as the CCPA.
Correct. Address what issues the Audit step has revealed. If you do not yet obtain consent, consider adding in procedures to obtain user consent via a click-wrap agreement, banner, or sign-in agreement. Talk with your attorneys to evaluate the pros and cons of each method and ensure your implementation is legally defensible under the ever-changing case law. Build the consent mechanism to meet what courts have actually required, not to what the industry considers standard.
Track. Websites change. They are by nature dynamic. Although they are often viewed as a single item, they are in reality more like a 1,000-piece puzzle that is assembled in milliseconds when the user visits the site. It is easy for a piece to be placed incorrectly. Suddenly, when a user opts out of nonessential technologies, a marketing tag still runs, and the user claims not only a wiretapping violation, but also asserts claims for fraud based on the now incorrect representation that users could opt out. To guard against website changes, or the underlying tracking tech tag mechanisms, causing future liability, it is critical that website owners track the behavior of their websites on an ongoing basis. This can be done in-house through your IT team or by external vendors.
Assuming the governor signs SB 690, exposure for website and app conduct under § 638 ends on January 1, 2027. Pending claims filed on or after January 1, 2025, become vulnerable to dismissal. That is meaningful relief, and it will take a substantial number of demand letters off the board. The claims that remain are the more expensive ones, and the Legislature has signaled that any relief, if it comes, is not coming soon. Companies that treat SB 690 as the end of website privacy litigation will find themselves defending the same conduct under a different statute. Companies that A-C-T to reduce their risk of website privacy litigation before the first demand letter arrives will be in a much stronger position to avoid significant liability.
