For three years, businesses have faced a particular brand of privacy suit: claims that ordinary website cookies, pixels, and chat tools are illegal “pen registers” under California Penal Code Section 638.51. On September 30, Gov. Gavin Newsom signed Senate Bill 690, cutting off the private right of action behind the pen register theory for conduct on websites and apps. That relief is certainly welcomed, but it does not end California Invasion of Privacy Act (CIPA) exposure.

Link to Why Section 638.51 Became a Lawsuit Magnet Why Section 638.51 Became a Lawsuit Magnet

Section 638.51 was originally intended to target physical devices that captured telephone routing information, not website code. Plaintiffs’ firms argued that IP addresses, device identifiers, and similar metadata collected by routine web tools satisfy that same definition, and trial courts split on the question. The volume of these suits became difficult to ignore: Legislative staff estimated close to 4,000 Section 638.51 actions were pending statewide, the great majority built on a website-tracking pen-register theory, and each violation could expose a company to the greater of $5,000 or treble actual damages without any need to show actual harm. Facing that math, many defendants chose to settle early rather than test the statutory theory in court.

Weeks before SB 690 passed, the California Court of Appeal tentatively addressed the same question in Variety Media, LLC v. Superior Court, No. B350578 (Cal. Ct. App. 2d Dist. tentative ruling Aug. 21, 2026). The court indicated that Section 638.51 can reach internet activity in principle, but the court concluded that an IP address alone — without data showing where that traffic was routed — does not state a claim. Notably, the panel rejected the argument that the pen-register provision is confined to telephone networks. Instead, the panel adopted a technology-neutral reading of the statute, even as it found the particular pleading before it wanting because an IP address shows where a communication came from, not where it was sent. While the ruling is not final, it signals that courts are willing to apply the statute’s language to modern technology, and that better-pleaded cases describing actual routing destinations may well survive where this one did not. SB 690 moots most of that fight for private plaintiffs.

Link to What SB 690 Actually Shuts Down What SB 690 Actually Shuts Down

The bill does not touch the underlying prohibition in Section 638.51 itself — installing a pen register or trap-and-trace device without a court order or the user’s consent remains unlawful. Instead, it adds a new enforcement limitation to Penal Code Section 637.2, CIPA’s civil remedy statute, specifying that a private-actor claim under Section 638.51 arising from conduct on a website, online application, or mobile application may be brought only by the California attorney general. Effective January 1, 2027, that change leaves the attorney general as the sole civil enforcer of these website and app claims, and the state’s Department of Justice is expected to add staff and funding to take on that role.

The statute also reaches back: It bars continuation of qualifying claims in actions already pending, provided those actions were commenced on or after January 1, 2025, which means the very oldest filed cases may fall outside the retroactive bar even as more recent ones are cut off. That retroactivity language is also written to reach pending claims in a filed action, not outstanding demand letters, so a demand that has not yet ripened into a lawsuit loses negotiating leverage without being formally extinguished.

It is also worth noting how much this final version was narrowed from where it started. The bill was first introduced in 2025 as a broad exemption for data processing undertaken for a “commercial business purpose,” which would have pulled routine online business activity outside CIPA altogether, before opposition forced lawmakers to pare it back to this narrower carve-out limited to Section 638.51 enforcement.

Link to Where CIPA Risk Remains Where CIPA Risk Remains

SB 690 reaches only Section 638.51. Sections 631 (wiretapping) and 632 (eavesdropping) are untouched, and both target the contents of a communication rather than routing data — a theory well suited to chat widgets, session-replay tools, and any feature that records what a customer typed into an account portal. These claims carry the same statutory damages exposure as Section 638.51 claims, and one industry coalition estimated that the bill as enacted would fully resolve the exposure of roughly a quarter of companies currently facing CIPA suits, leaving the majority still exposed under these surviving theories. Plaintiffs’ counsel previously pleaded claims under Section 631 and Section 632, and where available, plaintiffs will likely replead narrowed claims under these surviving theories. Section 631 claims do, however, carry a heavier pleading burden; a plaintiff must show that the intercepted material was the actual “contents of a communication” and that a third party read or tried to read it while it was still in transit.

Finally, Newsom acknowledged in his signing statement that CIPA still contains other decades-old provisions susceptible to the same kind of litigation abuse and called on the Legislature to revisit the statute again in 2027 to strike a better balance between protecting personal information and curbing opportunistic suits. So although future additional relief may be on the way, CIPA risk remains for now.

Link to Next Steps Next Steps

  • Reassess pending Section 638.51 matters for a retroactivity defense under SB 690.
  • Separate currently pending CIPA matters by statutory theory and by the date the action was filed, since the retroactive bar turns on when the suit was commenced rather than when the challenged tracking occurred.
  • Revisit settlement strategy on suits that assert only a Section 638.51 theory, since the calculus for resolving those matters may change once the retroactive bar applies.
  • Review pixels, chatbots, SDKs, and session-replay tools on consumer-facing sites and apps, flagging anything that captures form content rather than routing data alone.
  • Update vendor and data-processing agreements with analytics and chat providers to confirm how customer data is used, stored, and shared.
  • Build CIPA review into the product-launch process for new digital features, since litigation theories keep shifting.
  • Prepare for a shift in enforcement focus toward the California attorney general and the California Privacy Protection Agency rather than private plaintiffs’ counsel, and treat regulatory-readiness documentation as a priority alongside litigation defense.

Link to Conclusion Conclusion

SB 690 narrows the playing field, but it does not foreclose CIPA liability. If anything, it shifts the center of gravity: Private pen-register suits should recede, while attorney general inquiries and Section 631/632 claims become the theories to watch. Businesses that treat this as a reason to pause their compliance efforts, rather than a prompt to redirect them, may find themselves back in the same position under a different statutory heading. Additionally, relief under SB 690 is specific to California; exposure under the federal Wiretap Act and under comparable statutes in other states, such as Pennsylvania’s Wiretapping and Electronic Surveillance Control Act and Florida’s Security of Communications Act, along with state health-data privacy laws like Washington’s My Health My Data Act, is untouched by SB 690. For businesses collecting consumer data, these distinctions are worth considering when building a compliance plan.

Photo of Alexis M. Buese Alexis M. Buese

Alexis Buese’s practice involves all aspects of commercial litigation, with an emphasis on class action, contract disputes, and real estate and consumer class action litigation. She has broadly defended the consumer products and services industries against the expanding array of class actions that…

Alexis Buese’s practice involves all aspects of commercial litigation, with an emphasis on class action, contract disputes, and real estate and consumer class action litigation. She has broadly defended the consumer products and services industries against the expanding array of class actions that challenge their products, methodologies, and procedures. Her clients include numerous consumer goods manufacturers and retailers, including apparel, furniture, food, vitamin and dietary supplement companies, and e-commerce companies. Alexis regularly represents clients in telemarketing litigation brought under the Telephone Consumer Protection Act (TCPA), Florida Telephone Solicitation Act (FTSA), and other state telemarketing and consumer protection laws, and she frequently writes and speaks on telemarketing compliance.

Photo of Erin Jane Illman Erin Jane Illman

Erin Illman is a dynamic problem solver with a strong understanding of U.S. and international private-sector privacy laws and regulations and the legal requirements for the transfer of sensitive personal data to/from the United States, the European Union and other jurisdictions. She regularly…

Erin Illman is a dynamic problem solver with a strong understanding of U.S. and international private-sector privacy laws and regulations and the legal requirements for the transfer of sensitive personal data to/from the United States, the European Union and other jurisdictions. She regularly advises clients on CCPA, GLBA, HIPAA, COPPA, CAN-SPAM, FCRA, security breach notification laws, and other U.S. state and federal privacy and data security requirements, and global data protection laws. In addition to providing proactive privacy and information security compliance and legal advice, Erin manages privacy-related enforcement actions and litigation. Her practice includes representing companies in reactive incident response situations, including insider cybersecurity threats, electronic and physical theft of trade secrets, and investigation, analysis, and notification efforts with respect to security incidents and breaches.

Photo of L. Brock Trulove L. Brock Trulove

Brock Trulove is an associate in the firm’s Banking & Financial Services Practice Group.