On September 30, 2026, Governor Newsom signed SB 690, which removes the private right to sue under one of the most heavily used theories in California’s website-tracking litigation. For companies that have been receiving demand letters over analytics tools and advertising pixels, the law is real relief, though that relief is also narrower than the headlines suggest.
The California Invasion of Privacy Act, or CIPA, is a 1967 criminal wiretapping and eavesdropping statute that also lets individuals sue for $5,000 per violation, without proving they were harmed. In recent years, plaintiffs have used CIPA to argue that now ordinary website tools amount to illegal surveillance. Those tools include analytics scripts, advertising pixels, chat widgets, and session-replay software. With statutory damages counted per violation, the claimed exposure from routine web traffic can be very large, which is what made these claims attractive to consumer protection attorneys and their clients. While SB 690 takes the most common of these theories out of private hands, it does not remove the underlying law, the other theories, or the demand letters going after those unaware of the change.
What SB 690 Changes, and What Remains Unclear
SB 690 changes who may sue, not what the law prohibits. CIPA’s pen register provision bars using a device that captures dialing, routing, or addressing information about a communication, but not its content, without a court order. Plaintiffs have argued that website tools capturing IP addresses, device identifiers, and similar data fall within the pen register definition.
Beginning January 1, 2027, a claim under that provision arising from conduct on a website, online application, or mobile application may be brought only by the California Attorney General. Fortunately for businesses, the change also reaches claims still pending in lawsuits filed on or after January 1, 2025.
Three things remain unsettled.
First, the conduct is still prohibited. Using these tools without consent can still violate the statute, and the Attorney General retains authority to enforce it.
Second, the effect on past claims will be worked out case by case. Suits filed before 2025 fall outside the retroactivity window, and courts will need to address these if the plaintiffs do not voluntarily drop these as no longer an “easy” win.
Third, no court has definitively decided whether a pixel is a pen register at all. A California appellate case, Variety Media, was expected to answer that question. The court’s tentative ruling suggested it would not accept the argument that the statute reaches only telephones. The court has since asked the parties whether SB 690 moots the case. If the case ends without a published decision, both the Attorney General and claimants outside the retroactivity window will be left without a controlling answer.
The practical point is simple. SB 690 is not a finding that your tracking tools are lawful. The legislature decided only who gets to argue about it.
The Demand-Letter Model
Many of these claims, though not all, are a volume business for those making the demands. Some senders use automated tools to scan large numbers of websites and send near-identical letters, including to companies with no California presence. The letters are often vague about which tool, page, or data is actually at issue. Their purpose is to draw the recipient into a conversation in which settling feels like the easiest way out.
SB 690 removes the theory that made this model cheapest to run, but the model will adapt. Pen register claims were attractive because they were easy to allege. Expect demands to shift toward CIPA’s wiretapping provision, which remains fully available to private plaintiffs. That provision targets tools that capture the content of communications: chat widgets, session replay, and pixels that transmit search terms or form entries.
Good Practices Still Matter
The practices that defend against the claims that remain are the same ones that would have defeated most pen register demands. Know what runs on your site, describe it accurately, and make sure consent actually controls it.
Disclose accurately.
Your privacy policy should accurately describe the tracking technologies you use and why. Companies subject to the CCPA already owe this disclosure and may have similar obligations in the more than 20 states with privacy laws in effect or going into effect by January 1, 2027.
Configure consent so it works.
A cookie banner is only as good as its configuration. Most companies manage consent through a consent management platform, and a misconfigured platform can present another avenue for lawsuits by opportunistic plaintiffs. If tracking technologies keep firing after a visitor opts out or rejects cookies, the problem goes beyond CIPA exposure and your company has told visitors one thing and done another, this supports unfair or deceptive business practice claims and invites regulatory attention. California’s privacy regulator has already fined a retailer whose consent tool failed to process opt-outs for weeks. The regulator made clear that using a third-party tool does not shift responsibility for compliance and the tools often disclaim responsibility for misconfiguration.
Contact us today
Audit periodically.
Tag managers accumulate forgotten scripts, and marketing teams often innocently add pixels without legal review. The good news is that the scanning tools probable plaintiffs use to find targets are available to you as well.
As CIPA is also not the only claim built on this model, regular compliance review, hygiene, and triage, can also help to avoid website accessibility demands under the Americans with Disabilities Act (ADA), which follow a similar demand and settlement pattern.
If Your Product Is the Tracker
For SaaS companies that sell chat, analytics, personalization, or session-replay tools, the shift toward wiretapping theories moves exposure in your direction. Under those theories, the embedded vendor is often cast as the eavesdropping third party, and the website operator as the party that helped it listen in.
Customer agreements rarely address tracking technologies specifically. The risk sits instead in general provisions: compliance-with-laws representations, privacy and data protection terms, and indemnities for third-party claims. A customer that receives a CIPA demand tied to your tool will look to those provisions first and likely demand you take responsibility.
Vendors are unlikely to negotiate a carve-out for privacy-law claims, absent a customer’s own misconfiguration, so the protection has to come from how you build and operate the product. That means default configurations that respect consent signals, documentation customers can rely on, and data-use terms making clear that you process customer data for the customer rather than for yourself.
For the last point, Courts evaluating wiretapping claims often ask whether the vendor can use the data for its own purposes. Reserving broad rights to use customer data for your own analytics, product development, or AI training makes that argument harder to win.
If You Receive a Demand
The rule is: don’t panic, but don’t ignore it.
Don’t panic.
SB 690 has materially reduced the value of many demands. A demand that rests only on a pen register theory has lost most of its leverage and a suit filed between now and January 1 would fall inside the retroactivity window and, if still pending on that date, would be barred. However, a demand that includes a wiretapping claim still needs to be evaluated on its merits.
Don’t ignore it.
Absent certain narrow facts, ignoring a demand is not a strategy. The right response depends on who sent it and how that sender operates. For a volume sender with no record of following through, the considered choice may be not to engage at all. For a firm that actually files and arbitrates, it may be a substantive response. Either way, make that decision deliberately and with counsel, not by replying to the sender directly. An informal reply can confirm facts the sender is only guessing at, and any engagement tells the sender that you respond.
Keep a record.
Log every demand, including those you decide not to answer. Financing and M&A documents typically require disclosure of litigation threatened in writing, and a demand letter typically qualifies, however spurious the claims. A clean log showing each demand, its theory, and its outcome makes diligence faster. It also gives a buyer or investor less reason to ask for a special indemnity or a larger escrow.
Conclusion
SB 690 lowers the price of a bad tracking setup. It does not make a bad setup acceptable. Use the new leverage on any pending demand, and keep your consent configuration and your demand log in a state you would be comfortable showing a buyer.
Disclaimer
This article is provided for informational purposes only and does not constitute legal, tax, accounting, or business advice. Past results do not guarantee a similar outcome. Every situation is unique, and the issues discussed above may apply differently depending on the facts and circumstances involved. Readers should consult with qualified professional advisors regarding their specific situation before taking any action based on the information contained in this article.
