Executive Summary
- What’s new: On September 30, 2026, California Gov. Gavin Newsom signed into law Senate Bill 690, which amends the California Invasion of Privacy Act of 1967 (CIPA). The amendment removes the private right of action for purported website and app-based violations of CIPA § 638.51 (the pen register and trap-and-trace provision) and applies retroactively to any claim commenced within the prior two years.
- Why it matters: In recent years, plaintiffs’ firms have pivoted to pen register and trap-and-trace claims under CIPA, alleging that a website’s mere use of commonplace internet technologies violates the statute. Senate Bill 690 shuts down these attempts to apply CIPA § 638.51 in ways that were never intended.
- What to do next: Although plaintiffs’ firms have signaled that they will lodge constitutional challenges to the amendments’ retroactive provisions, the law is expected to take effect on January 1, 2027. Businesses currently assessing CIPA-related claims should consider factoring in these changes but should anticipate that plaintiffs’ firms will refocus their theories of liability on CIPA §§ 631 and 632 and other wiretapping statutes, such as the ECPA. Plaintiffs’ firms may also pursue other theories altogether, such as claims premised on a website’s consent banner disclosures and internet cookie configurations. In the meantime, it remains important to maintain robust privacy policies and disclosures, and ensure litigation and regulatory risk alignment within the business.
__________
The California Invasion of Privacy Act of 1967 (CIPA)1 — a criminal statute designed to prohibit the recording or wiretapping of communications without the consent of all participants — has been the basis of countless pre-suit letters, arbitration demands and putative class actions challenging the use of common, expected and commercially reasonable technologies on consumer-facing websites. We previously reported on the increasing number of these claims and examined initial versions of the proposed amendment to CIPA § 638.51 earlier this year.
CIPA § 638.51 emerged as a common cause of action for two reasons:
- First, CIPA broadly defines “pen register” as “a device or process that records or decodes dialing, routing, addressing or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted.” CIPA § 638.50(b). The plaintiffs’ bar often argues this broad language encompasses nearly all internet activity through the transmission of internet protocol (IP) addresses, geographic location, device identifiers and other data.2
- Second, CIPA provided a private right of action for violations of CIPA § 638.51 and permitted recovery of statutory damages of $5,000 per violation. Plaintiffs’ firms could use the potential damages exposure for settlement leverage.
But on September 30, 2026, Gov. Gavin Newsom signed into law California Senate Bill 690 to amend CIPA, with the amendments effective January 1, 2027.3 Senate Bill 690 removes the private right of action for purported internet tracking violations of CIPA § 638.51 and applies retroactively to any pending action filed within “two years before the operative date of that legislation.”4 This comes on the heels of the Second Appellate District’s tentative ruling in Variety Media, LLC v. Superior Court, which preliminarily concluded CIPA § 638.51 reaches internet communications.5
There has been strong momentum to get these amendments passed. The California legislature observed in July 2026 that “[t]hese [pen register] cases are very easy to assert, leading to serial filings by a handful of unscrupulous plaintiffs’ attorneys claiming technical violations for ordinary website activity. The result has been a mess for courts, a weapon against businesses, and a seemingly unneeded tool to protect against genuine privacy violations.”6
Senate Bill 690 is a strong first step in addressing the approximately 4,000 pending CIPA lawsuits,7 many of which attempt to stretch and distort CIPA § 638.51 in ways never originally intended. Senate Bill 690’s restrictions on private actions will help reduce the frequency of aggressive — and often meritless — claims targeting ordinary, everyday internet activity involving the use of cookies, pixels, online chat, and other customer service and analytics tools. Companies should consider assessing any pending CIPA lawsuits that they have against them and determining whether a partial or complete dismissal is appropriate after Senate Bill 690 becomes effective.
Plaintiffs’ firms are likely to challenge the retroactivity provision on constitutional grounds. Senate Bill 690 contains a severability clause8 stating that if a provision is invalidated, the rest of the act will remain in effect and continue to provide at least prospective relief against these pen register claims.
Plaintiffs’ firms still have options potentially available to them to pursue similar claims. The eavesdropping provisions of CIPA §§ 631 and 632 remain unaffected by Senate Bill 690. Plaintiffs’ firms might also focus on other wiretapping statutes, such as the federal Electronic Communications Privacy Act (ECPA), or shift their theory of liability altogether and allege other types of internet claims, such as those premised on a website’s consent banner disclosures and internet cookie configurations.
Given the continued litigation activity in this area, businesses should consider being proactive in maintaining robust privacy policies, disclosures and configurations applicable to all online platforms, including websites and apps. We also recommend continued monitoring of privacy and wiretapping-related legal developments, as this area continues to evolve rapidly, and encourage ongoing conversations to ensure that the business and legal teams are aligned on these issues to minimize legal and compliance risks.
The passage of SB 690 may be only the beginning of legislative reform surrounding outdated privacy statutes that have been used to threaten businesses of all sizes and across all industries with meritless claims based on ubiquitous and otherwise compliant practices. Other regulators and legislators at the state and federal levels may follow suit to curb the abuses under such statutes.
____________________
1 Cal. Penal Code §§ 630-638.55.
2 See Assembly Committee on Privacy and Consumer Protection, Proposed Amendments at 14-17 (July 1, 2026).
3 See Gavin Newsom, Governor of Cal., Signing Message for S.B. 690, 2025–2026 Reg. Sess. (Sep. 30, 2026).
4 See SB 690 (2025–2026 Reg. Sess.) (Cal. 2026) (amending Cal. Penal Code § 637.2).
5 See Variety Media, LLC v. Superior Court, No. B350578 (Cal. Ct. App. Aug. 21, 2026).
6 See Assembly Committee on Privacy and Consumer Protection, Proposed Amendments at 22 (July 1, 2026).
7 Id. at 6.
8 See SB 690 (2025–2026 Reg. Sess.) (Cal. 2026) (amending Cal. Penal Code § 637.2). (“The provisions of this act are severable. If any provision of this act or its application is held invalid, that invalidity shall not affect other provisions or applications that can be given effect without the invalid provision or application.”)
This memorandum is provided by Skadden, Arps, Slate, Meagher & Flom LLP and its affiliates for educational and informational purposes only and is not intended and should not be construed as legal advice. This memorandum is considered advertising under applicable state laws.