California’s New CIPA Law Is a Start—But Website-Tracking Claims Will Likely Continue
California has taken a useful first step toward curbing abusive website-tracking litigation, but Senate Bill No. 690 is not a complete solution. The law appears to address only one category of claim under the California Invasion of Privacy Act, leaves other California and federal theories untouched, and does not make the challenged conduct lawful. Businesses should expect the litigation to shift—not disappear.
CIPA prohibits several forms of unauthorized interception, recording, and tracking of communications. Plaintiffs have applied those statutes to commonplace website technologies—including pixels, cookies, analytics tools, session-replay software, and chat functions—under CIPA’s wiretapping, confidential-communications, and pen-register provisions. They claim statutory damages of $5,000 per violation without proof of actual damages, creating potentially enormous exposure from routine online activity.
As discussed in earlier alerts, these claims have produced a flood of demand letters, arbitration demands, and putative class actions against businesses with an online presence. Plaintiffs allege that ordinary website technologies secretly intercept communications or collect routing and signaling information without consent. Even where liability is uncertain and no concrete injury is alleged, the threat of uncapped statutory damages presents a familiar Hobson’s choice: settle or incur substantial defense costs responding to ever-evolving claims.
Earlier versions of SB 690 proposed broader relief for processing undertaken for a defined “commercial business purpose.” The proposal would have exempted qualifying interceptions or recordings under several CIPA provisions, restricted private claims based on qualifying processing of personal information, and excluded qualifying technologies from the definitions of a pen register and trap-and-trace device. Although it would not necessarily have immunized every business use of website technology, it would have narrowed CIPA’s substantive reach. The Assembly committee concluded that approach was too broad, and the Legislature enacted a far narrower change.
Effective January 1, 2027, SB 690 bars private claims against private actors under Penal Code section 638.51 when the alleged violation arises from conduct on an internet website, online application, or mobile application. Only the California Attorney General may bring those claims against private actors. The amendment applies retroactively to pending claims in actions commenced on or after January 1, 2025.
SB 690 provides meaningful relief to businesses defending section 638.51 claims, but it appears to change who may sue—not what conduct is unlawful. The law apparently leaves section 638.51’s substantive prohibition intact while reserving enforcement of this limited category of website- and application-based claims to the Attorney General.
SB 690 does not solve the broader CIPA problem. Private plaintiffs are likely to still pursue claims under Penal Code sections 631 and 632, other CIPA provisions, Penal Code section 502, federal statutes, fraud, unfair competition, and common-law theories based on the same technologies and data transmissions. Plaintiffs have already begun pleading these alternatives, and their efforts to recast section 638.51 allegations will be heavily litigated.
The Governor likewise acknowledged that SB 690 addresses only part of the problem. His signing message stated that “additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants.” He urged the Legislature to act next year “to ensure a fair balance between protecting private information and preventing rapacious litigation.”
Businesses therefore should not let down their guard or assume that SB 690 resolves existing website-tracking exposure. They should continue to obtain consent; inventory the cookies, pixels, session-replay tools, chat functions, and analytics technologies operating on their websites and applications; identify the data those tools collect and transmit; preserve consent and configuration records; and evaluate whether pending claims qualify for SB 690’s retroactive protection. Compliance remains important even for SB 690-related claims because the Attorney General retains authority to enforce section 638.51.
If your business has questions or received a website-tracking demand letter or lawsuit, please contact your Payne & Fears attorney.

