California Narrows CIPA Litigation: SB 690 Ends Pen Register and Trap-and-Trace Claims
A recent amendment to the California Invasion of Privacy Act (CIPA) may bring some relief to companies confronted with demand letters and lawsuits challenging the deployment of third-party software on websites and apps. On 30 September 2026, Governor Newsom signed into law Senate Bill 690 (SB 690), an amendment that prohibits private enforcement of CIPA’s pen register and trap-and-trace provisions as to such platforms. The governor’s signing message confirms the comments of observers that the reform is an appropriate beginning—but not the end—of legislative reform of the “decades-old” CIPA statute to align with modern online technologies.
SB 690’s Restrictions
As enacted, SB 690 amends the enforcement section of CIPA (Section 637.2) to provide that an action for alleged violation of Section 638.51—the pen register and trap-and-trace provisions—arising from conduct on an Internet website, online application, or mobile application may only be brought by the California attorney general. As a result, private plaintiffs and their counsel no longer have standing to assert claims that website or application technologies such as analytics, pixels, cookies, or session-replay tools violate the pen register or trap-and-trace restrictions of CIPA. Such claims—including the potential for aggregated US$5,000 statutory damages per violation—have driven the onslaught of CIPA litigation over recent years.
SB 690’s Limitations
SB 690’s effective date is 1 January 2027, and the amendment applies retroactively to any claim in an action commenced on or after 1 January 2025. While plaintiffs may attempt to challenge that retroactivity provision, long-standing California Supreme Court precedent supports its enforcement. If the retroactivity provision is successfully challenged, SB 690 includes a severability provision such that the amendment will nonetheless provide relief as of its effective date.
SB 690 is limited in scope and does not impact private enforcement of other provisions of CIPA, such as the antiwiretapping provisions (Sections 631-632) that are often invoked by plaintiffs in this context. As noted in the governor’s signing message, these and other provisions of CIPA should be the focus of further legislative reform efforts. The unanimous passage of SB 690 suggests a continued appetite to align the statute with technologies developed in the decades since its original enactment.
Practical Implications
- Businesses faced with active pen register or trap-and-trace claims or litigation filed on or after 1 January 2025 should evaluate whether the claims fall within the retroactivity window and whether to move for dismissal or other disposition.
- Businesses that have received demand letters alleging claims under Section 638.51—particularly those with additional claims under different legal theories—may be in a significantly stronger negotiating position.
- Businesses should evaluate the consent and disclosure practices that they have implemented previously in light of risks of enforcement activity by the attorney general and additional state enforcement actors, including those authorized by the California Consumer Privacy Act.
Our Commercial Disputes practice group is ready to guide clients through the complex and evolving data privacy landscape. Please contact the authors of this article if you have any questions or if we may be of any assistance.
This publication/newsletter is for informational purposes and does not contain or convey legal advice. The information herein should not be used or relied upon in regard to any particular facts or circumstances without first consulting a lawyer. Any views expressed herein are those of the author(s) and not necessarily those of the law firm's clients.