Skip to content
Graphic showing California state flag with black overlaying map of California

On September 30, 2026, California Governor Gavin Newsom signed Senate Bill 690, materially changing the litigation landscape under the California Invasion of Privacy Act (CIPA). The amendment sharply limits private lawsuits under Penal Code § 638.51 based on alleged use of a pen register or trap-and-trace device on a website, online application, or mobile application.

For businesses that have faced the recent wave of CIPA demand letters and class actions aimed at pixels, analytics tools, advertising technology, and other online tracking, the change is significant. But SB 690 is not a wholesale repeal of CIPA. It leaves intact CIPA’s separate wiretapping provision, Penal Code § 631, and it does not eliminate obligations under the California Consumer Privacy Act (CCPA), other state privacy laws, the federal Wiretap Act, or statutes such as the Video Privacy Protection Act where those laws otherwise apply.

Key Takeaway

SB 690 substantially weakens the private-plaintiff § 638.51 theory that has driven many recent website-tracking claims. It does not eliminate CIPA exposure where a plaintiff can plausibly allege interception of the contents or meaning of a communication under § 631, and it does not justify dismantling privacy controls that serve independent legal requirements.

What SB 690 Changes

CIPA generally authorizes a private plaintiff to seek statutory damages under Penal Code § 637.2. SB 690 creates a targeted exception. For alleged violations of § 638.51 arising from conduct occurring on an internet website, online application, or mobile application, an action under § 637.2 may be brought only by the California Attorney General.

That distinction matters because § 638.51 became the basis for a growing line of claims arguing that commonplace online technologies function as unlawful pen registers or trap-and-trace devices when they collect or transmit information such as IP addresses, device identifiers, browser data, URLs, advertising identifiers, or similar routing and attribution information. Those claims often sought statutory damages on a per-violation basis, creating substantial settlement pressure even where the underlying theory was contested.

SB 690 removes that private enforcement mechanism for the covered website and application conduct. A private plaintiff therefore should not be able to maintain a § 637.2 damages action based solely on an alleged § 638.51 violation falling within the amendment. The Attorney General retains enforcement authority.

The Amendment Also Reaches Qualifying Pending Cases

The Legislature did not limit the amendment to conduct occurring after the new law takes effect. SB 690 expressly applies the new restriction to a pending § 638.51 claim in an action commenced within two years before the operative date.

SB 690 takes effect January 1, 2027. As a result, qualifying actions commenced on or after January 1, 2025 can fall within the statute’s express retroactivity provision. Businesses defending pending cases or evaluating unresolved demand letters should therefore review the precise causes of action, filing date, and factual allegations rather than assuming that a pre-2027 claim necessarily survives.

This provision is especially important for cases built entirely around the pen-register theory. A case that also pleads § 631, the federal Wiretap Act, the Video Privacy Protection Act, unfair-competition claims, or other privacy theories requires a claim-by-claim analysis; SB 690 does not automatically dispose of those additional claims.

What SB 690 Does Not Change: Penal Code § 631

The most important limit on SB 690 is that it does not amend Penal Code § 631. Section 631 is CIPA’s separate wiretapping and interception provision. Among other things, it addresses unauthorized acquisition or learning of the contents or meaning of a communication while the communication is in transit.

That is a materially different theory from a § 638.51 claim based on routing, addressing, device, or attribution information. Plaintiffs have invoked § 631 against session-replay technology, chat tools, form-capture technology, analytics scripts, pixels, and other third-party code where the alleged transmission includes substantive communications rather than merely metadata.

Accordingly, businesses should continue to scrutinize technologies that can transmit or reconstruct substantive user interactions, including:

  • Chat messages, support communications, and other text entered into interactive tools.
  • Form entries, search queries, keystrokes, or field-level data captured before or when a user submits information.
  • Session-replay implementations that record detailed page interactions or the contents of user input.
  • Pixels or analytics configurations that transmit page titles, URLs, search terms, transaction details, or other information that can reveal the substance of what a user is doing or communicating.
  • Tracking on adult, health, financial, or similarly sensitive services where page or event context itself may reveal particularly sensitive information.

SB 690 Does Not Replace CCPA or Other Privacy Compliance

SB 690 also should not be read as permission to remove cookie banners, privacy preference centers, Global Privacy Control handling, sale/share opt-outs, or other tracking controls that were implemented for reasons independent of § 638.51.

For example, the CCPA continues to regulate the sale and sharing of personal information, including sharing for cross-context behavioral advertising. Where the CCPA applies, businesses must continue to honor applicable opt-out rights and recognized opt-out preference signals. Other state privacy statutes may impose similar requirements for targeted advertising or sensitive data.

Businesses operating internationally also must continue to assess consent and tracking requirements under the EU and UK privacy regimes. Likewise, adult-content and video businesses should separately consider whether the data transmitted through pixels or analytics tools creates exposure under the Video Privacy Protection Act or other sector-specific privacy laws. SB 690 changes one CIPA remedy; it does not displace these independent regimes.

What This Means for Pixels, Analytics, and Advertising Technology

The practical consequence is that businesses should stop treating every ordinary tracking technology as if it presents the same California CIPA risk. The correct analysis now turns much more heavily on what the technology actually collects, what it transmits, who receives the data, and for what purpose.

A conventional analytics or attribution tool that transmits device, browser, IP, campaign, or routing information presents a different CIPA profile from a tool that contemporaneously transmits chat text, form content, search terms, detailed browsing content, or other substantive communications. SB 690 materially reduces the private § 638.51 litigation risk associated with the former category. It does not eliminate the need to analyze the latter under § 631 and other privacy laws.

Businesses also should distinguish between client-side technology and server-side disclosures. Moving an advertising or conversion event to a server-side API does not necessarily remove privacy obligations if the business continues to disclose personal information for targeted advertising or another regulated purpose. The legal analysis should follow the data flow, not merely the technical implementation.

What Businesses Should Do Now

  • Review pending CIPA demand letters and lawsuits. Determine whether the claimant relies on § 638.51, § 631, or both. A § 638.51-only claim should be reassessed immediately in light of SB 690’s enforcement limitation and retroactivity language.
  • Do not pay or settle a § 638.51 demand based on the old risk model without reassessing the claim. The economics of a private pen-register claim have changed materially.
  • Do not automatically remove existing privacy controls. A consent mechanism, GPC implementation, advertising opt-out, or tracking restriction may remain necessary under § 631, the CCPA, another state privacy law, or an international privacy regime.
  • Inventory what tracking tools actually transmit. Businesses should know whether their technologies send metadata, advertising identifiers, page context, user-entered information, purchase details, video titles, search terms, chat content, or other substantive data to third parties.
  • Revisit engineering restrictions that were imposed solely because of § 638.51. If a control was adopted only to mitigate private pen-register litigation, it may no longer be necessary. Controls supported by other privacy laws should remain in place.
  • Preserve records relevant to pending claims. SB 690 can create a strong defense without eliminating the need to preserve evidence, litigation holds, configuration records, consent records, or vendor documentation while a matter remains pending.

Timing

SB 690 was signed September 30, 2026 and takes effect January 1, 2027. The period before January 1 should be used to evaluate pending matters, preserve defenses, and identify whether existing tracking controls were implemented solely because of the § 638.51 private-litigation theory or whether they remain independently required.

Contact Silverstein Legal

Businesses that have received a CIPA demand letter, are defending a pending CIPA case, or want to reassess pixels, analytics, session replay, advertising technology, or other tracking practices in light of SB 690 should contact Silverstein Legal before changing existing compliance controls.


This article does not constitute legal advice and is provided for your information only and should not be relied upon in lieu of consultation with legal advisors in your own jurisdiction. It may not be current as the laws in this area change frequently. Transmission of the information contained in this article is not intended to create, and the receipt does not constitute, an attorney-client relationship between sender and receiver.

About Silverstein Legal

Founded in 2006 by adult entertainment lawyer Corey D. Silverstein, Silverstein Legal is a boutique law firm that caters to the needs of anyone working in the adult entertainment industry. Silverstein Legal’s clients include hosting companies, affiliate programs, content producers, processors, designers, developers, and website operators.

Back To Top
Search