Skip to content

SB 690 and CIPA: What Changed in July 2026 (and What Didn't)

Mate Prgin 8/19/26, 5:05 PM

Table of Contents

Last verified: August 19, 2026. SB 690 is still moving through the California Legislature. We'll update this article when legislators have new guidance.

California's SB 690, amended in July 2026, ends private lawsuits under one part of CIPA: the pen register provision (§638.51). Only the state Attorney General can bring those claims now. The change reaches back to pen register claims filed in the two years before the law takes effect.

It leaves CIPA's main wiretapping provision (§631) alone. That is the provision behind most Meta Pixel, session-replay, and chatbot lawsuits, carrying $5,000 per violation.

Your website-tracking exposure continues under §631, and under similar wiretap laws in other states, starting with Florida's FSCA. SB 690 narrows one claim type; it does not end the litigation.

Many compliance roadmaps lost a line item in July. The headline read that California was fixing CIPA, the law behind the wave of website-tracking claims, so teams deprioritized the fix.

The bill did change. It changed far less than the headline suggests, and it left CIPA's most expensive claim exactly where it was.

Your exposure did not shrink. It moved. This guide covers what SB 690 does now, what it leaves standing, and where the litigation is going next, so you can decide what needs to happen before the August 31 vote.

sb690-timeline@3x

What SB 690 was supposed to do

The original SB 690 bill was a broad rollback of CIPA. Introduced in February 2025, it created a sweeping "commercial business purpose" exemption across CIPA's core provisions: wiretapping (§631), eavesdropping (§632), recording (§632.7), and pen register (§638.51).

In practice it would have given businesses a defense against most website-tracking claims under CIPA, including the ones aimed at session replay, live chat, and analytics pixels.

That version had real momentum. It passed the California Senate 35-0 on June 3, 2025, then stalled in the Assembly as a two-year bill after opposition to the "commercial business purpose" language.

 

Explaining SB 690's July 2026 amendment 

On July 2, 2026, SB 690 was gutted and rewritten, and the broad exemption came out. The bill now does one narrow thing. It removes the private right of action, the ability for individuals to sue on their own, for pen register claims under §638.51 that arise from a website, online application, or mobile app.

Enforcement of that provision is delegated solely to the California Attorney General.

A pen register or trap-and-trace claim is the theory that your site's tracking captured the digital version of the numbers dialed on a phone: routing data and metadata like IP addresses, rather than the content of a message.

That claim became the engine of a mass demand-letter business. Pen register filings climbed from roughly 600 to more than 4,000 after the bill was introduced, as plaintiffs rushed to file ahead of any deadline. Law firm Covington reports the provision was described in the legislature as a "poster child for abusive lawsuits."

What it changes for your exposure comes down to who can sue, how far back it reaches, and how soon it lands:

  • Only the Attorney General can act. Private plaintiffs can no longer sue on a §638.51 pen register theory, and they can no longer settle one either. As Covington puts it, these website and app claims would be enforceable "only by the Attorney General."
  • It reaches backward. The amendment applies "to any pending claim in an action commenced within two years before the operative date" (California bill text). Recently filed pen register claims could be dismissed if the bill passes.
  • The clock is short. The bill must clear the Assembly floor and Senate concurrence by August 31, 2026. If it passes this session, it takes effect January 1, 2027. Passage looks likely but is not settled; the opposition has not moved.

One clarification, because some coverage gets it backward: SB 690 does not force pen register cases into court instead of settlement. It removes the private claim entirely. Private plaintiffs cannot sue or settle on that theory anymore. Only the Attorney General can.

sb690-changed-survived@3x

What SB 690 does not do

CIPA's §631 wiretapping claims survive in full. Section 631 covers interception of the contents of a communication, which is what most tracking suits allege: a pixel, a session-replay script, or a chat widget capturing what a visitor typed or saw.

Under California Penal Code §637.2 it carries $5,000 per violation, or three times actual damages. It is the more expensive of CIPA's two website theories, and the one plaintiffs care about most.

SB 690 does not touch it. As Stoel Rives put it, "SB 690 does not clarify Section 631 (wiretap) or 632 (eavesdropping) for the current technological age. That, it seems, will be a different project, for a different legislature."

So the demand letters keep coming, in a new form. Plaintiff firms re-paper their claims from §638.51 to §631, which takes more pleading effort per case. Raw volume may fall, but §631 is the more valuable target.

 

The litigation is already moving to other states

Website-tracking litigation stopped being exclusive to California a while ago. The litigation now reaches states with their own wiretap laws, each with its own damages math. Plaintiffs have already migrated, and the case counts show where exactly.

Here's a breakdown:

Website-tracking wiretap litigation by state (early 2026)
State / law Active suits Statutory damages Note
California, CIPA §631 3,000+ $5,000 per violation, or 3× actual (§637.2) Core wiretapping claim; untouched by SB 690
Florida, FSCA ~600 Up to $1,000 per violation Fastest-growing venue after California
Pennsylvania, WESCA 48 Up to $1,000, plus punitive damages and fees Every party to a communication must consent
Illinois 95 See state statute Growing docket
New York 69 See state statute Growing docket
Federal, ECPA (Wiretap Act) Paired with state claims $10,000 per violation, or actual damages Federal law; reaches businesses in any state

A separate March 2026 analysis by Darrow Everett puts the precise counts close to these: California 3,135, Florida 586, Illinois 95, New York 71, Pennsylvania 48, Massachusetts 36.

Florida is the clearest case. In W.W. v. Orlando Health (M.D. Fla., March 2025), the suit alleged that website pixels intercepted a visitor's messages about "health conditions," "desired treatment," and "preferred doctors."

Since then, in the National Law Review's words, plaintiffs have "filed hundreds of similar wiretap claims in small claims court under the FSCA." Florida sets liquidated damages at up to $1,000 per violation.

Pennsylvania's WESCA is an all-party-consent law, meaning every party to a communication must consent. Fisher Phillips reports that plaintiffs there can recover "actual damages or liquidated damages up to $1,000 (whichever is higher), punitive damages, and reasonable attorneys' fees."

Federal exposure is rising alongside the state claims. Barnes & Thornburg reports plaintiffs "are increasingly pairing or replacing CIPA claims with claims under the federal Electronic Communications Privacy Act," which sets damages at $10,000 per violation and, as a federal law, reaches businesses in any state.

The same firms drive most of it. Barnes & Thornburg names Tauler Smith, Swigart Law Group, and Manning Law, as well as plaintiffs who "copy prior pleadings and file arbitration demands without notice."

Related theories widen the field too. The U.S. Supreme Court granted review in a Video Privacy Protection Act case, Salazar v. Paramount Global (No. 25-459), and Privacy Daily identifies chatbot-related wiretapping as "the recent trend" in these filings.

sb690-state-litigation@3x

What happens next

What happens next runs through the Assembly vote, the Governor's decision, and the effective date:

  1. August 31, 2026. The deadline for the Assembly floor vote and Senate concurrence.
  2. The Governor's decision. A signature or a veto follows passage.
  3. January 1, 2027. The effective date if the bill is signed this session.

Until that first date passes, nothing about §638.51 has changed. The private right of action is still live, and claims are still being filed.

What a §631 claim costs before it reaches a verdict

Most §631 cases never reach a verdict. Damages run $5,000 per violation under §637.2, and plaintiffs count each affected visitor as a violation, so the theoretical total climbs fast. The bill's committee analysis said as much: businesses settle quickly because the potential liability is staggering. That is what makes the demand letters worth sending in bulk.

The cost starts before any settlement figure is agreed. A demand letter opens a response clock: you bring in outside counsel, map which trackers fired and when, and reconstruct whether consent was recorded for each one. That work lands on whoever owns the site, usually with little notice and a short window to respond.

The firms behind these letters send them in volume, off templates, so the effort per letter is low. SB 690 shuts that engine down for the pen register theory only. For §631, it keeps running.

What to do now

Keep your CIPA work moving, whether or not SB 690 is signed. Your §631 exposure is unchanged, your exposure in other states is growing, and the work costs far less to do now than after a demand letter lands. The steps are the same ones that mattered before the bill:

  • Inventory your tracking technologies. Know every pixel, analytics tag, session-replay tool, and chat widget on the site, and where each one sends data.
  • Fire trackers only after consent. Non-essential trackers should load after the visitor agrees, not before. This is the single most important control.
  • Check your banner configuration. A consent banner that is set up wrong is itself a source of claims.
  • Look closely at chat and session replay. These are frequent targets, especially on pages that handle sensitive information.
  • Track the bill. Adjust as the August 31 vote and the January 1, 2027 effective date arrive.

sb690-what-to-do@3x

How Enzuzo handles tracking consent on your site

Enzuzo's consent management platform scans your site for tracking technologies, blocks non-essential tags until the visitor's consent state allows them, honours browser opt-out signals, and stores timestamped consent records. Teams typically go live in one to three days, and the same configuration covers wiretap exposure across states, not California alone.

Book a demo to learn your exposure risk and help mitigate any potential lawsuits.

 

FAQ

Did SB 690 pass?

Not yet, as of August 2026. The amended bill still has to clear the California Assembly floor and a Senate concurrence vote by August 31, 2026. If it passes this session, it takes effect on January 1, 2027. Passage looks likely, but the opposition has not changed its position, so it is not guaranteed.

Is CIPA litigation over?

No, CIPA litigation is not over. SB 690 removes only the private lawsuit for CIPA's pen register provision (§638.51). The main wiretapping provision, §631, carries $5,000 per violation and stays in force, and cases are spreading to Florida (FSCA), Pennsylvania (WESCA), and federal court (ECPA). The litigation is migrating to more states even as SB 690 narrows one California claim.

Does SB 690 apply retroactively?

In part, yes. The amendment reaches pending §638.51 pen register claims in actions started within the two years before the law takes effect. If the bill passes, many recently filed pen register claims could be dismissed. It does not reach §631 claims, which are unaffected.

What is a pen register claim?

A pen register claim, under CIPA §638.51, says your site's tracking logged routing details like IP addresses without consent: the metadata around a communication rather than its contents. SB 690 ends the private version of this claim and leaves it to the California Attorney General to enforce.

Can I still be sued under CIPA after SB 690?

Yes, you can still be sued under CIPA. SB 690 leaves §631 wiretapping claims in place, and those target interception of message contents through pixels, session replay, and chatbots, at $5,000 per violation. You can also face claims under Florida's FSCA, Pennsylvania's WESCA, and the federal ECPA. The bill closes one theory and leaves the rest of your exposure open.

Mate Prgin

Mate Prgin

Mate is the CEO & Founder of Enzuzo. He has an executive MBA from Ivey Business School and is a subject matter expert in data privacy and compliance.