Pixel Pause: California Pulls the Plug on Private CIPA ‘Pen Register’ Suits
On September 30, 2026, Governor Gavin Newsom signed Senate Bill 690 (SB 690). The bill ends private lawsuits under the California Invasion of Privacy Act (CIPA) for pen register and trap-and-trace claims under Penal Code Section 638.51 when those claims arise from conduct on a website, online application, or mobile application.
The bill passed the Legislature unanimously. It takes effect January 1, 2027, and applies retroactively to certain pending cases.
Why It Matters
For the past several years, companies have faced a surge of class-action lawsuits and pre-litigation demand letters under CIPA, many targeting routine online tracking technologies such as pixels, cookies, and analytics tools. While SB 690 provides meaningful relief from pen register and trap-and-trace claims, it does not address all CIPA theories of liability, and businesses should continue to evaluate their potential exposure.
This alert is the latest in AFS’ series of publications on CIPA litigation trends and legislative developments.
Key Provisions
- Only the Attorney General can sue. Only the California Attorney General may bring Section 638.51 claims against private actors based on online conduct.
- Narrow scope. The change applies only to Section 638.51 claims that arise from websites and apps.
- Damages unavailable. The $5,000 statutory damages and injunctive relief no longer apply to private plaintiffs bringing these claims.
- Retroactivity. The amendments apply to pending claims in actions filed within two years before January 1, 2027. In practice, this covers cases filed on or after January 1, 2025, that are still pending on that date. Plaintiffs may challenge this provision on constitutional grounds.
What Remains
- Wiretapping (Section 631): Private claims are still available under Section 631, which prohibits wiretapping and the interception of communications. This may become plaintiffs’ main theory, particularly against session-replay and chat tools.
- Section 632.7: Claims over interception of cellular and cordless phone communications are not affected.
- Federal law: Claims under the Wiretap Act and the Stored Communications Act, which plaintiffs have asserted in parallel with CIPA claims, are not affected.
The governor also urged the Legislature to address CIPA’s other “decades-old statutes” in 2027, so more reform may follow.
Key Takeaways
- Reassess pending and threatened claims. Consider whether SB 690 supports dismissal of pending Section 638.51 cases or rejecting a settlement demand.
- Keep auditing tracking technologies. Review pixels, cookies, session-replay, chatbots, and analytics for exposure under Sections 631 and 632.7 and under federal law.
- Strengthen consent and disclosures. Claims arising from “misleading” cookie banners are increasing, and their indiscriminate use can create the very exposure they were introduced to prevent. Consider avoiding an “Accept” button if you are firing cookies on arrival, and incorporate Terms of Use directly into the banner to further mitigate risk.
- Review vendor contracts. Confirm that agreements include appropriate representations, indemnity provisions, and data processing terms.
- Monitor the Legislature and the attorney general. Track 2027 reform proposals and any enforcement priorities the attorney general announces.
Bottom Line
SB 690 gives immediate and meaningful relief from online pen register and trap-and-trace litigation. Still, CIPA risk remains, and businesses should keep strong compliance programs in place. If you have questions about SB 690 or your online tracking compliance, please contact the authors or your AFS contact.
Contacts
- Related Industries
- Related Practices