'Tis But a Scratch: California Nicks CIPA Pen-Register Claims, but CIPA Litigation Lives On

On September 30, 2026, Governor Newsom signed Senate Bill 690, narrowing—but not ending—the wave of litigation challenging website tracking tools under California’s Invasion of Privacy Act (CIPA). The law bars private pen-register and trap-and-trace claims arising from activity on websites and online or mobile applications, and retroactively extinguishes such claims in actions filed on or after January 1, 2025. Even so, CIPA litigation—and claims targeting online tracking tools more broadly—is far from over.

From Telephone Wires to Tracking Pixels 

California enacted CIPA in 1967, long before websites, mobile apps, cookies or pixels existed. The statute targeted phone-line eavesdropping, not website code. For several years, plaintiffs have argued CIPA should apply to routine digital tools, generally through two theories:

  • Pen Register & Trap and Trace (Section 638.51). This theory treats online tracking tools as devices that unlawfully capture routing or signaling information.
  • Wiretapping and Eavesdropping (Sections 631 and 632). This theory casts chat and online-tracking tools as unauthorized interceptors or recorders of online communications.
The economics are a powerful draw. CIPA permits a private plaintiff to recover the greater of $5,000 per violation or three times actual damages. In a class action, that math turns trivial alleged harm into real exposure.

Courts have struggled to map CIPA’s analog language onto the digital ecosystem, producing inconsistent results. One California federal judge called CIPA a “total mess” and urged California’s legislature to fix the statute because it is “borderline impossible to determine whether a defendant’s online conduct fits within the language of the statute.” The Legislature first considered a sweeping solution that would have curtailed any claims related to website tracking technology. When that proposal stalled, lawmakers adopted a narrower approach aimed only at pen-register and trap-and-trace claims.

What Comes Next?

SB 690 will take effect on January 1, 2027. In his signing statement, Governor Newsom said the law responds to the “vexatious use of CIPA lawsuits and demand letters” against small businesses that may unknowingly deploy website software that tracks and shares visitor information. He also credited the bill’s author with protecting small businesses from claims under a decades-old statute not designed for modern technology. But the Governor made clear that SB 690 is only a partial solution. Noting that CIPA “contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants,” he urged the Legislature to pursue broader reform next year—one that better balances meaningful privacy protections with the need to curb abusive litigation.

Key Takeaways

SB 690 should provide meaningful relief to businesses facing pen-register and trap-and-trace claims and reduce some demands and lawsuits targeting commonplace website and mobile-app technologies. But its reach is limited. The law removes the private right of action only for Section 638.51 claims. It leaves Sections 631 and 632—and the rest of CIPA—untouched. Plaintiffs will therefore likely continue challenging the same technologies under CIPA’s wiretapping and eavesdropping provisions, the federal Wiretap Act, other states’ wiretapping laws, and common-law invasion-of-privacy theories. They may also pursue fraud and consumer-protection claims alleging that cookie consent management tools are deceptive or do not function as represented. To guard against those claims, businesses should continue to:

  • Inventory Tools. Catalog tracking technologies on their websites and mobile apps, including the information each tool collects and shares with third parties.
  • Lock Down Settings. Configure each tool to limit unnecessary collection and disclosure.
  • Audit Disclosures. Confirm cookie banners and privacy policies accurately describe what information is collected and how it is shared with third parties.
  • Test Consent Tools. Confirm cookie management tools are working properly.
  • Review Vendor Contracts. Check data use and sharing terms with vendors running tracking tools on your digital properties.

Businesses with pending matters should also:

  • Assess Retroactivity Exposure. Identify pending pen-register or trap-and-trace claims within the retroactivity window and consider seeking a stay or other scheduling relief before SB 690’s January 1, 2027, effective date.
  • Revisit Settlement Posture. Reassess settlement strategy in matters involving Section 638.51 now that the private right of action has been eliminated.