SB 690 Becomes Law – What’s Next for CIPA Claims in the Information Age?

For over half a century, the California Invasion of Privacy Act (CIPA) sat quietly as a telephone wiretapping statute that saw relatively little application in court.  Fast forward to today and it has become one of the busiest privacy litigation engines in the state, with plaintiffs alleging violations based on websites’ routine and industry-standard use of cookies, chat widgets, and analytics technologies.  Hundreds of such cases have been filed over the last few years alone, and defendants may find themselves on the hook for thousands of dollars in damages, even without plaintiffs providing any proof of actual harm.  Website owners have had to fend off these claims to the best of their ability, with courts offering little in the way of relief.  California Senate Bill 690, unanimously passed by the Legislature and just signed into law by Governor Newsom, attempts to reign in this rampant lawfare, but how much relief will it really provide?

CIPA History

CIPA was enacted in 1967 in response to Cold War-era concerns of telephone wiretapping and eavesdropping.  The law has been amended several times since then, primarily to update it to encompass modern (i.e., cellular and cordless) telephone technologies.  For the first 50+ years of its existence, CIPA was invoked mainly in the context of such telephonic interceptions, generating little in the way of noteworthy civil litigation or public controversy.

Several provisions of CIPA have been employed in the recent surge of litigation over website-tracking technology.  First, section 631 is the general anti-wiretapping provision, imposing liability on those who “by means of any machine, instrument, or contrivance” read or attempt to read “the contents or meaning of any message, report, or communication” while it is in transit through “any telegraph or telephone wire, line, cable, or instrument.”[1]  Next, section 632 is the general anti-eavesdropping provision, imposing liability where communications “by means of a telegraph, telephone, or other device, except a radio,” are listened in on without consent.[2]  Finally, section 638.51 makes it unlawful to install or use either a “pen register” or “trap and trace device” without first obtaining a court order, subject to certain exceptions.  A pen register is a device or process that records “dialing, routing, addressing, or signaling information” transmitted from an instrument or facility sending a wire or electronic communication, but not the contents of that communication.[3]  A trap and trace device is one that captures incoming signaling information that identifies the source of a communication.[4] 

But it’s CIPA’s enforcement mechanism, section 637.2, that makes it really appealing to plaintiffs.  This provision creates a private right of action allowing any person to sue for statutory damages of $5,000 per violation, which some courts have construed as not requiring an express showing that the plaintiff has suffered actual damages.

CIPA as a Website Litigation Engine

Plaintiffs have recently repurposed this old wiretapping law with a novel theory for the Information Age.  Essentially, they allege that routine website tracking technologies that capture and transmit information like IP addresses, websites visited, and cookie identifiers to third parties are installed on users’ devices without consent, constitute unlawful wiretapping and eavesdropping, and also qualify as pen registers or trap-and-trace devices.  If the theory is not rejected, those websites could be liable under CIPA for up to $5,000 in damages for each violation even if the users can show no actual harm done by the technologies, creating a massively scalable class-action vehicle.

To date, some courts – but not all – have permitted versions of this theory to survive the pleading stage.  State courts in California seem particularly reluctant to expand the statute’s applications beyond its original intent.  For example, one California Superior Court found that “public policy strongly disputes Plaintiff’s potential interpretation of privacy laws as one rendering every single entity voluntarily visited by a potential plaintiff, thereby providing an IP address for purposes of connecting the website, a violator.”[5]  Another court held that CIPA’s pen register provision “did not, and does not, criminalize the process by which all websites communicate with all users who choose to access them.”[6]  Federal courts, on the other hand, have appeared more willing to entertain the theory.  For example, in Garcia v. Anschutz Entm’t Grp., Inc.,[7] the plaintiff alleged that a ticket-selling website’s third-party cookies began collecting her IP address, session information, and geolocation data the instant she navigated to the website and before she had the opportunity to reject non-essential cookies through the website’s consent banner.  The court held that this could “plausibly constitute a pen register” and denied the defendant’s motion to dismiss.  Defendants have pushed back on multiple fronts in such cases, with a key argument being that IP addresses and similar routing metadata aren’t the “contents” of a communication, and that a statute drafted for telephone architecture shouldn’t be stretched to cover internet communications at all.  While this argument has found success in other contexts, it was rejected in Garcia.

A pending case, Variety Media, LLC v. Superior Court,[8] may address the merits question somewhat more broadly.  There, the parties are litigating whether or how CIPA’s pen-register provisions apply to standard website analytics and IP address collection, and on August 21 the Court of Appeal issued a tentative, two-tiered ruling.  On the broad threshold question, the panel tentatively rejected Variety’s argument that CIPA’s pen-register provisions are confined to telephone surveillance, suggesting the statute might reach internet communications generally.  But on the narrower question of what the statute actually requires, the panel tentatively held that a pen register must capture information identifying the destination of an outgoing communication, while an IP address, standing alone, only identifies the source of a communication.  In other words, the plaintiff’s IP-address-based theory likely fails to state a claim as pleaded.  This tentative ruling would grant Variety’s writ petition in part and direct the trial court to sustain its demurrer, with leave to amend.  No final order has been issued as of this writing, though, so this case remains one to watch.

SB 690

Given the appealing statutory recovery framework, the merits split, and appellate-level guidance still potentially months away, it is not shocking that litigation volume for CIPA cases has grown exponentially since 2024.  The California Legislature recognized the need to act, and SB 690 is the result of that action.  The bill passed the Legislature with unanimous consent was signed into law by Governor Newsom on September 30, 2026.

The rationale behind the bill is that CIPA’s decades-old language is being weaponized against routine, non-malicious web technologies and generating settlement pressure disconnected from any genuine privacy harm.  Garcia illustrates why that argument resonates, as a company can implement a cookie-consent banner that is facially compliant with California’s CCPA privacy laws and still potentially a face pen-register claim if the underlying tracking technology fires before the user has a chance to consent.  Proponents of the bill point to this as demonstrating the pen register statute’s mismatch with modern website architecture.

Still, the current bill has undergone substantial downsizing since it was first introduced.  In 2025, State Senator Anna Caballero proposed a broad “commercial business purpose” exemption to CIPA, modeled on the CCPA’s definitions and amending several sections to clarify that routine practices like session-replay software, chat features, and third-party analytics would not constitute unlawful wiretapping or eavesdropping when used for legitimate business purposes.  While the 2025 version of the bill unanimously passed the Senate, it stalled in a State Assembly committee and failed to advance.

The bill was revived in 2026, but in a narrower form.  Rather than including a broad commercial-purpose exemption, this version makes a single substantive change: Section 637.2 is amended so that an action alleging a Section 638.51 violation arising from conduct on a website, online application, or mobile application may be brought only by the California Attorney General.  Practically speaking, this amendment eliminates the private right of action for pen-register and trap-and-trace website-tracking claims specifically, while leaving the underlying prohibition in Section 638.51 itself intact for enforcement by the Attorney General.  However, Sections 631 and 632 are left untouched, so most other “wiretapping” or “eavesdropping” theories will remain available to private plaintiffs.

This version of the bill unanimously passed the State Assembly and received Senate concurrence the same day, with the final legislative passage taking place on August 31, 2026.  Now that it’s been signed into law, it will take effect starting January 1, 2027, though it will also retroactively apply to pending claims initiated on or after January 1, 2025.

Practical Takeaways

For litigators, pending Section 638.51 claims arising from website or app conduct filed on or after January 1, 2025, are likely to become subject to dismissal on January 1.  However, Section 631 and 632 claims (which still make up a substantial portion of CIPA website litigation) will be unaffected, so anticipate a return to theories rooted in those specific provisions.

Website owners and operators may breathe a sigh of relief as one category of lawsuit risk may be closing, but the underlying compliance work hasn’t necessarily gotten easier.  To avoid all litigation, companies still may have to implement procedures far in excess of what the CCPA requires, such as making non-essential tracking technologies wait for affirmative consent before firing.  Best practices continue to include ensuring that privacy disclosures accurately describe what is being collected and shared, and that “opt-out” and “reject all” mechanisms function appropriately and as they claim.

SB 690 offers some real, meaningful relief for website operators.  But it is not a panacea, and does not offer a complete resolution of CIPA’s collision with modern web technology.


Jonathan Downing is an attorney advising companies on copyright, privacy, and other intellectual property issues in the video game industry. He writes about legal developments affecting games, digital media, and emerging technologies.

*** ‍

[1] Cal. Pen. Code § 631.

[2] Cal. Pen. Code § 632.

[3] Cal. Pen. Code § 638.50(b).

[4] Cal. Pen. Code § 638.50(c).

[5] Licea v. Hickory Farms LLC, 23STCV26148 (Cal. Super. Mar. 13, 2024) (sustaining demurrer).

[6] Casillas v. Transitions Optical, Inc., 2024 WL 4873370 (Cal. Super. Sept. 9, 2024) (sustaining demurrer).

[7] Garcia v. Anschutz Entm’t Grp., Inc., 832 F.Supp.3d 993 (C.D. Cal. 2026).

[8] Variety Media, LLC v. Superior Court, Case No. 25-STCV-018565 (Cal. Ct. App.).

Next
Next

California’s GM Settlement Puts Data Minimization Front and Center