Skip to Main Content

Keeping you informed

California Legislature Approves Senate Bill 690, Narrowing Certain Website-Tracking Claims Under CIPA

    Client Alerts
  • August 31, 2026

Last week, the California Legislature approved Senate Bill 690, which would significantly narrow certain website-tracking claims asserted under the California Invasion of Privacy Act (CIPA). If signed by Governor Gavin Newsom, the legislation would limit private enforcement of certain pen register and trap-and-trace claims arising from websites, online applications, and mobile applications while creating additional protections for data processing conducted for commercial business purposes.

The bill is a significant development for businesses that have faced the wave of website-tracking demand letters and class actions filed under CIPA. It does not, however, eliminate website privacy risk. Companies should expect continued scrutiny of website disclosures, consent practices, privacy controls, and third-party data-sharing arrangements.

What SB 690 Would Change

Recent CIPA litigation has frequently centered on allegations that commonplace website technologies, including analytics, advertising, and session-replay tools, constitute unlawful interception or tracking under statutes originally enacted long before modern internet technologies existed.

SB 690 would make several significant changes.

First, it would limit private enforcement of certain pen register and trap-and-trace claims involving websites, online applications, and mobile applications. For those claims, enforcement authority would instead reside with the California Attorney General.

Second, it would exempt certain communications and data-processing activities conducted for a "commercial business purpose," including processing where consumers retain applicable opt-out rights.

Third, it would exclude certain commercial-business-purpose activities from the statutory definitions of pen registers and trap-and-trace devices.

Taken together, these changes are designed to narrow the application of specific CIPA provisions to routine website operations and common digital technologies.

Legislative History Reflects Concerns About Website-Tracking Litigation

The California State Assembly Committee on Privacy and Consumer Protection described the pen register statute as "a focal point in a recent surge of litigation related to third-party tracking of website user information" and characterized it as a "poster child for abusive lawsuits." The committee observed that businesses often faced significant settlement pressure because of the statutory exposure associated with these claims.

The final bill stops short of creating a broad exemption from CIPA, instead focusing on provisions that have generated substantial litigation concerning routine website functionality.

Why Website Privacy Risk Remains

SB 690 primarily targets pen register and trap-and-trace theories that have featured prominently in recent website-tracking litigation. The bill does not create a broad exemption from CIPA, nor does it eliminate all website privacy claims.

Plaintiffs have asserted a variety of theories involving session-replay tools, chat functionality, embedded third-party services, website form submissions, and similar technologies alleged to capture, record, replay, or disclose user interactions. Because SB 690 focuses on specific CIPA provisions, businesses should not assume that the legislation resolves disputes concerning all website-tracking technologies or all theories arising from their use.

The practical effect may be a shift in litigation strategy rather than the end of website privacy litigation. Plaintiffs may continue challenging the same technologies through other CIPA provisions, common-law privacy claims, unfair competition statutes, and theories based on consumer disclosures, consent mechanisms, and data-sharing practices.

Regulators Remain Focused on Website Data Practices

The regulatory focus has increasingly centered on what companies do with data and what companies tell consumers about those practices.

As we outlined in a previous client alert, California regulators continue to evaluate whether companies effectively implement privacy choices across advertising systems, analytics platforms, and downstream recipients. The California Attorney General and California Privacy Protection Agency have emphasized that privacy preferences must function in practice, and not merely appear in a cookie banner or privacy notice.

Federal regulators have taken a similar approach. In another prior client alert, we discussed the Federal Trade Commission's continued focus on whether a company's actual data practices match its public-facing privacy representations. The FTC continues to treat privacy policies, consent mechanisms, and data-sharing disclosures as enforceable representations to consumers and has emphasized that businesses must accurately describe how personal information is collected, used, and shared.

For many businesses, the practical risk analysis therefore remains largely unchanged.

Even where a company believes it has strong legal defenses, the practical burdens of litigation can materially affect the overall risk analysis. Those burdens may include substantial costs, discovery obligations, management distraction, reputational harm, customer inquiries, and follow-on claims.

Organizations that have received demand letters or otherwise identified concerns with website disclosures, consent mechanisms, or privacy controls should not assume that SB 690 eliminates the need for remediation.

SB 690 is a significant development that may narrow one of the most active areas of California website privacy litigation.

For most organizations, however, the core compliance question remains unchanged: whether website technologies, privacy disclosures, consent tools, and consumer-choice mechanisms operate consistently with one another. Companies that focus only on the narrowing of particular CIPA theories, rather than the underlying data collection, disclosure, and consent practices, may find that the risk has shifted rather than disappeared.

For more information, please contact us or your regular Parker Poe contact. Click here to subscribe to our latest alerts and insights.