- SB 690 was approved on September 30, 2026. It lets only the Attorney General bring a section 638.51 claim over conduct on a website or app. [1]
- It applies retroactively to pending claims in actions commenced within two years before the operative date. [1]
- Law firms put that date at January 1, 2027, which reaches cases filed on or after January 1, 2025. [2][3]
- The damages section is unchanged for everything else: $5,000 per violation, with no need to show actual damages. [1]
- Sections 631 and 632, the wiretapping and eavesdropping provisions, are untouched, and plaintiffs are already recasting claims under them. [4]
- The conduct was not legalized. The prohibition in section 638.51 stays, and the Attorney General can enforce it. [3]
- The governor urged the Legislature to go further in 2027. [4]
On September 30, 2026, California’s governor signed a bill that runs to two sections and changes one sentence that matters. Senate Bill 690 adds a subdivision to Penal Code section 637.2, the part of the California Invasion of Privacy Act that lets private plaintiffs sue. The new text says that an action for a violation of section 638.51, “alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.” [1]
Section 638.51 is the pen register provision. For three years it has been the cheapest way to sue a company over the tags on its website. That route is now closed to private plaintiffs. The route next to it is not.
What the statute now says
Three details in the text decide who is affected.
The first is scope. The carve-out covers a violation of section 638.51 only, and only where the conduct occurred on a website, an online application, or a mobile application. [1] Nothing else in the chapter moves.
The second is time. The amendments “apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.” [1] Clark Hill gives the effective date as January 1, 2027. [2] Glaser Weil, which says that date is expected absent an urgency clause, does the arithmetic: the law reaches pending cases filed on or after January 1, 2025, and cases filed before that are not covered. [3]
The third is what did not change. The bill removes a private right of action. It does not amend the prohibition. Glaser Weil puts it plainly: the conduct is not legalized, and the Attorney General keeps full authority to enforce the pen register statute. [3]
Why this was the cheap claim
Section 638.51 says a person “may not install or use a pen register or a trap and trace device without first obtaining a court order.” [5] No website operator has a court order for its analytics tag. So if a tracker counts as a pen register, the violation is nearly automatic, and the only real fight is over whether a law written for telephone lines reaches a browser.
Courts never settled that. Morgan Lewis describes years of division: some held that the statute’s history and structure limit it to telephones, while others found that “software trackers embedded in websites qualify as ‘pen registers’ when they collect users’ IP addresses, device identifiers, and browsing data.” [4] With the question open and statutory damages on the table, the firm writes, many companies chose early settlement over litigating it. [4]
How many cases that produced is harder to pin down than the coverage suggests. Clark Hill, citing Reuters, puts it at more than 4,700 lawsuits involving digital wiretapping claims since 2022, about two-thirds of them with a pen register claim. [2] We could not read the Reuters report at its source, so take that as a law firm’s summary of a news count, not a court statistic.
The timing was not an accident. Morgan Lewis notes that a California appellate court issued a tentative ruling on August 21, 2026 leaning toward the view that section 638.51 is not limited to telephone surveillance, which would have been the first state appellate decision on the point. [4] The Legislature passed SB 690 a week later, on August 28. [4]
What is still open
Closed to private plaintiffs for websites and apps. The theory was about addressing information: IP addresses, device identifiers, the fact of a visit. From the operative date only the Attorney General can bring it, and pending private claims filed within the two-year window fall under the same rule. [1][3]
Open, and where the cases are moving. Section 631 reaches anyone who, without the consent of all parties, “reads, or attempts to read, or to learn the contents or meaning of any message, report, or communication while the same is in transit.” [6] Procopio lists the technologies plaintiffs aim it at: pixels, session replay, chat tools, and SDKs. [7]
Unaffected. Glaser Weil’s list of what survives: the federal Electronic Communications Privacy Act, the California Consumer Privacy Act, the state’s computer data access and fraud statute, the Unfair Competition Law, and common-law privacy claims. [3]
The difference between the first two tabs is the difference between an envelope and a letter. A pen register claim was about the envelope: who connected to whom. A wiretap claim is about the letter, and the statute’s own word for it is “contents.” [6] That is our reading of the text, not legal advice, but it gives a marketing team a usable way to sort its own tags. A script that only records that a page loaded sits at one end. A script that captures what a visitor typed into a form, a search box, or a chat window, and sends it to a third party while the session is live, sits at the other.
Morgan Lewis adds one piece of comfort. Claims under sections 631 and 632 are generally harder to plead than pen register claims were. [4] Harder is not the same as rare. The firm also reports that plaintiffs have already signaled they will recast their section 638.51 claims under those sections. [4]
| Claim | Who can bring it after SB 690 | What it is aimed at |
|---|---|---|
| Section 638.51, pen register | Attorney General only, for website and app conduct | Trackers collecting IP addresses, device identifiers, browsing data |
| Section 631, wiretapping | Private plaintiffs, as before | Reading the contents of a communication in transit without consent |
| Section 632, eavesdropping | Private plaintiffs, as before | The eavesdropping provision, left intact by the bill |
| Other statutes and common law | Unchanged by the bill | Federal wiretap law, CCPA, computer data access, unfair competition, common-law privacy |
The governor asked for a second bill
SB 690 is narrower than the bill its author first wrote. The 2025 version would have added a broad “commercial business purpose” carve-out reaching beyond section 638.51. It met opposition, became a two-year bill, and came back in the form that passed. [4]
The signing message reads like someone who wanted more. As quoted by Morgan Lewis, the governor said he aligned “with the goal of protecting small businesses from overzealous lawsuits based on a statute written without today’s complex technological landscape in mind,” and urged the Legislature to act again in 2027 “to ensure a fair balance between protecting private information and preventing rapacious litigation.” [4] Clark Hill quotes the same message describing a “vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses.” [2]
So the statute may move again next year. Until it does, the wiretap section is the law as written.
What to do with your tags
- List every third-party script on the site and in the app, and for each one write down what it sends, to whom, and at what moment in the visit.
- Mark the ones that can see contents: chat widgets, session replay, form analytics, on-site search tracking, anything that captures keystrokes or transcripts.
- Check whether those fire before consent. A banner that loads the replay script first and asks second does not help under a statute that requires the consent of all parties.
- If you have a pending pen register case or an open demand letter, ask counsel how the retroactivity window applies. Glaser Weil’s view is that a demand letter is not a pending claim in an action. [3]
- Do not remove the consent work you did for the pen register theory. The same inventory is what a section 631 defense starts from.
None of this replaces the reasons to control tags that have nothing to do with California. The consent signals that decide whether your conversions still reach Google depend on the same inventory, and so does any move to server-side tagging. A lawsuit theory closing is a good week. It is not a reason to stop knowing what your site sends.
Sources
- California Legislative Information · SB 690, Crimes: invasion of privacy (chaptered text)Primary. Approved and filed September 30, 2026.
- Clark Hill · California Enacts CIPA Reform, Curtailing Some Website Tracking ClaimsLaw firm analysis, October 2, 2026. Its lawsuit count is attributed to Reuters, which we could not read at source.
- Glaser Weil · Governor Newsom Signs SB 690, Eliminating Private CIPA Pen Register Claims Tied to Websites and AppsLaw firm analysis, October 1, 2026. The firm represents defendants in these cases.
- Morgan Lewis · California Eliminates Private Right of Action Under CIPA’s ‘Pen Register’ and ‘Trap and Trace’ ProvisionLaw firm analysis, October 1, 2026. Source for the legislative history and the signing message quotes.
- California Legislative Information · Penal Code section 638.51Primary.
- California Legislative Information · Penal Code section 631Primary.
- Procopio · California Governor Signs SB 690, Curtailing CIPA Pen-Register LitigationLaw firm analysis, October 1, 2026.
Frequently asked questions
What does SB 690 change?
It amends California Penal Code section 637.2, the section that gives private plaintiffs a right to sue under the California Invasion of Privacy Act. The new subdivision (d) says an action against a private actor for a violation of section 638.51, alleged to arise from conduct on an internet website, online application, or mobile application, may be brought only by the Attorney General.
When does it take effect?
The bill was approved and filed on September 30, 2026. Clark Hill gives the effective date as January 1, 2027, and Glaser Weil says that, absent an urgency clause, the operative date is expected to be January 1, 2027.
Does it apply to lawsuits already filed?
Yes, within a window. The statute says the amendments apply retroactively to any pending claim in an action commenced within two years before the operative date. Glaser Weil reads that as covering pending cases filed on or after January 1, 2025, and notes that cases filed earlier are not affected.
Are tracking pixels legal in California now?
The bill does not say that. It removes the private right of action for one section and leaves the prohibition itself in place, enforceable by the Attorney General. It does not amend sections 631, 632, or 632.7, and law firms expect plaintiffs to recast their claims under those sections and under other statutes.
What is a pen register claim?
Section 638.51 says a person may not install or use a pen register or a trap and trace device without first obtaining a court order. Plaintiffs argued that website trackers collecting IP addresses, device identifiers, and browsing data fit that definition. Courts split on whether a statute written for telephone surveillance reaches websites at all.
Which claims remain against websites?
Section 631, the wiretapping provision, which covers reading or attempting to read the contents of a communication while it is in transit. Procopio says claims alleging interception through pixels, session replay, chat tools, SDKs, and other third-party technologies remain available. Glaser Weil also lists federal wiretap law, the CCPA, California’s computer data access statute, the Unfair Competition Law, and common-law privacy claims.
What about demand letters we already received?
Glaser Weil’s reading is that a demand letter is not a pending claim in an action, so the sender cannot rely on an existing filing to preserve the claim once the law is operative. That is one firm’s interpretation, not a court ruling, and it is a question for your own counsel.
Is more CIPA reform coming?
The governor asked for it. In his signing message, as quoted by Morgan Lewis, he urged the Legislature to take further action in 2027 to ensure a fair balance between protecting private information and preventing rapacious litigation. Nothing has been introduced that we can point to.



