Read
2 minute read
September 8, 2026
2 minute read
The California Legislature has passed Senate Bill 690, which restricts private lawsuits alleging that common website and application tracking technologies violate the pen-register and trap-and-trace provisions of the California Invasion of Privacy Act (“CIPA”). In recent years, these provisions have given rise to one of the most actively litigated legal theories in the data privacy arena. While the bill removes the private right of action for such claims, it does not amend other CIPA, state-law, or federal claims involving website tracking technologies.
The Rise of CIPA Pen-Register Claims
California Penal Code Section 638.51 generally prohibits the installation or use of a pen register or trap-and-trace device without a court order, subject to limited statutory exceptions. Historically, these provisions were associated with telephone surveillance and the collection of dialing, routing, addressing, or signaling information.
In recent years, plaintiffs have increasingly argued that common website technologies, including cookies, pixels, analytics tools, and similar scripts, qualify as pen registers or trap-and-trace devices because they collect IP addresses, URLs, device identifiers, and other metadata. CIPA’s civil-remedies provision, found in California Penal Code Section 637.2, allows a private plaintiff to pursue injunctive relief and statutory damages of $5,000 per violation without proving actual damages. These statutory damages, coupled with plaintiffs’ novel website tracking legal theories, have driven a substantial volume of demand letters and lawsuits against website owners.
What SB 690 Changes, and What it Doesn’t
SB 690 amends CIPA’s civil-remedies provision to effectively eliminate the private right of action for pen-register or trap-and-trace claims arising from conduct occurring on an internet website, online application, or mobile application. Moving forward, only the California Attorney General can bring such claims against private actors.
Importantly, SB 690 does not eliminate CIPA liability arising from website tracking. Rather, it provides that only the California Attorney General may bring website- and application-based pen-register and trap-and-trace claims against private actors. SB 690 also does not amend CIPA’s wiretapping provision, California Penal Code Section 631, which plaintiffs have separately invoked against advertising pixels, session-replay software, chat tools, and other third-party website technologies.
What Happens Next
SB 690 has cleared both houses of the California Legislature, and awaits action by Governor Newsom. It is expected to take effect January 1, 2027. Still, private litigation involving website-tracking technologies is likely to continue under CIPA’s wiretapping provisions, other federal and state privacy laws, and common-law privacy theories. The California Attorney General will also retain authority under CIPA to bring pen-register and trap-and-trace claims involving websites and applications. Accordingly, SB 690 should not be interpreted as reducing the need to review website tracking and consent practices.
This alert is for informational purposes only and does not constitute legal advice. For more information, please reach out to a member of our team.


