Key Takeaways:
- California SB 690 would end the wave of private CIPA “pen register” and “trap and trace” lawsuits by giving the California Attorney General exclusive jurisdiction over claims arising from website, online application, and mobile application activity
- Businesses currently facing serial-plaintiff CIPA demand letters targeting routine website analytics and third-party cookies would gain significant relief — though the bill does not clarify whether CIPA’s decades-old provisions were ever meant to apply to modern web technology
- The bill includes a 24-month retroactivity window tied to a January 1, 2027 operative date, which could reshape exposure for pending and recently threatened claims
- Passage is likely but not guaranteed — SB 690 must clear the Assembly floor and return to the Senate before the August 31, 2026 deadline, and opposition groups have not yet shifted position, so businesses should not pause CIPA risk mitigation in the meantime
In between, and sometimes during, the soccer matches this past weekend, I have been thinking about the strange journey of California SB 690. It has been amended (again) and re-referred to the Assembly Appropriations Committee. Assemblywoman Machado, Vice Chair of the Assembly Privacy and Consumer Protection Committee, is now a co-sponsor. All things being equal, this probably bodes well for the passage of the bill, in some form. I say some form because you can expect a healthy amount of discussion (jostling) between now and August 31, 2026, the drop-dead date for passing the bill, in both chambers. Recall, perhaps, that after being introduced on February 21, 2025, the bill passed the Senate on June 3, 2025, on a 35-0 vote. It was then referred to the Assembly Committee on Privacy and Consumer Protection, where more than a year later, on July 1, 2026, it was heard and passed as amended.
Whereas SB 690 was previously drafted to amend the California Invasion of Privacy Act (CIPA) to create a commercial business purpose exemption to California’s wiretap, eavesdropping, pen register, and trap-and-trace prohibitions, the bill would now give the California Attorney General exclusive jurisdiction to bring “pen register” and “trap and trace” claims (Section 638.51 of the California Penal Code) that are alleged to arise from conduct occurring on an internet website, online application, or mobile application. A “pen register” is a “device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, but not the contents of a communication.” A “trap and trace device” is a “device or process that captures the incoming electronic or other impulses that identify the originating number or other dialing, routing, addressing, or signaling information reasonably likely to identify the source of a wire or electronic communication, but not the contents of a communication.” Historically, pen registers and trap-and-trace devices were attached to telephones, capturing outgoing communications, such as the number called (pen register), and incoming communications, such as the originating phone number (trap-and-trace devices). The legislative history of Section 638.51 (2015) bears this out. In the past few years, some courts have extended the application of this statute to software and internet websites, such that litigants are claiming that the installation of the same third-party code on a visitor’s web browser constitutes a trap-and-trace device or a pen register. Put otherwise, litigants are muddling the definitions, confusing a pen register with a trap-and-trace device, or vice versa, assuming that these terms even have application to internet websites. Some are even claiming violations based on the alleged installation of an analytics (pageviews, etc.) cookie on a visitor’s browser. All these claims are from private, usually serial, litigants. I am not aware of any such claim being filed by the California Attorney General.
Courts are vexed, not only by the pen register and trap-and-trace device dichotomy as applied to visits to internet websites, but also whether the California legislature even intended to extend these concepts to internet websites (as well as online application or mobile application). SB 690 does not resolve any of this. Nor does SB 690 clarify Section 631 (wiretap) or 632 (eavesdropping) for the current technological age. That, it seems, will be a different project, for a different legislature.
In the current form of SB 690, there is a 24-month retroactivity period, commencing the date SB 690 would become operative (January 1, 2027). The latest amendments to SB 690 were posted on June 30, 2026. Quite a few groups were in opposition to the bill before the latest amendment, and while it is still early days, I am not aware of any of these groups officially changing their position to neutral or in favor. This may be just as well. The California legislature is currently in recess, until August 3, 2026. This will give the bill sponsors time to perhaps change a few minds or at least to withdraw opposition. Bear in mind that the bill still needs to go to the Assembly floor, after it clears committee, and then back to the Senate, as the current bill is completely different from the one passed last year.
In the meantime, businesses are being bombarded with CIPA demand letters, some of which are likely AI-generated and, at any rate, based on an “investigation” process that is highly automated. Actual damages are not required to plead a violation of CIPA, but, at least per the statute, there must be an injury. Statutory damages are $5000 per violation. Attorneys’ fees are available. Some of these are fashioned as class actions. Litigation is of course an option, and sometimes there is no choice but to litigate. SB 690, if passed, should change the landscape, but as intimated above, more work remains to be done.