Key Takeaways

  • Yesterday, on July 1, a narrowed version of SB 690 passed another legislative hurdle in lawmakers’ efforts to curb rampant wiretapping litigation in California.
  • The new amendments curtail enforcement of CIPA’s trap and trace/ pen register provisions to the attorney general and the law would be retroactively applied for two years.
  • There is no current fix proposed to the remaining traditional wiretapping sections of CIPA, and lots of uncertainty remains as to the law’s applicability to companies’ everyday use of third-party cookies, pixels and other tracking technology on websites and mobile applications.

The Quick Report

California lawmakers advanced a narrower version of Senate Bill 690, proposed legislation aimed at curbing a surge of California Invasion of Privacy Act (CIPA) claims challenging routine website and app technologies. Yesterday, on July 1, the Assembly Committee on Privacy and Consumer Protection voted to move the bill, as amended, to the Assembly Appropriations Committee, with the vote left open for absent members. If SB 690 continues to muster support through the remaining committee and legislative votes, the governor will have until September 30, 2026, to sign or veto the bill once the 2025-2026 legislative session ends.

The amended bill no longer proposes a broad “commercial business purpose” exemption from CIPA. Instead, it focuses on CIPA’s trap-and-trace and pen register statute, Cal. Penal Code § 638.51, by curtailing enforcement of certain website, online application and mobile application claims to the attorney general.

The amended bill also includes a retroactivity provision, which was met with skepticism by some assembly members and attendees. If enacted as amended, SB 690 would apply to pending claims in actions commenced within two years before the bill’s operative date but would not affect final judgments or claims under other statutes. 

SB 690 is a step in the right direction, garnering fierce support from over 40 attendees appearing on behalf of industry groups and companies large and small. Even original opponents of the bill turned a corner, most aligning with one of the guest opposition speakers for SB 690 who appreciated the most recent amendments to SB 690. But the narrowed approach creates a new issue. By limiting private enforcement of website- and app-based Section 638.51 claims, rather than clarifying that Section 638.51 does not apply to routine website activity, the bill could be cited to suggest that the statute does reach such activity – particularly if the retroactivity clause is removed, narrowed or unavailable in older cases. And while the threat of civil shakedowns for this part of the statute could disappear, companies would still be subject to the interpretation of the attorney general and could face civil litigation under other parts of CIPA, or common law claims like intrusion upon seclusion, often pled in tandem with Section 638.51 claims. The amended bill does not address Cal. Penal Code § 631 wiretapping claims, does not fix CIPA’s overall imprecise language, and does not resolve the potential tension between CIPA and the California Consumer Privacy Act (CCPA).

The Longer Read – Background

Enacted in 1967, CIPA, colloquially known as California’s wiretapping act, provides a private right of action and statutory damages of $5,000 per violation.1 In growing numbers over the last three years, plaintiffs have increasingly invoked CIPA to challenge ordinary website technologies, including cookies, pixels, analytics tools, advertising technologies, chat functions and session replay software.2

In the last year, the most active and abusive cases and demands have involved CIPA’s pen register and trap-and-trace provisions. Plaintiffs allege that website operators violate Section 638.51 when third-party software embedded in or deployed from a website collects IP addresses or other routing information from website visitors without first obtaining consent or a court order.3

Courts across the state and beyond grappling with CIPA’s vague language have split on those claims at the pleading stage. Some federal courts have allowed Section 638.51 claims to proceed based on third-party tracking allegations.4 By contrast, some California trial courts, including in the NetScout decision, have rejected similar theories as extending CIPA beyond its intended scope.5 The California Court of Appeal also is considering related issues in Variety Media, LLC v. Superior Court of Los Angeles.6

That uncertainty is not limited to Section 638.51. As Judge Vince Chhabria of the Northern District of California recently put it, “The language of CIPA is a total mess. It was a mess from the get-go, but the mess gets bigger and bigger as the world continues to change and as courts are called upon to apply CIPA’s already-obtuse language to new technologies. Indeed, we have reached the point where it’s often borderline impossible to determine whether a defendant’s online conduct fits within the language of the statute.”7

SB 690 is an attempt to respond to part of that problem, but it does not rewrite CIPA’s central language or fully resolve the tension between CIPA and the CCPA. As a result, even if the bill is passed in its current form, businesses may remain exposed to disputes over how a decades-old wiretapping statute interacts with California’s modern privacy framework for online data collection, notice and opt-out rights.

What SB 690 Would Do

Earlier versions of SB 690 would have created a broad exemption for “commercial business purpose” activity under several CIPA provisions, including sections 631, 632, 632.7, 637.2 and 638.50. The July 1 amendments substantially narrow that approach.8

As amended, SB 690 would strike the proposed changes to sections 631, 632, 632.7 and 638.50 due to unresolvable disputes over the reach of the definition of “commercial business purpose.” The bill would instead amend Section 637.2, CIPA’s private right of action provision, to provide that an action against a private actor for a Section 638.51 violation arising from conduct on an internet website, online application or mobile application may be brought only by the attorney general.9

That structure matters. The amendment would not say that website and app technologies fall outside Section 638.51. Nor would it amend the statutory definitions of “pen register” or “trap and trace device.” Instead, it would leave the substantive prohibition in place while changing who may enforce certain claims.10

The bill’s retroactivity provision may therefore be one of its most consequential features. The proposed amendments would apply retroactively to pending claims in actions commenced within two years before the bill’s operative date. The committee materials state that the bill would not affect final judgments or claims under other statutes and would include a severability clause in light of possible challenges to retroactivity.11

If retroactivity is stripped, narrowed or successfully challenged, defendants in pending cases may face a difficult argument: that the Legislature implicitly recognized that Section 638.51 can apply to website or app activity by creating a special enforcement rule for those claims. The same issue could arise for older cases outside the two-year window.

The July 1 Hearing

The July 1 hearing reflected both the significant momentum behind the need for reform and the concerns that led to the narrowed amendments. Supporters described a wave of high-volume CIPA claims targeting businesses, nonprofits, healthcare providers, public agencies and other website operators for routine online practices. State Sen. Anna Caballero and supporters emphasized that the amended bill focuses on Section 638.51, which they identified as the primary driver of recent website pen register and trap-and-trace litigation.

The hearing also drew substantial business participation. As the madam vice chair observed, “Senator Caballero brought quite a few friends,” referring to the 40-plus business owners, trade associations and representatives who traveled to Sacramento to express their support for the bill.

Opponents acknowledged that the amendments narrowed the bill but continued to raise concerns about retroactivity and the potential effect on meritorious privacy claims. In sum, assembly members appeared receptive to addressing high-volume litigation while encouraging continued work on safeguards, including language to preserve claims involving serious privacy intrusions.14

Final Takeaways

SB 690 is now a narrower, more targeted reform bill. That may improve its prospects, but it also means the bill would not resolve every CIPA theory asserted against website operators.

Businesses should closely monitor the retroactivity provision. If enacted as drafted, it could affect pending Section 638.51 claims filed within the two-year window before the bill’s operative date. If retroactivity is removed or limited, however, the amended bill could create disputes over whether the Legislature implicitly accepted that Section 638.51 reaches website and app activity.

Businesses should also watch how the attorney general approaches any retained enforcement authority. The amended bill would remove private enforcement for covered claims, but it would not eliminate regulatory enforcement. If the attorney general takes the position that Section 638.51 applies to certain website or app technologies, businesses may still face regulatory risk even if private plaintiffs lose standing to pursue covered claims.

The bill now moves to Assembly Appropriations. If it clears that committee and the Assembly floor, the Senate would need to concur in the Assembly amendments before the bill could be sent to the governor by the end of the 2025-2026 legislative session, which ends Aug. 31. After this, the legislature will be in a final recess, and the governor will have until Sept. 30 to sign or veto bills.

For now, businesses should continue reviewing their use of cookies, pixels, analytics, chat tools, session replay, advertising technologies and other third-party tools, evaluating disclosures and consent flows, and assessing vendor contracts and data flows.

SB 690 may offer meaningful relief for covered Section 638.51 claims, but it is not a complete solution. Section 631 wiretapping claims, other privacy theories, CIPA’s imprecise language, the unresolved relationship between CIPA and the CCPA, and potential attorney general enforcement remain active areas to watch.

If you have questions about SB 690, CIPA litigation risk or website privacy compliance, BakerHostetler’s Privacy and Class Action teams are available to assist.


Notes

1. Cal. Penal Code § 637.2(a), (c).

2. Assemb. Comm. on Privacy & Consumer Prot., Analysis of S.B. 690, 2025-2026 Reg. Sess., at 1-2 (Cal. July 1, 2026).

3. Cal. Penal Code §§ 638.50, 638.51.

4. See, e.g., Greenley v. Kochava, Inc., 684 F. Supp. 3d 1024, 1050-52 (S.D. Cal. 2023); Shah v. Fandom, Inc., 754 F. Supp. 3d 924, 931-33 (N.D. Cal. 2024).

5. See, e.g., Blaker v. NetScout Systems, Inc., No. 25STCV31283, 2026 WL 1709143, at *3 (Cal. Super. May 27, 2026);Rodriguez v. Ink Am. Int’l Grp. LLC, 2025 WL 4034985, at *4 (Cal. Super. Dec. 10, 2025); Licea v. Hickory Farms LLC, No. 23STCV26148, 2024 WL 1698147, at *3 (Cal. Super. Mar. 13, 2024); Casillas v. Transitions Optical, Inc., No. 23STCV30742, 2024 WL 4873370, at *4 (Cal. Super. Sept. 9, 2024); Sanchez v. Cars.com Inc., No. 24STCV13201, 2025 WL 487194, at *3-4 (Cal. Super. Jan. 27, 2025).

6. Variety Media, LLC v. Superior Ct. of L.A. Cnty., Case No. B350578 (Cal. Ct. App., 2nd Dist., Nov. 21, 2025).

7. Doe v. Eating Recovery Ctr. LLC, 806 F. Supp. 3d 1109, 1112 (N.D. Cal. 2025) (Chhabria, J.).

8. Assemb. Comm. on Privacy & Consumer Prot., Analysis of S.B. 690, supra note 2, at 22-23.

9. Id. at 23.

10. See Cal. Penal Code §§ 637.2, 638.50, 638.51.

11. Assemb. Comm. on Privacy & Consumer Prot., Analysis of S.B. 690, supra note 2, at 23-24.