CIPA Reform Signed Into Law

CIPA Reform Signed Into Law

Blog WilmerHale Privacy and Cybersecurity Law

On September 30, 2026, Senate Bill 690 (SB 690 or the Law), amending the California Invasion of Privacy Act (CIPA), was signed into law by California Governor Gavin Newsom. The Law eliminates the private right of action under CIPA for violations of the pen register and trap and trace device provisions from conduct on internet websites, online applications and mobile applications and applies retroactively for two years prior to the Law’s effective date.

While the Law provides some relief for companies subject to these claims, it notably does not eliminate the private right of action for all claims under CIPA. Plaintiffs can continue to bring other claims under CIPA that were not included within the scope of SB 690’s exemption, including those related to recording confidential communications without the consent of all parties involved. Additionally, the California Attorney General (AG) may enforce the pen register– and trap and trace device–related provisions under CIPA. Moreover, plaintiffs typically rely on several other theories of liability—the Electronic Communications Privacy Act, common-law privacy theories, and unfair or deceptive acts or practices allegations (among others)—that are still in play. Thus, companies using third-party trackers on their websites should understand that there is still meaningful litigation risk in this space, especially if they do not have a mechanism to obtain consent for this practice.

Still, the tide is turning on this issue. With Governor Newsom’s recognition that “CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants” and the Texas AG’s office’s recent consumer alert warning Texas companies that demand letters alleging violations of CIPA may be sent by a “vexatious litigant” or “may exaggerate or misrepresent a potential violation of law,” there may continue to be legislative and judicial developments that favor companies on this topic.

In this post, we summarize SB 690’s key provisions and practical implications for private businesses. To stay up to date on the latest developments in state privacy law, please subscribe to the WilmerHale Privacy and Cybersecurity Law Blog.

Summary

CIPA is a 1967 state law that criminalizes recording or intercepting private communications without the consent of all parties involved. Originally enacted to prevent phone and telegraph tapping, CIPA was amended in 2016 to limit the use of pen registers and trap and trace devices absent a court order or an endorsed purpose. A pen register records or decodes outgoing information transmitted about a wire or electronic communication, including the dialing, routing, addressing and signaling information, but not the contents of the communication. A trap and trace device captures the incoming electronic or other impulses that identify dialing, routing, addressing or signaling information about a wire or electronic communication, but not the contents of the communication. In practice, this means that websites with cookies and pixels that remember user preferences and behavior are subject to liability under provisions of CIPA codified at California Penal Code Sections 637.2 and 638.51.

SB 690 originally proposed sweeping changes to CIPA, including exempting certain actions relating to a “commercial business purpose” from CIPA’s prohibitions and redefining “pen register” and “trap and trace device” to exclude technologies used for a commercial business purpose. The Law also has a retroactive effect, likely resolving thousands of pending lawsuits in the state.

Although far narrower than its original draft, the version of SB 690 that passed in August indicates government acknowledgment that private litigants have abused CIPA protections in recent years.

SB 690 provides protections including:

  • Removal of Private Right of Action for Pen Register– and Trap and Trace–Related Violations: SB 690 removes any private right of action under Penal Code Section 637.2 for violations of Penal Code Section 638.51 alleged to arise from conduct occurring on an internet website, online application or mobile application.
  • Retroactive Effect: SB 690 applies retroactively to any pending claim in an action commenced within two years before the operative date of the new legislation.

Key Takeaways

Businesses operating websites and applications in California should keep in mind the following implications:

  • Underlying Action Remains Illegal: SB 690 does not legalize the underlying use of pen registers or trap and trace devices; it only restricts who can bring enforcement actions against private businesses. Businesses evaluating strategic risk should be careful not to read SB 690 too broadly. SB 690 makes clear that the California AG still has authority to bring criminal enforcement action for violations of Penal Code 638.51. The volume and pace of enforcement remain within the AG’s discretion; while the AG has not yet focused on bringing CIPA claims against businesses for online business activity, a future AG may take a different approach.
  • Other CIPA Violations Remain: SB 690 leaves much of CIPA as is. In particular, plaintiffs may still be able to bring cases where they can successfully allege that the trackers in question collected the “contents” of communications. Still, these may be more difficult, fact-intensive claims compared with previous theories of liability for plaintiffs tied to pen registers and trap and trace devices that would simply rely on the fact that a particular website collected IP addresses (or other routine tracking information) to move forward.
  • Effect on Ongoing Litigation: Because SB 690 is retroactive to pending claims in actions commenced within two years of the legislation’s operative date, businesses should consider closely evaluating any ongoing lawsuits to determine whether relevant claims can be dismissed under the amendment. Businesses should be careful not to overstate the effect of SB 690 on litigation; while Section 638.51 claims may be void, private plaintiffs often bring numerous claims at the same time, such that SB 690 may not resolve the lawsuit entirely.
  • Protection From Overzealous Litigation: The successful passage of SB 690 indicates an increased focus on protecting businesses from overzealous litigants in California.

For more privacy and cybersecurity news, follow the WilmerHale Privacy and Cybersecurity Law Blog.

Authors

More from this series

Notice

We appreciate your interest in WilmerHale. While we are pleased to have you contact us, please keep in mind that merely contacting WilmerHale does not create an attorney-client relationship. Such a relationship will not arise until the Firm agrees in writing to represent you in connection with a particular matter. Importantly, unless and until this has occurred, you should not provide us with any confidential information, and we have no duty to keep confidential any information that we may receive from you. Thank you for your understanding.