California's legislature did something unusual in late August: it passed a bill, SB 690, by a unanimous 66 to 0, to shut down a category of litigation that had grown to roughly 4,000 lawsuits. The bill amends the California Invasion of Privacy Act to strip the private right of action for pen register claims, under Penal Code section 638.51, when the alleged conduct happens on a website, online application, or mobile application. Enforcement of that provision would belong to the California Attorney General alone. The bill now awaits the governor's signature, which is widely expected before the September 30 deadline, and would take effect January 1, 2027, reaching back into pending cases.
The unanimity is the tell. A legislature that votes 66 to 0 is not weighing privacy against business. It is ending something that both sides, for different reasons, had concluded was out of control. The law being retired was written in the wiretapping era to regulate devices attached to phone lines. What it became, in the hands of the plaintiffs' bar, was a near-strict-liability machine pointed at the analytics code that runs on nearly every commercial website in the country.
A phone-tap statute, aimed at web pixels
CIPA section 638.51 prohibits installing a pen register or trap and trace device without consent, a court order, or another exception, and lets an injured person recover the greater of $5,000 per violation or three times actual damages, with no need to prove actual damages at all. A pen register is a device that records the numbers dialed from a phone. The statute's mental picture is a 1980s wiretap investigation. The plaintiffs' innovation, beginning around 2023, was to argue that the same provision covers a website's collection of IP addresses, device identifiers, and routing information through the cookies, pixels, session replay software, and chat tools that underpin modern advertising and analytics. The theory had a powerful simplicity: the tracker fired when the page loaded, consent banners came after the fact, and the $5,000-per-violation damage formula made every website visit a potential claim. By July 2026, the legislature was told, 4,000 CIPA cases had been filed, and demand letters had gone out to thousands of businesses whose only offense was using the same analytics stack as everyone else.
The two sides tell this story in opposite registers. To plaintiffs' attorneys, section 638.51 was the only provision with enough teeth to reach invisible tracking, because other CIPA claims require showing interception of communication contents or a violation of a reasonable expectation of privacy, burdens that routing data often cannot carry. To the businesses and their counsel, the wave was a settlement machine: a $5,000-per-violation strict-liability count asserted against conduct the entire commercial internet engages in, where the cost of litigating exceeds the cost of paying. Both descriptions are accurate. That is why the fix drew no opposition worth recording.
The bill that almost went further
The version of SB 690 that reached the governor's desk is the survivor of a much more ambitious bill. The original proposal, introduced in February 2025, would have gone beyond pen register claims to bar private suits under the wiretapping provisions themselves, sections 631 and 632, when the conduct served a commercial business purpose. That version passed the Senate 35 to 0 in June 2025 and then stalled in the Assembly, where the scope of the immunity it would have created drew sustained opposition. The compromise that emerged in July 2026 cut the bill back to section 638.51 only, leaving the wiretapping and recording claims fully intact, and it is that narrower bill that passed unanimously at the end of August. The legislative history is the clearest statement of what Sacramento thinks it is doing: killing the claim it considers indefensible, while declining to touch the claims it considers debatable.
The distinction the legislature drew, between the pen register claim and everything else, tracks the legal structure. A pen register records the fact of a communication, not its content, and the plaintiffs' theory had to argue that IP addresses and device identifiers fit that old definition well enough to trigger $5,000 statutory damages per violation. The wiretapping theories are harder for plaintiffs, because they must show interception of content, but they are also harder for the legislature to dismiss, because they rest on a principle, that private communications deserve protection, which most members are not prepared to vote against. SB 690 is therefore not a verdict on website tracking. It is a verdict on one particular legal instrument, and the instrument was retired because it was too powerful for its purpose.
What the Attorney General can do with it
The consequence of replacing private enforcement with Attorney General enforcement is a change of scale and motive. Private plaintiffs' lawyers filed 4,000 cases because each case carried the prospect of statutory damages multiplied across visits, and the settlement economics worked even at modest per-case amounts. The Attorney General's office does not operate on that model. It can bring one case, or a few, against the conduct it considers most harmful, and the remedy is injunctive or civil penalties that go to the state rather than to individual website visitors. The predictable result is fewer cases, targeted at the clearest offenders, and a doctrine built through a handful of high-quality enforcement actions rather than thousands of settlements. That is not a flaw. It is what the legislature chose, and the choice has a consequence nobody should miss: the consumer whose visit was tracked now depends on the Attorney General's enforcement priorities, and the Attorney General's priorities are set by one office, not by a market of 4,000 filings.
For businesses, the flip side of that concentration is strategic clarity. The Attorney General's targets are unlikely to be the ordinary analytics stack; the political and legal value lies in cases with demonstrable harm, such as tracking of sensitive health or financial information, or tools that operate without any disclosure at all. Companies that want to stay out of that category can read the enforcement posture of the past several years: disclosure, meaningful choice, and restraint with sensitive data have been the themes. The demand-letter era is ending. The era of a single, well-aimed enforcement action is beginning, and it will be aimed at whoever the office decides least deserves the benefit of the doubt.
An enforcement fix, not a legality fix
What SB 690 does not do is as important as what it does. It does not declare the underlying tracking lawful. It does not amend section 638.51's prohibition. It does not touch the wiretapping claims under section 631 or the confidential-communication recording claims under section 632, which remain privately enforceable. The bill is, in the phrasing its drafters would recognize, an enforcement fix: it removes the private claim against web operators and hands the statute to the Attorney General. If the same analytics practices violated section 638.51 before, they violate it after. What changes is who can say so, and what it costs the defendant when they do. The Attorney General's office does not send 4,000 demand letters a year, and nobody is getting $5,000 per visit from it.
The retroactivity provision is the bill's quiet radicalism. It applies to pending claims in actions commenced within two years before the operative date, which could reach cases filed as far back as January 2025. Retroactivity provisions of this kind are routinely challenged, and the bill carries a severability clause anticipating exactly that fight. But the drafting signals intent: the legislature wanted the wave to stop, not merely to slow. Defendants will seek dismissal or judgment on the pleadings on covered section 638.51 counts, and plaintiffs asserting only the pen register theory face the disappearance of their claim. Completed settlements and final judgments are not unwound, so the checks already cut stay cut.
The litigation is migrating, not ending
The most predictable consequence of SB 690 is a surge of refiled cases under sections 631 and 632. The difference between those theories and the pen register claim is the word "contents." A wiretapping claim under section 631 requires interception of the content of a communication; section 632 requires recording a confidential communication. Whether an IP address, a device fingerprint, or a search term typed into a chat widget counts as content is now the single most valuable open question in California privacy law, and two pending cases are aimed directly at it. In Variety Media v. Superior Court, the California Court of Appeal is considering whether section 638.51 applies to internet tracking at all, a question SB 690 may moot before the court answers it. In Drummer v. CoStar Group, the Ninth Circuit is weighing Article III standing for these claims. Whatever those courts say will determine whether the wave re-forms around the surviving sections or breaks against standing limits.
Beyond California, the economics do not change. Florida, Pennsylvania, Arizona, and Washington have their own wiretapping statutes, and the same theories can travel. The national privacy litigation market has spent three years learning that website tracking is a claim-rich environment, and SB 690 closes only one of its entrances. What California has decided is narrower and more honest than headlines suggest: a statute written for telephone surveillance will no longer be privately enforceable against the web. The question of what the web is allowed to collect, and who can sue over it, remains exactly as unresolved as it was the day before the vote.
Primary sources
- Mondaq for SB 690's passage, its amendment to section 637.2, the retroactivity provision, and the litigation counts.
- Troutman Amin's companion analysis on Mondaq for the pending appellate cases, including Variety Media and Drummer v. CoStar Group, and the migration of claims to sections 631 and 632.