California Overhauls Privacy Litigation: Governor Newsom Signs SB 690 to Curb “Vexatious” CIPA Lawsuits

In a significant pivot for California’s digital privacy landscape, Governor Gavin Newsom signed Senate Bill 690 into law on September 30, 2026. The legislation marks the end of a prolific era for class-action attorneys who have spent the last two years utilizing the California Invasion of Privacy Act (CIPA) to target website and mobile app operators. By removing the private right of action for “pen register and trap-and-trace” claims related to digital tracking, the state has effectively shut down a litigation pipeline that had ensnared thousands of businesses, ranging from local retailers to national technology giants.

The signing, which occurred on the final day of the governor’s constitutional window, serves as a direct response to a surge in litigation that critics labeled as “rapacious.” While the law curtails the ability of private plaintiffs to sue over tracking pixels and analytics code, it leaves other sections of CIPA—specifically those related to wiretapping and recording—untouched, setting the stage for continued legislative battles in 2027.

The Legislative Shift: A New Era for CIPA

Senate Bill 690 adds a crucial new subdivision, (d), to Penal Code Section 637.2. This amendment mandates that any civil action against a private actor for violating Section 638.51—the statute governing the use of pen register and trap-and-trace devices—must now be brought exclusively by the California Attorney General.

For nearly two years, plaintiffs’ firms have argued that common website infrastructure, such as pixels, site tags, and software development kits (SDKs), essentially function as “pen registers.” Under this interpretation, these tools, which transmit page addresses, search terms, and IP addresses to third-party ad-tech providers, constitute a violation of CIPA. Because CIPA allows for statutory damages of the greater of $5,000 per violation or three times actual damages—without requiring proof of actual harm—the statute became a potent weapon for high-volume litigation.

The new law effectively strips the financial incentive for private law firms to pursue these claims. While the Attorney General’s office remains empowered to enforce the statute, the shift from thousands of private litigants to a single regulatory office represents a massive reduction in the legal threat landscape for businesses operating in California.

Chronology of a Legislative Correction

The trajectory of SB 690 reflects the growing urgency felt by California lawmakers to address what many perceived as an abuse of the court system.

  • February 21, 2025: Senator Anna Caballero introduces an ambitious version of the bill aimed at providing a broader shield for commercial entities.
  • June 3, 2025: The Senate passes the initial version of the bill in a 35-0 vote. However, the bill subsequently stalls in the Assembly, evolving into a two-year legislative project.
  • August 2026: As litigation volume peaks, the Assembly Privacy and Consumer Protection Committee amends the bill into its final form.
  • August 28, 2026: The Assembly passes the bill 66-0; the Senate concurs unanimously with a 40-0 vote.
  • September 4, 2026: The bill is formally presented to Governor Newsom.
  • September 30, 2026: Governor Newsom signs the bill, effectively closing the window on private pen register claims for any suit initiated after January 1, 2025, that remains pending on January 1, 2027.

Supporting Data: The Litigation Explosion

The impetus for SB 690 was the sheer volume of filings. According to industry tracking data, Section 638.51 filings skyrocketed from approximately 600 annually to nearly 4,000 following the legislative activity in early 2025. While sources differ on the exact methodology of these counts, the trend was undeniable.

Beyond formal lawsuits, the legal market saw a deluge of demand letters. Many of these letters, which critics allege were generated by AI, targeted small businesses, nonprofits, and news outlets that lacked the resources to engage in protracted discovery or complex settlement negotiations. The “Stop CIPA Shakedown Lawsuits” coalition, which championed the bill, argued that the law was never intended to regulate the metadata of standard web analytics, but rather to police unauthorized government surveillance of telephone lines.

The economic impact of this litigation was profound. Companies were forced to implement aggressive consent management platforms, tag governance protocols, and pre-consent script blocking—measures often driven more by the fear of CIPA’s $5,000-per-violation penalty than by the California Consumer Privacy Act (CCPA).

Official Responses and the Governor’s Warning

In his signing message, Governor Newsom provided a nuanced view of the legislation. While he praised the effort to protect small businesses from “overzealous lawsuits,” he explicitly acknowledged that the software in question does, in fact, track and share user information.

Crucially, the Governor issued a warning to both the legislature and the legal community: “Additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants. I urge the Legislature to take this on next year to ensure a fair balance between protecting private information and preventing rapacious litigation.”

The Governor’s message highlights a central tension: while the legislature has acted to stop “shakedown” litigation, it has not yet arrived at a permanent consensus on how to regulate the underlying data-sharing practices that sparked the lawsuits in the first place.

Implications for Businesses and Plaintiffs

The implications of the law taking effect on January 1, 2027, are immediate and far-reaching:

1. Extinction of Pending Claims

The law includes a two-year look-back provision. This means that any lawsuit filed since January 1, 2025, that relies on the pen register theory under Section 638.51 will lose its legal basis if it remains pending on January 1, 2027. While resolved or settled matters are not reopened, the risk profile for ongoing litigation will change overnight, likely leading to a flurry of dismissals or forced withdrawals in the final weeks of 2026.

2. The Shift to Other CIPA Provisions

The law leaves Sections 631 (interception of communications), 632 (recording of confidential communications), and 632.7 (intercepting mobile communications) entirely untouched. Plaintiffs’ attorneys are expected to pivot their strategies, attempting to reframe claims regarding pixels and tracking tools as “interception” under Section 631.

Legal analysts note that Section 631, which requires proof of the interception of the contents of a communication, presents a higher evidentiary burden than the pen register statute. However, high-profile successes—such as the 2025 jury verdict against Meta regarding the Flo app—suggest that plaintiffs will continue to test the limits of these remaining sections.

3. Concentration of Enforcement

By granting exclusive enforcement authority to the Attorney General, California has signaled that it prefers a centralized, regulatory approach to digital privacy over a decentralized, litigation-driven one. Attorney General Rob Bonta’s office has already demonstrated its appetite for large-scale privacy settlements, including significant actions against Disney, Healthline Media, and Meta. With the private litigation avenue closed, the Attorney General will likely become the primary arbiter of whether specific web-tracking technologies violate California’s privacy statutes.

The Broader Regulatory Landscape

The passage of SB 690 does not occur in a vacuum. It is part of a larger, broader calibration of California privacy law. As of January 1, 2027, several other significant changes will take effect:

  • SB 923: Expands the CCPA deletion right to cover information acquired from third parties.
  • AB 566 (The Opt Me Out Act): Mandates that browsers include settings for an opt-out preference signal, such as Global Privacy Control.

These laws represent a shift toward user-centric privacy controls, contrasting with the punitive nature of the CIPA litigation wave. As the state moves toward a more structured regulatory framework, the role of the “private attorney general”—the individual citizen suing on behalf of the public—is being systematically curtailed in favor of state-led enforcement.

Conclusion: A Delicate Balance

The signing of SB 690 represents a victory for the business community, which has long campaigned for relief from what it termed “automated” and “frivolous” litigation. However, it also represents a challenge to the legislature. By signing the bill, Governor Newsom has effectively put the legislature on notice that the current CIPA framework is an imperfect instrument for the modern digital age.

As the state enters 2027, the focus will shift from the courtroom to the capitol. With the “pen register” loophole closed, the debate will likely turn to whether the remaining sections of CIPA—dating back to 1967—can be modernized without gutting the privacy protections that California citizens have come to expect. Until then, the state’s privacy landscape will remain a complex, evolving map of regulatory oversight, with the Attorney General’s office standing as the sole gatekeeper for a significant portion of California’s digital privacy enforcement.