Skip to content

The California Legislature has delivered some great news in the fight against plaintiffs’ firms and pro se litigants seeking to aggressively apply the California Invasion of Privacy Act’s (“CIPA”) prohibition on the use of pen registers and trap and trace technology to website pixels and similar technologies. The California Senate recently passed SB 690, substantially restricting the private rights of action available under CIPA. Unless Governor Gavin Newsom vetoes the bill, it will become law in short order, complete with a retroactivity clause applying to claims made up to two years before the statute’s enactment. But while SB 690 will substantially reduce the claims that have harassed businesses of all types and sizes for several years, it stops short of eradicating all private rights of action under CIPA or providing a “commercial business purpose” exemption.

SB 690 limits the ability to bring claims for the unauthorized use of pen registers and trap and trace technology to the California Attorney General if the claim arises from conduct occurring on an Internet website, online application, or mobile application. Thus, private litigants could no longer assert claims for website-related violations of California Penal Code § 638.51, which has become a cottage industry for certain firms and pro se individuals in recent years. Moreover, the bill, if it becomes law, would apply this limitation retroactively to any pending claim in an action commenced within two years before the operative date of the law, meaning that many businesses currently litigating these claims would soon be freed of that burden.

While this is all fantastic news, the California Senate unfortunately did not completely eliminate private litigation under CIPA, which was contemplated by earlier versions of SB 690. Private plaintiffs can still bring claims under California Penal Code § 631 (related to wiretapping) and § 632 (related to electronic eavesdropping), which provide the basis for many lawsuits under CIPA. And businesses are not freed from all forms of trap and trace/pen register liability—the Attorney General still has the authority to bring actions for alleged violations.

Ultimately, companies still need to carefully evaluate how they are deploying website pixels, cookies, and related tracking technologies, providing notice of privacy practices, and giving users opportunities to opt out, particularly in California. But the numerous letters demanding a payoff under CIPA for illegally deploying trap and trace/pen register technology on company websites should soon be a thing of the past.

Related Capabilities

Related People

Stay up to date

Subscribe

Attorney Advertising ©2026 Vedder

cping