This website uses cookies

Read our Privacy policy and Terms of use for more information.

The Maze: California has narrowed a lucrative route for private lawsuits over website tracking. Governor Gavin Newsom signed SB 690 on September 30, reserving one type of claim under the California Invasion of Privacy Act (CIPA) to the state attorney general from January 1, 2027. It targets allegations that pixels, cookies or other site tools violate the law's pen-register rule. The change reaches qualifying pending claims too. It does not legalize tracking, end state enforcement or remove other privacy claims. Retailers gain a narrower litigation threat, not a free pass for their marketing stack.

  • The law closes a specific private claim, not the privacy rule. SB 690 amends CIPA's civil-remedy section. Only the attorney general may sue a private actor under Section 638.51 for alleged conduct on a website or app. That section restricts pen registers, which record routing or addressing information rather than message contents. Plaintiffs had argued that pixels and analytics tags fit the definition when they shared identifiers and page data. Courts had disagreed. The bill changes who may bring this civil claim; it does not repeal the underlying rule.

  • The timing reaches some open cases, but there is a boundary. The non-urgency law is expected to start January 1, 2027. Its retroactivity clause covers pending claims in actions begun within the previous two years, roughly from January 1, 2025. It does not reopen settled cases or make every cookie suit disappear. Courts will still apply the provision to individual claims. CIPA's civil formula—the greater of $5,000 per violation or triple actual damages—continues outside the exception. For a defendant, the first question is which legal theory a complaint actually pleads.

  • The pressure behind the bill was real, though its headline count is soft. Bill author Anna Caballero said in August that related lawsuits had climbed from about 600 in 2025 to nearly 4,000. Her office did not publish the docket data or define every case counted, so this is a sponsor estimate, not an audited total. The enacted wording has no small-business threshold: large retailers and local shops both fall within its stated scope. Fewer private plaintiffs may ease settlement pressure, but the saving is unknown and the attorney general retains enforcement power.

  • Other paths keep the tracking audit on the operator's desk. The bill leaves CIPA's wiretapping and eavesdropping sections alone. Legal analysis says private plaintiffs may still bring Sections 631 and 632 claims and dispute what a search box, chat tool or pixel sends to third parties. Those claims have different elements and are not automatic wins. Retailers should still map their tags, check what fires before consent and understand vendor data flows. SB 690 narrows one litigation route; it does not decide whether a site's collection or disclosures comply with other law.

Why it matters: SB 690 shifts one expensive enforcement path from private plaintiffs to California's attorney general. That may take some leverage out of tracking-related demand letters, especially for smaller sites, once the law starts. But treating the bill as permission to ignore pixels would be a costly misread. Operators should know which tools transmit customer data and when, then watch how courts handle pending cases and whether lawmakers revisit other CIPA provisions. The practical win is a narrower risk map; the remaining map still needs reading.

Reply

Avatar

or to participate