California Legislature Eliminates Private Right of Action for Certain Claims Under CIPA
On September 30, 2026, California Governor Gavin Newsom signed Senate Bill 690 (“SB 690”), which the California Legislature unanimously passed on August 28, 2026. The new law, which will take effect on January 1, 2027, eliminates the private right of action for online pen register and trap and trace claims under the California Invasion of Privacy Act (“CIPA”). Although SB 690 marks a substantial change to the CIPA landscape, which has been flooded with claims in recent years, it does not provide complete relief to companies that use commonplace online tracking technologies like cookies. Rather, the law shifts enforcement from private plaintiffs to the California Attorney General. Further, plaintiffs may try to challenge the same tracking technologies under other provisions of CIPA or other laws.
Background
CIPA was originally enacted in 1967. It prohibits any interception or recording of confidential communications of another without their consent. Broadly speaking, the law prohibits wiretapping, eavesdropping, the recording of private communications, and the use of pen registers or trap and trace devices. As relevant to SB 690, Section 638.51 of CIPA prohibits the installation or use of a pen register or trap and trace device without having first obtained a court order or consent. CIPA’s civil enforcement provision, Section 637.2, provides statutory damages of $5,000 per violation plus three times the amount of actual damages, if any, that a plaintiff sustains.
Prior to the enactment of SB 690, CIPA provided individuals with a direct cause of action against any private actor for violations of the law. Over the past few years, the number of CIPA pen register and trap and trace lawsuits has exploded. Plaintiffs have used CIPA’s private right of action to threaten and/or bring thousands of claims, including class action lawsuits, against companies. By and large, these claims argue that companies violated CIPA’s prohibition on pen register and trap and trace devices through their use of common online tracking technologies, including cookies, third-party pixels, website analytics, and similar technologies. Plaintiffs typically allege that such technologies are pen registers or trap and trace devices and that companies violate Section 638.51 by using those technologies without a court order or consent. Plaintiffs in these actions seek the statutory damages of $5,000 per violation, which is the maximum amount recoverable without showing actual damages. Courts have determined that CIPA applies so long as the internet user is within California, meaning that companies based outside of California may still be subject to CIPA liability.
Key Changes
Effective January 1, 2027, SB 690 amends CIPA’s civil enforcement provision, resulting in two major changes.
Private plaintiffs can no longer file pen register and trap and trace claims for conduct occurring on an internet website, online application, or mobile application. Only the California Attorney General may bring such claims.
SB 690 is retroactive to January 1, 2025. Any lawsuit filed by a private plaintiff on or after January 1, 2025 that alleges an unlawful pen register or trap and trace device in connection with an internet website, online application, or mobile application will be barred. Cases filed prior to January 1, 2025 are left unaffected, as are civil enforcement claims brought by the California Attorney General.
What SB 690 Has Not Changed
Although the elimination of the private right of action for certain pen register and trap and trace claims is a major development that will bar many threatened and pending lawsuits, SB 690 is not a complete overhaul of CIPA.
Online pen registers and trap and trace devices are still illegal without a court order or consent. SB 690 only shifts the enforcement to the California Attorney General.
Plaintiffs still have a private right of action for wiretapping claims or eavesdropping claims. SB 690 specifies that only the California Attorney General may bring lawsuits alleging violations of Section 638.51. Private plaintiffs may still bring wiretapping claims under Section 631 or eavesdropping claims under Sections 632 and 637. These plaintiffs may still seek the $5,000 statutory damages for such violations of CIPA and may still potentially file class action lawsuits.
Legislative action to curb these claims may be forthcoming. When Governor Newsom signed SB 690, he noted that “additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants,” and he urged the California legislature to take this on next year to “ensure a fair balance between protection private information and preventing rapacious litigation.”
Looking Forward
While SB 690 is an important change, companies should remain vigilant with respect to the use of third-party tools within their websites and potential CIPA lawsuits. It is likely that plaintiffs will now allege that the same internet tracking technologies amount to wiretapping or eavesdropping violating Sections 631, 632, and 632.7 and seek the $5,000 statutory damages per putative violation, in addition to violations of other laws. Further, the California Legislature’s elimination of a private right of action for online pen register and trap and trace device cases does not eliminate the risk of suit under Section 638.51. The California Attorney General may pick up where private lawsuits have left off, though Governor Newsom stated that he is aligned with the “goal of protecting small businesses from overzealous lawsuits based on a statute written without today’s complex technological landscape in mind.”
If you would like assistance with, or have any questions about, CIPA claims, please contact one of the authors of this alert.