LawFlash

California Eliminates Private Right of Action Under CIPA’s ‘Pen Register’ and ‘Trap and Trace’ Provision

October 01, 2026
6 minute read

Key Takeaways

  • California Governor Gavin Newsom signed SB 690 into law, which eliminates private claims under CIPA Section 638.51 arising from conduct on websites and online or mobile applications, leaving enforcement of those claims to the California attorney general.
  • The law applies retroactively to certain pending Section 638.51 claims filed within two years of its effective date, potentially providing businesses with a defense to those claims.
  • SB 690 does not eliminate website-based wiretapping litigation completely, as plaintiffs may continue pursuing claims under CIPA Sections 631 and 632 and other statutory or common-law theories.
  • Businesses may want to reassess cookie consent practices, website tracking technologies, and privacy disclosures, in light of the changing litigation landscape.
California Governor Gavin Newsom has signed Senate Bill 690 into law, eliminating the private right of action for claims under California Penal Code Section 638.51, which broadly prohibits the installation of “pen registers” or “trap and trace devices” without a court order. Section 638.51 served as a primary vehicle for the wave of wiretapping litigation under the California Invasion of Privacy Act targeting the use of third-party cookies and other advertising technologies on websites.

After a years-long effort to address California Invasion of Privacy Act (CIPA) litigation targeting routine website technologies, Senate Bill 690 (SB 690) was enacted on September 30, 2026.

Specifically, the bill amends California Penal Code Section 637.2, which provides CIPA’s private right of action, to specify that “[a]n action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.” The bill also affects ongoing litigation: the law contains a retroactivity provision that applies to pending claims filed within two years of its effective date.

BACKGROUND ON CIPA AND SB 690

Since 2023, CIPA Section 638.51 has been a significant driver of class-action litigation, mass arbitration threats, and settlement demands. Except in certain limited circumstances, the provision states that “a person may not install or use a pen register or a trap and trace device without first obtaining a court order.”[1] Given its broad language, Section 638.51 provided a basis for plaintiffs to bring claims against websites that otherwise complied with California’s existing comprehensive consumer privacy laws, such as the California Consumer Privacy Act (CCPA), on the grounds that the business did not obtain a court order to install cookies on its website.

The application of the statute to internet technologies has divided courts for years. Some courts have held that the statute does not apply, finding that “CIPA’s history and structure represents a telephonic limitation.” In contrast, others have found that “software trackers embedded in websites qualify as ‘pen registers’ when they collect users’ IP addresses, device identifiers, and browsing data.”[2] Given this uncertainty, many companies facing litigation under Section 638.51 have pursued early settlements rather than litigating the issue.

In 2025, State Senator Anna Caballero authored the initial version of SB 690, which would have added a broad “commercial business purpose” carve-out from CIPA liability that extended beyond Section 638.51. Due to opposition, the bill was converted into a two-year bill and reworked into its current iteration, which passed both houses of the California Legislature on August 28, 2026. In signing the bill, Governor Newsom stated that he aligned “with the goal of protecting small businesses from overzealous lawsuits based on a statute written without today’s complex technological landscape in mind.”[3] He also “urge[d] the Legislature” to take further action in 2027 “to ensure a fair balance between protecting private information and preventing rapacious litigation.”[4]

EFFECT OF SB 690

SB 690 will provide relief for businesses. In particular, companies defending against existing “pen register” and “trap and trace” claims filed within two years of the effective date will be able to rely on the retroactivity provision as a defense to such claims. Further, SB 690 signals the legislature’s broader awareness of and concern about litigation arising under CIPA, a 1960s-era criminal statute. Some courts have expressed similar concerns.[5]

SB 690 is particularly notable in light of the California Court of Appeal’s tentative August 21, 2026 ruling in Variety Media LLC v. Superior Court, No. B350578, which indicates a leaning toward finding that Section 638.51 is not limited to telephonic surveillance. If adopted, the ruling would be the first state appellate decision on the issue and, without SB 690, would have potentially led to additional pen register and trap and trace litigation.

THE FUTURE OF ‘WIRETAPPING’ LITIGATION

Although SB 690 is a significant development for businesses, it does not, in itself, eliminate all wiretapping litigation. Notably, the bill leaves intact the “traditional” wiretapping and eavesdropping provisions of CIPA, Sections 631 and 632. Plaintiffs have already signaled their intent to recast Section 638.51 claims as claims under Sections 631 and/or 632, as well as other statutory and common-law causes of action, such as claims under the California Comprehensive Computer Data Access and Fraud Act or for intrusion upon seclusion.

These claims are generally more difficult to plead than those brought under Section 638.51 and thus create additional barriers for plaintiffs pursuing wiretapping litigation. For example, claims under CIPA Section 631(a) require proof that the information at issue constitutes the “contents of a communication” and that a third party read or attempted to read such information while it was “in transit.” However, early reactions from the plaintiffs’ bar suggest that plaintiffs will seek to adapt their allegations rather than abandon their “wiretapping” claims altogether.

KEY TAKEAWAYS AND CONCLUSION

SB 690 changes the landscape of wiretapping litigation. Specifically, it provides relief from pen register and trap and trace claims and reflects the legislature’s response to CIPA litigation. However, SB 690 does not appear to mark the “end” of all website-based wiretapping litigation, but rather, a turning point. The following are some possible ways businesses can prepare for this changed landscape:

  • Consider an opt-in model: Websites that are configured such that cookies fire only after a user explicitly consents to tracking, particularly in litigation-heavy jurisdictions such as California, have a strong defense to wiretapping claims.
  • Reassess cookies with litigation risk in mind: Companies may periodically review their websites to identify all cookies, particularly those that fire by default, and consider whether each cookie’s business benefit is worth the litigation risk. Cookies that present marginal business value may be considered for removal.
  • Implement a process for ongoing legal review of cookies: Companies may adopt cookie compliance guidelines and processes to ensure that their legal teams are involved as new technologies are added to their websites.
  • Craft strong cookie banner and privacy policy language: Businesses may regularly review and update their privacy policies and cookie banners to disclose the types of information that may be collected and shared with third parties. It may be helpful to ensure that privacy policies are prominently displayed and that the business obtains users’ affirmative assent to the privacy policy and other terms.
  • Correctly configure search bars and chat box features: Search bars and chat boxes may feature more prominently in the next wave of CIPA litigation given the shifting focus back to the contents of a communication. Companies may consider how to provide adequate notice in the event these common website features transmit user communications to third parties.


[1] Cal. Penal Code § 638.51(a).

[2] Compare Rodriguez v. Ink Am. Int’l Group LLC, No. 25STCV15350, 2025 WL 4034985, at *3–4 (Cal. Super. Ct. Dec. 10, 2025), with Fregosa v. Mashable, Inc., No. 25-CV-01094-CRB, 2025 WL 2886399, at *2 (N.D. Cal. Oct. 9, 2025).

[3] Gavin Newsom, Governor of Cal., Signing Message for S.B. 690, at 1 (Sept. 30, 2026).

[4] Id.

[5] See, e.g., Doe v. Eating Recovery Ctr., 806 F. Supp. 3d 1109, 1119 (N.D. Cal. 2025) (“As difficult as it is to apply CIPA to the physical world, it's virtually impossible to apply it to the online world . . . courts should not contort themselves to fit the type of conduct alleged in this case into the language of a 1967 criminal statute about wiretapping.”).