California Moves To Strip Private Plaintiffs Of Key CIPA Privacy Claim As Court Of Appeal Issues Critical Ruling

California’s legislature has passed an amended version of Senate Bill 690, a move that significantly reshapes how website privacy claims can be pursued under state law.

For the past two years, plaintiffs’ lawyers have increasingly relied on an unlikely provision of the California Invasion of Privacy Act to target ordinary website technologies used by businesses.

The Assembly and Senate passed the amended bill, which would effectively eliminate the private right of action for Section 638.51 claims based on activity occurring on websites, online applications, and mobile applications.

The legislation also contains a retroactivity provision that would apply the amendment to pending claims in actions commenced within two years before the legislation’s operative date.

Plaintiffs have argued that cookies, pixels, analytics tools, and similar technologies qualify as illegal pen registers or trap and trace devices under California Penal Code Section 638.51 because they collect IP addresses and other routing data.

Those legal theories have generated hundreds of lawsuits and demand letters, with courts across California reaching conflicting conclusions about whether such tools actually fall within the statute’s scope.

Under the amended bill, only the California Attorney General may bring an action alleging a Section 638.51 violation arising from conduct occurring on a website or application, stripping private plaintiffs of that avenue entirely.

That is a significant departure from the current position, where Section 637.2 allows private plaintiffs to seek $5,000 per violation without needing to demonstrate actual damages suffered.

Crucially, the underlying conduct is not legalised and businesses running websites do not receive immunity, meaning the Attorney General retains full enforcement authority over alleged violations.

While SB 690 may remove one category of CIPA claims from private litigants, claims under Sections 631 and 632 remain viable options for plaintiffs pursuing privacy cases.

On 21 August 2026, the California Court of Appeal issued a tentative ruling in Variety Media, LLC v. Superior Court, Case No. B350578, tackling whether CIPA’s pen register provision reaches everyday website tracking tools like cookies and pixels.

The court held that CIPA’s pen register definition is technology-neutral, meaning it can extend beyond telephone equipment to internet communications, a setback for businesses that argued the statute was never intended to reach such tools.

However, the ruling was not entirely unfavourable to businesses, as the plaintiff in that case still lost on the specific claim before the court.

The court held that a pen register must capture information about where a communication is headed, not where it originated, meaning an IP address identifying the visitor’s device failed to meet that standard as pleaded.

The tentative ruling arrived just one week before the amended SB 690 reached the Assembly floor, placing both developments on a collision course that redefines the litigation landscape simultaneously.

Because the bill contains no urgency provision, if signed this year, California’s standard rule would make it effective January 1, 2027, leaving a window during which existing exposure may remain.

Businesses and their counsel should understand exactly what SB 690 does and what it leaves unchanged before concluding that existing claims or demand letters have been resolved.