News & Insights
Legal Alert

On August 28, 2026, the California Legislature unanimously passed Senate Bill 690 (SB 690), a measure intended to curb a substantial portion of website-tracking and privacy litigation that has proliferated under the California Invasion of Privacy Act (CIPA) and related federal and state law. While SB 690 has yet to be signed into law, it is expected to be approved by Governor Newsom and would take effect on January 1, 2027.
Businesses with websites, online applications, and mobile applications have spent the last several years defending a wave of demands and lawsuits brought based on alleged violations of CIPA. These actions typically challenge the use of routine web technologies, such as cookies, pixels, and other analytics tools. Plaintiffs claim such tools collect or transmit information about a visitor's online activity without consent in violation of CIPA. In such suits, Plaintiffs commonly rely on the argument that the use of cookies and pixel technologies violate CIPA as such tools are the same as “pen registers” or “trap and trace” devices, which are tools historically used by law enforcement to log routing information and identify the sources of communications. Because CIPA provides statutory damages, such claims have become a favored litigation tool, driving a significant increase in the volume of litigation and costs.
If signed into law, SB 690 would preclude a significant volume of private suits under CIPA brought based on the alleged use of “pen register” and “trap-and-trace” technologies. Plaintiffs’ claims have relied heavily on these theories but, under SB 690, the right to bring such claims would be reserved solely for the California Attorney General. The bill also applies retroactively to lawsuits filed within two years before its operative date, potentially affecting many pending cases.
Although SB 690 would likely reduce website-tracking litigation if signed into law, it would not eliminate such claims altogether. Plaintiffs may still pursue claims under other provisions of CIPA or similar federal and state statutes.
Thus, even with passages of SB 690, businesses should continue to evaluate their use of web technologies and implement sufficient consent tools and safeguards to avoid privacy violations and statutory damages.
Allen Matkins has substantial experience assisting clients with such disputes, including under CIPA, the California Privacy Rights Act (CPRA), and federal law under the Electronic Communications Privacy Act (ECPA) and related statutes. Please contact Scott Leipzig, Tim Hsu, or Adam Korn if you require any assistance.
Authors
Partner
Partner
Senior Counsel
RELATED SERVICES
News & Insights
Allen Matkins Leck Gamble Mallory & Natsis LLP. All Rights Reserved.
This publication is made available by Allen Matkins Leck Gamble Mallory & Natsis LLP for educational purposes only to convey general information and a general understanding of the law, not to provide specific legal advice. By using this website you acknowledge there is no attorney client relationship between you and Allen Matkins Leck Gamble Mallory & Natsis LLP. This publication should not be used as a substitute for competent legal advice from a licensed professional attorney applied to your circumstances. Attorney advertising. Prior results do not guarantee a similar outcome. Full Disclaimer