California's Legislature today has sent Governor Gavin Newsom a bill that would strip private citizens of the right to sue websites and apps over a decades-old wiretapping statute, closing off a category of litigation that surged from a few hundred filings to thousands in less than two years.
Senate Bill 690 was enrolled on August 31, 2026, according to the Bill Status page maintained by the California Legislative Information system. The bill amends Section 637.2 of the Penal Code so that only the state Attorney General, not private plaintiffs, may bring an action against a private business for violating Section 638.51 of the California Invasion of Privacy Act when the alleged conduct occurs on an internet website, online application, or mobile application. The Assembly approved the measure on a 66-0 vote on August 28, 2026, and the Senate concurred in the Assembly's amendments the same day on a 40-0 vote, according to the Bill Votes record. Every recorded floor and committee vote across both chambers, going back to the bill's introduction, shows zero recorded opposition.
Governor Newsom has not yet acted on the bill. Under the enrollment date of August 31, he has until September 30, 2026, to sign it, veto it, or allow it to become law without his signature. If enacted in its current form, the amendment takes effect January 1, 2027, and applies retroactively to any pending claim in an action commenced within two years before that date.
What the bill changes, and what it does not
Section 638.51 covers the unauthorized use of a pen register or a trap and trace device, terms originally written for telephone-era surveillance. A pen register recorded outgoing numbers dialed from a phone line; a trap and trace device captured incoming numbers calling in. Plaintiffs' firms have argued in recent years that modern website tracking tools, including analytics pixels and marketing tags, function the same way by logging metadata about which pages a visitor loads, what they search, and when.
The bill text, as reflected in the enrolled version, adds a new subdivision (d) to Section 637.2. It states plainly that an action against a private actor for a violation of Section 638.51 "alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General." A companion clause makes that limitation retroactive to any pending claim filed within the two years preceding the law's operative date. The final section of the bill declares its provisions severable, meaning that if a court strikes down any part of the amendment, the remaining provisions stand.
What the bill does not touch is just as important for marketers evaluating their exposure. CIPA's older wiretapping provision, Section 631, which addresses direct interception of communications in transit, is untouched by SB 690. So is Section 632, covering the recording of confidential communications without consent from all parties, a provision plaintiffs have used against AI meeting-recording tools. The private right of action for those two sections remains fully available to any injured party, along with the same $5,000-per-violation or triple-actual-damages formula set out in Section 637.2(a).
A bill that took a year and a half and several rewrites
The current text is narrower than what Senator Anna Caballero introduced. According to the Bill History record, SB 690 was introduced on February 21, 2025, with coauthors including Senators Niello and Valladares and Assembly Members Irwin, Macedo, and Blanca Rubio. Earlier drafts proposed a broad "commercial business purpose" exemption that would have amended Sections 631, 632, and 632.7 directly, along with the statutory definitions of pen register and trap and trace device themselves. That version stalled in the Assembly during 2025 and was reclassified as a two-year bill, meaning it could not be taken up again until the 2026 session.
The bill's path through 2026 shows repeated near-misses before its final passage. It cleared the Senate Public Safety Committee on April 29, 2025, by a 6-0 vote, then the Senate Appropriations Committee on May 23, 2025, also 6-0, before passing the full Senate on June 3, 2025, by a 35-0 vote with five members recorded as not voting. In the Assembly, it passed the Public Safety Committee on July 1, 2025, by 9-0, then stalled for nearly a year before the Assembly Privacy and Consumer Protection Committee took it up again on July 1, 2026, passing it 14-0 with one member not voting. On August 5, 2026, the bill was placed on the Appropriations suspense file, a procedural holding pen where many bills quietly die. It emerged eight days later, on August 13, 2026, when the Assembly Appropriations Committee passed it 15-0.
The litigation surge behind the bill
The legislative push did not happen in a vacuum. PPC Land has tracked a sustained wave of CIPA filings against companies across sectors, most invoking the same statutory damages formula that SB 690's supporters say has become a business model for plaintiffs' firms rather than a genuine privacy remedy.
In April 2026, three plaintiffs sued Ace Hardware, alleging the retailer's cookie banner kept Google Analytics and a Bazaarvoice pixel firing even after visitors opted out of non-essential tracking, with the complaint invoking both Section 631 and Section 638.51. Days earlier, LinkedIn was hit with a proposed class action alleging its browser code scanned Chrome users for more than 6,000 installed extensions and built device fingerprints without disclosure, a case that similarly combined federal Wiretap Act claims with California's pen register statute, as PPC Land reported at the time. That case's damages arithmetic drew on the same $5,000-per-violation figure written into Penal Code Section 637.2, a mechanism PPC Land examined in detail in its anatomy of the LinkedIn complaint.
The pattern extended beyond conventional websites. In March 2026, a class action against Perplexity AI alleged the company embedded the Meta Pixel and Google Analytics inside its chat interface, forwarding users' queries, including health and finance topics, to advertising platforms without consent, a case PPC Land covered in detail; it was later voluntarily dismissed without prejudice. A structurally similar complaint followed against OpenAI in May 2026, alleging ChatGPT.com carried the same two tracking tools and forwarded conversation topics, Facebook identifiers, and Google profile identifiers in real time, as PPC Land detailed in its coverage of the filing. And in July 2026, Granola, a venture-backed AI meeting notetaker, was sued for allegedly recording virtual conversations without most participants' knowledge and feeding the recordings into model training, relying on CIPA Sections 631 and 632 rather than 638.51.
Those cases sit alongside a landmark verdict that has repeatedly served as a reference point for plaintiffs' firms. In August 2025, a federal jury in San Francisco found that Meta violated CIPA by collecting health data from users of the Flo period-tracking app without consent, a decision PPC Land reported centered on Meta's software development kit embedded inside a third-party app. By March 2026, a San Francisco Superior Court had entered a separate $50 million final judgment and permanent injunction against Meta over how Facebook user data was shared with third-party developers, a case California Attorney General Rob Bonta brought and PPC Land covered as part of the broader pattern of privacy exposure across the advertising industry.
The scale of the filings
The volume behind SB 690's introduction is stark. Section 638.51 filings rose from roughly 600 to nearly 4,000 since the bill was first introduced in February 2025, according to legal industry tracking cited in law firm analyses of the legislation. That trajectory, multiplied against a statutory floor of $5,000 per violation with no requirement to prove actual harm, produced enough demand letters and lawsuits that a coalition describing itself as representing small businesses, nonprofits, healthcare providers, local news outlets, farmers, and public agencies lobbied for the bill's passage through 2026.
Not every legal observer treats SB 690 as a complete resolution, even assuming Newsom signs it. Because Section 631 remains untouched, attorneys advising defendants have noted that plaintiffs can reframe tracking allegations as interception claims rather than pen register claims. A California appellate court added a further wrinkle days before the bill's passage: in Variety Media v. Superior Court, the Second Appellate District issued a tentative ruling rejecting the argument that CIPA's pen register definition categorically excludes modern website tracking technology, a signal that the underlying legal theory retains force even as the specific enforcement mechanism narrows.
An industry practitioner's view
The legislative development drew commentary from people who work directly in tracking implementation. Felipe Maté, a partner at Trackstars, a firm specializing in tracking implementation and website consent compliance, posted about the bill on LinkedIn after it passed both chambers. "California is about to remove one of the main ways a person can sue you over website tracking," Maté wrote, adding that the change "takes effect January 1, 2027, reaching back to suits filed in the prior two years."
Maté offered a mixed assessment of the underlying law the bill narrows. "It has changed how websites operate more than any other law," he wrote of CIPA's private right of action, noting it effectively forced companies to wire their "do not sell" links and consent banners to pixels and tags. He also acknowledged the commercial stakes for his own firm: "This has a direct effect on Trackstars. We do tracking implementation and privacy audits, and anything that lowers the number of companies who feel they have to act on privacy is bad for us." Maté's assessment of the likely market effect was that litigation "now shifts to other laws or other sections of CIPA, and overall volume drops."
Why this matters for advertisers and publishers
For marketers, agencies, and publishers operating websites reachable from California, the practical calculus is narrower than the headline suggests but still consequential. Companies currently facing demand letters or active lawsuits grounded solely in Section 638.51's pen register and trap-and-trace language would, if the bill is signed, gain a basis to seek dismissal of those specific claims once the law becomes operative, including claims filed as far back as two years before January 1, 2027. That reaches back to actions commenced on or after roughly January 1, 2025.
Companies should not read a signature, if it comes, as removing exposure from tracking pixels, analytics tools, or session replay software generally. Section 631's interception theory, the same provision underlying the Ace Hardware, LinkedIn, ChatGPT, and Perplexity complaints alongside their 638.51 claims, remains fully available to private plaintiffs. The retroactivity provision also does not touch claims that were resolved, settled, or already dismissed before the law's operative date, and it does not affect the California Attorney General's own enforcement authority, which the bill preserves and, in the pen register context, makes exclusive.
The bill's fate now depends entirely on one signature. Newsom's office has not issued a public statement indicating his intent as of this writing, and the unanimous nature of every recorded vote on the bill throughout its eighteen-month path through the Legislature is the strongest signal available that a veto is considered unlikely by the attorneys and advocates who tracked its progress.
Timeline
- February 21, 2025 - Senator Anna Caballero introduces SB 690 in the California Senate, with an early version proposing broad commercial-purpose exemptions across multiple CIPA sections.
- April 29, 2025 - The Senate Public Safety Committee passes the bill 6-0.
- May 23, 2025 - The Senate Appropriations Committee passes the bill as amended, 6-0.
- June 3, 2025 - The full Senate passes the bill 35-0, with five members not voting.
- July 1, 2025 - The Assembly Public Safety Committee passes the bill 9-0.
- August 2025 - A federal jury in San Francisco finds Meta violated CIPA by collecting health data from Flo app users without consent, a verdict PPC Land reported that plaintiffs' firms have since cited as precedent.
- March 3, 2026 - A San Francisco Superior Court enters a $50 million final judgment and permanent injunction against Meta over Facebook data shared with third-party developers, covered by PPC Land.
- March 31, 2026 - A class action against Perplexity AI alleges Meta Pixel and Google Analytics tracking inside its chat interface, reported by PPC Land.
- April 6, 2026 - LinkedIn is hit with a class action over an alleged hidden browser scan of more than 6,000 Chrome extensions, detailed by PPC Land.
- April 12, 2026 - Three plaintiffs sue Ace Hardware over tracking that allegedly persisted after cookie opt-out, reported by PPC Land.
- May 13, 2026 - A class action against OpenAI alleges ChatGPT.com forwarded user queries to Meta and Google, covered by PPC Land.
- July 1, 2026 - The Assembly Privacy and Consumer Protection Committee passes the narrowed bill 14-0.
- July 30, 2026 - Granola is sued over alleged unauthorized meeting recording used for AI model training, reported by PPC Land.
- August 5, 2026 - The bill is placed on the Assembly Appropriations suspense file.
- August 13, 2026 - The Assembly Appropriations Committee passes the bill 15-0.
- August 28, 2026 - The Assembly passes the bill 66-0; the Senate concurs in Assembly amendments 40-0.
- August 31, 2026 - The bill is enrolled and sent to Governor Gavin Newsom.
- September 30, 2026 - Deadline for Newsom to sign, veto, or allow the bill to become law without his signature.
- January 1, 2027 - If enacted, the operative date of the amendment, with retroactive effect reaching claims filed within the prior two years.
Related PPC Land coverage
- Jury finds Meta violated privacy law collecting health data - The August 2025 federal jury verdict against Meta under CIPA that plaintiffs' firms have since cited as a template for other cases.
- Ace Hardware sued for tracking users who opted out of cookies - A proposed class action combining Section 631 and Section 638.51 claims over persistent post-opt-out tracking.
- LinkedIn hit with class action over hidden browser scan of 6,000 extensions - A complaint alleging covert browser fingerprinting that invoked California's pen register statute among six causes of action.
- LinkedIn's BrowserGate: the full anatomy of a covert intelligence system - A deeper look at the statutory damages arithmetic under Penal Code Section 637.2.
- Lawsuit claims Perplexity shared AI chat data with Google and Meta secretly - An AI platform case built on the same tracking-as-interception legal theory, later dismissed without prejudice.
- OpenAI's ChatGPT secretly sent your queries to Meta and Google, lawsuit claims - A structurally similar complaint against ChatGPT.com alleging embedded advertising trackers.
- Granola sued for recording meetings without consent to train AI models - An AI notetaker case relying on CIPA's recording provisions, illustrating claims SB 690 does not touch.
- California court signs $50M Meta privacy injunction over Facebook data controls - The March 2026 judgment against Meta forming part of the broader privacy enforcement pattern in the state.
Summary
Who: The California State Legislature, led by Senator Anna Caballero with coauthors Senators Niello and Valladares and Assembly Members Irwin, Macedo, and Blanca Rubio, passed the bill. It now awaits action from Governor Gavin Newsom.
What: Senate Bill 690 amends Penal Code Section 637.2 to eliminate the private right of action for California Invasion of Privacy Act Section 638.51 pen register and trap-and-trace claims arising from website, app, or online conduct, leaving only the state Attorney General able to bring such claims against private actors.
When: The bill was enrolled on August 31, 2026, following unanimous floor votes in both chambers on August 28, 2026. Newsom has until September 30, 2026, to act. If signed, the law takes effect January 1, 2027, with retroactive application to claims filed within the prior two years.
Where: California, applying to any website, online application, or mobile application reachable by California residents, regardless of where the operating company is headquartered.
Why: Section 638.51 filings climbed from roughly 600 to nearly 4,000 since the bill's February 2025 introduction, driven by a statutory damages formula of $5,000 per violation that required no proof of actual harm. The bill responds to that litigation volume without touching CIPA's separate wiretapping and recording provisions, meaning tracking-related legal exposure narrows rather than disappears for companies operating in the state.
Discussion