Governor Gavin Newsom signed Senate Bill 690 on September 30, 2026, the last day of his constitutional window, removing the ability of private plaintiffs to sue website and app operators under the pen register and trap-and-trace provision of the California Invasion of Privacy Act. In the same two-paragraph signing message, he asked the Legislature to take on the statute's other provisions next year.

In Short

California's governor signed a law that stops people and their lawyers from suing websites and apps under a rule written for telephone surveillance, which law firms had applied to pixels, cookies and analytics code. Thousands of lawsuits and demand letters relied on that rule, so the change reaches almost any business running tracking code on a site Californians can visit. From January 1, 2027, only the state Attorney General can bring those claims, pending private claims filed since early 2025 lose their footing, and the law's separate wiretapping claims stay available to anyone.

What the signing message says

The letter carries the governor's seal, a date stamp of September 30, 2026, and is addressed to the members of the California State Senate, the chamber where the bill began. Its opening sentence describes a measure that "eliminates the private right of action under the California Invasion of Privacy Act (CIPA) for violations of the pen register and trap-and-trace statute arising from conduct occurring on an internet website, online application, or mobile application."

The reasoning follows in a single paragraph. According to the message, the bill "addresses the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites that at times have tracked and shared the information of visitors to the site." Newsom wrote that he applauded the efforts of the author, Senator Anna Caballero, and aligned himself "with the goal of protecting small businesses from overzealous lawsuits based on a statute written without today's complex technological landscape in mind."

Then comes the qualification. "However, additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants," the governor wrote. "I urge the Legislature to take this on next year to ensure a fair balance between protecting private information and preventing rapacious litigation."

Two details of that wording are easy to miss. The message does not deny that tracking took place: it states that the software at times tracked and shared visitor information, and it places the businesses' position in a single adverb, "unwittingly." And while the reasoning is framed around small businesses, the amendment contains no size threshold. The enrolled text covers actions against any private actor, a category that takes in professional networks and national retailers as readily as a local bakery.

Which statutes does the governor have in mind? The message names none. The provisions that keep their private rights of action are Section 631, covering interception of communications, Section 632, covering recording of confidential communications, and Section 632.7. The Stop CIPA Shakedown Lawsuits coalition, which lobbied for SB 690, said after the signing that it would keep working with policymakers on further reforms addressing Section 631, according to its statement.

The age of the provision

"Decades-old" fits CIPA's core, enacted in 1967. It fits less well the provision SB 690 narrows. Sections 638.50 through 638.53 were added to the Penal Code by Assembly Bill 929, approved by then-Governor Jerry Brown on August 13, 2015 and filed as Chapter 204 of the Statutes of 2015, according to the chaptered bill; they took effect on January 1, 2016. The California Court of Appeal's tentative ruling in Variety Media, issued in August 2026, also records that the Legislature added the pen register provisions in 2015.

According to a Bloomberg Law professional perspective, those provisions were drafted in consultation with the Los Angeles District Attorney's Office, the Los Angeles County Sheriff's Department and the ACLU, to address law enforcement use of pen registers and trap and trace devices on telephone lines without a court order. The statute at the center of the dispute is therefore about eleven years old. It was written for police surveillance of phone lines, well into the smartphone era, and its application to commercial website code came later, through litigation rather than legislative design. The sections that remain open to private suit date from 1967.

How the amendment works

SB 690 adds a subdivision (d) to Penal Code Section 637.2, the provision that gives individuals a civil claim under CIPA. Under it, an action against a private actor for violating Section 638.51, where the alleged conduct took place on a website, online application or mobile application, may be brought only by the Attorney General. The damages formula in Section 637.2(a), the greater of $5,000 per violation or three times actual damages, is unchanged for every claim that remains available, and it requires no proof of actual harm.

The amendment leaves Section 638.51 itself, and the definitions in Section 638.50, as they were. Under those definitions a pen register is a device or process that records or decodes the routing, addressing and signaling information attached to a wire or electronic communication, without capturing its contents. Plaintiffs' firms argued that pixels, site tags and tracking SDKs fit that description because they transmit page addresses, search terms, IP addresses and device identifiers to third parties. The attraction of the theory, according to Bloomberg Law, lay in what it did not require: Section 631 claims turn on interception of the contents of a communication, while Section 638.51 reaches metadata alone.

Two law firms describe the limits of the fix in complementary terms. According to Duane Morris, the bill removes the private claim regardless of how courts resolve the underlying dispute over whether tracking tools are pen registers. According to Sidley Austin, it does not clarify the provision's reach over tracking technologies at all, leaving that question to the courts. The criminal side is also untouched: a violation of Section 638.51 remains punishable by a fine of up to $2,500 or imprisonment of up to one year, according to Bloomberg Law.

The two-year look-back

The amendment becomes operative on January 1, 2027. A companion clause applies it to any pending claim in an action commenced within the two years before that date, a window reaching back to actions filed on or after roughly January 1, 2025. According to Akin, Section 638.51 claims filed after that date could be extinguished rather than merely prevented. Matters already resolved, settled or dismissed are not reopened, and the bill carries a severability clause.

Two complaints from 2026 show how the window operates. The proposed class action against LinkedIn, filed on April 6, 2026, pleaded six causes of action, among them the pen register statute and Section 631, over a browser script alleged to scan for more than 6,000 Chrome extensions. Six days later, three plaintiffs sued Ace Hardware, alleging that Google Analytics and a Bazaarvoice pixel kept firing after visitors rejected non-essential cookies, again with counts under both Section 631 and Section 638.51. Both actions sit inside the look-back window. If they remain pending on January 1, 2027, their pen register counts lose their private basis. Their wiretapping counts do not.

Eighteen months and no recorded opposition

The version Newsom signed is far narrower than the bill Caballero filed on February 21, 2025. That draft would have exempted conduct carried out for a commercial business purpose, a term borrowed from the California Consumer Privacy Act, from Sections 631, 632 and 632.7, and would have narrowed the definitions of pen register and trap and trace device, according to Jones Walker and Duane Morris.

The Senate passed that version 35-0 on June 3, 2025. It then stalled in the Assembly and became a two-year bill. On July 1, 2026, the Assembly Privacy and Consumer Protection Committee amended it into its present form, removing the exemption entirely, according to Jones Walker, and approved it 14-0. The bill was placed on the Assembly Appropriations suspense file on August 5, emerged on August 13 with a 15-0 vote, and passed the Assembly 66-0 on August 28, the same day the Senate concurred 40-0. It was enrolled on August 31 and presented to the governor on September 4. His deadline, under article IV, section 10(b)(2) of the California Constitution, was September 30, according to Jones Walker. Every recorded floor and committee vote across both chambers showed no opposition.

In its statement after the signing, the coalition thanked Caballero and Assemblymember Bauer-Kahan for moving the bill through the Legislature.

The filing curve

The volume behind the bill is the reason it moved. Section 638.51 filings climbed from about 600 to nearly 4,000 after the bill's introduction in February 2025, based on legal industry tracking cited in law firm analyses. The sources do not agree on what that number counts. Sidley Austin attributes the same 600-to-4,000 figure to the bill's sponsors and describes it as a count of CIPA website-tracking lawsuits in general, not pen register claims alone. The coalition's post-signing statement puts the total above 4,000. None of the sources publishes the underlying docket data, so the share attributable to Section 638.51 cannot be confirmed.

Lawsuits were only part of the activity. Businesses and nonprofits collectively received thousands of demand letters built on the pen register theory, many of them thought to be AI-generated, according to Sidley Austin. A post on the CyberAdviser legal blog described many of those letters as coming from self-represented claimants. News publishers were among the recipients: according to the News/Media Alliance, its members faced lawsuits and arbitration demands for using standard online tools and tracking technology. The coalition backing the bill described itself as representing small businesses, nonprofits, healthcare providers, local news outlets, farmers and public agencies.

Variety Media and the definitional question

On August 21, 2026, the California Court of Appeal's Second Appellate District, Division Three, issued a tentative ruling in Variety Media, LLC v. Superior Court, case B350578. According to commentary in the National Law Review, the panel tentatively rejected Variety's argument that the pen register provisions reach only telephone surveillance, concluding that the definition, modeled on federal law, can extend to processes that record metadata from online communications. The same tentative ruling found the complaint deficient, because the plaintiff relied on IP addresses, which identify the source of a communication rather than its destination. The panel would direct the trial court to sustain Variety's demurrer with leave to amend, according to Seyfarth Shaw.

Commentary published in late August described the decision as tentative, and the material reviewed for this article did not establish whether a final opinion has issued. For private claims, the outcome stops mattering once SB 690 applies. For everyone else it does not. Whether a pixel counts as a pen register now bears on any action the Attorney General chooses to bring and on criminal exposure under Section 638.51.

What stays open

Sections 631, 632 and 632.7 keep their private rights of action and the $5,000 formula, as PPC Land noted in its analysis of the bill. What leaves private hands is narrower: Section 638.51, the provision plaintiffs' firms had applied to browser fingerprinting, tracking pixels and analytics scripts.

The surviving provisions underpin the most significant CIPA results to date. In August 2025, a federal jury in San Francisco found that Meta violated CIPA by collecting reproductive health data from users of the Flo app through a software development kit embedded in it. The AI cases filed across 2026 lean on the same sections. A class action against OpenAI in May 2026 alleged that ChatGPT.com forwarded user queries to Meta and Google through embedded trackers, pleading Sections 631 and 632. Granola was sued in July 2026 over alleged meeting recordings used for model training, again under Sections 631 and 632. A comparable complaint against Perplexity, filed in March 2026, was later voluntarily dismissed without prejudice.

According to Duane Morris, plaintiffs may seek to reframe existing or future Section 638.51 allegations as Section 631 claims. Felipe Maté, a partner at tracking implementation firm Trackstars, expected overall volume to drop and litigation to shift to other laws or other CIPA sections when the bill passed. Exposure from tracking pixels, analytics tools and session replay software under the interception theory is, on the text, unchanged.

Enforcement passes to a single office

Under SB 690, pen register claims over websites and apps become the exclusive province of Attorney General Rob Bonta's office. The bill names the Attorney General, not the California Privacy Protection Agency, which now operates as CalPrivacy and fined PlayOn Sports $1.1 million in February 2026 under the CCPA.

The Attorney General's recent privacy actions give a sense of scale. They include a $1.55 million settlement with Healthline Media in July 2025, a $1.4 million settlement with Jam City in November 2025 and a $2.75 million settlement with Disney in February 2026, all under the CCPA, alongside a $50 million judgment against Meta entered on March 3, 2026 under the Business and Professions Code. Set against a private filing count close to 4,000, the amendment moves enforcement of Section 638.51 online from thousands of potential claimants to one public office with a docket measured in individual cases.

The design is not unique to SB 690. Earlier in September, Newsom signed AB 1709, which bars covered platforms from offering addictive features to users under 16 and exposes operators to penalties of up to $50,000 per affected minor. That law carries no private right of action, leaving enforcement to the Attorney General or local prosecutors.

January 1, 2027

Several California privacy changes converge on the same date. SB 923, the Expanding Privacy Rights Act by Senator Josh Becker, extends the CCPA deletion right to personal information a business obtained from third parties and requires online-only businesses to offer a web form for privacy requests. Newsom signed it on September 27, according to Osano, and it takes effect on January 1, 2027. The same day he vetoed AB 1542, which would have prohibited selling or sharing sensitive personal information outright, according to Privisy; one outlet, Tech Times, dated the veto September 28. Akin had grouped both measures with SB 690 as companion bills in California's recalibration of privacy enforcement.

The Opt Me Out Act, AB 566, signed on October 8, 2025, is also operative from January 1, 2027, and bars businesses from developing or maintaining browsers that lack a setting to send an opt-out preference signal. The dominant implementation of that signal is Global Privacy Control, a browser header telling sites not to sell or share personal information. On one date, then, private exposure under a single CIPA provision narrows while browser-level opt-outs and deletion rights widen.

Why the marketing community has a stake

The pen register theory shaped website infrastructure far beyond the courtroom. PPC Land argued in early September that consent management platform deployment, tag governance programs and pre-consent script blocking in the United States grew primarily out of Section 638.51 exposure rather than out of the CCPA, which has never carried comparable damages. Maté made a related point when the bill passed, writing that CIPA's private right of action had changed how websites operate more than any other law, and acknowledging that fewer companies feeling pressure to act on privacy would hurt his own firm's business.

On January 1 the damages claim most associated with that build-out leaves private hands. The conduct those tools were meant to prevent does not leave the law. A webXray audit of 7,634 websites in March 2026 found Google, Meta and Microsoft setting advertising cookies after users opted out, the same pattern the Ace Hardware complaint pleads under Section 631. Publishers sit on both sides of the ledger: as defendants, according to the News/Media Alliance, and as the operators of sites where advertising and analytics tags load.

The governor's message turns the 2027 legislative session into the next venue. California statutes passed in a regular session generally take effect on January 1 of the following year, so any change to Sections 631 or 632 enacted in 2027 would ordinarily apply from January 1, 2028. Will a Legislature that voted 66-0 and 40-0 for SB 690 move as uniformly on the wiretapping provisions? The bill's own history offers one data point. The 2025 version reached Sections 631, 632 and 632.7 directly, stalled in the Assembly for a year, and passed only after those provisions were removed.

Timeline

Summary

Who: California Governor Gavin Newsom signed SB 690, authored by Senator Anna Caballero. Attorney General Rob Bonta's office becomes the only party able to bring the affected claims. Website and app operators, publishers, advertisers and the plaintiffs' firms behind close to 4,000 filings are directly affected.

What: The law adds subdivision (d) to Penal Code Section 637.2, removing the private right of action for CIPA Section 638.51 pen register and trap-and-trace claims arising from conduct on websites, online applications and mobile applications. Sections 631, 632 and 632.7 keep their private claims and the $5,000-per-violation formula. In his signing message, Newsom asked the Legislature to address CIPA's other provisions next year.

When: Newsom signed the bill on September 30, 2026, the final day of his deadline. It becomes operative on January 1, 2027, and applies to pending claims in actions commenced within the two years before that date.

Where: California, covering websites and apps reachable by Californians wherever their operators are based, with litigation spread across state and federal courts.

Why: Filings grew from about 600 to nearly 4,000 after February 2025, alongside thousands of demand letters, according to figures whose exact scope differs between sources. The governor's message describes the litigation as vexatious and aimed at small businesses, while acknowledging that the software involved at times tracked and shared visitor data.