The Interactive Advertising Bureau's legal affairs and public policy unit on October 1, 2026 distributed a paper arguing that California's newly signed Senate Bill 690 leaves website operators exposed to litigation under the California Invasion of Privacy Act, a day after Governor Gavin Newsom signed the measure. Written by Steven Stein and Spencer MacDonald of FTI Consulting for IAB's fall Class Action & Litigation Insights series, the paper treats the bill's removal of private pen register claims as partial relief, not protection, and sets out six controls covering tracking scripts, consent banners, session replay, vendor contracts and consent records.

In Short

California has signed a law that will end private lawsuits under one part of an old wiretapping statute, the part lawyers had used against website trackers by treating them like telephone pen registers. A paper circulated by the advertising industry's trade body says the larger risk is still there, because other parts of the same law still let people sue when a website passes their clicks or typing to another company before they agree to it. If your site loads analytics, chat, session replay or ad tags for Californians, the moment that data leaves the browser relative to the cookie banner is what plaintiffs' lawyers look at. The paper also gets ahead of the calendar on one point: it describes the ban as already in force, while the enrolled bill only takes effect on January 1, 2027.

What the paper says SB 690 does

According to the paper, the law as signed removes the private right of action for alleged violations of Section 638.51 of the California Penal Code where the conduct took place on websites, online applications or mobile applications. Those claims are reserved to civil actions brought by the California Attorney General. The bill also looks backwards. Its prohibition applies to pending claims initiated within the two years preceding the operative date, the authors write.

That operative date matters more than the paper lets on. The authors state that the law "now prohibits" private actions. IAB's own email announcing the edition, sent on October 1, uses the future tense, saying the law "will restrict private lawsuits involving certain website- and app-related pen-register and trap-and-trace claims." The enrolled text, which PPC Land examined when it cleared the Legislature, adds a subdivision (d) to Penal Code Section 637.2 and takes effect on January 1, 2027, reaching pending claims in actions commenced within two years before that date. Until then, private pen register suits stay on the docket.

Some passages read as though they were drafted before the signature and updated afterwards. SB 690 appears in a list of "pending developments in the courts and legislature," and one sentence says that even with the bill "enacted into law, it would not restrict" claims under other provisions. The conditional mood sits awkwardly beside the confirmation, two paragraphs earlier, that Newsom signed the bill on September 30, 2026.

The bill's path through Sacramento was unopposed at every recorded stage. The Senate passed it 35-0 on June 3, 2025; the Assembly approved it 66-0 on August 28, 2026, and the Senate concurred 40-0 the same day before the bill was enrolled on August 31. The governor's signing message, reproduced in the paper, aligns him "with the goal of protecting small businesses from overzealous lawsuits." It then adds a qualification that frames the rest of the document:

"However, additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants."

The paper names those surviving provisions only as CIPA's "wiretapping and eaves dropping provisions." In statutory terms they are Section 631, covering interception of communications, Section 632, covering the recording of confidential communications, and Section 632.7, all of which keep their private rights of action.

No safe harbor, and numbers that need checking

The central claim is blunt. "SB 690 reforms do not equate to a substantive safe harbor from adtech related litigation in California," the authors write. Until courts or the Legislature formally reject applying CIPA to website technologies, according to the paper, the statute remains a risk area for any organization serving California residents, including those whose controls were built to satisfy the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

Scale comes in a single sentence. Tens of thousands of demand letters and more than 4,000 lawsuits have been filed under CIPA, according to the paper, many of them concerning website practices. No time period is given, and no source for the count.

That figure sits uneasily against the one PPC Land has used. The September 3 report put Section 638.51 filings at roughly 600 rising to nearly 4,000 since February 2025, based on legal industry tracking cited in law firm analyses. One count covers the pen register provision alone over about eighteen months; the other covers all of CIPA over an unstated period. If pen register filings by themselves approached 4,000, a CIPA-wide total of "more than 4,000" would be conservative. Neither document publishes the underlying dockets, so the two cannot be reconciled.

The damages description is the more consequential discrepancy. When CIPA is applied to website practices, the paper says, its provisions "can support penalties of up to $5,000 per violation." The statute works the other way round. Section 637.2(a) provides the greater of $5,000 per violation or three times actual damages, with no requirement to prove actual harm. Five thousand dollars is the floor of each violation, not the ceiling, and class actions multiply it by every visitor in the class.

A smaller historical point also needs correcting. The paper describes CIPA as a 1960s law developed to protect Californians against illegal wiretapping and "pen register tracing." The core of the statute was enacted in 1967. The pen register sections, 638.50 through 638.53, were added much later, by Assembly Bill 929, approved by the governor on August 13, 2015, according to the chaptered bill. The provision SB 690 takes out of private hands is therefore eleven years old. Sections 631 and 632, which stay open to private suits, belong to the 1967 statute.

What replaces the pen register theory? The paper's answer is consent timing. "One key area of focus in many of the demand letters is the claim that interception occurs before consent," the authors write.

The argument turns on two incompatible models. The CCPA and the CPRA operate on an opt-out basis, under which tracking or data collection is permitted unless the consumer declines. Plaintiffs' CIPA theories, according to the paper, suggest a stricter opt-in model, under which websites serving California residents may face claims if they transmit certain user data to a third party before explicit permission is offered. A site can be fully compliant with the state's modern privacy statute and still be sued under its older one.

The distinction between the two CIPA theories is technical. The pen register theory rested on metadata: plaintiffs argued that pixels and tags behave like call-logging devices by recording which pages a visitor loads, what they search and when. Section 631 is about content. Its subsection (a) reaches anyone who, without the consent of all parties, reads or attempts to learn the contents of a message while it is in transit. For private plaintiffs after January 1, 2027, the question of what a third-party script captured, and whether it captured it before the visitor clicked anything, carries more weight than the fact that it fired at all.

Evidence that scripts routinely fire against users' stated preferences is not hard to find. An independent webXray audit of more than 7,000 California-facing websites, conducted from a California address in March 2026, found 194 of the 242 ad tech vendors it evaluated setting advertising cookies after a Global Privacy Control opt-out, with Google failing 86 percent of the time. In July 2025, Healthline Media paid $1.55 million in the largest CCPA settlement to that date, in a case in which a privacy compliance vendor may not have identified and blocked all relevant trackers after users opted out.

Private litigation has followed the same pattern. A complaint filed on March 12, 2026 in the Northern District of California alleges that Google Analytics and a Bazaarvoice pixel kept firing on Ace Hardware's site after visitors rejected non-essential cookies, pleading counts under both Section 631 and Section 638.51. A class action against LinkedIn filed on April 6, 2026, over a browser script that allegedly scanned for more than 6,000 Chrome extensions, likewise paired the pen register statute with Section 631. Once SB 690 applies, the pen register counts in such cases lose their private footing; the interception counts do not. How many of the nearly 4,000 pen register filings carry a Section 631 count alongside? None of the published sources says.

Six controls, as the authors set them out

The paper presents its list as steps legal and privacy teams can take to limit CIPA risk and reduce the chance of receiving a demand letter. What follows describes those recommendations; it does not endorse them.

Website audit and risk analysis

The first step is an inventory. The authors call for identifying every script on a site, naming analytics, session replay, chat, advertising and pixels, and including async, deferred, hard-coded and tag-managed scripts. The audit maps first- and third-party tracking technologies, the specific data each third-party tool collects (keystrokes, clicks and personal data elements are the examples given), any downstream use and sharing, and the business purpose of each collection. The results feed a risk analysis that may lead to collecting less data, removing tools and masking sensitive fields, according to the paper.

The script categories are not a formality. Code injected by a tag manager, or loaded with async or defer attributes, does not necessarily appear in a page's source HTML at the moment it loads, so an inventory built from source code alone can miss precisely the scripts most likely to fire early.

The second step goes to the heart of the timing argument. Courts and plaintiffs, according to the paper, have focused on whether a third party received keystrokes, clicks, searches, chat or replay data in real time before the user interacted with the cookie banner. The authors' answer is to block third-party scripts from loading or transmitting data about California users until a banner selection is made, and they extend this explicitly beyond advertising to session replay, analytics and performance tools. Performance tooling is a category that takes in real user monitoring scripts, which measure page load timings in the visitor's browser and send them to a server.

Consent options, in this model, are grouped into four categories: analytics, session replay, chat and advertising. The paper also proposes a risk-benefit analysis weighing litigation risk against expected marketing-driven gains before deciding whether to implement notice and opt-in controls. It does not quantify either side of that ledger. A "California-specific" banner also implies that a site works out where a visitor is before showing anything, usually from the IP address.

This is where the paper intersects most directly with PPC Land's own reading of the bill. A weekly analysis published on September 5 argued that consent management platform deployment, tag governance and pre-consent script blocking in the United States grew primarily out of Section 638.51 exposure rather than the CCPA, which has never carried comparable damages. The FTI authors describe the same infrastructure but anchor it to the interception theory. On their account, the rationale for pre-consent blocking shifts sections. It does not lapse.

Session replay and keystrokes

The third control is the most specific. Session replay, the authors write, is to be disabled by default. Courts have treated unmasked keystrokes as potentially revealing the "contents of a communication," according to the paper, so where replay is used its scope is strictly limited and keystrokes, free-text fields, search inputs and forms are masked.

European regulators have reached similar technical conclusions through a different body of law. France's CNIL opened a consultation on February 25, 2026 on a draft recommendation that requires prior consent for session replay, treats it as a distinct purpose in consent interfaces and applies masking by default to images, forms, free-text inputs and dynamically populated fields. Microsoft Clarity began requiring a call to its Consent API before enabling recordings in December 2024 and enforced consent signals for sessions from the EEA, the UK and Switzerland from October 31, 2025. California arrives at masking through wiretap law; the CNIL's draft reaches it through the GDPR.

Fourth comes the banner itself. The paper calls for avoiding dark patterns and providing symmetry of choice between options, with notices presented before any alleged interception. Confusing layouts, double negatives and excessive steps that steer users towards less private choices are named as the design failures to avoid.

Vendor contracts

The fifth control moves from code to paper. Vendors, according to the authors, are to act only as service providers and processors, and agreements are to prohibit independent use of data, cross-customer analytics, model training and audience building, "otherwise courts may treat vendors as third-party interceptors."

That list maps onto recent enforcement and litigation. CCPA amendments in force since January 1, 2026 expanded contractual obligations for transfers of personal information. The Healthline settlement required the publisher to verify that advertising partners maintain CCPA-compliant contracts. Model training, one of the four prohibited uses, sits at the centre of the suit filed against Granola on July 30, 2026 over meeting recordings allegedly used to train models, pleaded under Sections 631 and 632. And the verdict plaintiffs' firms have repeatedly cited, the August 4, 2025 finding against Meta, concerned data collected through a software development kit embedded in another company's app.

The sixth control is evidentiary. The authors describe logging, for every user, the timestamp, geolocation, categories enabled and banner version displayed. Where an organization cannot prove that consent preceded interception, according to the paper, it is more likely to struggle against CIPA claims. The paper does not address how long such logs are retained, or the fact that a geolocation entry for every visitor is itself a data point about that visitor.

Governance around the six

A final section wraps the controls in process: periodic website audits and risk assessments, off-cycle audits after material changes to a site, privacy impact assessments before any new tracking tool or site update goes live, and training for marketers, engineers and other stakeholders. Organizations are also expected to keep complete and current inventories of the tracking technologies on their websites, according to the paper, until federal, state or court authorities provide more clarity.

Beyond California

The paper's last substantive claim reaches outside the state. Claims of this nature are already being brought in other states, "even where no pen-register requirements exist," the authors write. They do not name the states.

PPC Land has documented one of them in detail, and IAB is a party to it. On April 10, 2026, IAB filed an amicus brief in Baker v. Seattle Children's Hospital at the Washington Supreme Court, case number 1045905. The plaintiffs allege that the Meta Pixel on the hospital's public website intercepted their searches in breach of the Washington Privacy Act, a 1967 statute requiring the consent of all participants. The trial court dismissed the complaint in February 2024, the Court of Appeals affirmed on August 18, 2025, and the Supreme Court accepted review on January 8, 2026. IAB's brief argued that treating routine browser-to-server requests as private communications would threaten ad measurement, and that securing consent for every packet transmission would be unworkable.

So the trade body is arguing in court that decades-old wiretap statutes do not reach ordinary web traffic, while its legal affairs unit circulates a paper describing how to operate on the assumption that they might. The positions are not contradictory. One concerns how courts ought to read the statutes; the other concerns the exposure that exists until they do.

Who wrote it, and who sponsors it

Every page of the paper carries a footer stating that the Class Action & Litigation Insights series is sponsored by FTI Consulting, and IAB's email describes the edition as "courtesy of our partner at FTI Consulting." The paper lists Stein as a senior managing director and MacDonald as a senior director at FTI Consulting; the email refers to "Steve Stein" and places both authors at FTI Technology, the firm's technology business.

FTI Technology markets AdTech and digital marketing risk management services intended to reduce privacy, compliance and litigation risk from online tracking technologies, including consent management and tag management remediation, according to its website. The six controls in the paper describe work of the kind that service line sells. That does not make the analysis wrong, but it places the authors in a position comparable to Felipe Maté, a partner at the tracking implementation firm Trackstars, who acknowledged when the bill passed that fewer companies feeling pressure to act on privacy would hurt his firm, and who expected litigation to shift to other laws or other CIPA sections while overall volume fell. The FTI authors predict the first half of that and are silent on the second. The plaintiffs' bar, they write, is likely to keep turning to obscure and legacy laws to pursue civil litigation.

Why the marketing community has a stake

For marketers, the paper's practical effect is to move the conversation from which tags fire to what those tags capture, and when. Analytics, chat, session replay and performance tools are named alongside advertising pixels, and marketers are listed among the staff the authors expect to be trained on consent controls. IAB's announcement addresses the paper to legal, privacy, compliance, marketing and technology teams, and states that compliance with modern state privacy laws alone "may leave gaps."

The paper also complicates a reasonable expectation that some of the consent machinery built around Section 638.51 might be scaled back after January 1, 2027. If, as PPC Land argued in September, the pen register exposure drove that build-out, the FTI authors are making the case that a different provision now justifies keeping it. Attorneys advising defendants had already noted that plaintiffs can reframe tracking allegations as interception claims rather than pen register claims, and a tentative ruling from the Second Appellate District in Variety Media v. Superior Court rejected the argument that CIPA's pen register definition categorically excludes website tracking.

The next venue is the Legislature. Newsom's message asks lawmakers to address CIPA's other provisions, and California statutes passed in a regular session ordinarily take effect on January 1 of the following year, so any change to Sections 631 or 632 enacted in 2027 would most likely apply from January 1, 2028. Will the same chambers move as uniformly on the wiretapping provisions? The bill's own history offers a warning. Its 2025 version, which reached Sections 631, 632 and 632.7 directly through a broad commercial-purpose exemption, stalled in the Assembly for a year and passed only once those provisions were removed.

Timeline

Summary

Who: The Interactive Advertising Bureau's Public Policy and Legal Affairs unit published the paper, written by Steven Stein, senior managing director, and Spencer MacDonald, senior director, of FTI Consulting, which sponsors the series. The law it analyses was signed by California Governor Gavin Newsom. Website and app operators, publishers, advertisers and the vendors whose scripts run on their pages are the organizations exposed.

What: "The Overlooked Law Quietly Undermining Privacy Compliance," the fall 2026 edition of IAB's Class Action & Litigation Insights, argues that SB 690's removal of private Section 638.51 claims is not a safe harbor, because CIPA's wiretapping and eavesdropping provisions still support suits alleging that data reached third parties before consent. It sets out six controls: a script audit, California-specific consent blocking, session replay masking, neutral consent design, restrictive vendor contracts and consent logging. The paper describes the ban as already in effect, understates the statutory damages as a ceiling of $5,000 and gives no period or source for its count of more than 4,000 lawsuits.

When: IAB distributed the paper on October 1, 2026, a day after Newsom signed SB 690 on September 30, 2026. The bill becomes operative on January 1, 2027, and reaches pending claims in actions filed within the prior two years.

Where: California, covering websites and apps that serve California residents wherever their operators are based, with the paper noting similar claims in other states, including a Washington case in which IAB has filed a brief.

Why: Tens of thousands of demand letters and more than 4,000 CIPA lawsuits, according to the paper, have targeted website practices, and the surviving provisions carry damages of at least $5,000 per violation without proof of harm. The governor's own message asks the Legislature to revisit the remaining provisions, leaving the interception theory available to private plaintiffs unless and until lawmakers act.