California Governor Signs SB 690, Limiting Private Right of Action Under CIPA’s “Pen Register” and “Trap and Trace” Provisions
Client Alert | 4 min read | 10.08.26
At a glance: Governor Gavin Newsom signed SB 690, amending CIPA to restrict private plaintiffs from bringing “pen register” and “trap and trace” claims arising from web-based conduct. The amendment is meant to reduce the wave of private CIPA litigation targeting website tracking technology. However, businesses remain exposed to several major types of claims and enforcement mechanisms under CIPA and related statutes and should audit their tracking technologies, consent mechanisms, and litigation posture accordingly.
Background
On September 30, 2026, California Governor Gavin Newsom signed SB 690 into law, amending Section 637.2 of the California Invasion of Privacy Act (CIPA) and clarifying that only the attorney general may bring actions against private parties for violations of the “pen register” and “trap and trace” provisions “aris[ing] from conduct occurring on an internet website, online application, or mobile application.”
Under CIPA Section 638.51 and subject to certain exceptions, “a person may not install or use a pen register or trap and trace device without first obtaining a court order.” A pen register is defined as a “device or process” that records outgoing routing information transmitted by an instrument, such as a device that collects the numbers a telephone dials. A trap and trace is defined as a “device or process” that captures incoming information to identify the originating source, such as a device that collects the numbers a telephone receives. In neither case does the “device or process” collect the contents of a communication.
The meaning of “device or process” has sparked extensive litigation since the pen register and trap and trace provisions were added to CIPA in 2015. Increasingly, plaintiffs have applied the provisions to the context of web-tracking technology, with mixed results. In 2024, two rulings from the same state court arrived at opposite interpretations.
In Licea v. Hickory Farms, the Los Angeles Superior Court granted the defendant’s demurrer, concluding that tracking technology installed by the defendant’s website on the plaintiff’s internet-connected device to collect IP addresses did not constitute a pen register or trap and trace device under CIPA. A ruling to the contrary, the court held, would “potentially disrupt a large swath of internet commerce.” Less than a month later, in Levings v. Choice Hotels, a different judge denied the defendant’s demurrer, finding that the plaintiff’s allegations that the defendant deployed software on the plaintiff’s laptop which installed tracking code were sufficient at the pleading stage to state a pen register claim under CIPA.
Adding to the confusion, the California Court of Appeal, Second Appellate District, tentatively ruled in Variety Media, LLC v. Superior Court that “CIPA’s definition of ‘pen register’ . . . reach[es] a device or process that records or decodes metadata associated with either telephonic or online communications.” However, the court held that web trackers that collect only IP addresses are not pen registers under the statute “because they collect information identifying the sender of a communication . . . rather than the destination to which the communication is directed.”
What SB 690 changes and what it does not
Instead of defining the scope of “device or process,” SB 690 limits who can bring a web-based claim under Section 638.51, namely the California attorney general, not private plaintiffs.
SB 690 also has retroactive effect, applying to “any pending claim in an action commenced within two years before the operative date” of the law. The operative date of the law is January 1, 2027.
While SB 690 significantly limits private plaintiffs’ ability to bring claims under Section 638.51, other CIPA sections are unaffected and carry continued private litigation risk, including the Section 631 wiretapping provision and the Section 632 eavesdropping provision. What’s more, statutes such as the California Comprehensive Computer Data Access and Fraud Act, the California Consumer Privacy Act, other state wiretapping statutes, and common law claims such as breach of contract and invasion of privacy, leave private plaintiffs with plenty of actionable options.
How should businesses respond?
SB 690 brings a swath of CIPA litigation to a halt, but it does not eliminate CIPA litigation risk altogether, much less other causes of action. Here are a few considerations for businesses to keep in mind:
- Assess how SB 690 may improve your posture regarding settlement demands leveraging Section 638.51 claims. Relatedly, triage pending litigation based on whether it may be dismissed or stayed under the retroactive provision of SB 690, while recognizing that the retroactivity provision itself may be challenged.
- Maintain general CIPA compliance by reconciling your cookie banners and privacy notices with the reality of your web-tracking technology. Privacy notices need to be reviewed and updated periodically, at least annually, to align with your data collection and use practices. Determine what information and categories of data your trackers collect, how that collection takes place, and who receives that data, disclosing these details in your privacy notices. Assess whether the data you collect is tied to a meaningful business purpose; if not, query whether it is worth collecting or retaining at all. If so, consider an opt-in regime for web-tracking technology to reduce your risk exposure.
- Expect that Section 638.51 claims may be repackaged under different legal theories using greater factual specificity. Trackers that collect the content of communications, such as session replay software, AI chatbots, and pixels, may form the basis of a colorable CIPA Section 631 claim, which is still available to private plaintiffs.
SB 690 is an attempt to limit the number of private CIPA lawsuits, but it is not a complete stopgap measure. Crowell’s Privacy and Cybersecurity Group is prepared to help your business adjust to this new landscape, from technology auditing to privacy notice review and updating, consent management counseling, regulatory readiness, and litigation strategy. Please contact us if you want to discuss.
Contacts
Insights
Client Alert | 7 min read | 10.21.26
Securities Law for Entrepreneurs
Do you want your startup to expand and become a major player in your industry? If so, you will most likely need to seek capital from outside investors to help you build infrastructure and fulfill orders.
Client Alert | 4 min read | 10.08.26
Court of Federal Claims Provides a Roadmap for Adequate Rule-of-Two Set Aside Market Research
Client Alert | 5 min read | 10.08.26
Client Alert | 4 min read | 10.07.26
Don’t Try to Deny It: Federal Court Holds FCA Settlement is Covered by Insurance



