California Just Cracked Down on CIPA Lawsuits — But the Fight Is Far From Over

Table of Contents

SB 690 passed the California Legislature on August 28, 2026, after an extraordinary wave of CIPA lawsuits and demand letters targeting pixels, cookies, analytics tools and ordinary website technology. If Governor Newsom signs it, thousands of pending pen-register claims could be affected. But California has not repealed CIPA, Section 631 remains untouched, and the next generation of website privacy litigation is already taking shape and business owners and law firms are leaning on Captain Compliance’s technology to help protect against these vexatious claims. 

For businesses that have spent the past several years watching routine website technologies transformed into alleged wiretaps, spyware and illegal pen registers, August 28, 2026 may ultimately prove to be one of the most consequential dates in the history of modern U.S. privacy litigation.

California’s CIPA Reckoning: SB 690 Targets Pen-Register Lawsuits, but the Next Privacy Litigation Wave Is Already Forming

On Friday, the California Legislature passed Senate Bill 690, Senator Anna Caballero’s effort to curb what lawmakers increasingly came to view as an abusive wave of litigation under the California Invasion of Privacy Act, or CIPA.

The final Assembly vote was 66-0. The Senate then unanimously concurred in the Assembly amendments, and the bill was ordered to engrossing and enrollment. As of August 29, SB 690 has passed the Legislature but has not yet been signed by Governor Gavin Newsom. California Legislature voting record.

That distinction matters. California has not yet changed the law.

But if Newsom signs SB 690, private plaintiffs will effectively lose one of the most prolific weapons in the current website-privacy litigation arsenal: CIPA’s Section 638.51 pen-register and trap-and-trace theory for conduct occurring on websites, online applications and mobile applications.

Even more significantly, the Legislature made that restriction retroactive to certain pending claims.

This is not, however, the end of CIPA litigation.

It may be the beginning of its next phase.

How a Telephone-Surveillance Law Became a Website-Litigation Machine

To understand SB 690, it is necessary to separate two different pieces of CIPA that are frequently lumped together.

California enacted the original CIPA framework in 1967, decades before Google Analytics, Meta Pixel, JavaScript, cookies, smartphones or even the commercial internet. Its core provisions prohibited unauthorized interception, wiretapping and recording of communications.

Section 631 eventually became the provision most commonly associated with website wiretapping claims. The Ninth Circuit has expressly recognized that Section 631 can apply to internet communications. In its influential 2022 decision in Javier v. Assurance IQ, the court also held that consent obtained after an alleged interception is not enough: the plaintiff plausibly stated a claim where a third-party technology allegedly began recording his interactions before he assented to the site’s privacy policy. Read the Ninth Circuit decision.

That decision helped put technical sequencing at the center of website privacy litigation.

A disclosure sitting in a privacy policy could no longer necessarily rescue a company if the challenged technology had already fired.

But the enormously controversial “pen register” theory came later.

California added Sections 638.50 through 638.53 in 2015 through AB 929, effective January 1, 2016. The legislation defined a pen register as a “device or process” recording or decoding dialing, routing, addressing or signaling information, while excluding the contents of a communication. The legislation was principally concerned with giving California law enforcement a state-law framework for pen registers and trap-and-trace devices. Read AB 929.

That phrase — “device or process” — would eventually become extraordinarily important.

In the telephone world, a pen register traditionally recorded information such as the number dialed rather than what callers said.

In the internet world, plaintiffs began asking a provocative question:

What if JavaScript, an SDK, an advertising pixel or another tracking technology is the modern equivalent of that “process”?

Greenley v. Kochava Opened the Door – California Is Closing the Door on CIPA Pen-Register Claims BUT Another Door Is Already Opening

The critical turning point came in 2023.

In Greenley v. Kochava, a federal court considered allegations involving an SDK that allegedly collected and correlated information about mobile-app users. The court rejected the argument that software categorically could not constitute a pen register.

The court focused on CIPA’s use of the word “process,” reasoning at the pleading stage that software capable of identifying consumers, gathering information and correlating data through fingerprinting could potentially fit the statutory definition.

It was an important ruling — but also a factually unusual one. Kochava was a data broker, and the allegations involved allegedly surreptitious collection through SDKs embedded in third-party applications. The decision did not establish that every cookie, analytics script or advertising pixel on every ordinary commercial website violated CIPA.

That distinction did not stop the theory from spreading.

By 2024, plaintiffs were increasingly asserting that ordinary website trackers themselves qualified as pen registers.

In Shah v. Fandom, a Northern District of California court allowed such a theory to survive based in part on the alleged collection of users’ IP addresses. The court emphasized that CIPA’s text was not limited to traditional telephone hardware and treated IP-address information as potentially within the concept of addressing information.

Once those decisions existed, the economics became irresistible.

Why Section 638.51 Became Such a Powerful Demand-Letter Tool

The underlying prohibition appears in Penal Code Section 638.51. Subject to statutory exceptions, it prohibits installation or use of a pen register or trap-and-trace device without a court order. Consent is among the statutory exceptions available to certain providers. Read California Penal Code Section 638.51.

But the real economic engine was Section 637.2.

That provision permits an injured person to pursue the greater of:

  • $5,000 per violation; or
  • Three times actual damages.

It also expressly says actual damages are not a prerequisite to bringing an action. See the SB 690 legislative text.

That combination changed the litigation calculus.

A plaintiff did not necessarily need to allege that a hacker stole money, that private photographs were released, that identity theft occurred or even that the plaintiff suffered measurable economic damage.

A lawyer could examine network traffic, identify an IP address or cookie identifier transmitted to a third-party tracker, characterize that technology as a pen register, and threaten statutory damages.

And because website traffic occurs at enormous scale, the phrase “per violation” created potentially catastrophic theoretical numbers.

Defendants disputed how violations should actually be counted, whether the technology was a pen register at all, whether plaintiffs had standing, whether consent existed and whether CIPA was being stretched far beyond its intended scope.

But many businesses faced a simpler commercial question:

Spend substantially more money litigating a novel statutory issue, or settle the demand.

That economic asymmetry is exactly what eventually attracted Sacramento’s attention.

From Roughly 600 Claims to More Than 4,000

When Senator Caballero introduced SB 690 in February 2025, the problem was already significant.

By the time she returned to the Assembly Privacy and Consumer Protection Committee in July 2026, she said the universe of Section 638.51 matters had increased from roughly 600 to more than 4,000. Reports of her testimony said many were attributable to just four law firms using repeat plaintiffs, and that those numbers did not include the unknown volume of pre-suit demands resolved privately.

The Assembly committee’s analysis became remarkably candid.

The pen-register litigation wave was described as a “poster child for abusive lawsuits.”

The committee observed that the prospect of staggering statutory liability could cause businesses to settle rapidly, which in turn encouraged vexatious litigants to continue sending large volumes of demand letters. Read the legislative analysis coverage.

That language matters.

This was no longer merely defendants complaining that they disliked being sued.

California lawmakers themselves were acknowledging that the enforcement mechanism was generating litigation incentives that had become disconnected, at least in some cases, from meaningful consumer harm.

SB 690 Originally Would Have Gone Much Further

The legislation that passed this week looks dramatically different from the bill introduced in 2025.

The original approach was broad.

SB 690 proposed creating a “commercial business purpose” exception affecting several major CIPA provisions, including Sections 631, 632 and 632.7, as well as the pen-register definitions.

The basic idea was that routine processing of personal information for recognized commercial purposes — particularly processing already regulated through California’s modern consumer-privacy regime — should not simultaneously expose companies to potentially massive damages under a criminal wiretap statute written for another technological era.

Had that version survived, SB 690 could have fundamentally reshaped website privacy litigation.

  • Section 631 pixel cases could have been affected.
  • Session-replay litigation could have been affected.
  • Chatbot and form-interception cases could have been affected.
  • The commercial-purpose exception might have dramatically reduced the ability to convert routine analytics and advertising activity into CIPA claims.

But privacy advocates opposed the breadth of that approach.

Organizations including ACLU California Action, EPIC, consumer organizations and other advocacy groups warned that a broad commercial-purpose exception could immunize genuinely invasive surveillance simply because a company could articulate a business reason for the processing. They argued that CIPA continues to serve an important function where companies secretly capture genuinely sensitive communications, including reproductive-health, location or other highly private information. Read the opposition letter.

Those concerns changed the bill.

The 2026 Compromise: Attack the Litigation Mechanism, Not CIPA Itself

By June and July 2026, SB 690 had been transformed.

The broad commercial-purpose exemption disappeared.

Changes to Sections 631, 632 and 632.7 disappeared.

The Legislature instead chose what the Assembly analysis characterized as a more targeted or “surgical” solution.

The final bill amends essentially one provision: Penal Code Section 637.2, CIPA’s civil-remedies statute. Read the final bill text.

The operative language is extremely important.

For a violation of Section 638.51 allegedly arising from conduct occurring on an internet website, online application or mobile application, an action against a private actor under Section 637.2 may be brought only by the California Attorney General.

That is the heart of SB 690.

Notice what California did not do.

  • It did not declare that pixels can never satisfy the statutory definition of a pen register.
  • It did not amend Section 638.50’s technical definitions.
  • It did not declare that website tracking is categorically lawful.
  • It did not legalize collection of IP addresses.
  • It did not repeal Section 638.51.

Instead, California changed who can sue.

That distinction is fundamental.

If SB 690 becomes law, a private claimant would no longer be able to turn an alleged website or app-based Section 638.51 violation into a $5,000-per-violation private damages action under Section 637.2.

The Attorney General would retain enforcement authority.

The profit incentive driving the private pen-register demand-letter industry would therefore be substantially eliminated.

Retroactivity May Be the Most Consequential Part of the Entire Bill

SB 690 does not merely apply going forward.

The final text expressly says the amendment applies retroactively to:

“any pending claim in an action commenced within two years before the operative date”

of SB 690. See the statutory language.

Assuming the bill becomes effective January 1, 2027, the practical window would generally reach pending qualifying actions commenced on or after approximately January 1, 2025.

That is precisely the period during which the explosion in Section 638.51 litigation occurred.

The Legislature also added a severability clause, meaning that if one portion of the legislation is eventually held invalid, the remaining provisions are intended to survive where possible.

The retroactivity provision could immediately transform settlement negotiations in pending cases.

A business presently facing a pure Section 638.51 claim has a very different negotiating position today than it had six months ago.

A plaintiff demanding settlement now has to confront the possibility that, if the case remains pending when the legislation becomes operative, the statutory basis for private enforcement could disappear.

There will still be significant procedural questions.

The exact effect on individual pending cases may depend on filing dates and procedural posture. Settled claims, final judgments, arbitration proceedings and claims containing multiple causes of action may present different issues. Courts may also be asked to interpret exactly what constitutes a “pending claim in an action.”

So businesses should not simply assume that every existing demand letter evaporates January 1.

But the leverage has unquestionably shifted.

Where SB 690 Stands Today

As of August 29, the official Legislature record lists SB 690 as an “Active Bill – Passed.” It was approved by the Assembly on August 28 and the Senate unanimously concurred in the Assembly amendments that same day. It has been ordered into the enrollment process and is awaiting gubernatorial action. View the official bill history.

There is some nuance surrounding the governor’s deadline.

California’s Constitution generally gives the governor 12 days to act on a bill presented during this portion of the session. For bills passed before September 1 that remain in the governor’s possession on or after September 1, however, Article IV establishes September 30 as the final deadline. California’s official legislative calendar therefore identifies September 30 as the ultimate end-of-session signing deadline. California Constitution, Article IV, Section 10.

Because SB 690 is a non-urgency measure, if enacted during this session it should take effect January 1, 2027.

Date Development
February 21, 2025 Senator Caballero introduces SB 690
June 3, 2025 Senate passes original broader bill 35-0
2025 Bill stalls in Assembly and becomes a two-year bill
June/July 2026 Bill narrowed substantially; broad commercial-purpose exemption removed
July 1, 2026 Assembly Privacy and Consumer Protection Committee advances amended approach 14-0
August 13, 2026 Assembly Appropriations advances bill 15-0
August 28, 2026 Assembly passes SB 690 66-0
August 28, 2026 Senate unanimously concurs
Current Awaiting Governor Newsom
January 1, 2027 Expected effective date if enacted

SB 690 Does Not End CIPA Website Lawsuits

This is the single biggest point businesses need to understand.

Section 631 remains untouched.

And Section 631 is not some obscure fallback provision.

It is CIPA’s principal wiretapping statute and has been the basis for years of litigation involving session replay, chat software, pixels, form inputs and third-party tracking technologies.

Under the theory plaintiffs typically advance, a website operator communicates with a visitor, a third-party technology receives or acquires the contents of that communication contemporaneously, and the third party allegedly does so without adequate prior consent.

SB 690 does nothing to eliminate those claims.

Indeed, the narrowing of Section 638.51 could make Section 631 more important.

Plaintiffs’ lawyers who previously pleaded both causes of action can simply devote more attention to proving that the information transmitted was not merely metadata but contents.

That means the next battlefield will increasingly concern what, exactly, the technology received.

  • An IP address alone is one thing.
  • A search query can be another.
  • A URL revealing a medical condition can be another.
  • Text typed into a chatbot or form presents an even stronger factual narrative.
  • Session-replay technology capturing mouse movements, field entries or page interactions creates yet another.

The distinction between metadata and content is therefore likely to become more important, not less.

Flo Health Showed Plaintiffs That Section 631 Can Actually Reach a Jury

For years, much of website-tracking litigation consisted of demand letters, motions to dismiss and settlements.

Then came Frasco v. Flo Health.

The case involved allegations that reproductive-health information entered into the Flo application was transmitted through embedded technologies to companies including Meta, Google and Flurry.

Google and Flurry settled before trial. Flo settled during trial. Meta proceeded to verdict.

The jury concluded that Meta violated CIPA and if you read California Lawyers Association analysis there aren’t many surprises for those who have been following this. Especially as vexatious litigant Vivek Shah has gone haywire with his filings over the past summer.

Whatever one thinks of the sprawling universe of CIPA claims based on ordinary website telemetry, Flo Health illustrates the opposite end of the factual spectrum.

There is a substantial difference between an analytics tool learning that a browser at a particular IP address visited a shoe store and technology allegedly receiving reproductive-health information associated with an identifiable user.

That is precisely why the Legislature ultimately rejected a wholesale commercial-purpose exemption.

And it is also why Section 631 will remain dangerous.

The strongest future cases are likely to migrate toward content-rich and sensitivity-rich allegations, where plaintiffs can tell a much more compelling privacy story than “the defendant collected my IP address.”

At the Same Time, Courts Are Becoming More Skeptical of Manufactured Privacy Injury

The plaintiffs’ bar also faces substantial headwinds.

In Popa v. Microsoft, the Ninth Circuit held in 2025 that a plaintiff challenging Microsoft’s Clarity session-replay technology had not established the concrete injury necessary for Article III standing.

The court distinguished ordinary website-interaction information from the kinds of highly offensive or private invasions historically actionable under privacy tort law.

That does not prevent a plaintiff from suing in California state court, where federal Article III requirements do not apply.

And it does not mean sensitive-data cases will fail.

But it gives federal defendants a powerful threshold argument where the alleged interception involves nothing more than ordinary browsing telemetry.

The trend continued into 2026. Courts have increasingly asked plaintiffs to identify what information was actually captured, why it was private, what the third party did with it and how the alleged interception produced a legally cognizable injury.

The era in which simply saying “tracker” or “IP address” automatically sounds sinister is becoming more difficult to sustain.

The Variety Media Appellate Case May Still Reshape CIPA

Another extraordinary development occurred only days before SB 690 passed.

On August 21, the California Court of Appeal issued a tentative ruling in Variety Media, LLC v. Superior Court, potentially the first California appellate decision squarely addressing whether ordinary website tracking can constitute pen-register activity under CIPA.

The tentative opinion produced a nuanced result.

It rejected the broad defense argument that CIPA’s pen-register provisions categorically cannot apply to internet communications.

But it also concluded that a traditional pen register captures destination-identifying information associated with an outgoing communication.

A website visitor’s IP address generally identifies the source of the communication.

Under that reasoning, IP-address collection alone would not adequately plead a pen-register violation.

The court heard oral argument on August 25 and submitted the matter. As of August 29, the tentative ruling is not a final published appellate decision.

That means California now has two different mechanisms converging on the same litigation problem.

The Legislature is potentially eliminating private enforcement.

The judiciary is simultaneously considering narrowing what counts as a pen register.

If SB 690 becomes law, the immediate private-litigation significance of Variety Media may decline dramatically.

But the opinion could still matter for Attorney General enforcement, interpretation of the statute and pending cases before SB 690 becomes operative.

So What Comes After the CIPA Pen-Register Wave?

This is where the story becomes more important than SB 690 itself.

Privacy litigation does not disappear when one theory becomes less profitable.

It migrates.

The legal infrastructure built during the CIPA boom already exists: plaintiffs’ firms, technical experts, automated scanning, browser-network captures, repeat plaintiffs, template complaints and sophisticated methods of identifying sites whose tracking stacks do not match their disclosures.

The next wave is therefore unlikely to look like a sudden replacement of CIPA with one new statute.

It is more likely to be layered website privacy litigation.

Section 631 Will Become the Primary California Battlefield

Expect more emphasis on proving actual “contents” interception.

Search bars, chatbots, lead-generation forms, login pages, appointment forms, symptom checkers, financial calculators and other interactive website elements are far more attractive than a bare IP-address case.

Plaintiffs will increasingly ask whether third-party JavaScript sees text while the visitor is typing, rather than merely whether a cookie exists.

Technical architecture will consequently matter enormously.

  • When was the information transmitted?
  • Was it readable when received?
  • Was the vendor actually a third party?
  • Did it have independent rights to use the information?
  • Was it merely processing information for the website operator?
  • Was consent obtained before the transmission?

These questions already dominate modern Section 631 litigation and will become even more important after SB 690.

The Federal Wiretap Act May Become a Larger Part of the Litigation Portfolio

The Electronic Communications Privacy Act and federal Wiretap Act provide plaintiffs with another path that is not dependent on California residence.

One important emerging theory involves the federal statute’s so-called crime-tort exception.

Ordinarily, participation or one-party consent can provide a powerful defense under federal wiretap law. Plaintiffs increasingly argue, however, that 18 U.S.C. § 2511(2)(d) removes that protection when an interception is undertaken for the purpose of committing a criminal or tortious act.

Courts are divided over how much wrongful purpose must actually be alleged.

Some require something considerably more than a commercial advertising objective.

Others have allowed more aggressive theories to survive longer.

Either way, ECPA is no longer merely a decorative count attached to a CIPA complaint. If California reduces the economics of one statutory cause of action, plaintiffs have an obvious incentive to invest further in making the federal theory work.

VPPA Litigation Will Continue Wherever Video and Identity Collide

The Video Privacy Protection Act presents another attractive statutory-damages framework.

The modern theory typically alleges that a website or application disclosed information linking an identifiable consumer with specific video-viewing activity through pixels or other third-party tracking technology.

Courts remain divided over critical questions, including who qualifies as a “consumer,” what businesses constitute video tape service providers and what information is sufficiently identifying.

But publishers, media companies, healthcare-content providers, education businesses and other organizations presenting video content remain particularly exposed.

And unlike Section 638.51, SB 690 does absolutely nothing to affect the VPPA.

Healthcare and Sensitive-Data Pages Are Likely to Become Premium Litigation Targets

The next generation of cases will increasingly differentiate between generic browsing and sensitive interactions.

Recent litigation already shows why.

In Doe v. Adventist Health System/West, plaintiffs alleged that Meta Pixel and Google Analytics collected information from health-related websites and a patient portal, including potentially identifying and health-related information. The California Court of Appeal issued a decision in that litigation on August 24. Read the decision.

The Meta Pixel tax-filing litigation similarly illustrates how URLs and other technical transmissions can allegedly reveal highly contextual information. Plaintiffs there alleged that Meta received URLs associated with inquiries concerning dependents, loans, COVID-19 and other tax-related issues; a federal court permitted CIPA theories to proceed past pleading challenges. Read the decision.

This is where plaintiffs’ cases become far more persuasive.

The future target is not simply:

“Your website has Google Analytics.”

It is:

Your website transmitted what a specific person was researching, buying, typing, watching, asking, scheduling or disclosing — and did so before that person meaningfully consented.

That is a much harder case for a defendant to dismiss rhetorically or legally.

Website Privacy Litigation Is Also Becoming National

California will remain the center of gravity, but this is no longer exclusively a California problem.

Florida is becoming an important front under the Florida Security of Communications Act.

Pennsylvania’s Wiretapping and Electronic Surveillance Control Act continues to generate website-tracking cases.

Plaintiffs are also exploring related theories in other states and combining them with federal claims, common-law privacy torts and consumer-protection statutes.

This geographic migration matters.

A company cannot simply configure a California banner, conclude that CIPA is handled, and assume the rest of the United States presents no comparable exposure.

  • Consent standards differ.
  • Statutory language differs.
  • Standing differs.
  • Damages differ.
  • The same technical data flow can produce different legal consequences depending on the user’s state.

The broader website-privacy litigation market is becoming a multistate consent and interception problem, rather than a California-only CIPA problem.

The Next Frontier May Be Identity Resolution and Real-Time Advertising

There is another technical development worth watching closely.

The earliest tracking lawsuits focused on easy-to-explain technologies: chat tools, session replay and Meta Pixel.

The next frontier is potentially more sophisticated.

Identity-resolution platforms can combine pseudonymous identifiers, hashed information, IP addresses, browser information, advertising IDs and existing customer profiles to determine that otherwise disconnected activity belongs to a particular individual or household.

Real-time bidding creates even more complicated data flows, because information may be distributed across multiple participants in the advertising ecosystem in fractions of a second.

Industry and litigation practitioners were already discussing RTB as the “next front” of CIPA-style litigation earlier this year. IAB discussion of the next CIPA litigation front.

That shift is important because plaintiffs are learning to argue not merely that a website transmitted an individual data point, but that seemingly innocuous data becomes identifying through aggregation.

A cookie ID by itself may reveal very little.

A browser identifier by itself may reveal very little.

A page URL may reveal very little.

But when those fields are connected with an existing advertising profile, plaintiffs can argue that the system knows both who the person is and what the person just did.

Expect aggregation, fingerprinting and identity resolution to become central concepts in the next generation of privacy complaints.

Consent Is About to Matter More Than Ever

One of the biggest mistakes businesses could make after SB 690 is assuming that a cookie banner is now less important.

The opposite is true.

As plaintiffs shift from a relatively mechanical pen-register theory toward interception and content-based claims, meaningful prior consent becomes even more valuable.

Javier already established the importance of obtaining consent before alleged interception begins.

Courts increasingly examine not merely whether a banner existed, but what happened technically underneath it.

  • Did Meta Pixel fire before consent?
  • Did the session-replay library initialize immediately?
  • Did a chatbot send text to its vendor while someone was typing?
  • Was a “Reject” choice actually honored?
  • Did Google Tag Manager continue firing technologies assigned to advertising categories?
  • Did the privacy notice say information was not sold while vendor contracts permitted independent advertising use?
  • Did the user consent to the website collecting information, but not to a completely separate company receiving it?

A beautiful consent banner sitting above broken tag logic is not a privacy control.

It is evidence.

This Is Becoming an Evidence Problem, Not Merely a Privacy-Policy Problem

The companies best positioned for the next phase will be the ones capable of proving exactly what their websites did at a particular point in time.

That requires more than a privacy policy.

Businesses need:

  • Historical consent logs.
  • Versioned banner configurations.
  • Records showing which tags were categorized as necessary, analytics, advertising or functional.
  • Evidence of which network requests occurred before and after consent.
  • Preserved tag-manager versions.
  • Documentation of vendor data rights.
  • Proof that session-replay masking worked as configured.
  • Evidence that sensitive pages were excluded where appropriate.
  • Records showing whether a California visitor who clicked “Reject” actually caused the advertising stack to stop.

Modern website privacy litigation is increasingly forensic.

A plaintiff can capture a browser session.

A defendant needs to be able to reconstruct it.

California’s Message in SB 690 Is Narrower — and More Important — Than “CIPA Is Fixed”

The easy headline is:

California passed legislation ending abusive CIPA lawsuits.

That headline is wrong.

The more accurate headline is:

California decided that private plaintiffs should no longer be able to monetize one particularly controversial interpretation of CIPA’s pen-register statute against websites and apps.

That is still a major event.

Potentially thousands of Section 638.51 matters sit inside the retroactive window.

A litigation theory that exploded from hundreds of claims to thousands in little more than a year could lose the private-enforcement mechanism that made the model economically viable.

But the California Legislature very deliberately preserved Section 631.

It preserved meaningful CIPA remedies where actual communication content is allegedly intercepted.

It preserved the Attorney General’s authority.

And it refused to adopt the sweeping commercial-purpose immunity contemplated by earlier versions of SB 690.

That compromise tells us a great deal about where website privacy law is heading.

The future will probably be less hospitable to claims based solely on the unavoidable metadata generated when someone connects to the internet.

At the same time, it may become considerably less forgiving when businesses capture meaningful contents, sensitive searches, health information, chat conversations, form entries or identifiable behavioral histories without obtaining consent first.

That is a much more rational dividing line.

The CIPA Shakedown Era May Be Ending. Website Privacy Litigation Is Not.

SB 690 could represent the beginning of the end for the extraordinary Section 638.51 demand-letter industry that developed around IP addresses, cookies and routine website metadata.

It does not eliminate CIPA.

It does not eliminate Section 631.

It does not eliminate ECPA.

It does not eliminate VPPA claims.

It does not eliminate state wiretap statutes.

It does not eliminate health-data litigation.

And it certainly does not make uncontrolled third-party website tracking safe.

Instead, the market is likely to evolve from metadata litigation toward content, consent and identity litigation.

That may ultimately be a healthier development.

Businesses should not face ruinous statutory-damages demands simply because an ordinary website established the network connections necessary to function.

But businesses should also understand exactly what third-party code is doing when consumers search, type, watch, buy, schedule or communicate.

The next wave of lawsuits will increasingly ask that question.

And unlike the first wave, the answer will often be sitting directly inside the website’s network traffic.

Current as of August 29, 2026. SB 690 has passed the California Legislature but has not yet become law.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.