California Closes the CIPA Pen Register Loophole. The Wiretap Cases Are Still Coming.

Table of Contents

California just cut the private right of action out of the most-used theory in website-tracking litigation. On September 30, 2026, Governor Gavin Newsom signed Senate Bill 690, ending private lawsuits under the California Invasion of Privacy Act’s pen register and trap-and-trace statute when the alleged conduct happens on a website, online application, or mobile app. Enforcement of those claims against private companies moves to the Attorney General alone. The law takes effect January 1, 2027, and it reaches back to pending cases filed on or after January 1, 2025.

It is a real change. It is not the end of CIPA website litigation unfortunately but the good news is Captain Compliance’s software tools work to protect you against other claims.

SB690 Veto for CIPA Lawsuits

What Newsom signed

SB 690, authored by Senator Anna Caballero, passed both chambers on August 28, 2026 without a recorded no vote. The Assembly approved it 66–0. The Senate concurred. Newsom signed it on the last day of his constitutional window and chaptered it as Chapter 976 of the Statutes of 2026.

In his signing message to the Senate, Newsom wrote that the bill “eliminates the private right of action under the California Invasion of Privacy Act (CIPA) for violations of the pen register and trap-and-trace statute arising from conduct occurring on an internet website, online application, or mobile application.” He framed the target as “vexatious” lawsuits and demand letters used “to extract settlement money from small businesses that unwittingly install software on their websites.” He also said the job is unfinished. CIPA still contains “other decades-old statutes that are also susceptible to abuse,” and he urged the Legislature to take those up next year.

Why this statute became a litigation machine

CIPA is a 1967 wiretapping law. The pen register and trap-and-trace rules, Penal Code sections 638.50 and 638.51, were written for devices that record the numbers dialed on a phone line or the numbers of incoming calls. For decades they sat almost unused in civil court.

Starting around 2022, plaintiffs’ firms began arguing that ordinary website tools do the same thing. A cookie, pixel, analytics script, session-replay tool, or chat widget that records an IP address, device identifier, or page event, they said, is a pen register. No court order, no consent, statutory violation.

The economics were built for volume. Penal Code section 637.2 lets an injured person sue for the greater of $5,000 per violation or three times actual damages, and actual damages are not a prerequisite. A single site with a Meta pixel or a Google tag could be pleaded as thousands of violations. Defense lawyers have said class claims under this theory can reach tens of millions of dollars on the face of the complaint. Reuters reported that Forbes settled a CIPA class action for $10 million and the Los Angeles Times settled one for $3.85 million. Fisher Phillips has estimated more than 4,700 digital-wiretapping lawsuits filed in California, or filed elsewhere but invoking California law, since 2022. Of the CIPA website cases, roughly a third alleged only a pen register claim.

Courts never settled whether the theory was right. Some dismissed. Some let the claims proceed. That split was enough. Demand letters went out to small businesses that had installed a plugin and never read the vendor’s data-sharing terms.

What the enrolled text actually does

SB 690 amends one section: Penal Code section 637.2, the civil-remedy provision. It does not rewrite the definition of a pen register. It changes who may sue.

New subdivision (d)(1) says an action against a private actor for a violation of section 638.51 “alleged to arise from conduct occurring on an internet website, online application, or mobile application” may be brought under section 637.2 only by the Attorney General.

Read that carefully. Four limits sit inside one sentence.

  • Private actor. The restriction is aimed at suits against businesses, not government defendants.
  • Section 638.51 only. Wiretapping under section 631, recording of confidential communications under section 632, and the cordless/cellular provision in section 632.7 are untouched.
  • Website, online app, or mobile app. The old phone-line pen register rules still have a private right of action outside that setting.
  • Attorney General only. The prohibition itself remains. The AG can still sue. The AG has had civil authority here for years and has not used it against routine tracking tools.

The earlier draft was broader. It would have created a commercial-purpose exception across multiple CIPA sections. That version stalled. The July 2026 rewrite narrowed the bill to the pen register private right of action, which sponsors said was the main driver of the demand-letter wave. That is the bill that passed unanimously.

Retroactivity, and what it does not wipe out

There is no urgency clause, so the operative date is January 1, 2027. Subdivision (d)(2) applies the change to any pending claim in an action commenced within two years before that date. In practice, that reaches cases filed on or after January 1, 2025.

Businesses with a live section 638.51 website claim filed in that window should expect dismissal motions once the statute is operative. Demand letters that rest only on the pen register theory lose their leverage on the same date.

Everything else stays. A complaint that also pleads section 631 wiretapping, section 632, the federal Wiretap Act, the Video Privacy Protection Act, or a common-law intrusion claim is not dead. Plaintiffs’ firms are already saying they will replead. Session replay, chat transcripts, and pixels that capture the contents of a communication, not just routing data, are the theories most likely to survive.

SB 690 also does not decide the underlying legal question. It does not say a pixel is not a pen register. It takes the private plaintiff out of that fight and leaves the definitional question to the Attorney General and the courts.

What compliance teams should do now

Treat this as a narrowing, not a safe harbor.

  • Inventory the stack. Pixels, tag managers, session replay, heatmaps, chat widgets, SDKs, and server-side tagging all still create section 631 exposure if they capture message contents.
  • Separate routing data from contents. The pen register theory was about who called whom. Wiretap theories are about what was said. Chat widgets and form-fill tools sit on the wrong side of that line.
  • Do not assume January 1 ends open matters. Only qualifying 638.51 claims in actions filed on or after January 1, 2025 are covered. Older cases, non-website claims, and mixed complaints need a claim-by-claim read.
  • Watch 2027. Newsom asked the Legislature to revisit the rest of CIPA. A second bill aimed at sections 631 and 632 is the obvious next fight, and privacy advocates will treat the signing message as an invitation to narrow, not expand, that effort.

CIPA Private Lawsuits Still Exist

SB 690 takes the cheapest, highest-volume CIPA theory away from private plaintiffs and gives it to an Attorney General who has not been filing these cases. That should collapse a large share of the demand-letter business aimed at small sites. It does not legalize undisclosed tracking, it does not amend the wiretap statute, and it does not stop a plaintiff who can plead that a tool captured the contents of a communication. The governor said as much in the signing letter: this fixes one abused provision, and the rest of a 1967 statute is still on the table.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.