At a Glance
- Governor Newsom has signed SB 690, closing the private right of action for Section 638.51 pen-register claims tied to website and app tracking.
- Sections 631 and 632, CIPA’s wiretapping and eavesdropping provisions, are untouched either way, and plaintiffs’ firms are already building claims around them (and other state and federal laws).
- Statutory damages run $5,000 per violation or three times actual damages, with no requirement to prove harm.
- A federal court approved a $3.85 million CIPA settlement against the Los Angeles Times in June 2026 over three ad-tech trackers.
- The fix for all three CIPA theories is the same: stop trackers from firing before a visitor consents.
Governor Newsom has signed California’s SB 690. This will limit enforcement of one CIPA theory, Section 638.51 (pen register and trap-and-trace), to the California Attorney General when the claim arises from a website, online application, or mobile application.
Section 631 and 632 exposure remains fully intact, and plaintiffs’ firms are already pivoting. Here’s what changed, what to do next, and why website consent enforcement still matters.
In June 2026, a federal judge approved a USD 3.85 million settlement against the Los Angeles Times. The claim was that three ad-tech trackers — TripleLift, GumGum, and Audiencerate — fired on the paper’s website before visitors gave consent.
The newspaper admitted no wrongdoing. It paid because fighting a California Invasion of Privacy Act claim all the way through court is expensive, slow, and rarely a sure win.
That’s the backdrop Governor Newsom signed SB 690 into. Starting January 1, 2027, private individuals can no longer sue over Section 638.51 for tracking on a website, app, or online application.
Only the California Attorney General will be able to enforce it now. The law also reaches back: pending claims filed within the two years (starting roughly January 1, 2025) before that date may not survive it.
But that one fact doesn’t tell the whole story. SB 690 was never a repeal of CIPA. It only narrowed one theory inside it.
What SB 690 Actually Touches
SB 690 amends Penal Code Section 637.2 covering Section 638.51, but the bill never touched these sections:
- Section 631, CIPA’s core wiretapping provision, covering interception of communications in transit
- Section 632, covering eavesdropping on confidential communications
Earlier drafts of SB 690 would have carved out a broader “commercial business purpose” exemption reaching Sections 631 and 632 as well. That language didn’t survive the amendment process. The version Newsom signed deals only with pen registers.
Plaintiffs’ firms know this too. Legal analysts tracking the bill through 2026 have flagged the obvious next move: businesses relieved of Section 638.51 exposure should expect claims reframed as Section 631 interception theories instead. That shift is already showing up in newer filings.
Why “It Passed” Isn’t the Headline You Think It Is
Signing SB 690 is a real change, but only for one specific type of claim. If you’re facing a CIPA demand letter or lawsuit, this narrows your exposure, and some pending claims may get dismissed once the law takes effect. Treat that as good news, not as an all-clear.
The real question was never “Will SB 690 pass?” It’s always been “Does anything on your website fire before a visitor makes a consent choice?” That question is answered by your own site’s setup, not by Sacramento, and not by any of the other states now bringing similar claims.
The Part of CIPA That Nobody’s Legislation Is Fixing
Section 631 claims work differently, and they’re arguably easier to bring. A plaintiff doesn’t have to argue that a tracking pixel acts like an old phone-tapping device. They just have to argue that a communication — page content, form data, a chat transcript — was intercepted without everyone’s consent. Chat widgets, session-replay tools, and analytics scripts have all shown up in recent Section 631 lawsuits.
None of that depends on what happened to SB 690. If your business spent 2026 waiting on this bill instead of checking what fires on page load, you’re exposed today under the same theory that produced the Los Angeles Times settlement — just filed under a different section number.
It’s Not Just CIPA
California’s law gets the headlines, but it’s one of several wiretapping-style laws now used against the same tracking behavior.
Florida Security of Communications Act (FSCA)
Florida requires consent from everyone in a conversation before it can be recorded or tracked. A 2025 court ruling let pixel-tracking claims move forward under this law, and plaintiffs have since filed hundreds of small-claims suits.
Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA)
Pennsylvania has a similar all-party consent law. A federal appeals court ruled in Popa v. Harriet Carter Gifts that it can reach website tracking too, treating the “interception” as happening right at the visitor’s browser.
Video Privacy Protection Act (VPPA)
The VPPA was originally written to protect video rental records. Courts are now applying it to websites that share video-viewing data through pixels or trackers without proper consent.
Electronic Communications Privacy Act (ECPA)
The ECPA is the federal version of these state wiretapping laws. It’s increasingly pleaded alongside state claims like CIPA, FSCA, and WESCA in the same website-tracking lawsuits.
Each law has its own rules and its own damages, but the underlying complaint is always the same: a script collected or shared visitor data before the visitor said yes.
What to Do About It to Protect Your Website
The fix is the same no matter which law applies, because the underlying problem is the same: something collected or shared visitor data before that visitor had a chance to say no.
Audit every script, pixel, and SDK that loads before a consent banner renders.
Make sure your consent tool blocks non-essential trackers by default — not just after someone opts out. (If you don’t have one yet, start your free trial now.)
Keep a record of consent for each request, not just each session, so you can show exactly what fired and when.
Check your privacy policy against what your site actually does today, not what it did at last year’s audit.
The Usercentrics CIPA Consent Template is built to close exactly this gap. Instead of treating California visitors the same as the rest of your U.S. traffic, it applies a GDPR-style opt-in layer specifically to California IP addresses.
Session replay tools, chatbots, and advertising pixels stay blocked until a California visitor actively says yes. Visitors outside California keep your standard U.S. experience.
It’s pre-configured inside the Usercentrics Web CMP, so current customers don’t need custom development to turn it on. It also keeps a timestamped log of every consent interaction, which is the record that actually matters if a demand letter arrives.
It also includes settings to support VPPA and ECPA compliance for businesses running embedded video or streaming features, since that risk often overlaps with CIPA risk on the same site.
None of this is a legal safe harbor, and it’s not a substitute for qualified legal counsel to address your specific business operations or privacy compliance needs. Or the assistance you need once a claim exists, but it addresses trackers firing before consent, which is the exact problem behind nearly every current CIPA filing.
