Screenshot of California SB 690 text highlighting the repeal of private pen register actions

California’s SB 690 May Close One Door on Website Tracking Claims While Leaving Others Open

California’s new privacy statute, SB 690, reshapes the legal battlefield for website tracking disputes by stripping private parties of a key enforcement tool while preserving a narrow avenue for the state, a shift that could alter litigation strategy for any firm handling user data online.

Scope and Retroactivity of SB 690

SB 690, signed on September 30, 2026, eliminates the private right of action for pen register and trap‑and‑trace claims under § 638.51 of the California Invasion of Privacy Act (CIPA) when the alleged conduct occurs on a website, online application, or mobile application. The statute applies retroactively to claims filed within a two‑year window ending January 1, 2027, meaning any action commenced on or after January 1, 2025 is subject to dismissal.

The retroactive provision creates a legal cutoff: plaintiffs who filed before the window cannot rely on the new rule, but those whose cases are still pending may invoke the statute to argue that the law now governs their claim. Courts will have to balance the legislative intent to curb “high‑volume privacy claims” against the constitutional prohibition on retroactive impairment of vested rights.

Shift of Enforcement to the Attorney General

Under SB 690, only the California Attorney General may bring a § 638.51 action against a private actor, effectively centralizing enforcement and removing the “private right of action” that had enabled individuals and consumer groups to sue en masse. This concentration of authority limits the diversity of litigants and may reduce the volume of filings, as the AG typically pursues cases with broader public interest.

For defendants, the change means that the threat of statutory damages—once a powerful leverage point in CIPA demand letters—diminishes unless the AG decides to act. Companies must therefore monitor the AG’s enforcement priorities, which historically focus on systemic violations rather than isolated incidents.

Strategic Implications for Ongoing Litigation

Practitioners representing defendants should assess whether a pending claim falls within the retroactive scope; if it does, filing a motion to dismiss based on SB 690 is a viable first step. However, challenges may arise concerning the statute’s retroactivity, and courts could interpret the two‑year carve‑out narrowly.

Beyond dismissal tactics, the law underscores the importance of aligning data‑collection practices with disclosed policies. Since future claims will likely hinge on whether trackers capture “substantive or sensitive information,” firms must conduct a thorough audit of data flows and ensure that cookie notices, privacy policies, and vendor agreements accurately reflect actual tracking behavior.

What This Actually Means For You

  1. Review any pending § 638.51 lawsuits to determine if they were filed on or after January 1, 2025; if so, prepare a dismissal argument anchored in SB 690’s retroactive clause.
  2. Conduct a comprehensive inventory of all website and app trackers, focusing on whether they collect personally identifiable or sensitive data that could trigger future privacy claims.
  3. Update privacy notices, cookie consent mechanisms, and vendor contracts to mirror the real‑world operation of your tracking technologies, closing gaps that plaintiffs often exploit.
  4. Monitor announcements from the California Attorney General’s office for shifts in enforcement focus, as only the AG can now initiate new § 638.51 actions.
  5. Engage counsel early to evaluate both defensive and proactive measures, recognizing that the legal landscape now favors state‑led actions over private litigation.

Immediate Action Steps

Start by mapping every data‑capture point on your digital properties, documenting the type of information collected and the legal basis for its use. This map will serve as the foundation for both compliance reviews and any litigation defenses.

Simultaneously, convene a cross‑functional team—including legal, product, and engineering—to reconcile your privacy disclosures with the actual tracking practices, ensuring that any inconsistencies are corrected before the AG or a court scrutinizes them.

Frequently Asked Questions

Can private individuals still sue for pen register violations after SB 690?

No. SB 690 removes the private right of action for § 638.51 claims, limiting lawsuits to those brought by the California Attorney General.

Does SB 690 apply to claims filed before January 1, 2025?

Claims filed before that date are not covered by the retroactive provision and therefore remain subject to the pre‑SB 690 legal framework.

What types of tracking activities are most likely to trigger future CIPA claims?

Future claims will focus on whether website tools capture substantive or sensitive information, making the scope of data collected by trackers a critical factor.

What Do You Think?

Given SB 690’s narrowing of private enforcement, will companies prioritize internal compliance over waiting for state action, or will they gamble on the reduced litigation risk?

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.