California Legislature Halts Class Actions Alleging That Common Website Advertising Technologies Are Pen Registers And Trap And Trace Devices

By Gerald L. Maatman, Jr., Justin R. Donoho, and Hayley Ryan

Duane Morris Takeaways:  On September 30, 2026, California Governor Newsome signed Senate Bill 690, which amends the California Invasion of Privacy Act (“CIPA”) to eliminate the private right of action under California Penal Code § 638.51 for pen register and trap-and-trace device claims arising from website, online application, and mobile application activity. Under the amended statute, only the California Attorney General may bring such claims against private actors. The law takes effect on January 1, 2027, and it applies retroactively to any pending claim in an action commenced within two years before that date. For the thousands of companies now facing CIPA § 638.51 class actions and demand letters over the use of pixels, cookies, and similar website advertising technologies (“adtech”), Senate Bill 690 offers significant and fast relief. It is not, however, the end of CIPA litigation. The wiretapping provision (§ 631) and the eavesdropping provision (§ 632), which plaintiffs have also used in adtech cases, are untouched.

The bill’s final form is much narrower than the version first introduced. As introduced, Senate Bill 690 would have exempted all processing of personal information for a “commercial business purpose” as defined by the California Consumer Privacy Act (“CCPA”) from civil and criminal liability under all three sections of the CIPA. See Assembly Committee On Privacy And Consumer Protection Committee Report (July 1 , 2026) (“Committee Report”) at 6-7. The analysis in our blog post covers the legal landscape that led to the bill, the scope and mechanics of the enacted statute, how the bill narrowed during the legislative process, and what corporate counsel and class action practitioners should do now.

Background

The CIPA was adopted in 1967 to criminalize wiretapping, eavesdropping, interception, and recording of telephone communications without court authorization. Section 637.2 confers a private right of action to any person injured by a violation of the CIPA. Available relief includes statutory damages of $5,000 per violation, three times the actual damages suffered by the plaintiff, if any, and injunctive relief. Section 637.2(c) specifically provides that plaintiffs do not need to show actual damages. The Assembly Committee on Privacy and Consumer Protection observed that, in the adtech context, these violations “can stack up rapidly, causing defendants to face potentially devastating liability.” See Committee Report at 7.

Recent adtech litigation has relied on three CIPA provisions: § 631 (wiretapping), § 632 (recording confidential communications), and § 638.51 (pen registers and trap-and-trace devices). Section 638.51 was added only in 2015, and according to the Assembly Committee on Privacy and Consumer Protection, the Legislature gave “little, if any, thought” to how it would apply online or interact with the CIPA’s private right of action. See Committee Report at 1. The Committee called the pen register and trap and trace device statute “a poster child for abusive lawsuits,” explaining that “[b]ecause the potential liability can be staggering, businesses generally settle this litigation hastily, encouraging vexatious litigants to continue blasting out demand letters.” See id. at 1.

The case law gave businesses little certainty.  For example, federal district courts in California are split as to whether third-party collection of website-user information may constitute a trap and trace device or pen register under § 638.51.  California state trial courts, by contrast, have mostly dismissed these claims, as in Licea v. Hickory Farms LLC, No. 23STCV26148, 2024 WL 1698147 (Cal. Super. Ct. Mar. 13, 2024), Casillas v. Transitions Optical, Inc., No. 23STCV30742, 2024 WL 4873370 (Cal. Super. Ct. Sep. 9, 2024), and Sanchez v. Cars.com Inc., No. 24STCV13201, 2025 WL 487194 (Cal. Super. Ct. Jan. 27, 2025). The Committee noted that there is no published California appellate authority applying § 638.51 to software. See Committee Report at 16. According to the bill’s sponsors, § 638.51 lawsuits rose from about 600 to nearly 4,000 after SB 690 was introduced, and tens of thousands of businesses received demand letters. See id. at 7.

What Does SB 690 Change?

SB 690 amends only § 637.2, the CIPA’s civil remedies provision. Its main features are as follows:

  • AG-Only Enforcement For Online Pen Register And Trap-And-Trace Claims. An action against a private actor for a violation of § 638.51 “alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.”
  • The Private Right Of Action Otherwise Remains. Subdivisions (a) and (b) of section 637.2 still authorize private suits for statutory damages, treble damages, and injunctive relief for all other CIPA violations, now subject only to the new subdivision (d) exception. The no-actual-damages provision in subdivision (c) also remains.
  • Retroactivity. The amendments “apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.” The Committee explained that this provision is meant to relieve defendants in pen register lawsuits filed within the two-year period before January 1, 2027. It also stated that the amendments would not affect any case in which final judgment has been entered.
  • Severability. The Committee explained that a severability clause was added “in view of possible constitutional challenges to the retroactivity provisions.” See Committee Reportat 25.

Who And What Is Covered?

The carve-out is narrow and depends on four elements. First, it applies only to claims under § 638.51. Second, it applies only to actions against a “private actor.” Third, the claim must be “alleged to arise from conduct occurring on” a website, online application, or mobile application. Fourth, it removes only private standing. The underlying prohibition in § 638.51 remains, and the Attorney General may pursue violations using the remedies the CIPA already provides.

SB 690 does not define “private actor,” and it does not explain when conduct “arise[s] from conduct occurring on” a website or app. Defendants should expect plaintiffs to test those terms. Possible targets include back-end service providers to websites and apps, such as companies that provide payroll, shipping logistics, cybersecurity and antifraud technology, cloud storage, HR, and analytics and advertising tools, which the bill’s sponsors noted had also been sued.

How Did The Bill Change During The Legislative Process?

The introduced and enacted versions of SB 690 differ significantly. As introduced, the bill would have exempted any “commercial business purpose,” as defined by the CCPA, from both civil and criminal liability under the CIPA. The enacted version does much less: it removes private standing only for certain § 638.51 claims. The introduced bill would have changed CIPA §§ 631, 632, 632.7, and 638.51. The Committee’s amendments struck all changes to §§ 631, 632, 632.7, and 638.50, so the enacted law amends only § 637.2, the CIPA’s civil remedies provision. See Committee Report at 25-26.

The two versions also differ in reach. The original bill applied to all civil and criminal violations, was not limited to website activity, and could have covered any recording or interception of a confidential communication made for a commercial business purpose. Id. at 15. The enacted bill leaves criminal liability unchanged, focuses only on the civil private right of action against private actors, and is limited to conduct occurring on an internet website, online application, or mobile application. Further, the original bill did not provide for public enforcement, while the enacted version gives the California Attorney General standing to pursue these pen register and trap-and-trace violations using the remedies the CIPA already provides. The enacted version also adds two provisions the original bill did not have: retroactive application to pending claims in actions commenced within two years before the operative date, and a severability clause added in view of possible constitutional challenges to that retroactivity.

The Committee called the original bill “too blunt” and warned that the bill could “unintentionally shield wiretapping violations that involve highly offensive intrusions.” See Committee Report at 2, 25. The Committee also treated the trap and trace device and pen register statute differently from the other provisions, noting that trap and trace device and pen register cases usually involve “seemingly innocuous technical violations arising from ordinary operation of websites.” Id. at 2. By contrast, it found that §§ 631 and 632 cases often involve “highly offensive intrusions on users’ reasonable expectations of privacy, although they are not immune from abuse.” Id.  The narrowed bill passed the Legislature unanimously in late August 2026.

What SB 690 Does Not Do

Claims under Sections 631 (wiretapping) and 632 (eavesdropping), which carry the same $5,000 per-violation exposure, remain available to private plaintiffs in class action litigation. The Committee acknowledged that § 631 “continues to be challenging for courts to apply” to conduct occurring on websites. See Committee Report at 2. It concluded that targeted reform of § 631 “appears warranted, albeit not as urgent as reforms to the pen register statute.” Id. at 24. The Committee also noted that plaintiffs have moved toward other theories, including claims under California’s Comprehensive Computer Data Access and Fraud Act and the federal Electronic Communications Privacy Act. Id. at 25. In his signing message, Governor Newsom noted that “additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants,” and “urge[d] the Legislature to take this on next year to ensure a fair balance between protecting private information and preventing rapacious litigation.”

Implications For Companies

SB 690 should sharply reduce the volume of § 638.51 class actions and demand letters. In the short term, however, the plaintiffs’ bar may shift its claims rather than abandon them. Companies with any online presence, including websites, mobile applications, and online forms and applications, should consider the following steps.

  • Assess Pending § 638.51 Matters Now. For cases filed within the two-year retroactivity window, defendants should consider motions for judgment on the pleadings or dismissal once the law becomes operative on January 1, 2027, and should consider seeking stays in the meantime. Defendants should also reconsider their settlement posture on pen register-only demands.
  • Expect The Retroactivity Provision To Be Challenged. The Legislature added the severability clause because it anticipated constitutional challenges. Defendants should be prepared to defend retroactive application.
  • Expect Claims To Be Repleaded Under §§ 631 and 632. Plaintiffs asserting trap and trace device and pen register claims under § 638.51 are likely to recast adtech, claims as wiretapping or eavesdropping claims, particularly where descriptive URLs, search terms, or health information are involved, as adtech plaintiffs typically argue that such items constitute “contents” of a communication under § 631 and that transmission of such items to adtech companies constitutes “eavesdropping” or aiding and abetting eavesdropping under § 632. These claims still carry $5,000 per-violation statutory damages and remain suitable for class treatment.  Of course, adtech plaintiffs will continue to face numerous significant legal challenges regarding the merits and certifiability of their §§ 631 and 632 claims, as we blogged about here, here, and here.
  • Continue Auditing Website Advertising Technologies. The relief provided by SB 690 fails to limit exposure not only under the CIPA §§ 631 and 632 but also under the Electronic Communications Privacy Act (ECPA), the Video Privacy Protection Act (VPPA), the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA), the Florida Security of Communications Act (FSCA), and other state and federal privacy statutes. Companies should continue to review and evaluate their adtech, data practices, consent mechanisms, and privacy notices, in light of rapidly evolving legal precedent regarding whether these old statutes apply to adtech, to ensure compliance with these other privacy laws.
  • Watch The 2027 Legislative Session. Given the Governor’s call for further reform, additional CIPA amendments are a realistic possibility.

Companies should consider Senate Bill 690 as a narrow solution providing limited relief to adtech defendants rather than a comprehensive reform. Companies that treat it that way will be better positioned for the next phase of CIPA class action litigation.

© 2009- Duane Morris LLP. Duane Morris is a registered service mark of Duane Morris LLP.

The opinions expressed on this blog are those of the author and are not to be construed as legal advice.

Proudly powered by WordPress