Governor Newsom signed SB 690 on September 30, 2026, the last day he had to act on it. The bill passed both chambers of the California Legislature without a single no vote on August 28, 2026 and was presented to him on September 4. It carries no urgency clause, so it takes effect on January 1, 2027.
A lot of the coverage of this bill has described it as the end of CIPA website-tracking lawsuits. It is not. SB 690 takes away one of the two theories plaintiffs use against website trackers and leaves the other exactly where it was. What follows is what the signed text does, what it leaves untouched, and what a business should still check.
What the law changes
CIPA is not one statute for website-tracking purposes. It is two, and SB 690 touches only one of them. Section 631 is the wiretapping provision: it covers the interception of communication content, and a claim built on it alleges that a tracker captured what a visitor typed, clicked, or submitted. Section 638.51 is the pen register and trap-and-trace provision: it covers a device or process that records routing or addressing information rather than content, and it is the provision under which an advertising pixel gets described as recording where a visitor's traffic went.
SB 690 adds a new subdivision to section 637.2, the section that gives injured parties a private right to sue for $5,000 per violation or three times actual damages. Under the new text, an action against a private actor for a section 638.51 violation alleged to arise from conduct on an internet website, online application, or mobile application can be brought only by the California Attorney General. A consumer can no longer sue a business directly under that provision for that conduct.
The change also reaches backward. The bill applies it to any pending claim in an action commenced within the two years before its operative date, so a section 638.51 website claim filed during that window and still open on January 1, 2027 is covered too. That language is in the enrolled text itself.
The distinction that matters
Everything else in this law follows from one split. Read it once and the rest of this page, and any coverage of SB 690 you come across elsewhere, gets easier to sort.
- Section 638.51 pen register and trap-and-trace claims tied to website or app conduct. From January 1, 2027, only the Attorney General can bring these. A business still faces state enforcement under section 638.51; what goes away is the private lawsuit and the demand letter that threatens one.
- Section 631 wiretapping claims. Untouched. A private plaintiff keeps the same right to sue directly under section 631 that exists today, and the statutory damages in section 637.2, the greater of $5,000 per violation or three times actual damages, still apply to a claim brought under it.
Expect the volume to move rather than vanish. A complaint that would have pleaded a pixel as a pen register can plead the same pixel as an interception of content under section 631. That theory asks more of a plaintiff, because it needs content rather than addressing information, and session-replay scripts and chat widgets are where it fits most naturally.
What the Governor asked for next
The signing message is short. It describes the bill as ending the private right of action for pen register and trap-and-trace claims arising from websites and apps, and it frames the target as lawsuits and demand letters aimed at small businesses that installed common tracking software. It then says that "additional work in this area is needed," because CIPA contains other decades-old provisions open to the same kind of litigation, and it asks the Legislature to take that on next year.
That is a request, not a law. It does not change section 631 today, and nothing guarantees a bill next session will pass or what it would say. It does mean the section 631 question is likely to be back in Sacramento in 2027.
What to re-check now
None of this touches the CCPA, which is a separate statute from CIPA and is not affected by SB 690 in any way. The CCPA already gives a consumer the right to direct a business not to sell or share personal information, under section 1798.120, and a mechanism for signaling that opt-out automatically, the opt-out preference signal in section 7025. A business that treats pixel and pen-register-style reporting as a sale or share for CCPA purposes, and suppresses it on signal under section 7025, has its own reason those requests should not fire before a visitor's choice registers. SB 690 does not change that obligation.
What stays worth measuring is which third-party requests your site makes before a visitor interacts with your consent interface, and which domain each one contacts. Pay closest attention to session-replay and chat tools, since they are the section 631 theory's natural fit. A scan of a site's live network traffic can show which trackers fired before that first interaction, the domain each one reached, and the timing relative to it. That measurement means the same thing after SB 690 as before it.
Check what fires before consent
Start with our free CCPA checker, which tests whether one URL honors the Global Privacy Control signal. Save the result to a free account and your first full audit is on us: it records which trackers fired before your consent interface got its first interaction, and the domain each one contacted.
Start with a free check