California Senate Bill 690 is finally moving forward. The original bill would have broadly exempted disclosures made for a “commercial business purpose,” as defined under the California Consumer Privacy Act (CCPA), potentially eliminating many California Invasion of Privacy Act (CIPA) claims involving common website technologies. The amended version is narrower but could still offer meaningful relief to businesses facing the recent wave of CIPA litigation.

Under the amended bill, private plaintiffs could no longer bring claims under California Penal Code § 638.51 alleging that conduct on websites or online or mobile applications constitutes the unlawful use of a pen register or trap and trace device. Those claims could be brought only by the California Attorney General. The change would apply retroactively to certain pending lawsuits filed within the two years prior to the bill’s operative date. Plaintiffs could still pursue claims under § 631(a), although businesses often have stronger defenses to those claims, including consent and arguments that the information collected was not communication “content” or was not intercepted “in transit.”

SB 690 was approved unanimously by both the Assembly and Senate and has been sent to the Governor’s desk for signature, which must be completed by September 30, 2026. If enacted, it would take effect January 1, 2027. While it would not end CIPA website-tracking litigation, the bill signals legislative support for curbing private lawsuits based on increasingly common pen register and trap and trace theories. Businesses should continue monitoring the bill while reviewing their online tracking technologies, consent mechanisms, disclosures, and vendor relationships.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.