All Blog Posts

California Just Signed a Fix for CIPA Into Law — Your Website Might Still Get Sued

Close
Read time
5 mins
Published
Oct 1, 2026
Share
  • SB 690 is now law and removes one specific type of CIPA lawsuit: pen-register claims over website tracking.
  • Two other parts of the same law, covering wiretapping and eavesdropping, were never part of the bill and remain fully active (as do other comparable state and federal laws).
  • A single tracking script firing before a visitor consents is enough to trigger a claim, and statutory damages start at $5,000 per violation, with no requirement to prove harm.
  • A California news publisher settled a CIPA tracking case for $3.85 million in mid-2026, over just three ad-tech scripts.
  • Blocking scripts until a visitor consents addresses the actual behavior all three CIPA theories target, regardless of which one gets used.

In California, Governor Newsom has signed SB 690, and it narrows exactly one CIPA theory: § 638.51, the pen-register claims tied to website tracking. Expect it to come into effect January 1, 2027.

Wiretapping (§ 631) and eavesdropping (§ 632) claims are untouched. Here's a plain-language breakdown for website owners and what to fix before it becomes someone else's lawsuit.

If you run a website that serves California visitors, here's a number worth sitting with: USD 3.85 million. That's what a major California newspaper paid in mid-2026 to settle a lawsuit over three advertising trackers that loaded before visitors clicked "accept" on a cookie banner. 

The publisher didn't admit wrongdoing. It paid to make the case go away, which tells you something about how expensive it is to fight one of these to the end.

That's the environment California's SB 690 was signed into. Starting January 1, 2027, the specific lawsuit type behind that settlement (the § 638.51 "pen-register" claim) can no longer be brought by a private individual against a website or app. Only the state Attorney General can enforce it going forward, and some pending cases filed within the two years before that date (roughly January 1, 2025) may not survive the change.

Here's the part that matters most: SB 690 was never a fix for CIPA lawsuits generally. It only ever touched one theory out of three.

The Details Most Coverage Skipped

California's Invasion of Privacy Act (CIPA) gives plaintiffs three separate tools, and SB 690 closed exactly one of them:

  • Section 638.51: the "pen-register" theory, targeting tools that capture routing information like IP addresses. This is the one SB 690 narrows.
  • Section 631: the wiretapping theory, targeting interception of a communication in transit. Untouched by any version of SB 690.
  • Section 632: the eavesdropping theory, targeting recording of confidential communications. Also untouched by SB 690.

Earlier drafts of SB 690 tried to cover all three with a broad "commercial purpose" exemption. That language was stripped during amendments. What became law deals with pen-register claims only, which means the other two theories were never on the table to begin with.

Legal trackers following CIPA litigation through 2026 have already flagged the obvious next move: plaintiffs shifting newer filings toward Section 631 claims specifically to route around SB 690's narrower scope.

Why This Doesn't Change Your To-Do List

Website owners have spent much of 2026 watching this bill's progress like it was the deciding factor in their CIPA exposure. It wasn't, and signing it into law doesn't make it one.

A narrower Section 638.51 is genuinely good news if a pen-register claim is what you're facing. It is not the same as CIPA compliance. Those using Sections 631 and 632 don't care what happened in Sacramento, or any of the other laws being used to bring claims.

The actual question, in both versions of this story, is whether anything on your site collects or shares visitor data before that visitor has made a consent choice. That's a website configuration question, and it has nothing to do with a bill number.

What Actually Triggers a CIPA Claim

Recent CIPA filings share a pattern regardless of which section gets cited: a script, pixel, chat widget, or analytics tool loads and starts collecting data the moment a page renders, before the visitor has clicked anything on the cookie banner. 

Whether a court calls that a pen register, a wiretap, or eavesdropping is a legal argument for your counsel. Whether it happened on your site is something you can check today.

It's More Than Just CIPA 

CIPA gets the headlines, but it's only one of several wiretapping-style laws now aimed at the same site behavior. Plaintiffs are increasingly pairing them together in the same lawsuit.

Florida Security of Communications Act (FSCA) 

Florida also requires consent from everyone in a conversation before it can be recorded or tracked. A 2025 court ruling let pixel-tracking claims move forward under this law, and plaintiffs have since filed hundreds of small-claims suits. 

Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA) 

Pennsylvania has a similar all-party consent rule. A federal appeals court ruled in Popa v. Harriet Carter Gifts that it applies to website tracking too. The "interception" is treated as happening right in the visitor's browser. 

Video Privacy Protection Act (VPPA) 

The VPPA was originally written to protect video rental records, but courts are now applying it to sites that share video-viewing data through pixels or trackers without proper consent. 

Electronic Communications Privacy Act (ECPA) 

The ECPA is the federal version of these state wiretapping laws. It's showing up more often alongside state claims like CIPA, FSCA, and WESCA in the same website-tracking lawsuits. 

Different states, different statutes, but same underlying complaint: something on the site collected or shared visitor data before the visitor said yes.

Addressing the Actual Problem

Checklist icon

Check what fires before your cookie banner renders, not what fires after a visitor accepts.

Confirm non-essential scripts are blocked by default until consent is given, not just hidden from view. (If you don’t have a CMP doing that, start your free trial now.)

Keep a record of consent choices tied to the specific page and session, so you can show what happened if you're ever asked.

Revisit your privacy policy against what your site currently does, not what it did when the policy was written.

The Cookiebot CIPA Consent Template is built to close exactly this gap. Instead of giving California visitors the same opt-out setup as the rest of your U.S. traffic, it applies a GDPR-style opt-in layer specifically to California IP addresses. 

Session replay tools, chatbots, and advertising pixels stay blocked until a California visitor actively says yes. Visitors outside California keep your standard consent experience.

It's ready to use inside your Cookiebot dashboard, so there's no custom development needed to turn it on. It also logs every consent interaction with a timestamp, which is the record that actually matters if a demand letter arrives. It also supports VPPA and ECPA configuration for sites running embedded video, streaming features, or other tracking that overlaps with CIPA risk on the same site. 

None of this is a legal safe harbor, and it's not a substitute for qualified legal counsel to address your specific business operations, privacy compliance needs, or the assistance you need once a claim exists. But it does address trackers firing before consent, which is the exact problem behind nearly every current CIPA filing.

Frequently asked questions

Not automatically. A banner that's visible but doesn't actually block scripts until a visitor responds is exactly the fact pattern behind most CIPA claims. The banner has to control what fires, not just what's displayed. Additionally, even if you are CCPA-compliant, that law’s consent and notice requirements do not address CIPA risks at all.

No. It removes one lawsuit type, pen-register claims, for conduct on websites and apps. Wiretapping and eavesdropping claims under Sections 631 and 632 are completely unaffected and remain the more commonly cited theories in newer filings.

You'll want to consult qualified legal counsel if you're already facing a claim or demand letter. Fixing the underlying issue — scripts firing before consent — is a configuration change most site owners can make with the right consent management tool, but if you’ve received a claim or demand letter, don’t change anything until obtaining legal advice.

Yes. No configured script runs until a California visitor has actually interacted with the consent banner and said yes, including anything that would otherwise send routing or device information in the background. It also addresses CCPA requirements like the opt-out link and automatically honors GPC signals.

 

If nothing fires before consent, nothing gets captured before consent, which is exactly the problem behind Section 638.51 "pen register" claims. It's not a legal safe harbor, though, and  you'll still want your lawyer to confirm which tools on your site actually need prior consent.

Statutory damages under CIPA's civil remedy provision run as high as $5,000 per violation, or three times actual damages, whichever is greater, and plaintiffs don't have to prove they were actually harmed. Multiply that across a class of visitors and the numbers escalate quickly, as the 2026 newspaper settlement showed.