---------------------------
Title: California Just Signed a Fix for CIPA Into Law — Your Website Might Still Get Sued
URL: https://www.cookiebot.com/us/sb-690-website-owners-cipa-risk/
---------------------------

# California Just Signed a Fix for CIPA Into Law — Your Website Might Still Get Sued

## At a Glance

- SB 690 is now law and removes one specific type of CIPA lawsuit: pen-register claims over website tracking.
- Two other parts of the same law, covering wiretapping and eavesdropping, were never part of the bill and remain fully active (as do other comparable state and federal laws).
- A single tracking script firing before a visitor consents is enough to trigger a claim, and statutory damages start at $5,000 per violation, with no requirement to prove harm.
- A California news publisher settled a CIPA tracking case for $3.85 million in mid-2026, over just three ad-tech scripts.
- Blocking scripts until a visitor consents addresses the actual behavior all three CIPA theories target, regardless of which one gets used.

[In California, Governor Newsom has signed SB 690](https://www.gov.ca.gov/wp-content/uploads/2026/09/SIGN-msg-SB-690.pdf), and it narrows exactly one CIPA theory: § 638.51, the pen-register claims tied to website tracking. Expect it to come into effect January 1, 2027.

Wiretapping (§ 631) and eavesdropping (§ 632) claims are untouched. Here's a plain-language breakdown for website owners and what to fix before it becomes someone else's lawsuit.

If you run a website that serves California visitors, here's a number worth sitting with: [USD 3.85 million](https://www.latimescipasettlement.com/). That's what a major California newspaper paid in mid-2026 to settle a lawsuit over three advertising trackers that loaded before visitors clicked "accept" on a cookie banner.

The publisher didn't admit wrongdoing. It paid to make the case go away, which tells you something about how expensive it is to fight one of these to the end.

That's the environment California's [SB 690](https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB690) was signed into. Starting January 1, 2027, the specific lawsuit type behind that settlement (the § 638.51 "pen-register" claim) can no longer be brought by a private individual against a website or app. Only the state Attorney General can enforce it going forward, and some pending cases filed within the two years before that date (roughly January 1, 2025) may not survive the change.

Here's the part that matters most: SB 690 was never a fix for CIPA lawsuits generally. It only ever touched one theory out of three.

## The Details Most Coverage Skipped

[California's Invasion of Privacy Act (CIPA)](https://www.cookiebot.com/us/cipa-california-invasion-of-privacy-act/) gives plaintiffs three separate tools, and SB 690 closed exactly one of them:

- **Section 638.51**: the "pen-register" theory, targeting tools that capture routing information like IP addresses. **This is the one SB 690 narrows.**
- **Section 631**: the wiretapping theory, targeting interception of a communication in transit. **Untouched by any version of SB 690.**
- **Section 632**: the eavesdropping theory, targeting recording of confidential communications. A**lso untouched by SB 690.**

Earlier drafts of SB 690 tried to cover all three with a broad "commercial purpose" exemption. That language was stripped during amendments. What became law deals with pen-register claims only, which means the other two theories were never on the table to begin with.

Legal trackers following CIPA litigation through 2026 have already flagged the obvious next move: plaintiffs shifting newer filings toward Section 631 claims specifically to route around SB 690's narrower scope.

## Why This Doesn't Change Your To-Do List

Website owners have spent much of 2026 watching this bill's progress like it was the deciding factor in their CIPA exposure. It wasn't, and signing it into law doesn't make it one.

A narrower Section 638.51 is genuinely good news if a pen-register claim is what you're facing. It is not the same as CIPA compliance. Those using Sections 631 and 632 don't care what happened in Sacramento, or any of the other laws being used to bring claims.

The actual question, in both versions of this story, is whether anything on your site collects or shares visitor data before that visitor has made a consent choice. That's a website configuration question, and it has nothing to do with a bill number.

## What Actually Triggers a CIPA Claim

Recent CIPA filings share a pattern regardless of which section gets cited: a script, pixel, chat widget, or analytics tool loads and starts collecting data the moment a page renders, before the visitor has clicked anything on the cookie banner.

Whether a court calls that a pen register, a wiretap, or eavesdropping is a legal argument for your counsel. Whether it happened on your site is something you can check today.

## It's More Than Just CIPA

CIPA gets the headlines, but it's only one of [several wiretapping-style laws](https://btlaw.com/en/insights/alerts/2026/cipa-ecpa-website-tracking-privacy-litigation-in-2026) now aimed at the same site behavior. Plaintiffs are increasingly pairing them together in the same lawsuit.

### Florida Security of Communications Act (FSCA)

Florida also requires consent from everyone in a conversation before it can be recorded or tracked. A 2025 court ruling let pixel-tracking claims move forward under this law, and plaintiffs have since filed hundreds of small-claims suits.

### Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA)

Pennsylvania has a similar all-party consent rule. A federal appeals court ruled in *Popa v. Harriet Carter Gifts* that it applies to website tracking too. The "interception" is treated as happening right in the visitor's browser.

### Video Privacy Protection Act (VPPA)

The [VPPA](https://usercentrics.com/us/knowledge-hub/video-privacy-protection-act-vppa/) was originally written to protect video rental records, but courts are now applying it to sites that share video-viewing data through pixels or trackers without proper consent.

### Electronic Communications Privacy Act (ECPA)

The [ECPA](https://usercentrics.com/us/knowledge-hub/electronic-communications-privacy-act-ecpa/) is the federal version of these state wiretapping laws. It's showing up more often alongside state claims like CIPA, FSCA, and WESCA in the same website-tracking lawsuits.

Different states, different statutes, but same underlying complaint: something on the site collected or shared visitor data before the visitor said yes.

## Addressing the Actual Problem

- Check what fires before your cookie banner renders, not what fires after a visitor accepts.
- Confirm non-essential scripts are blocked by default until consent is given, not just hidden from view. (If you don’t have a CMP doing that, start your free trial now.)
- Keep a record of consent choices tied to the specific page and session, so you can show what happened if you're ever asked.
- Revisit your privacy policy against what your site currently does, not what it did when the policy was written.

The [Cookiebot CIPA Consent Template](https://cookiebot.com/us/cipa-consent-template) is built to close exactly this gap. Instead of giving California visitors the same opt-out setup as the rest of your U.S. traffic, it applies a GDPR-style opt-in layer specifically to California IP addresses.

Session replay tools, chatbots, and advertising pixels stay blocked until a California visitor actively says yes. Visitors outside California keep your standard consent experience.

It's ready to use inside your Cookiebot dashboard, so there's no custom development needed to turn it on. It also logs every consent interaction with a timestamp, which is the record that actually matters if a [demand letter](https://www.cookiebot.com/us/understand-and-respond-to-cipa-demand-letter/) arrives. It also supports VPPA and ECPA configuration for sites running embedded video, streaming features, or other tracking that overlaps with CIPA risk on the same site.

None of this is a legal safe harbor, and it's not a substitute for qualified legal counsel to address your specific business operations, privacy compliance needs, or the assistance you need once a claim exists. But it does address trackers firing before consent, which is the exact problem behind nearly every current CIPA filing.

## Get the Cookiebot™ CIPA Consent Template

It's built into Cookiebot CMP. Activate it from your dashboard to start addressing California's CCPA and CIPA consent requirements. Try it free for 14 days.

[Start free trial](https://admin.cookiebot.com/signup)

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot plugin for WordPress](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.4 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)