California SB 690 & CIPA: What It Means for Tag Governance

Estimated Reading Time: 2 minutes
September 9, 2026

California Senate Bill 690 (SB 690) targets the recent explosion of website privacy litigation by amending CIPA’s civil remedy provision. Rather than rendering unmanaged website tracking legal, the bill changes who can bring pen-register lawsuits rather than altering the technical requirements for web data collection.

What SB 690 Does

Strips Private Pen Register Lawsuits: Eliminates the private right of action under CIPA § 638.51, preventing class-action lawyers from filing suits over online “pen register” or “trap and trace” metadata tracking on websites and apps.

Shifts Enforcement to the AG: Moves exclusive authority to prosecute web pen-register violations directly to the California Attorney General.

Preserves Statutory Violations: Keeps the underlying statutory prohibition intact, meaning non-compliant tag behavior remains illegal. It instead moves enforcement from private bounty-hunter litigation to state regulatory scrutiny.

What It Changes (and Doesn't Change) for Tag Governance

DOES NOT Eliminate Private Wiretapping Risk: Section 631 wiretapping and eavesdropping claims remain active for private litigation. Class-action attorneys are already pivoting to target the exact same analytics pixels, session replay tools, and chat widgets under § 631.

DOES NOT Change the Need for Technical Pre-Consent Proof: Having a cookie banner on your site isn’t a defense unless you can prove it stops tags from firing. Mitigating wiretapping risk demands verified, automated proof that high-risk marketing and analytics tags stay completely dark until an explicit CMP opt-in signal fires.

CHANGES Your Strategy from Dodging Lawsuits to Proving Compliance: Static annual privacy audits won’t protect you when tag managers load unvetted technology. Staying compliant requires continuous tag auditing and maintaining a historical record to prove to courts or regulators that tags are executed according to user consent choices.

In short, SB 690 eliminates one specific cause of action, but it doesn’t solve the underlying technical problem of unmanaged client-side tracking. Much of the same risk still exists and the laws still apply. Having a mechanism to validate and prove compliance will make it easier to squash private litigation stemming from wiretapping claims, but this proof will be required if any enforcement is brought from the AG.

Author

  • Lucas Long is co-author of the Amazon best-selling book, Crawl, Walk, Run: Becoming a Privacy-Centric Marketing Organization. He is also the Director of Privacy Strategy at InfoTrust, working with global organizations at the intersection of digital strategy, privacy regulations, and technical data collection architecture. Through these efforts, Lucas helps companies understand their limitations for data enablement due to privacy challenges and design optimal ways to accomplish core use cases in a compliant manner.

    When not discussing the intricacies of GDPR and cookie laws with clients, Lucas enjoys traveling and exploring new cultures, one bite at a time. Based in Barcelona, he is also a presenter, featured at industry events organized by Google, the Digital Analytics Association, the American Marketing Association, and the Journal of Applied Marketing Analytics.

    View all posts Head of Global Privacy Strategy
Last Updated: September 9, 2026

Get Your Assessment

Talk To Us

Receive Book Updates

Fill out this form to receive email announcements about Crawl, Walk, Run: Advancing Analytics Maturity with Google Marketing Platform. This includes pre-sale dates, official publishing dates, and more.

Search InfoTrust

Leave Us A Review

Leave a review and let us know how we’re doing. Only actual clients, please.