California Senate Bill 690 (SB 690) targets the recent explosion of website privacy litigation by amending CIPA’s civil remedy provision. Rather than rendering unmanaged website tracking legal, the bill changes who can bring pen-register lawsuits rather than altering the technical requirements for web data collection.
What SB 690 Does
Strips Private Pen Register Lawsuits: Eliminates the private right of action under CIPA § 638.51, preventing class-action lawyers from filing suits over online “pen register” or “trap and trace” metadata tracking on websites and apps.
Shifts Enforcement to the AG: Moves exclusive authority to prosecute web pen-register violations directly to the California Attorney General.
Preserves Statutory Violations: Keeps the underlying statutory prohibition intact, meaning non-compliant tag behavior remains illegal. It instead moves enforcement from private bounty-hunter litigation to state regulatory scrutiny.
What It Changes (and Doesn't Change) for Tag Governance
DOES NOT Eliminate Private Wiretapping Risk: Section 631 wiretapping and eavesdropping claims remain active for private litigation. Class-action attorneys are already pivoting to target the exact same analytics pixels, session replay tools, and chat widgets under § 631.
DOES NOT Change the Need for Technical Pre-Consent Proof: Having a cookie banner on your site isn’t a defense unless you can prove it stops tags from firing. Mitigating wiretapping risk demands verified, automated proof that high-risk marketing and analytics tags stay completely dark until an explicit CMP opt-in signal fires.
CHANGES Your Strategy from Dodging Lawsuits to Proving Compliance: Static annual privacy audits won’t protect you when tag managers load unvetted technology. Staying compliant requires continuous tag auditing and maintaining a historical record to prove to courts or regulators that tags are executed according to user consent choices.
In short, SB 690 eliminates one specific cause of action, but it doesn’t solve the underlying technical problem of unmanaged client-side tracking. Much of the same risk still exists and the laws still apply. Having a mechanism to validate and prove compliance will make it easier to squash private litigation stemming from wiretapping claims, but this proof will be required if any enforcement is brought from the AG.