SB 690 Explained: What California's CIPA Reform Bill Actually Does Now
SB 690 was supposed to be the bill that ended the CIPA lawsuit wave. Then, in July 2026, it was gutted and rewritten — and what's left is far narrower than the headlines suggest. If you've heard "California is fixing CIPA" and assumed your exposure is about to disappear, this is the reality check: here's what the amended bill actually does, what it pointedly leaves untouched, and why it changes much less than you'd hope.
As originally drafted, SB 690 would have created a broad "commercial business purpose" exemption shielding routine website tracking from CIPA. That version is gone. After a July 2026 amendment, the bill now does one much narrower thing: it would give the California Attorney General exclusive authority over pen register / trap-and-trace claims (Penal Code §638.51) arising from website and app activity — eliminating the private right of action for that one provision.
Crucially, it leaves §631 (wiretapping) and §632 (confidential communications) private lawsuits fully intact — the theories behind most of the biggest CIPA cases. It is also not yet law. This is general information about a pending bill, not legal advice.
What this guide covers
Few pieces of state legislation have been watched as closely by website operators as SB 690. For businesses buried under CIPA demand letters, it looked like the cavalry — a bill that would finally declare that using ordinary cookies, pixels, and analytics for business isn't illegal wiretapping. That's not the bill that's moving through the California Assembly anymore, and the gap between the original promise and the current text is the whole story.
What SB 690 is
SB 690 is a California bill, introduced by Senator Anna Caballero on February 21, 2025, aimed at the explosion of lawsuits and demand letters brought under the California Invasion of Privacy Act (CIPA) over routine website technologies.[1] CIPA is a 1967 wiretapping statute written for telephone eavesdropping; plaintiffs have repurposed its provisions to argue that cookies, pixels, session-replay tools, and chat widgets amount to illegal interception. SB 690's purpose, from the start, was to tamp down that litigation. How it proposed to do so is what changed dramatically.
The bill passed the California Senate by a unanimous 35–0 vote on June 3, 2025, then stalled in the Assembly, which made it a "two-year bill" — carried over for reconsideration in the 2026 session.[2] When the Assembly finally took it up in mid-2026, it didn't just advance the bill — it fundamentally rewrote it.
What it originally promised — and why businesses cheered
The original SB 690 was ambitious. It sought to create a broad "commercial business purpose" exemption across CIPA's core provisions — its wiretapping (§631), eavesdropping (§632), and pen register / trap-and-trace (§638.51) prohibitions.[3] In plain terms, it would have declared that when a business uses these technologies for a legitimate commercial purpose — analytics, advertising, customer service — that use doesn't constitute unlawful wiretapping or eavesdropping under CIPA.
Had it passed in that form, it would have largely insulated ordinary website tracking from CIPA's private lawsuits — a near-comprehensive answer to the demand-letter wave. An early version even included a retroactivity provision that would have reached pending cases, though that piece was stripped out before the Senate's unanimous vote amid objections from consumer-privacy advocates.[4] Even without retroactivity, the broad exemption is why businesses were optimistic. That optimism is now largely obsolete. (Notably, the current amended version has since restored a narrower retroactivity clause tied to a January 1, 2027 operative date — see “Where it stands” below.)
The July 2026 rewrite that changed everything
On July 1, 2026, the Assembly Committee on Privacy and Consumer Protection heard SB 690 and passed it as amended — and the July 2, 2026 amendment replaced the bill's entire approach.[5] Gone is the broad "commercial business purpose" exemption. In its place is a much narrower proposal focused on a single statutory provision.
As one analysis put it, SB 690 shifted from fundamentally rewriting how CIPA applies to modern business practices, to simply limiting one category of lawsuits. The sweeping exemption that would have covered cookies, pixels, chatbots, and session replay across the whole statute was replaced by a targeted change to who may enforce the pen register provision. That is a categorically smaller intervention.
Why the retreat? The committee analysis is candid: the pen register theory in particular was described as a "poster child for abusive lawsuits," where staggering potential liability pressures businesses into quick settlements and thereby encourages more demand letters.[2] So the amended bill zeroes in on that one provision — but does so by changing enforcement, not by declaring the underlying conduct lawful.
In testimony, the bill’s author noted that §638.51 cases had exploded from roughly 600 when the bill was introduced to more than 4,000 — much of it driven by a small number of firms using repeat plaintiffs.
What the amended bill actually does now
The current version of SB 690 does one specific thing: it would give the California Attorney General exclusive jurisdiction to bring pen register and trap-and-trace claims under Penal Code §§638.50–638.51 (the pen register and trap-and-trace provisions) that arise from conduct on a website, online application, or mobile application.[6]
The practical effect is to remove the private right of action for that one theory. Today, private plaintiffs (and the firms sending demand letters) can bring §638.51 pen register claims themselves. Under the amended bill, only the Attorney General could — meaning the flood of private §638.51 demand letters and lawsuits over website tracking would lose their statutory footing. For the specific and heavily abused pen register theory, that's a meaningful change.
A "private right of action" is what lets an ordinary person (not a government agency) file suit under a statute. Most of the CIPA demand-letter economy runs on private rights of action — individuals and firms filing at scale. Stripping the private right of action from §638.51 wouldn't make website pen registers legal; it would mean only the state's Attorney General could bring that particular claim, which realistically means far fewer of them.
What SB 690 leaves completely untouched
Here's the part that matters most for your risk, and the part the "California is fixing CIPA" headlines obscure. The amended bill touches only §638.51. It leaves the other two workhorse CIPA provisions entirely alone:
- §631 — wiretapping / interception of communications is untouched. Private plaintiffs can still bring §631 claims over trackers that allegedly intercept the contents of a communication in transit.
- §632 — recording confidential communications is untouched. Private plaintiffs can still bring §632 claims, including over session-replay and SDK tools.
This is not a technicality — it's where the biggest cases live. Consider the two most significant CIPA developments of the past year:
- The Flo Health jury verdict against Meta — the first major CIPA jury verdict in history — was under §632. SB 690 wouldn't have touched it.
- The NFL case, built on a session recorder allegedly capturing keystrokes, leads with a §631 "contents" theory. SB 690 wouldn't touch that either.
It's worth understanding why §631 and §632 are the provisions plaintiffs increasingly favor, because it explains why leaving them intact matters so much. The pen register theory under §638.51 has always been the shakiest of the three — it stretches a provision about capturing dialing and routing information to cover website tracking, and courts have split sharply on whether that even works, with several dismissing such claims outright. The §631 and §632 theories, by contrast, are closer to CIPA's core: §631 reaches the interception of the contents of a communication, and §632 the recording of confidential communications. When a session recorder captures what a user types, or an SDK captures a confidential exchange, those theories map onto the conduct far more naturally. So SB 690, as amended, targets the weakest of the three theories while leaving the two strongest fully available to private plaintiffs.
"SB 690 is fixing CIPA, so I can relax." Even if the amended bill passes exactly as written, the §631 and §632 private claims — the theories behind the Flo verdict, the NFL keystroke case, and the healthcare-pixel settlements — remain fully available to private plaintiffs. SB 690 would prune one branch of CIPA litigation. It would not fell the tree.
Don't wait on a bill to reduce your CIPA exposure
Whatever SB 690 becomes, §631 and §632 claims stay live — and they turn on trackers firing without consent. ConsentPixel blocks third-party trackers until visitors genuinely consent, honors opt-outs, and logs the proof, so the fact pattern behind these claims never happens on your site. Start free, or scan first to see where you stand.
There's a broader lesson in how far SB 690 traveled from its original form. A bill can pass one chamber unanimously, generate a year of optimistic commentary, and still emerge transformed into something a fraction of its original scope — or not pass at all. That's the normal texture of legislation, and it's precisely why treating a pending bill as a compliance plan is risky. The version that made businesses hopeful in 2025 is not the version moving in 2026, and the version that ultimately becomes law, if any, may differ again.
Where SB 690 stands
As of this writing, SB 690 is still a pending bill, not law. After passing the Senate 35–0 in June 2025 and being heard and passed as amended by the Assembly Privacy and Consumer Protection Committee on July 1, 2026, it faces further steps in the Assembly and, given the substantial amendments, likely additional negotiation between the chambers. As of mid-August 2026, the bill sits on the Assembly Appropriations Committee’s suspense file following an August 5 hearing — the stage where fiscal bills are held for cost review before the floor. If passed and signed, it carries a January 1, 2027 operative date, so even in the best case it would not take effect until then.[7] The practical deadline to pass the bill this session is August 31, 2026, and commentators expect continued jostling up to that date.[7]
That means several outcomes remain possible: the bill could pass in its narrowed form, be amended again, or fail to clear the legislature this session (as it did in 2025). Even if it passes, it would not take effect immediately. Because the situation is genuinely fluid, treat any single description of "what SB 690 does" — including this one — as a snapshot, and verify the current status before relying on it.
SB 690 has already been rewritten once in a way that dramatically changed its effect. It can change again before the August 31, 2026 deadline. Nothing in this article should be read as predicting the final law — only as describing the bill as it stood after the July 2026 amendment.
Why SB 690 changes less than you'd hope — and what to do
Step back and the strategic picture is clear. Even in the best realistic case for businesses — SB 690 passes exactly as amended — the change is limited to removing private §638.51 pen register claims. That would genuinely reduce one high-volume category of demand letters, which is not nothing. But your underlying exposure would remain, because:
- §631 and §632 private claims survive — and they cover the interception and recording theories behind the largest verdicts and settlements.
- The Attorney General can still bring §638.51 claims — the conduct isn't declared lawful, just reassigned to a different enforcer.
- Other states have their own wiretap laws — a California bill does nothing about Pennsylvania's WESCA, Florida's FSCA, or the other state statutes plaintiffs are increasingly using.
- Retroactivity is back — and it cuts toward plaintiffs’ pending claims, not away from them. An early version’s retroactivity was stripped before the 2025 Senate vote, but the current amended bill restored a retroactivity clause: it would reach pending §638.51 claims within a two-year window tied to its January 1, 2027 operative date. So if the bill passes, certain already-filed private pen-register claims could be extinguished — but this reduces plaintiffs’ pending cases; it does nothing to shield a business’s past conduct from the untouched §631 and §632 theories.
It's also worth being precise about who a narrowed SB 690 would and wouldn't help. A business whose CIPA exposure comes specifically from private §638.51 pen register demand letters — a large share of the current wave — would see real relief if the bill passes, since those private claims would lose their footing. But a business facing a §631 interception theory (say, over a session recorder or a chat tool) or a §632 recording theory (say, over an SDK or session-replay tool) would get essentially nothing from the amended bill; those claims proceed exactly as before. And any business with visitors or exposure outside California gains nothing at all, because SB 690 is a California statute that does nothing about the parallel wiretap laws in other states. The bill's benefit, in other words, is real but narrowly distributed — and impossible to count on until it's actually enacted.
The throughline is that legislation is an unreliable shield. It's uncertain, it's slow, it's narrower than the headlines, and it's outside your control. What's inside your control is what fires on your site. Every one of the surviving CIPA theories — §631, §632, other states' laws — rests on the same fact: a tracker capturing or transmitting a visitor's activity without consent. Remove that fact, and the claims lose their hook regardless of what happens to SB 690.
That's what ConsentPixel is built to deliver: it blocks third-party trackers at the browser level until genuine consent, honors opt-out signals, verifies what actually fires, and logs each decision as evidence. It's a prevention-first consent layer that works the same whether SB 690 passes, fails, or is rewritten again — and it's not legal advice. For your specific position, and for tracking the bill, work with qualified counsel.
The bottom line
SB 690 began as a sweeping fix that would have exempted routine website tracking from CIPA. After the July 2026 rewrite, it's a much narrower bill: it would give the California Attorney General exclusive authority over §638.51 pen register claims from website and app conduct, removing the private right of action for that one provision. That would meaningfully cut one category of abusive demand letters — a real, if partial, win for businesses.
But it leaves §631 and §632 private claims fully intact — the theories behind the Flo verdict, the NFL keystroke case, and the healthcare-pixel settlements — and it isn't law yet. Reading SB 690 as "CIPA risk is over" would be a serious misjudgment.
So watch the bill, but don't build your risk strategy on it. The durable protection is the same whatever the legislature does: block non-essential trackers until consent, honor opt-outs, and keep the proof. That works under the current CIPA, under an amended CIPA, and under every other state's wiretap law — none of which are waiting on a vote in Sacramento.
Build on what you control, not on a pending bill
Whatever happens to SB 690, §631 and §632 claims turn on trackers firing without consent. ConsentPixel blocks them until visitors genuinely agree, honors opt-outs, and logs the evidence. Start a 14-day trial, or scan your site first to see what fires.
Start your 14-day free trial → or browse the CIPA lawsuit tracker →No credit card · from $8.99/domain/mo · information, not legal advice
We build prevention-first consent tooling: blocking third-party trackers until visitors genuinely consent, honoring opt-out signals, continuously verifying what fires, and logging each decision as evidence. This article describes a pending bill for general information as of its date; legislation changes, so verify the current status of SB 690 and your own position with qualified counsel. ConsentPixel — Privacy · Verified is not a law firm and takes no position on the policy merits of the legislation described.
Frequently asked questions
What does SB 690 do in its current form?
As amended in July 2026, SB 690 would give the California Attorney General exclusive jurisdiction over pen register and trap-and-trace claims under Penal Code §§638.50–638.51 (the pen register and trap-and-trace provisions) that arise from conduct on a website, online application, or mobile application — effectively removing the private right of action for that one CIPA provision. It no longer contains the broad "commercial business purpose" exemption from its original version. It leaves CIPA's §631 (wiretapping) and §632 (confidential communications) private claims untouched. Note that SB 690 is a pending bill, not current law, and its text has already changed significantly; verify its status before relying on it. This is general information, not legal advice.
Did SB 690 already become law?
No. As of this writing SB 690 is still a pending bill. It passed the California Senate 35–0 in June 2025, became a two-year bill after stalling in the Assembly, and was heard and passed as amended by the Assembly Privacy and Consumer Protection Committee on July 1, 2026. It still faces further steps, and the practical deadline to pass this session is August 31, 2026. It could pass in its narrowed form, be amended again, or fail to advance, as it did in 2025. Even if enacted, it would not take effect immediately. Confirm the current status before relying on any description of it.
Why was SB 690 changed so much?
The original SB 690 proposed a broad "commercial business purpose" exemption that would have shielded routine website tracking across CIPA's wiretap, eavesdropping, and pen register provisions. In July 2026 the Assembly rewrote it into a far narrower measure focused only on the pen register provision (§638.51), which a committee analysis described as a "poster child for abusive lawsuits" because staggering potential liability pressures businesses into quick settlements. Rather than declaring the conduct lawful, the amended bill changes who may enforce that one provision — giving the Attorney General exclusive authority — which is a much smaller intervention than the original exemption.
If SB 690 passes, is my CIPA risk gone?
No. Even if the amended bill passes exactly as written, it only removes private §638.51 pen register claims. Private lawsuits under §631 (wiretapping) and §632 (confidential communications) remain fully available — and those are the theories behind the biggest CIPA outcomes, including the Flo Health jury verdict against Meta (§632) and the session-replay keystroke cases (§631). The California Attorney General could still bring §638.51 claims, other states have their own wiretap laws unaffected by a California bill, and nothing applies retroactively. SB 690 would prune one category of litigation, not end CIPA exposure. This is general information, not legal advice.
What's the difference between §631, §632, and §638.51?
They're three provisions of CIPA that plaintiffs use against website tracking. §631 is the wiretapping provision, covering interception of the contents of a communication while in transit — used against trackers and session recorders that allegedly capture what a user types or sends. §632 covers the recording of confidential communications without all-party consent — used, for example, against SDK and session-replay tools, and the basis of the Flo Health verdict. §638.51 is the pen register / trap-and-trace provision, originally about capturing dialing and routing information, repurposed against website tracking. SB 690, as amended, targets only §638.51, leaving §631 and §632 private claims intact.
What should my business do while SB 690 is pending?
Don't build your risk strategy around a bill that's uncertain, narrow, and outside your control. The durable protection is the same regardless of what the legislature does: block non-essential third-party trackers until a visitor genuinely consents, honor opt-out signals (including Global Privacy Control) across cookie-based and cookieless tools, keep session replay off sensitive fields, and log each consent decision as evidence. That posture removes the fact pattern every surviving CIPA theory depends on — trackers firing without consent — and it also addresses other states' wiretap laws that a California bill wouldn't touch. Track the bill with qualified counsel, but act on what you control now. This is general information, not legal advice.