Businesses with websites that employ cookies and other tracking technologies (collectively, “internet tracking technology”) can breathe a partial sigh of relief. The private right of action under the California Invasion of Privacy Act (“CIPA”), relating to violations of Section 638.51 “alleged to arise from conduct occurring on an internet website, online application, or mobile application,” will be eliminated as of January 1, 2027, as Governor Newsom signed SB-690 on September 30, 2026. The law is retroactive and will apply to all pending lawsuits that commenced after January 1, 2025. Only the California Attorney General will be able to bring pen register and trap-and-trace claims related to conduct occurring on websites, apps, and mobile apps.
However, SB-690 is not a total shield to CIPA claims arising from internet tracking technology, as it does not address other CIPA provisions such as wiretapping (Section 631) and eavesdropping (Section 632), which are frequently used by plaintiffs to target common internet tracking technology notwithstanding that these laws predate internet tracking technology and conflict with the way the newer California Consumer Privacy Act regulates them. In Governor Newsom’s signing statement, he specifically called on the California Legislature to address CIPA again next year to address CIPA’s “other decades-old statutes that are also susceptible to abuse by overly aggressive litigants,” while “ensur[ing] a fair balance between protecting private information and preventing rapacious litigation.”
While pen register claims will soon be relegated to the exclusive authority of the California Attorney General, plaintiffs frequently allege a laundry-list of privacy violations (e.g., federal law, other state laws, common law, constitutional violations) related to the same internet tracking technologies.
Now is a great time to audit your website and app internet tracking technologies, especially given that privacy programs and notices should be updated annually. Here are some initial key action items to include in that review:
Of course, this list is in no way definitive and does not address all privacy claims that are now being raised concerning internet tracking technology or the nuances of the law developing in this area. A more detailed review of marketing practices and internet-based collection is required to fully assess risk and craft ways to reduce liability while still achieving the business’s goals.
Please feel to reach out to the author if you have any questions.
Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.
Stay Ahead on Consumer Privacy News
Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.
Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

