Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
SB 690 Closes California's Privacy Litigation WindowLaws and Regulations
4 min readFor Legal Counsel

SB 690 Closes California's Privacy Litigation Window

Scope

This guide explains how SB 690 eliminates private rights of action under the California Invasion of Privacy Act (CIPA) Section 638.51, which has led to numerous digital-privacy lawsuits since 2022. If Governor Newsom signs the bill, your organization will face a new enforcement landscape in California.

Use this reference when assessing litigation exposure, updating legal budgets, or recalibrating compliance priorities for California operations.

Key Concepts and Definitions

California Invasion of Privacy Act (CIPA): Originally designed to prevent unauthorized phone-line interception, this statute has been applied to digital tracking technologies, allowing website visitors to file lawsuits.

Section 638.51 (Pen Register Provision): This section prohibits the installation or use of pen registers without authorization. Plaintiffs have used it to target session-replay tools, analytics scripts, and third-party tracking pixels.

Private Right of Action: This allows individuals to file lawsuits directly, without waiting for government action. SB 690 removes this right under Section 638.51.

SB 690: This bill, passed unanimously by the California Assembly and Senate, eliminates private lawsuits under the pen register provision while preserving government enforcement authority.

The Litigation Pattern SB 690 Addresses

Since 2022, over 5,300 digital-privacy lawsuits have been filed, with 85% in California. Nearly all included CIPA claims, and two-thirds specifically cited Section 638.51.

This concentration indicates that California's private right of action created a unique litigation environment. Plaintiffs' firms developed templates, identified vulnerable website configurations, and filed in volume.

Your compliance strategy likely reflected this. You may have prioritized California-specific risk assessments or conducted pen register audits. If SB 690 becomes law, that strategy will need to change.

What Changes (and What Doesn't)

What SB 690 eliminates:

  • Private lawsuits under Section 638.51
  • Financial incentives for plaintiffs' firms to file in volume
  • Statutory damages claims tied to pen register allegations
  • The need to defend against individual plaintiff actions in this area

What remains:

  • Government enforcement by the California Attorney General
  • All other CIPA provisions and their enforcement mechanisms
  • CCPA private rights of action for data breaches
  • Federal wiretapping claims under different statutes
  • Common-law privacy torts

SB 690 shifts the risk from high-volume private litigation to lower-frequency but potentially higher-stakes government enforcement.

Implementation Guidance

If the Bill Becomes Law

Immediate actions:

  1. Reassess your litigation reserves. If you've budgeted for CIPA defense costs based on past filings, you can likely reduce those projections. Consult your finance team about reallocation.

  2. Review pending CIPA matters. If you're defending Section 638.51 claims filed before the effective date, determine whether the law applies retroactively. Your outside counsel should brief you on transition provisions.

  3. Update your risk matrix. California may drop from your highest-risk jurisdiction for privacy litigation. Adjust your compliance prioritization accordingly, but maintain oversight.

  4. Preserve your documentation practices. Government enforcers will expect the same diligence you maintained under private-action risk. Keep your consent records, vendor contracts, and configuration audits current.

Medium-term strategy:

  1. Watch for Attorney General priorities. Without private plaintiffs driving enforcement, the AG's office will set the agenda. Monitor their press releases and enforcement actions to understand where scrutiny will focus.

  2. Compare with other jurisdictions. Illinois, Washington, and other states maintain private rights of action under their wiretapping statutes. If you operate nationally, your compliance baseline should meet the strictest standard, not just California's new posture.

  3. Revisit your session-replay and analytics configurations. These tools triggered many Section 638.51 claims. Even without private litigation risk, they still raise consent and transparency questions under CCPA and common law.

If the Governor Vetoes

If Newsom declines to sign SB 690, the current litigation environment continues. Your existing CIPA compliance program remains your baseline. Don't make changes in anticipation of a law that hasn't taken effect.

Common Pitfalls

Assuming SB 690 eliminates all California privacy risk. It doesn't. CCPA enforcement continues. The Attorney General can still pursue CIPA violations. You're removing one enforcement channel, not the underlying obligations.

Treating this as a national shift. It isn't. Other states haven't followed California's lead. If you operate in Illinois, you still face Biometric Information Privacy Act exposure. If you operate in Washington, the state's privacy act includes its own enforcement mechanisms.

Cutting compliance resources too aggressively. Yes, you can reduce litigation reserves. No, you shouldn't eliminate your privacy program. Government enforcement may be less frequent, but penalties can be steeper and reputational damage more severe.

Ignoring the political signal. A 66-0 Assembly vote and 40-0 Senate vote indicate broad legislative consensus that the private-action model wasn't working as intended. That consensus may inform future privacy legislation. Stay engaged with California's legislative process.

Quick Reference Table

Element Before SB 690 After SB 690 (if signed)
Private lawsuits under Section 638.51 Authorized Eliminated
Attorney General enforcement Available Unchanged
CCPA private right of action Data breaches only Unchanged
Other CIPA provisions Private action available Unchanged
Litigation volume (projected) High (85% of 5,300+ cases) Significantly reduced
Compliance documentation standard Must defend against private claims Must satisfy government review
Session-replay/analytics risk Primary litigation target Still requires consent analysis
Multi-state operators Must meet California + other states Must meet strictest state standard

Bottom line: SB 690 doesn't eliminate your California privacy obligations. It changes who enforces them and how often you'll defend your practices in court. Adjust your budget and risk assessment, but maintain your compliance rigor.

Promotional banner for the Penetration Report Template Kit

You Might Also Like