Governor Gavin Newsom signed Senate Bill 690 on September 30, 2026, limiting private lawsuits under the California Invasion of Privacy Act (CIPA) related to website-tracking technologies. This raises a key question for your legal team: does your current compliance strategy still hold, or should you adjust now that one litigation risk has been reduced?
SB 690 changes the landscape for pen register and trap-and-trace claims, but it doesn't eliminate exposure under other laws or excuse poor tracking practices. Your decision should consider your risk profile, business model, and the state of your tracking infrastructure.
The Decision You're Facing
You need to decide whether to:
Path A: Maintain your current tracking compliance framework
Path B: Scale back measures that were primarily CIPA-driven
Path C: Rebuild your tracking stack from the ground up
Choosing the wrong path could waste resources or leave you vulnerable. The right choice requires understanding SB 690's impact and what remains unchanged.
Key Factors That Affect Your Choice
Your historical litigation exposure. If you've faced CIPA-related lawsuits over your Tag Manager or analytics pixels, SB 690 directly addresses those claims. The law aims to protect small businesses from what Governor Newsom described as "vexatious use of CIPA lawsuits."
Your regulatory compliance obligations beyond CIPA. SB 690 doesn't affect the California Consumer Privacy Act (CCPA), your obligations under the ePrivacy Regulation for EU visitors, or the EDPB Guidelines on Valid Consent. If your framework was built to meet these requirements, SB 690's changes don't alter your baseline obligations.
The complexity of your tracking ecosystem. If you're using complex tracking methods like Container Tags, Hashed Email Identifiers, or Canvas Fingerprinting, your compliance risk extends beyond pen register theories. SB 690 doesn't permit deploying tracking technologies without a proper legal basis.
Your appetite for being an early test case. The statute aims to address lawsuits "based on a statute written without today's complex technological landscape in mind." While this suggests courts will limit older theories, there's no case law yet to define the new boundaries.
Path A: Maintain Your Current Framework
Choose this path if:
Your compliance program is based on CCPA requirements, consent for California residents, or multi-jurisdictional obligations beyond CIPA. SB 690 removes one litigation risk but doesn't lower standards for consent or purpose disclosure.
You're in a regulated industry where tracking practices face scrutiny from sector-specific regulators. Financial services, healthcare, and telecommunications should expect examination regardless of CIPA's private enforcement mechanism.
You receive significant traffic from the EU, UK, or other regions with strict consent requirements. If you're already implementing prior consent and granular consent notices, scaling back to save costs doesn't make sense.
What this looks like in practice:
Continue using your Consent Management Platform as configured. Keep your cookie audit schedule and vendor review process. Document your legal basis for each tracking technology.
Your compliance budget remains stable, and you're protected if courts interpret SB 690 narrowly or if plaintiffs' counsel shifts strategies.
Path B: Scale Back CIPA-Specific Defensive Measures
Choose this path if:
You implemented tracking restrictions solely to avoid CIPA claims, and those don't align with your actual obligations. If you disabled analytics features due to theoretical CIPA exposure, you can revisit that decision.
You're a small business targeted by demand letters for standard website analytics. SB 690 was designed to curb "overzealous lawsuits" against businesses that "unwittingly install software."
You operate only in California, without CCPA obligations for granular consent, and aren't subject to sector-specific regulations. This narrow category has more flexibility post-SB 690.
What this looks like in practice:
Re-enable tracking features disabled for CIPA risk. Simplify vendor approval for analytics tools without CCPA obligations. Reduce legal review frequency for standard Tag Manager setups.
You're not abandoning compliance; you're aligning your program with actual legal requirements instead of theoretical risks.
Path C: Rebuild Your Tracking Stack
Choose this path if:
Your tracking infrastructure has accumulated technical debt, and SB 690 provides an opportunity for overhaul. You might have legacy Container Tags or third-party vendors misaligned with data governance standards.
You're aiming for Data Protection by Design, not retrofitting compliance. Consider whether you need third-party cookies, can shift to server-side tracking, or achieve goals with consent-exempt cookies.
You're expanding into stricter jurisdictions and want a global standard. Building for the EDPB Guidelines on consent offers a framework that works in California and satisfies EU requirements.
What this looks like in practice:
Audit every tag in your Tag Manager. Document the purpose of each tracking tool. Consider less invasive methods. Implement partitioned cookies where suitable. Build a consent architecture supporting withdrawal and renewal.
This path requires budget and executive support, but SB 690's passage is a good moment to propose it.
Summary Matrix
| Factor | Path A: Maintain | Path B: Scale Back | Path C: Rebuild |
|---|---|---|---|
| Multi-jurisdictional obligations | Yes | No | Yes |
| CCPA compliance requirements | Yes | Minimal | Yes |
| Recent CIPA litigation | Low impact | High impact | Medium impact |
| Tracking stack complexity | Well-documented | Simple/standard | Complex/legacy |
| Regulatory scrutiny | High | Low | Variable |
| Budget for changes | Maintenance-level | Reduction possible | Investment required |
| Risk tolerance | Conservative | Moderate | Forward-looking |
SB 690 isn't a crisis or a free pass. It's a recalibration of one specific litigation risk within a broader compliance landscape. Your tracking stack should reflect your legal obligations, business model, and risk appetite. The statute allows revisiting decisions made to avoid CIPA exposure, but it doesn't change the fundamentals of lawful tracking or immunity from other enforcement.
If you're unsure which path fits, start by documenting why you made each tracking decision. If the reason is "CIPA litigation risk" alone, you have flexibility now. If it involves CCPA, ePrivacy Regulation, sector-specific rules, or data governance standards, SB 690 doesn't change your approach.




