Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Should You Restructure Your California Tracking Stack After SB 690?Laws and Regulations
4 min readFor Legal Counsel

Should You Restructure Your California Tracking Stack After SB 690?

Governor Gavin Newsom signed Senate Bill 690 on September 30, 2026, limiting private lawsuits under the California Invasion of Privacy Act (CIPA) related to website-tracking technologies. This raises a key question for your legal team: does your current compliance strategy still hold, or should you adjust now that one litigation risk has been reduced?

SB 690 changes the landscape for pen register and trap-and-trace claims, but it doesn't eliminate exposure under other laws or excuse poor tracking practices. Your decision should consider your risk profile, business model, and the state of your tracking infrastructure.

The Decision You're Facing

You need to decide whether to:

Path A: Maintain your current tracking compliance framework
Path B: Scale back measures that were primarily CIPA-driven
Path C: Rebuild your tracking stack from the ground up

Choosing the wrong path could waste resources or leave you vulnerable. The right choice requires understanding SB 690's impact and what remains unchanged.

Key Factors That Affect Your Choice

Your historical litigation exposure. If you've faced CIPA-related lawsuits over your Tag Manager or analytics pixels, SB 690 directly addresses those claims. The law aims to protect small businesses from what Governor Newsom described as "vexatious use of CIPA lawsuits."

Your regulatory compliance obligations beyond CIPA. SB 690 doesn't affect the California Consumer Privacy Act (CCPA), your obligations under the ePrivacy Regulation for EU visitors, or the EDPB Guidelines on Valid Consent. If your framework was built to meet these requirements, SB 690's changes don't alter your baseline obligations.

The complexity of your tracking ecosystem. If you're using complex tracking methods like Container Tags, Hashed Email Identifiers, or Canvas Fingerprinting, your compliance risk extends beyond pen register theories. SB 690 doesn't permit deploying tracking technologies without a proper legal basis.

Your appetite for being an early test case. The statute aims to address lawsuits "based on a statute written without today's complex technological landscape in mind." While this suggests courts will limit older theories, there's no case law yet to define the new boundaries.

Path A: Maintain Your Current Framework

Choose this path if:

Your compliance program is based on CCPA requirements, consent for California residents, or multi-jurisdictional obligations beyond CIPA. SB 690 removes one litigation risk but doesn't lower standards for consent or purpose disclosure.

You're in a regulated industry where tracking practices face scrutiny from sector-specific regulators. Financial services, healthcare, and telecommunications should expect examination regardless of CIPA's private enforcement mechanism.

You receive significant traffic from the EU, UK, or other regions with strict consent requirements. If you're already implementing prior consent and granular consent notices, scaling back to save costs doesn't make sense.

What this looks like in practice:

Continue using your Consent Management Platform as configured. Keep your cookie audit schedule and vendor review process. Document your legal basis for each tracking technology.

Your compliance budget remains stable, and you're protected if courts interpret SB 690 narrowly or if plaintiffs' counsel shifts strategies.

Path B: Scale Back CIPA-Specific Defensive Measures

Choose this path if:

You implemented tracking restrictions solely to avoid CIPA claims, and those don't align with your actual obligations. If you disabled analytics features due to theoretical CIPA exposure, you can revisit that decision.

You're a small business targeted by demand letters for standard website analytics. SB 690 was designed to curb "overzealous lawsuits" against businesses that "unwittingly install software."

You operate only in California, without CCPA obligations for granular consent, and aren't subject to sector-specific regulations. This narrow category has more flexibility post-SB 690.

What this looks like in practice:

Re-enable tracking features disabled for CIPA risk. Simplify vendor approval for analytics tools without CCPA obligations. Reduce legal review frequency for standard Tag Manager setups.

You're not abandoning compliance; you're aligning your program with actual legal requirements instead of theoretical risks.

Path C: Rebuild Your Tracking Stack

Choose this path if:

Your tracking infrastructure has accumulated technical debt, and SB 690 provides an opportunity for overhaul. You might have legacy Container Tags or third-party vendors misaligned with data governance standards.

You're aiming for Data Protection by Design, not retrofitting compliance. Consider whether you need third-party cookies, can shift to server-side tracking, or achieve goals with consent-exempt cookies.

You're expanding into stricter jurisdictions and want a global standard. Building for the EDPB Guidelines on consent offers a framework that works in California and satisfies EU requirements.

What this looks like in practice:

Audit every tag in your Tag Manager. Document the purpose of each tracking tool. Consider less invasive methods. Implement partitioned cookies where suitable. Build a consent architecture supporting withdrawal and renewal.

This path requires budget and executive support, but SB 690's passage is a good moment to propose it.

Summary Matrix

Factor Path A: Maintain Path B: Scale Back Path C: Rebuild
Multi-jurisdictional obligations Yes No Yes
CCPA compliance requirements Yes Minimal Yes
Recent CIPA litigation Low impact High impact Medium impact
Tracking stack complexity Well-documented Simple/standard Complex/legacy
Regulatory scrutiny High Low Variable
Budget for changes Maintenance-level Reduction possible Investment required
Risk tolerance Conservative Moderate Forward-looking

SB 690 isn't a crisis or a free pass. It's a recalibration of one specific litigation risk within a broader compliance landscape. Your tracking stack should reflect your legal obligations, business model, and risk appetite. The statute allows revisiting decisions made to avoid CIPA exposure, but it doesn't change the fundamentals of lawful tracking or immunity from other enforcement.

If you're unsure which path fits, start by documenting why you made each tracking decision. If the reason is "CIPA litigation risk" alone, you have flexibility now. If it involves CCPA, ePrivacy Regulation, sector-specific rules, or data governance standards, SB 690 doesn't change your approach.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like