On September 30, 2026, the California Governor signed SB 690, which amends the California Invasion of Privacy Act (CIPA) to restrict private enforcement—but only for claims under CIPA’s pen register and trap-and-trace provisions arising from websites and online or mobile applications.
As we had previously written, the bill originally created additional exclusions, but the legislative process narrowed its scope. This new law not only bars new private lawsuits alleging CIPA violations based on its pen register and trap-and-trace provisions, but also applies retroactively to any claim pending in an action commenced within the past two years.
The Governor signed the bill, but made clear in his signing letter that he would like to see additional legislation next year:
This measure addresses the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites that at times have tracked and shared the information of visitors of the site. I applaud the author’s efforts and align myself with the goal of protecting small businesses from overzealous lawsuits based on a statute written without today’s complex technological landscape in mind . However, additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants. I urge the Legislature to take this on next year to ensure a fair balance between protecting privacy information and preventing rapacious litigation.
The Texas Attorney General on September 17 issued a warning about CIPA lawsuits and demand letters. The warning stated that: “Demand letters of this type may exaggerate or misrepresent a potential violation of law.” It also advised, “While receiving such a letter can be concerning, entities should not respond directly to the sender or provide payment without first consulting qualified legal counsel, if possible.”
Our Take
We are already seeing signs of this shift. Plaintiffs increasingly contend that website search queries, information entered into forms, chat interactions, and allegedly ineffective cookie opt-out mechanisms involve the interception of communication contents or fraudulently deceive consumers into believing that their communications are confidential. Expect plaintiffs’ lawyers to continue developing increasingly creative theories designed to recast ordinary website functionality as the interception of protected communications. The success of those theories will likely determine the next chapter of privacy litigation.


