California Signs Landmark CIPA Reform — Private Pen Register Claims Eliminated with Two-Year Lookback
1. Background
The California Invasion of Privacy Act (“CIPA”), codified at California Penal Code §§ 630–638.55, was originally enacted to protect individuals against eavesdropping and the unauthorized interception of communications. For decades, CIPA was rarely invoked in civil litigation. That changed dramatically when an aggressive plaintiffs’ bar began repurposing the statute to argue that routine website technologies (i.e. analytics tags, tracking pixels, session-replay tools, and chatbot widgets) amount to illegal wiretapping or eavesdropping under §§ 631 and 632, or function as “pen register” or “trap and trace” devices under § 638.51.
Because CIPA permits statutory damages of $5,000 per violation with no requirement that a plaintiff demonstrate actual harm, and because plaintiffs contend that violations may be counted on a per-visitor or per-session basis, ordinary website activity exposed businesses to potentially massive liability. The result has been a flood of demand letters and lawsuits targeting companies and nonprofits of all sizes. According to the sponsors of SB 690, the number of CIPA website-tracking lawsuits grew from roughly 600 to nearly 4,000 since the bill was first introduced. Many of these demand letters are widely believed to have been AI-generated.
It is important to understand that CIPA claims generally fall into two categories: (a) pen register/trap-and-trace claims under § 638.51, and (b) wiretap/eavesdropping claims under §§ 631 and 632. Pen register claims target the collection of metadata and addressing information (such as dialing, routing, or signaling data), while wiretap claims target the interception of the contents of communications. Roughly one-third of CIPA matters filed rest on the pen register/trap-and-trace theory alone, and roughly another third pair that theory with a second CIPA wiretap count.
2. What the New Law Does
On Governor Newsom’s signing of Senate Bill 690, California enacted a targeted reform to its CIPA enforcement framework. SB 690 amends California Penal Code § 637.2 by adding a new subdivision (d), which will take effect on January 1, 2027.
Key provisions of SB 690:
Elimination of private right of action for pen register claims. New § 637.2(d)(1) provides that an action against a private actor for a violation of § 638.51, alleged to arise from conduct occurring on an internet website, online application, or mobile application, may be brought only by the Attorney General. Private plaintiffs will no longer be able to bring pen register claims based on website or app activity.
Two-year lookback provision. New § 637.2(d)(2) provides that the amendments apply retroactively to any pending claim in an action commenced within two years before the January 1, 2027 operative date, that is, covering claims filed since approximately January 1, 2025. This provision is designed to address the wave of litigation that has already been filed.
Preservation of Attorney General Enforcement. SB 690 does not eliminate the underlying prohibition against pen register activity. The Attorney General retains full enforcement authority under § 638.51. The bill narrows only the private right of action.
SB 690 passed the Assembly 66–0 and the Senate 40–0, reflecting broad bipartisan support.
Impact on pending and future claims:
Companies facing pending § 638.51 claims in actions filed in 2025 or 2026 should evaluate whether to seek a stay, hold claims in abeyance, or prepare a dispositive motion timed to the January 1, 2027 operative date.
If a pending matter pairs a pen register theory with a wiretap or eavesdropping theory, then the pen register count will be barred from private enforcement, but the surviving wiretap count will proceed.
Future private plaintiffs will be unable to bring § 638.51 claims for website or app conduct; only the Attorney General may do so.
3. Key Distinction — Pen Registers vs. Wiretaps
SB 690’s reform is textually limited to § 638.51 (pen register and trap-and-trace) violations. It does not alter private rights of action under §§ 631 (wiretapping) or 632 (recording of confidential communications).
Understanding this distinction is critical for assessing your company’s remaining exposure.
Pen register/trap-and-trace claims (§ 638.51):
A “pen register” is defined under § 638.50 as a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility—but not the contents of a communication.
A “trap and trace device” captures incoming electronic impulses identifying the originating number or other addressing information, again, not the contents of a communication.
These claims target metadata collection. Under SB 690, private plaintiffs will no longer be able to bring these claims for website or app conduct. Only the Attorney General may enforce § 638.51 in this context.
Wiretap/eavesdropping claims (§§ 631, 632):
Section 631 prohibits the intentional wiretapping or interception of the contents of wire or electronic communications.
Section 632 prohibits the recording of confidential communications without the consent of all parties.
These claims remain fully viable for private plaintiffs. Companies whose website technologies could be characterized as intercepting the contents of communications—as opposed to merely collecting metadata—remain exposed to private litigation.
Bottom line: If a technology collects only addressing or routing metadata, then it falls under the pen register framework and is now shielded from private suits. If a technology captures the substance of user communications, then it may still support a wiretap claim under §§ 631 or 632.
4. Recommendations
While SB 690 provides significant relief from pen register litigation, it does not eliminate all CIPA exposure. We recommend that clients take the following steps:
Assess your current CIPA exposure. If your company has received demand letters or is facing pending litigation under § 638.51, then contact the PierFerd Privacy and Data Protection practice group to evaluate how SB 690’s two-year lookback provision and the January 1, 2027 operative date affect your pending claims.
Evaluate remaining wiretap risk. Review the website technologies deployed on your platforms—including analytics tools, session-replay software, chatbot implementations, and tracking pixels—to determine whether any could support a wiretap or eavesdropping theory under §§ 631 or 632. Technologies that capture the contents of user interactions (rather than metadata alone) may still give rise to private claims.
Consider litigation strategy for pending matters. If your company has pending matters that include a § 638.51 count, then work with counsel to evaluate whether to seek a stay pending the January 1, 2027 operative date, move for dismissal on the pen register count, or negotiate resolution of any remaining wiretap theories.
Update your privacy compliance framework. Even though private pen register claims will be barred, the underlying prohibition remains in effect, and the Attorney General retains enforcement authority. Ensure that your data-collection practices align with CIPA’s requirements and broader California privacy obligations, including the California Consumer Privacy Act (CCPA).
5. Contact Us
SB 690 represents a landmark development in California privacy litigation, but the CIPA landscape remains complex. The PierFerd Privacy and Data Protection practice group is prepared to help you navigate these changes, assess your exposure under both the lookback window and remaining wiretap theories, and develop a forward-looking compliance and litigation strategy.
We encourage you to reach out to Maryam Meseha, Co-Chair of the PierFerd Privacy and Data Protection Practice Group, or any member of the practice group to discuss how SB 690 affects your organization.
This publication and/or any linked publications herein do not constitute legal, accounting, or other professional advice or opinions on specific facts or matters and, accordingly, the author(s) and PierFerd assume no liability whatsoever in connection with its use. Pursuant to applicable rules of professional conduct, this publication may constitute Attorney Advertising. © 2026 Pierson Ferdinand LLP.