California Takes Aim at CIPA Website Lawsuit Wave

California businesses may soon get significant relief from one of the most aggressively used theories in the recent wave of litigation under the California Invasion of Privacy Act (“CIPA”).

The California Legislature has passed Senate Bill 690, which would eliminate private lawsuits under CIPA’s pen register and trap-and-trace provision for conduct occurring on websites and online or mobile applications. The bill now awaits action by Governor Gavin Newsom. If it becomes law, only the California Attorney General could bring these claims under California Penal Code § 638.51. The restriction would also apply to pending § 638.51 claims in lawsuits filed during the two years before the legislation becomes operative, potentially affecting cases and demands already being litigated or negotiated.

Section 638.51 has fueled a wave of demand letters and lawsuits targeting ordinary website technologies. Plaintiffs have increasingly characterized cookies, pixels, analytics tools, and other software that collects IP addresses or similar routing information as illegal “pen registers.” Because CIPA provides statutory damages of $5,000 per violation without requiring proof of actual damages, these claims can create substantial potential exposure and settlement leverage even where there is no alleged injury. SB 690 would largely shut down this theory for websites and apps while preserving enforcement authority for the Attorney General.

The bill would not, however, end CIPA website litigation. Most importantly, SB 690 leaves California Penal Code § 631 intact. Plaintiffs have relied on § 631 to challenge pixels, session replay software, chat tools, and other website technologies based on the alleged interception of communications. Earlier versions of SB 690 proposed a broader exemption for commercial business activity, but the Legislature removed that language from the final bill.

Businesses that have already received CIPA demand letters or settlement demands from plaintiffs’ attorneys should consult with counsel before responding or resolving those claims, as SB 690 could materially affect their validity and settlement value. At the same time, businesses should continue reviewing their website tracking technologies, consent mechanisms, and privacy disclosures because § 631 and other privacy laws would remain in place.

Previous
Previous

Texts, AI, State Laws & Robocalls: What’s Changing in Outbound Compliance

Next
Next

No Call, No Claim: Missouri Court Dismisses TCPA Text Case