Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

California SB 690 was signed on September 30, 2026, and is reported to take effect January 1, 2027. It limits who can bring a specific kind of California Invasion of Privacy Act (CIPA) claim: a private lawsuit against a private actor alleging a violation of Penal Code Section 638.51 arising from conduct on a website, online application, or mobile application. For those claims, only the California Attorney General may sue under the amended provision. The change does not end every lawsuit over online tracking or repeal California wiretapping law.

What SB 690 changes

Section 638.51 is CIPA’s pen-register and trap-and-trace provision. Legal analyses describe SB 690’s enacted amendment as restricting private actions against private actors when a Section 638.51 violation is alleged to arise from conduct on an internet website, online application, or mobile application. The statutory sentence reproduced in Morgan Lewis’s analysis says: “An action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.” Morgan Lewis

In practical terms, the reported change is about enforcement of that defined claim, not a general ruling that website tracking is lawful. It does not establish that every analytics or advertising tool violates Section 638.51, nor does it decide whether the provision applied to internet communications before the amendment. Fenwick notes that the question of Section 638.51’s underlying application to internet communications remains distinct from the new limit on private actions. Fenwick

What the law does not remove

SB 690 should not be described as ending all private enforcement under CIPA, eliminating all claims involving surveillance, or creating blanket immunity for commercial websites. The analyses report that private claims under CIPA Sections 631 and 632 are not affected by this amendment, and that federal Wiretap Act claims or other applicable legal theories are not foreclosed. Whether any particular claim can proceed depends on its facts, legal basis, and applicable law. DLA Piper Morgan Lewis

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Issue What the reported amendment means
CIPA Section 638.51 claim arising from website or app conduct Only the Attorney General may bring an action against a private actor under this section.
Private CIPA claims under Sections 631 or 632 The reported amendment does not remove these claims.
Federal or other legal theories Not foreclosed by SB 690; availability depends on the claim and facts.

When it takes effect and what retroactivity means

Current legal analyses report that Governor Gavin Newsom signed SB 690 on September 30, 2026, and that it becomes effective January 1, 2027. They also report retroactive application to qualifying pending actions commenced during the two years before the operative date, including actions commenced on or after January 1, 2025. That does not mean every claim filed since that date automatically disappears: the reported rule is limited to pending actions within the provision’s defined scope. Morgan Lewis DLA Piper

  • Signed: September 30, 2026, according to current legal analyses.
  • Reported effective date: January 1, 2027.
  • Reported retroactive reach: qualifying pending Section 638.51 actions commenced on or after January 1, 2025.

Why website tracking became part of the debate

Recent lawsuits have invoked a telephone-era pen-register law against online advertising and analytics practices. As described in legal commentary, plaintiffs have alleged that tracking technologies capture IP addresses or other metadata in ways that implicate Section 638.51. Those are allegations and legal theories, not a judicial determination that all such technologies violate the statute. DLA Piper identifies Section 638.51’s $5,000-per-violation statutory damages provision as one factor associated with the litigation wave; that figure is litigation context, not a new penalty created by SB 690. DLA Piper

Rank #2
Notary Privacy Guard Suitable for Journal of Notarial Events
  • No more exposed information in unprotected notary journals. This product shields clients' confidential information from prying eyes. It allows the Notary Public to keep the journal open during the transaction, as NO prior client information is viewable.
  • Shields clients' AND Notaries Public' confidential information
  • GLBA and HIPAA require strict confidentiality policies and procedures. Notary Privacy Guard is a compliance tool for the professional Notary Public.
  • Decreases Notary Public's liability from exposing client information
  • Journal column headers are printed on the Notary Privacy Guard, no having to peek underneath to complete the journal entry. Becomes part of the journal and also acts as a place marker.

An earlier 2025 legislative summary described a broader proposed exemption tied to a “commercial business purpose.” That proposal should not be confused with the narrower change reported in the enacted law, which concerns private Section 638.51 claims tied to website and app conduct. California legislative summary Morgan Lewis

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What businesses should review

The amendment is not a general compliance safe harbor. Businesses may want to reassess how tracking technologies are deployed, how consent-management processes work, and whether privacy disclosures accurately describe data collection and sharing. A review by privacy counsel or a qualified website-tracking specialist can help evaluate a business’s particular practices, but neither a service nor a software tool guarantees compliance. Fenwick DLA Piper

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 2
Notary Privacy Guard Suitable for Journal of Notarial Events
Notary Privacy Guard Suitable for Journal of Notarial Events
Shields clients' AND Notaries Public' confidential information; Decreases Notary Public's liability from exposing client information
$9.95
Bestseller No. 3
Blumberg's Law Products Official Journal of Notarial Acts without Privacy Guard Published by National Notary Association (Softcover 5-Pack)
Blumberg's Law Products Official Journal of Notarial Acts without Privacy Guard Published by National Notary Association (Softcover 5-Pack)
Published by National Notary Association; Record full details of 488 notarizations in this notary journal
$106.25
Rank #3
Blumberg's Law Products Official Journal of Notarial Acts without Privacy Guard Published by National Notary Association (Softcover 5-Pack)
  • Published by National Notary Association
  • Record full details of 488 notarizations in this notary journal
  • Heavyweight ledger paper with special area for a thumbprint
  • 122 pages
  • 10-7/8" wide x 8-7/16" high

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.