California Governor Gavin Newsom has signed Senate Bill 690 into law, narrowing the scope of the California Invasion of Privacy Act (CIPA) to limit lawsuits targeting online businesses, including adult websites. The new law eliminates the private right of action for certain CIPA claims, transferring enforcement authority exclusively to the California Attorney General.

CIPA Reform and Its Impact

Governor Newsom signed SB 690 on September 30, 2026, officially enacting a CIPA reform measure. The bill amends Section 637.2 of the Penal Code, specifically limiting who may bring certain claims under California’s pen register and trap and trace statute. This change eliminates private lawsuits for website-based pen register claims, meaning claims arising from conduct "occurring on an internet website, online application, or mobile application" can now only be brought by the Attorney General.

The legislation is designed to curb a wave of lawsuits and demand letters asserting "pen register" claims under CIPA. Industry attorney Nick Zargarpour explained in an XBIZ article that CIPA prohibits improper monitoring of communications without consent or a court order, including through trap-and-trace devices or "pen registers." Adult sites and other online businesses have faced CIPA lawsuits alleging violations by planting trackers and cookies and sharing user information without prior permission. While some courts have ruled CIPA does not apply to websites, others have allowed plaintiffs to seek monetary settlements.

SB 690 is partially retroactive, applying to "any pending claim" in an action commenced on or after January 1, 2025. This retroactivity could affect many existing lawsuits. The amendments to CIPA, specifically California Penal Code Section 638.51 (the pen register/trap and trace device section), are effective January 1, 2027. Consequently, any such claims filed on or after January 1, 2025, are subject to a motion to dismiss or motion for judgment on the pleadings.

Governor's Stance and Future Reforms

In his signing message to the state legislature, Governor Newsom praised SB 690 as a measure that addresses "the vexatious use of CIPA lawsuits and demand letters to extract settlement money" from businesses. He specifically mentioned small businesses that "unwittingly install software on their websites that at times have tracked and shared the information of visitors to the site." Newsom applauded the author's efforts and aligned himself with the goal of protecting small businesses from "overzealous lawsuits based on a statute written without today’s complex technological landscape in mind."

Despite the significant changes, Governor Newsom indicated that "additional work" on broader CIPA reform is still needed. He emphasized that SB 690 addresses only one category of CIPA claims and urged the Legislature to revisit other CIPA provisions next year. The Governor noted that "CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants." He called for a "fair balance between protecting private information and preventing rapacious litigation."

Industry Response and Continued Vigilance

Attorney Corey Silverstein shared an update on the legislation, describing the change as "significant." However, Silverstein cautioned adult businesses to continue scrutinizing technologies that could still fall under CIPA’s provisions and to comply with other privacy statutes. Silverstein stated that the practical consequence is that businesses should stop treating every ordinary tracking technology as if it presents the same California CIPA risk. He added that the correct analysis now turns much more heavily on what the technology actually collects, what it transmits, who receives the data, and for what purpose.

CIPA, enacted in 1967, was originally directed at telephone line wiretapping. Over recent years, plaintiffs have applied its pen register and trap and trace provisions to common website technology, including cookies, pixels, analytics tools, and chat widgets. These complaints alleged that such tools captured information about a visitor's online activity in a manner akin to a pen register. CIPA provides statutory damages of at least $5,000 per violation without requiring proof of actual harm, which has led to over 4,000 filings and demand letters against businesses across various sectors, according to some litigation tracking efforts.

Key Facts

  • Governor Gavin Newsom signed Senate Bill 690 (SB 690) into law on September 30, 2026.
  • SB 690 narrows the scope of the California Invasion of Privacy Act (CIPA).
  • The law eliminates the private right of action for pen register and trap-and-trace claims arising from conduct on internet websites, online applications, or mobile applications.
  • Enforcement authority for these specific CIPA claims now rests exclusively with the California Attorney General.
  • The new law applies retroactively to claims filed on or after January 1, 2025, and becomes effective on January 1, 2027.
  • Governor Newsom called for further legislative work to address other CIPA provisions susceptible to abuse.