California Wiretapping Law Gets an Update, Removes Right to Sue Over Internet Surveillance

California hands exclusive enforcement of web-tracking privacy claims to the attorney general, stripping individuals of the right to sue under CIPA Section 638.51 starting 2027

Rex Edison Avatar
Rex Edison Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • California’s SB 690 transfers Section 638.51 enforcement from individuals to the attorney general only.
  • CIPA Sections 631 and 632, covering wiretapping and eavesdropping, remain open for private lawsuits.
  • SB 690’s retroactivity provision affects qualifying pending lawsuits filed on or after January 1, 2025.

That cookie consent banner you dismiss without reading just got more consequential. Gov. Gavin Newsom signed Senate Bill 690 on September 30, 2026, removing your ability to bring a private lawsuit under the section of California’s Invasion of Privacy Act (CIPA) that covers secretly tracking users via internet-based metadata surveillance. Starting January 1, 2027, only the state attorney general can pursue those Section 638.51 claims against private actors on websites and online or mobile applications.

This is not a repeal of privacy law. It is a transfer of enforcement power, and the distinction matters enormously.

A 1967 Law Meets the Cookie Era

CIPA predates the internet by decades; its 2015 update created the opening that SB 690 now closes.

California enacted CIPA in 1967 to address telephone-era wiretapping and surveillance concerns. The 2015 addition of Section 638.51 used broad language covering pen registers (tools that log metadata such as routing and addressing information, not the content of communications) and trap-and-trace devices, which capture corresponding incoming data. Plaintiffs’ attorneys eventually applied that language to modern commercial practices, and cookies, advertising pixels, analytics tags, and session replay tools became targets in some litigation.

The litigation pressure on businesses was documented and real, and SB 690 is the Legislature’s response to it. Under the amended law, qualifying Section 638.51 claims arising from conduct on websites, online applications, or mobile applications fall exclusively under attorney general enforcement. The underlying prohibition on unauthorized pen registers remains on the books; what changed is who gets to enforce it in those covered contexts.

What You Can Still Do

Two core CIPA provisions stay intact, keeping other tracking lawsuits on the table.

If online tracking concerns you, the legal landscape shifted but did not go dark. CIPA Sections 631 and 632, which cover traditional wiretapping, eavesdropping, and the recording of confidential communications, remain available for private claims. Federal Wiretap Act claims may also be available where the facts and statutory elements support them.

Earlier drafts of SB 690 proposed changes affecting those sections as well. The final version is narrower, focused solely on Section 638.51 claims involving website and application conduct. Legal analysts expect plaintiffs’ attorneys to redirect cases toward surviving theories where the alleged facts can support a wiretapping or eavesdropping framing, though each claim will depend on its own facts and applicable legal requirements.

The Cases Already in Motion

Pending lawsuits filed as recently as January 2025 could be directly affected.

The law reaches backward in a targeted way. Its retroactivity provision applies to qualifying pending claims in actions commenced on or after January 1, 2025. If a lawsuit was already moving through the courts under the pen-register theory and meets the statutory criteria, this amendment can affect it. That is a live issue for active litigation involving a surveillance app or web-based tracking tool, not an abstract legal footnote.

Two Perspectives, One Honest Assessment

Supporters call it a correction to abusive litigation patterns; privacy advocates call it a loss of consumer power.

Business groups and bill supporters argue that SB 690 corrects a litigation pattern that generated disproportionate demand letters and settlement pressure, including against smaller companies using common web analytics tools. The Electronic Frontier Foundation and other privacy advocates counter that removing the private right of action reduces individual accountability tools. They argue the change makes it easier for companies to collect and monetize metadata without meaningful legal exposure, a concern worth noting as a stated advocacy position rather than a confirmed outcome.

The core disagreement is about enforcement structure: whether state-led action can adequately substitute for individual lawsuits. Supporters favor a more targeted, government-led approach. Privacy advocates contend that the attorney general’s office cannot address every individual harm, a tension already visible in debates over digital surveillance at the state and local level.

Where This Leaves You

The attorney general’s enforcement priorities now carry significantly more weight for this category of claim. Courts still face open questions about how Sections 631 and 632 apply to modern tracking practices, and other state and federal statutes remain potentially available depending on the facts. The private lawsuit route under Section 638.51 is closed for qualifying internet conduct; other legal avenues remain contested and in play.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →