
California businesses, including automobile dealers, received welcome news in the continuing wave of website privacy litigation. On August 28, 2026, the California Legislature approved Senate Bill 690, legislation designed to curb one of the more aggressive theories being used to bring claims under the California Invasion of Privacy Act (CIPA). The bill now heads to the Governor.
If enacted, SB 690 could significantly reduce claims alleging that ordinary website technologies violate California’s restrictions on “pen registers” and “trap and trace devices.” These claims have become increasingly common as plaintiffs attempt to apply decades-old surveillance laws to modern website technologies such as analytics and advertising tools. Importantly, the legislation would also apply to many pending claims made during the two years before the law takes effect. This means the legislation could provide relief not only from new claims going forward, but also to businesses already defending recently filed pen-register and trap-and-trace claims involving websites and applications.
The legislation represents meaningful progress for businesses facing these claims. At the same time, SB 690 is targeted legislation. It addresses California pen-register and trap-and-trace claims involving websites and applications – NOTABLY HOWEVER, it does not affect other CIPA claims, including traditional website “wiretapping” claims. Similar claims under the laws of other states also remain unaffected.
How Website Technology Became a “Pen Register”
CIPA was enacted decades before modern websites, cookies, analytics platforms and digital advertising technology. Nevertheless, plaintiffs have increasingly argued that commonplace website tools qualify as technologies regulated by provisions of CIPA originally addressing “pen registers” and “trap and trace devices.”
These theories have helped fuel a wave of demand letters, lawsuits and arbitration claims against businesses that use common website technologies. Auto dealers have been among the targets because dealership websites commonly use analytics, retargeting, advertising, chat, lead-generation and other third-party technologies.
The potential statutory damages available under CIPA can create significant litigation pressure even where a business reasonably believed that it was using ordinary commercial website technology.
What SB 690 Would Change
SB 690 would reserve enforcement through CIPA’s civil-remedies provision to the California Attorney General. In practical terms, private plaintiffs would no longer be able to bring these website-based pen-register and trap-and-trace claims themselves.
The legislation also contains an important retroactivity provision. The limitation on private enforcement would apply to qualifying pending claims in actions commenced within two years before the legislation’s operative date. If SB 690 becomes law, businesses already defending certain Section 638.51 claims may benefit as well.
CIPA Wiretapping Claims Will Continue
While this bill addresses an important piece of the recent CIPA litigation wave, it does not eliminate private CIPA litigation involving websites.
In particular, the final legislation does not eliminate private claims under the separate section of the CA Penal Code (Section 631) commonly relied upon for website “wiretapping” claims. Those cases generally involve a different theory: that third-party website technologies intercept the contents of communications between a website visitor and the business.
That distinction is important. A claim alleging that technology improperly captured routing or addressing information may be affected by SB 690, while a plaintiff alleging that a third party intercepted the contents of website communications may continue to pursue that “wiretapping” claim.
It is likely that many plaintiffs will simply amend their claims if this bill is finalized, but not abandon them altogether.
The Risk Extends Beyond California
SB 690 addresses California law only; businesses operating websites accessible nationwide continue to face evolving claims under wiretapping, surveillance and privacy laws in other states. This has become particularly important as plaintiffs experiment with older statutes that were never drafted with modern websites in mind. The specific legal theories vary by state, but website technologies that transmit information to third parties continue to attract scrutiny.
How ComplyAuto Can Help
ComplyAuto’s Privacy solution is designed to help dealers identify and manage the website technologies that can create these risks. Our Web Scanner identifies cookies and other tracking technologies operating on dealership websites, helping dealers better understand what information may be collected or shared with third parties.
The Privacy solution also includes a functioning, customizable cookie banner that can control when certain technologies are permitted to operate based on a consumer’s choices. Dealers can configure their consent settings based on their risk tolerance and applicable legal requirements rather than relying solely on a static privacy notice.
Because website privacy risks vary significantly by state, ComplyAuto also offers geofencing capabilities that allow dealers to apply more conservative cookie-banner settings to visitors from higher-risk jurisdictions while using different configurations elsewhere.
SB 690 is an encouraging development that could meaningfully reduce one of the more aggressive categories of California website privacy claims. But website privacy litigation is continuing to evolve both inside and outside California. ComplyAuto can help dealers maintain a more defensible privacy program by identifying website tracking technologies, providing consumers appropriate choices, and adapting those protections as the legal landscape changes. Contact us today to learn more.