TL;DR: California SB 690 passed August 28, 2026 and heads to Governor Newsom's desk. If signed, it eliminates private lawsuits under CIPA Section 638.51 for cookies, pixels, analytics tools, and behavioral tracking on websites and apps -- effective January 1, 2027, with retroactivity to claims filed on or after January 1, 2025. Only the California AG can enforce Section 638.51 after that. But here is the gap that matters: Section 631 (wiretapping), the provision used for session replay and live chat lawsuits, is not touched. Those suits live on.
For the past three years, a cottage industry of privacy plaintiffs has been using a 1960s California wiretapping statute to sue companies over software that was never designed for surveillance. Session replay tools, behavioral analytics pixels, AI chatbots, and heatmapping scripts were getting litigated as illegal "pen registers" -- devices once regulated to stop phone company employees from identifying callers without a warrant.
California's legislature has now moved to shut that off. The question for compliance teams is what exactly gets shut off, and what does not.
What SB 690 does
The California legislature passed SB 690 through both chambers on August 28, 2026. The bill amends the California Invasion of Privacy Act (CIPA) by stripping private plaintiffs of the right to sue under Section 638.51 for claims arising from websites, online applications, and mobile applications.
Section 638.51 is the CIPA provision that plaintiffs have been using to argue that routine website tracking constitutes an illegal pen register -- a device that captures routing and addressing information (IP addresses, page visits, referrer URLs, device identifiers) without consent. The $5,000-per-violation statutory damages provision made class actions financially attractive: multiply any common website's daily visitor count by $5,000 and the potential damages figure becomes staggering.
SB 690 does not repeal Section 638.51. It removes the mechanism that made it useful to plaintiffs. After January 1, 2027, the only party who can bring a Section 638.51 enforcement action arising from a website, app, or mobile platform is the California Attorney General.
The retroactivity window
The provision that will matter most to companies currently in litigation is the retroactivity clause. The bill covers claims filed on or after January 1, 2025 -- two years before the operative date of January 1, 2027.
That is a wide window. CIPA pen register lawsuits accelerated sharply in 2024 and 2025 as plaintiff firms identified the theory and began filing in volume. A substantial portion of the current docket falls within the retroactivity period.
The practical effect: if a company is a defendant in a pending Section 638.51 pen register case filed after January 1, 2025, and Newsom signs the bill, that case may lose its legal footing when the law takes effect. Companies currently in early-stage litigation or facing threatened suits will need to analyze whether the timing of the claim filing falls within the retroactive window and whether the specific claims alleged are 638.51 (pen register) or something else.
The critical gap: Section 631 survives intact
This is the part of SB 690 that every compliance team needs to understand before drawing conclusions about their exposure.
SB 690 amends Sections 631, 632, 632.7, 637.2, and 638.50 of the Penal Code. It does not eliminate the private right of action under Section 631.
Section 631 is CIPA's "in-transit" wiretapping provision. It prohibits intentionally intercepting "any message in transit" without consent. A separate line of CIPA lawsuits -- arguably the more significant one for companies using session replay tools and AI live chat -- relies on the theory that these tools intercept user communications while they happen, not merely that they collect routing information.
The two theories operate differently:
Section 638.51 (pen register/trap-and-trace) -- Covers collection of routing and addressing data: IP addresses, device identifiers, page visit data, referrer URLs. Think of analytics platforms, tracking pixels, and behavioral data collection that records where users go without intercepting what they say. This is what SB 690 removes from private enforcement.
Section 631 (wiretapping in transit) -- Covers interception of communications content while in transit. Session replay tools that record user keystrokes, mouse movements, and form interactions; AI chat widgets that process conversations in real time; live customer support tools that route messages to third-party processors. These are the primary Section 631 targets, and they remain available to private plaintiffs after January 1, 2027.
Approximately two-thirds of current California privacy litigation involves pen register and trap-and-trace theories under Section 638.51. SB 690 addresses that majority. But for companies using session replay, live AI chat, or real-time interaction recording, the litigation exposure that comes from Section 631 is unaffected.
Why this matters for AI analytics stacks specifically
The intersection of this reform with AI tooling is not incidental. The wave of CIPA pen register lawsuits accelerated as companies deployed AI-powered behavioral analytics -- tools that collect more data points, more granularly, than traditional web analytics. When a tool can track mouse hover timing, scroll velocity, hesitation patterns, and click sequence data across a session, the data it collects looks more like surveillance to a plaintiff's attorney than a pageview counter.
SB 690's passage gives companies some relief on the routing-and-addressing data theory. The AI analytics platform that collects IP addresses, device fingerprints, and navigation sequences faces reduced exposure after January 1, 2027 -- at least from private plaintiffs in California.
But the AI-powered session replay tool that records what users type and does real-time interaction analysis is still a Section 631 target. And the AI chatbot that processes customer queries and routes responses through third-party AI providers has been litigated under both theories simultaneously in multiple pending cases.
The liability split is now cleaner, but it is not gone.
What to do with pending cases and vendor relationships
If you have active CIPA litigation filed after January 1, 2025:
Work with counsel to identify the specific statutory claims alleged. If the complaint alleges Section 638.51 violations arising from your website or app's analytics and tracking infrastructure, and does not allege Section 631 violations, SB 690 may significantly change your settlement calculus. Cases filed after January 1, 2025 fall within the retroactivity window.
Do not take action on pending cases based solely on this article. The bill has not yet been signed, and the retroactivity analysis requires case-specific review. But this is the moment to resurface any pending matters with counsel and ask how the retroactivity provision applies.
If you have no active CIPA litigation but use third-party analytics, pixels, or chatbots:
The risk profile split is now cleaner. The Section 638.51 exposure that applied to analytics pixels, cookies, and behavioral tracking tools is going away (if Newsom signs). The Section 631 exposure from session replay, live AI chat, and real-time interaction recording is not going away.
Audit your vendor stack by claim type. Which tools collect routing and addressing data only (analytics, attribution, pixels)? Which tools intercept and process communications in transit (chat, session replay, support AI)? The first category's legal risk posture changes materially under SB 690. The second does not.
If you are a SaaS company whose product is the analytics or chatbot tool:
Your exposure picture bifurcates after January 1, 2027. The pen register theory that drove class action filings against analytics platforms weakens substantially. But if your product is a session replay or live-interaction AI tool, Section 631 suits remain available and you should update your risk disclosures accordingly.
For vendor due diligence on your AI analytics stack, the AI data privacy guide for small teams covers the broader privacy compliance framework. For how the FTC approaches analytics and AI tool enforcement separately, see the FTC AI enforcement tracker.
The AG-only enforcement model and what it signals
Making the California AG the sole enforcement party for Section 638.51 after the effective date is not just a relief valve for pending litigation. It is a deliberate choice about how California wants to govern website tracking law going forward.
The CIPA pen register class action model worked because of the $5,000-per-violation statutory damages floor. When private attorneys found a legal theory that applied to every website visitor and multiplied it by millions of potential class members, the threat value of litigation was enormous relative to the actual harm. The AG-only model caps that threat: state enforcement resources are finite, the AG selects targets, and enforcement tends to focus on egregious conduct rather than commonplace industry practice.
That does not mean companies can ignore Section 638.51 after January 1, 2027. The AG retains enforcement authority and can seek penalties. But the business model that made CIPA pen register class actions an industry in themselves no longer functions under the new structure.
California has made similar moves in other contexts -- the California Consumer Privacy Act enforcement shifted toward AG-exclusive enforcement in certain categories before the CPPA took over. The pattern suggests a legislative preference for state-administered enforcement over private litigation as the primary compliance mechanism for California privacy law. That preference affects how companies should think about their compliance programs: the question shifts from "what makes us defensible against a plaintiff attorney" to "what would the AG focus on if they investigated this category of conduct."
Timeline and next steps
August 28, 2026: SB 690 passed both chambers of the California Legislature.
September-October 2026: Governor Newsom has approximately 30 days from receipt of the enrolled bill to sign or veto. No urgency clause was attached.
January 1, 2027: Effective date if signed. Private Section 638.51 enforcement ends for website and app claims. Retroactivity applies to claims filed on or after January 1, 2025.
For companies in active litigation, the relevant analysis window is the next 60 days. Engage counsel now to assess whether pending claims fall within the retroactivity window and to develop a position on how the bill affects existing settlement negotiations.
For companies assessing vendor risk, the time to update your analytics and chatbot tool inventory is before the effective date -- not after the next lawsuit arrives. The California SB 942 compliance guide covers the separate AI content disclosure obligations that apply to generative AI tools in California as of August 2026. Both laws now define what California expects from companies using AI-powered user interaction tools, and they operate in parallel.
Related Reading
- AI data privacy for small teams: GDPR, CCPA, and what AI tools do with your data
- California SB 942 AI Transparency Act: August 2026 compliance guide
- FTC AI enforcement actions tracker 2026
- Georgia SB 540 AI chatbot compliance 2027
- AI employee monitoring disclosure laws 2026
- Vetting AI tools: fake packages, malware, and vendor risk
Sources: ZwillGen: SB 690 passes California legislature, Mullen Law: California SB 690 retroactivity analysis, Ecomm Innovation Alliance: SB 690 governor deadline, California Legislature official text: leginfo.legislature.ca.gov
