Article

What does California SB 690 change for website tracking lawsuits?

Start a free audit

A public-source summary of California SB 690: what a narrowed pen-register claim would change for website and app tracking if the bill becomes law, which private theories public alerts say remain, and which storefront checks to keep.

In brief

If it becomes law, SB 690 would stop private plaintiffs from bringing certain California pen-register and trap-and-trace claims about website or app tracking, and leave those claims to the Attorney General. Public firm alerts say private wiretap theories would remain. This page summarizes that public reporting. It is not legal advice and not a guarantee about any lawsuit. As of September 22, 2026 the bill was enrolled and with the Governor, not enacted.

Not legal advice

This page summarizes public reporting about California SB 690. It is not legal advice. It is not a guarantee about any lawsuit. Readers should consult their own counsel before they rely on the bill for a demand letter, a pending case, or a decision to change tracking.

Re-check the official bill status before you tell a team the bill is in effect. On September 22, 2026 the status page listed SB 690 as an active enrolled bill, House location Governor, presented to the Governor on September 4, 2026 at 2 p.m. The latest history actions did not show a signature or a veto. The Governor can still sign it, veto it, or let the calendar run.

Short answer

On August 28, 2026, the California Legislature passed SB 690. If it becomes law, the bill would stop private plaintiffs from bringing certain California Invasion of Privacy Act pen-register and trap-and-trace claims under Penal Code section 638.51 when the alleged conduct is on a website, online application, or mobile application. Enforcement of that slice would be left to the California Attorney General.

Public firm alerts say the bill leaves wiretap and eavesdropping theories under Penal Code sections 631 and 632 available to private plaintiffs. Operators should still test what loads before consent and after Reject. Passage on August 28 is not enactment.

Timeline

The official history shows introduction on February 21, 2025, several later amendments, and enrollment after the August 28 floor votes. Public alerts describe that path as a broader bill that was later narrowed. The last amendment date on the status page is July 2, 2026. This table is a reading aid. Confirm the live status page before you treat any row as the final legal result.

SB 690 timeline from the official status page and public firm alerts. Checked September 22, 2026. Not a statement that the bill is law.
DateEvent
February 21, 2025Introduced. Later amendments narrowed the text that the Legislature passed. Some alerts describe the early bill as broader.
August 28, 2026Legislature passes the narrowed bill. Assembly third reading ayes 66, noes 0. Senate concurrence ayes 39, noes 0.
Through about September 30, 2026Governor sign or veto window in public reporting. As of September 22, 2026 the status page showed no signature and no veto. Confirm live.
January 1, 2027Expected operative date if it becomes law. The enrolled text reviewed here does not print that date. The bill is marked non-urgency. Confirm on the chaptered text.

What would change if it becomes law

The enrolled text amends Penal Code section 637.2. New subdivision d, paragraph 1, says an action against a private actor for a violation of section 638.51, alleged to arise from conduct on an internet website, online application, or mobile application, may be brought under section 637.2 only by the Attorney General.

That is the narrowing public alerts describe: private enforcement of that section 638.51 site and app slice would be closed, and the Attorney General would be the plaintiff for that slice. Sidley, Fenwick, and Taft each describe the same enrolled limit. This page does not add a prediction about whether the Governor will sign.

  • Private plaintiffs would lose section 637.2 as a path for the covered section 638.51 website, online-app, and mobile-app claims.
  • The Attorney General would be the one who may bring that slice, according to the enrolled text and the firm alerts.
  • Subdivision d, paragraph 2, applies the amendments retroactively to any pending claim in an action commenced within two years before the operative date. The enrolled sentence uses that lookback. It does not print a filing date. Alerts that assume a January 1, 2027 operative date describe filings on or after January 1, 2025. Verify the bill text and the operative date before you map a specific case.

What would not change

The enrolled bill does not repeal section 638.51. Subdivisions a through c of section 637.2 still describe private damages and injunction actions, except as provided in subdivision d. Subdivision d is limited to the section 638.51 website and app slice.

Public alerts name sections 631 and 632 as private theories the enrolled text does not rewrite. A vote in the Legislature also does not clear a demand letter. Counsel has to read the letter against the text that actually becomes law, if it becomes law. Pre-consent blocking is still worth measuring, because a change in who may file one kind of claim does not turn tags off.

  • Private theories under sections 631 and 632 remain, per the firm alerts and the limit written into subdivision d.
  • Demand letters are not automatically cleared by passage or by a later signature.
  • Cookies, pixels, and banners still need a browser check. The enrolled text does not mention a cookie banner, Global Privacy Control, or the California Consumer Privacy Act.

Checks that still belong on the storefront

If it becomes law, a narrower private lawsuit path is not a reason to skip the runtime record. Keep the passes separate, and label every file by step.

  1. Fresh, no click: clean profile, public URL, do not touch the banner. Record cookies, storage, and third-party requests.
  2. Reject All, then navigate: new profile, use the reject control, confirm an observable preference or banner-state change, open one more page, and recapture the same layers.
  3. Accept baseline: another new profile. Accept, then record which vendors appear so you can compare them with fresh and reject.
  4. Optional GPC: only when the claim is about Global Privacy Control. Run matched GPC-off and GPC-on visits on a California-facing path. SB 690 does not perform that comparison.
  5. Evidence: save the request list, the cookie table, and screenshots labeled by step. Strip query secrets before you share the pack.

FAQ

Does SB 690 end all CIPA website lawsuits?

No. If it becomes law, the enrolled limit covers private section 638.51 claims about website or app conduct, and it would leave those actions to the Attorney General. Public alerts say private sections 631 and 632 theories remain.

We only have a demand letter. Is that cleared?

Not automatically. Ask your own counsel to read the letter against the enrolled text, the operative date, and whether the claims are the section 638.51 slice or a different theory. This page is not a guarantee about any lawsuit.

Should we remove the cookie banner?

No. The bill does not configure tags. Testing what loads before a choice and after Reject is still useful for operations, even if one private filing path narrows.

Is this page legal advice?

No. It summarizes public reporting about California SB 690. Consult your own counsel for a case, a demand, or a go-live decision.

Has the Governor signed or vetoed it?

Not on the official status page checked September 22, 2026. The bill was presented to the Governor on September 4, 2026. Public reporting describes a sign or veto window through about September 30, 2026. Confirm the live page before you describe the bill as law.

A technical record, not a bill outcome

ConsentProbe can store a labeled technical record of cookies, requests, and screenshots. A free US-baseline visit is one non-California pass for format and wiring. Paid EU runs isolate fresh, reject, and accept. Paid California runs compare GPC off with GPC on. None of those packs is a reading of SB 690, and a signature would not turn a report into legal advice.

Related guides

Use the pre-consent and reject guides for the browser work, the runtime audit versus CMP guide when banner copy and the wire disagree, and the free versus paid page before you stretch a US-baseline file into an EU or California claim.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

California SB 690 and website tracking | ConsentProbe