文章
What does California SB 690 change for website tracking lawsuits?
A public-source summary of California SB 690: what a narrowed pen-register claim would change for website and app tracking if the bill becomes law, which private theories public alerts say remain, and which storefront checks to keep.
In brief
If it becomes law, SB 690 would stop private plaintiffs from bringing certain California pen-register and trap-and-trace claims about website or app tracking, and leave those claims to the Attorney General. Public firm alerts say private wiretap theories would remain. This page summarizes that public reporting. It is not legal advice and not a guarantee about any lawsuit. As of September 22, 2026 the bill was enrolled and with the Governor, not enacted.
Not legal advice
This page summarizes public reporting about California SB 690. It is not legal advice. It is not a guarantee about any lawsuit. Readers should consult their own counsel before they rely on the bill for a demand letter, a pending case, or a decision to change tracking.
Re-check the official bill status before you tell a team the bill is in effect. On September 22, 2026 the status page listed SB 690 as an active enrolled bill, House location Governor, presented to the Governor on September 4, 2026 at 2 p.m. The latest history actions did not show a signature or a veto. The Governor can still sign it, veto it, or let the calendar run.
Short answer
On August 28, 2026, the California Legislature passed SB 690. If it becomes law, the bill would stop private plaintiffs from bringing certain California Invasion of Privacy Act pen-register and trap-and-trace claims under Penal Code section 638.51 when the alleged conduct is on a website, online application, or mobile application. Enforcement of that slice would be left to the California Attorney General.
Public firm alerts say the bill leaves wiretap and eavesdropping theories under Penal Code sections 631 and 632 available to private plaintiffs. Operators should still test what loads before consent and after Reject. Passage on August 28 is not enactment.
Timeline
The official history shows introduction on February 21, 2025, several later amendments, and enrollment after the August 28 floor votes. Public alerts describe that path as a broader bill that was later narrowed. The last amendment date on the status page is July 2, 2026. This table is a reading aid. Confirm the live status page before you treat any row as the final legal result.
| Date | Event |
|---|---|
| February 21, 2025 | Introduced. Later amendments narrowed the text that the Legislature passed. Some alerts describe the early bill as broader. |
| August 28, 2026 | Legislature passes the narrowed bill. Assembly third reading ayes 66, noes 0. Senate concurrence ayes 39, noes 0. |
| Through about September 30, 2026 | Governor sign or veto window in public reporting. As of September 22, 2026 the status page showed no signature and no veto. Confirm live. |
| January 1, 2027 | Expected operative date if it becomes law. The enrolled text reviewed here does not print that date. The bill is marked non-urgency. Confirm on the chaptered text. |
What would change if it becomes law
The enrolled text amends Penal Code section 637.2. New subdivision d, paragraph 1, says an action against a private actor for a violation of section 638.51, alleged to arise from conduct on an internet website, online application, or mobile application, may be brought under section 637.2 only by the Attorney General.
That is the narrowing public alerts describe: private enforcement of that section 638.51 site and app slice would be closed, and the Attorney General would be the plaintiff for that slice. Sidley, Fenwick, and Taft each describe the same enrolled limit. This page does not add a prediction about whether the Governor will sign.
- Private plaintiffs would lose section 637.2 as a path for the covered section 638.51 website, online-app, and mobile-app claims.
- The Attorney General would be the one who may bring that slice, according to the enrolled text and the firm alerts.
- Subdivision d, paragraph 2, applies the amendments retroactively to any pending claim in an action commenced within two years before the operative date. The enrolled sentence uses that lookback. It does not print a filing date. Alerts that assume a January 1, 2027 operative date describe filings on or after January 1, 2025. Verify the bill text and the operative date before you map a specific case.
What would not change
The enrolled bill does not repeal section 638.51. Subdivisions a through c of section 637.2 still describe private damages and injunction actions, except as provided in subdivision d. Subdivision d is limited to the section 638.51 website and app slice.
Public alerts name sections 631 and 632 as private theories the enrolled text does not rewrite. A vote in the Legislature also does not clear a demand letter. Counsel has to read the letter against the text that actually becomes law, if it becomes law. Pre-consent blocking is still worth measuring, because a change in who may file one kind of claim does not turn tags off.
- Private theories under sections 631 and 632 remain, per the firm alerts and the limit written into subdivision d.
- Demand letters are not automatically cleared by passage or by a later signature.
- Cookies, pixels, and banners still need a browser check. The enrolled text does not mention a cookie banner, Global Privacy Control, or the California Consumer Privacy Act.
Checks that still belong on the storefront
If it becomes law, a narrower private lawsuit path is not a reason to skip the runtime record. Keep the passes separate, and label every file by step.
- Fresh, no click: clean profile, public URL, do not touch the banner. Record cookies, storage, and third-party requests.
- Reject All, then navigate: new profile, use the reject control, confirm an observable preference or banner-state change, open one more page, and recapture the same layers.
- Accept baseline: another new profile. Accept, then record which vendors appear so you can compare them with fresh and reject.
- Optional GPC: only when the claim is about Global Privacy Control. Run matched GPC-off and GPC-on visits on a California-facing path. SB 690 does not perform that comparison.
- Evidence: save the request list, the cookie table, and screenshots labeled by step. Strip query secrets before you share the pack.
FAQ
Does SB 690 end all CIPA website lawsuits?
No. If it becomes law, the enrolled limit covers private section 638.51 claims about website or app conduct, and it would leave those actions to the Attorney General. Public alerts say private sections 631 and 632 theories remain.
We only have a demand letter. Is that cleared?
Not automatically. Ask your own counsel to read the letter against the enrolled text, the operative date, and whether the claims are the section 638.51 slice or a different theory. This page is not a guarantee about any lawsuit.
Should we remove the cookie banner?
No. The bill does not configure tags. Testing what loads before a choice and after Reject is still useful for operations, even if one private filing path narrows.
Is this page legal advice?
No. It summarizes public reporting about California SB 690. Consult your own counsel for a case, a demand, or a go-live decision.
Has the Governor signed or vetoed it?
Not on the official status page checked September 22, 2026. The bill was presented to the Governor on September 4, 2026. Public reporting describes a sign or veto window through about September 30, 2026. Confirm the live page before you describe the bill as law.
A technical record, not a bill outcome
ConsentProbe can store a labeled technical record of cookies, requests, and screenshots. A free US-baseline visit is one non-California pass for format and wiring. Paid EU runs isolate fresh, reject, and accept. Paid California runs compare GPC off with GPC on. None of those packs is a reading of SB 690, and a signature would not turn a report into legal advice.
Related guides
Use the pre-consent and reject guides for the browser work, the runtime audit versus CMP guide when banner copy and the wire disagree, and the free versus paid page before you stretch a US-baseline file into an EU or California claim.
- Pre-Consent Cookie Audit: A Storefront Checklist
- Pre-consent audit checklist: what to verify before Accept
- Reject All Still Tracking: What to Check After You Say No
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Runtime Audit vs CMP: What Each One Measures
- Testing Shopify Pixels Before Consent
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
- California Legislative Information — SB 690 enrolled text
- California Legislative Information — SB 690 status
- Sidley Austin — SB 690 clears the Legislature, September 2026
- Fenwick — Legislature passes SB 690, September 2026
- Taft — CIPA reform on the Governor's desk, September 2026
- ConsentProbe methodology
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。