Summarize this article with
In May I wrote about what to do when a CIPA demand letter lands on your desk. Don't ignore it. Pull your consent logs and run a scan before you answer, because a good number of these letters do not survive contact with what your website was actually doing.
Since then, the statute underneath those letters moved and the privacy community is getting just a little excited about it.
On August 28, 2026 the California Legislature passed SB 690, and the commentary since has read like a eulogy for the CIPA demand letter. Several of the alerts in my inbox describe it as the end of the wave.
Unfortunately for many in-house teams, it is not that. It is narrower than the headlines, so we need to break down exactly what this passage means.
SB 690 removes one count from the menu. It hands that count to the California Attorney General. And it reaches backward into lawsuits already filed. It does not cancel the demand letter sitting unanswered in your inbox. What it may do is take the claim out from under it, and whether that happens turns on a line in the letter most people never read closely.
If you are holding one of those, the next four months decide what it costs you. And if you are not, read the next paragraph anyway, because the part of this that applies to everyone is the part nobody is writing about: the law governing what you may collect did not change at all. Only the list of people who can sue you over it did.
Disclaimer: This article is provided for general informational and educational purposes only and does not constitute legal advice. Nothing here should be relied upon as a substitute for advice from qualified counsel licensed in your jurisdiction, and reading it does not create an attorney-client relationship with Ketch or any contributor. SB 690 is not law as of publication, and CIPA case law is unsettled and changing rapidly. Consult privacy counsel before acting on any demand letter or pending claim.
What SB 690 actually does
The mechanism is a change to who may sue, not a change to what is lawful.
SB 690 would amend California Penal Code § 637.2 so that a private plaintiff can no longer sue a business under CIPA's pen register and trap-and-trace provision, § 638.51, for conduct occurring on an internet website, online application, or mobile application. Only the California Attorney General could bring that claim.
That is a much narrower bill than the one most privacy teams have been tracking since February 2025. The original version would have created a broad "commercial business purpose" exemption reaching CIPA's wiretapping, eavesdropping, recording, and pen register provisions at once. It passed the Senate unanimously in June 2025, stalled in the Assembly, and was rewritten on July 1, 2026 to drop the exemption entirely. What survived is one provision, one enforcer, and one retroactivity clause.
Two dates matter. The bill carries no urgency provision, so if signed it takes effect January 1, 2027. Governor Newsom has until September 30, 2026 to sign it, veto it, or let it become law without a signature. Every recorded vote across both chambers, including the 66 to 0 Assembly vote and the Senate concurrence on August 28, showed no opposition, which is the only signal available about the Governor's likely action. It is not a commitment.
The part worth reading twice
Everything else survives. CIPA § 631, the wiretapping and interception provision, is untouched. So is § 632, which covers the recording of confidential communications. So are the federal Wiretap Act, the VPPA, and the wiretap analogues in Florida, Pennsylvania, Arizona, and Washington that plaintiffs' firms have been developing in parallel.
A complaint resting only on § 638.51 may become dismissible once the law is operative. A complaint pleading § 638.51 as one count among several will not go away, because the other counts survive intact.
So the useful question is not, "does SB 690 help us?" It is, "what does our letter actually plead?" A lot of teams have never had to answer that with precision, and they are about to find out which kind of letter they are holding.
Your demand letter didn't expire, but the claim behind it might
The Legislature addressed pending litigation directly. The enrolled language applies the amendment retroactively to any pending claim in an action commenced within two years before the operative date, which means qualifying § 638.51 claims filed on or after January 1, 2025 are reachable. Expect plaintiffs to contest retroactive application rather than accept it: there is an obvious vested-rights argument available to anyone holding a claim they filed under the law as it stood. Treat the pending-litigation half of this as a strong argument to preserve, not a result to bank.
Read the words, "action commenced." A pre-suit demand letter is not an action commenced. If you are holding an unanswered demand letter, nothing in SB 690 extinguishes it by operation of law, and the response deadline in the letter is exactly as real as it was last month.
But look at what happens to the claim underneath it. Once the law is operative, a private claimant cannot bring a website-based § 638.51 claim at all. That is prospective, not retroactive: the cause of action is simply no longer available to them. And filing early does not solve their problem either, because a complaint filed in, say, November 2026 lands inside the two-year retroactivity window and gets swept up with the rest. The clause reads like it was written to close that door.
So the letter survives and the theory may not. What changes at the demand stage is leverage. A claimant asserting only a website-based § 638.51 theory is asserting a theory they will soon be unable to prosecute privately at all.
A claimant asserting § 631 alongside it is in a different position, but not an unchanged one. They still have a case. What they lose is the fallback, and it was the good one. Section 638.51 was the count that did not require them to prove what anyone said, and it was there to catch the claim if the interception theory failed. Take it away and the case has to stand on the harder theory alone, which changes what it is worth long before anyone gets to a courtroom.
Those are two very different negotiating positions arriving in envelopes that look identical. Telling them apart means reading the letter against what your site was actually doing: the same advice I gave in May, now with considerably more money riding on it.
The economics behind these letters have not changed either. A demand typically seeks roughly $50,000 in settlement plus roughly $30,000 in legal fees, an $80,000 problem per instance, and a company that becomes a target can typically expect two to six per year. Removing one count from the menu narrows the model. It does not retire it.
None of your obligations changed
This is the part I would put in front of an executive who reads one paragraph of this.
SB 690 does not amend the substantive prohibitions in § 638.50 or § 638.51. It does not define a pixel out of the statute, bless session replay, or declare any data collection practice lawful. What a pen register is, and whether the technology on your site behaves like one, is exactly what it was on August 27. The bill changes the name on the caption. It does not change what your website is doing when someone loads it.
Everything around it is equally unmoved. Your CCPA obligations are where they were: the opt-out mechanism, the treatment of a Global Privacy Control signal, the requirement to pass an opt-out downstream to the recipients you shared data with. CCPA compliance has never provided a defense to a CIPA claim and still does not. The federal Wiretap Act, the VPPA, and four other states' wiretap statutes never depended on the pen register theory in the first place.
So the operational work is unchanged, and so is the standard it will be measured against: know what is firing on your properties, know when it fires relative to the notice you showed, know the consent state of the specific person it fired for, and be able to produce that record on demand rather than describe it. A narrower set of people can sue you over getting it wrong. That is the entire delta.
Anyone reading SB 690 as permission to slow down on that work is reading the one clause and skipping the statute it sits in.
The § 631 pivot raises the technical bar, for both sides
Here is the shift I think privacy teams should be planning around.
A § 638.51 pen register theory alleges that a technology captured routing, addressing, or signaling information: an IP address, device details, and similar metadata. That is straightforward to plead from an automated scan of a page. You do not need to show what anyone said.
A § 631 interception theory alleges something harder: that a third party read or learned the contents of a communication while it was in transit, without the consent of all parties. Contents means the search a person typed, the fields they filled, the chat they held, the video they watched, the items in their cart. Courts have divided on how this applies to web technology, and pleading it takes more work per case.
More work per case, on a claim worth the same $5,000 per violation, points in one direction. Raw filing volume may fall. The claims that remain will be more carefully targeted, and they will turn on evidence about payloads rather than evidence about tags.
That reframes the diagnostic question entirely. "Which trackers are on my site" is a tag inventory question, and a cookie scanner answers it. "What did that tag transmit, to whom, and what was this person's consent state at that moment" is a contents question, and it requires reading the actual data packets leaving the site.
Most privacy programs are instrumented for the question that is going away, and blind to the one that is arriving.
Enforcement does not disappear, it changes hands
SB 690 reserves website and app § 638.51 claims for the California Attorney General. That is not the same as ending them.
The AG's office has an active and escalating record on data practices. The Disney settlement entered February 11, 2026 in People of the State of California v. Disney DTC, LLC, Case No. 26STCV04425, resolved for $2.75 million, the largest CCPA settlement in California history at the time of entry, over opt-out failures across services and devices. The Sling TV and Dish Media Sales settlement, Case No. 25STCV31561, resolved in October 2025 for $530,000 and carried a three-year compliance-monitoring requirement.
Both are CCPA matters rather than CIPA matters, and the distinction is real. What they establish is the posture of the office SB 690 would hand § 638.51 to: an enforcer that asks for records rather than descriptions, and that writes settlement terms specifying what a business must be able to verify. Our technical breakdowns of the Disney settlement and the Sling TV settlement go through what each one required at a systems level.
One more distinction worth holding onto: CCPA compliance has never provided a defense to a CIPA claim. They are separate statutes on separate theories. SB 690 does nothing to change that.
What to do between now and January 1, 2027
Here's what I'd recommend, in this order:
- Inventory the theories in every open matter. For each demand letter and pending complaint, identify whether it pleads § 638.51 alone, or § 638.51 alongside § 631, § 632, the federal Wiretap Act, the VPPA, or a common law count. This determines whether SB 690 is relevant to that matter at all.
- Do not settle on the calendar. A response deadline arriving before the Governor acts is not a reason to pay a claim whose private prosecution may be foreclosed in four months. Take that assessment to counsel rather than to the clock.
- Preserve the issue in pending litigation. Where a § 638.51 claim falls inside the two-year retroactivity window, the argument needs to be preserved now so it is available once the law is operative.
- Instrument for the contents question. Move from a tag inventory to a record of what left the page, to which third party, and against what consent state, at the level of an individual visitor and a timestamp. This is what a § 631 theory will be argued over.
- Check your non-California footprint. If you serve Florida, Pennsylvania, Arizona, or Washington traffic, a California-only fix reduces a fraction of your exposure. Scope the assessment to where your visitors actually are.
How Ketch supports this work
Ketch is permissioning infrastructure, not counsel. How you respond to a claim is a legal decision. What Ketch helps with is the evidence your counsel has to work with.
Ketch Data Sentry continuously monitors data collection across your websites and mobile apps by analyzing real-time network traffic, the actual data packets leaving your site, which is the contents-level view a § 631 theory turns on. It also processes HAR files directly, so when a letter arrives with a network request log attached as proof, you can reproduce what happened and verify or refute the allegation before you respond. In practice those files frequently do not establish what the letter claims.
Ketch Consent Management supports a configurable delay between the presentation of notice and the moment tags may fire, which answers the contemporaneous-disclosure argument that a notice appearing at the same moment as collection is not meaningful consent. Dynamic tag control holds trackers until privacy conditions are met.
Ketch Privacy 360 Analytics produces the timestamped, identity-linked record of what notice a person saw, what they chose, which downstream systems were instructed, and whether each call succeeded. A banner is a claim that something happened. That record is evidence it did, and it is what turns the notice delay from an assertion into a provable fact for a specific visitor on a specific date.
The Ketch Agent Network assembles the response workstream: it classifies the allegation, pulls tracker results, consent logs, rights workflow state, data maps, and policy records, proposes remediation, and hands legal and privacy teams a review packet showing what was found, what changed, and who approved it.
None of these software products make a claim go away, we won't pretend they will. Don't believe a vendor that makes that promise. But good privacy software WILL affect whether you are reconstructing history under a deadline, or reading from a record you already have.
The bottom line
SB 690 is meaningful, narrow, and not yet law. It would take one heavily used count off the board for website and app conduct, reach back to pending claims filed since January 1, 2025, and hand that provision to the Attorney General. It leaves the wiretapping theory, the federal claims, the video privacy claims, and four other states' statutes exactly where they were.
And it leaves your obligations untouched. This is an enforcement bill, not a permission slip. The rules about what you may collect, from whom, and on what notice are identical to what they were the day before it passed. All that moved is who gets to bring you to court over them.
The teams that come out of this well are the ones treating it as a change in which claim they will face, not as the end of the exposure. The rest will find out in January, when the § 638.51 count falls out of a complaint and the § 631 count is still sitting right underneath it.





