CIPA Claims Receive a Blow from the California Legislature
With the proliferation of claims against businesses that utilize cookies and other tracking technologies on their websites utilizing the California Invasion of Privacy Act (the “CIPA”), the California legislature stepped into the conversation. We previously outlined the basis of these CIPA claims in detail, where the claims originate under two sections of the CIPA. The first relates to the interception of a “conversation,” and the second for the use of particular technologies to capture information regarding the devices party to the conversation. CIPA claims also afford individuals private rights of action and statutory damages of $5,000 per violation, making these claims particularly advantageous to plaintiffs. The key question of whether the application of the CIPA to website operators is proper is still being fought out in the court system, but SB 690 has partially answered that question for private actions with respect to the technologies that capture information about the devices party to a conversation. In particular, SB 690 eliminates the private right of action for claims under § 638.51, which are referred to as pen register and trap-and-trace claims. Additionally, SB 690 carries a two year look back period, so that claims made in the prior two years would be ineffective.
SB 690 passed in the California legislature and while it has not yet been signed by Governor Newsom, it will be passed into law if not vetoed by the Governor before September 30, 2026. It is widely believed that the Governor will either sign the law or allow it to pass without veto, where it will become effective on January 1, 2027. While this is a boon for business with an online presence, it is not total relief, as the wiretapping portions of the law still permit private rights of action, and we have already seen plaintiffs convert CIPA claims to allege these wiretapping violations. Additionally, we are seeing litigation arise in other states, such as Illinois and Florida, with laws similar to the CIPA, so it remains a best practice to update your website with a cookie banner that collects consent before collecting non-essential information on website visitors.

