California lawmakers have sent Senate Bill 690 to Governor Gavin Newsom, teeing up a narrowing of website-tracking litigation under the California Invasion of Privacy Act (CIPA), who has until September 30 to sign or veto the legislation. If signed, the bill would eliminate private lawsuits asserting website-based “pen register” and “trap and trace” claims under Section 638.51 of CIPA. For businesses that have received demand letters or are defending lawsuits premised on routine website technologies—such as cookies, pixels, analytics tools, or similar tracking technology—the bill would offer relief from certain types of claims asserted under CIPA. Additionally, the bill would apply retroactively to pending claims in actions commenced within two years before its operative date, which is expected to be January 1, 2027, if the bill becomes law. 

The Impetus

The legislation responds to a surge of CIPA claims built on a statute originally designed for telephone-era wiretapping, not modern website traffic. Because CIPA carries statutory damages that can reach at least $5,000 per violation without proof of actual harm, even ordinary commercial web practices have created substantial litigation leverage for plaintiffs to demand large sums from website owners. SB 690 targets that specific theory by removing the private right of action for Section 638.51 claims.

Limitations

SB 690 is not a complete end to website privacy litigation. Notably, the bill does not eliminate the ability of the California Attorney General to bring claims under Section 638.51. Nor does the bill eliminate private right of action claims under CIPA Section 631, the provision focused on content of a communication that plaintiffs continue to invoke against session replay tools, chat features, pixels, and other third-party website technologies. Seemingly having seen the likelihood of passage, plaintiffs have increasingly asserted multiple claims under CIPA and the Electronics Communications Privacy Act (“the Federal Wiretapping Act”) in order to avoid the anticipated statutory effect of SB690 and its retroactive provisions. In practical terms, SB 690 may shrink one category of claims while leaving plaintiffs with alternative theories that can still create litigation and settlement pressure.

Key Considerations and Action Items

For companies with pending Section 638.51 claims or demand letters, the immediate priority is to assess how SB 690’s retroactivity language could affect the matter’s procedural posture if the Governor signs the bill. For companies facing Section 631 claims, the risk calculus is different: those claims remain intact and should continue to be evaluated on their own facts. More broadly, business leaders and legal teams should use this moment to inventory website tracking technologies, confirm when third-party tracking technologies fire, review cookie and consent practices, and ensure privacy disclosures align with actual data collection and sharing. If signed, SB690 will be a welcome development for many defendants, and hopefully a sign of more legislation to come, but it is not a substitute for a disciplined website privacy governance.

The California Court of Appeal, Second Appellate District, has issued its tentative ruling in Variety Media, LLC v. Superior Court, the closely watched writ proceeding that asks whether the pen register provisions of the California Invasion of Privacy Act (“CIPA”) apply to common website tracking technologies. The tentative decision would grant Variety’s petition in part and direct the trial court to sustain Variety’s demurrer with leave to amend. The court’s reasoning cuts in both directions. The panel would hold that CIPA’s pen register statute reaches internet communications, rejecting the threshold defense that has anchored many motions to dismiss. But it would also hold that a pen register captures only metadata identifying the destination of an outgoing communication, and that a website visitor’s IP address identifies the source of a communication rather than its destination. Under that construction, the complaint before the court fails to state a claim.

Continue Reading California Court of Appeal Tentatively Holds That Collecting a Website Visitor’s IP Address Alone Does Not Constitute Pen Register Activity Under CIPA

On August 11, 2026, the Colorado Department of Law released a single set of proposed rules substantially building out two 2026 statutes: the Automated Decision-Making Technology Act (“ADMT Act”) and the Conversational Artificial Intelligence Service Operator Requirements (the “Chatbot Safety Act”). Both laws take effect January 1, 2027, and the proposed rules would become effective the same day. The Rules are not yet final – for covered organizations and interested parties the weeks until September 4 are the time to submit comments to be considered for a redraft – and there is a specific ask to help shape the definition of covered ADMT.

Continue Reading Colorado Releases Proposed Rules for Its AI and Chatbot Safety Laws: These Create More Operational Work than the Statutes Suggest

Senior United States District Judge William H. Orrick, sitting in the Northern District of California, denied a motion to dismiss last week in an Automated License Plate Recognition (“ALPR”) matter, McGinty v. Reimagined Parking LLC, d/b/a Imperial Parking.[1] Judge Orrick held that the plaintiff plausibly alleged actionable harm based on his “right to know” about the use of ALPR systems in two garages. The order follows Bartholomew v. Parking Concepts, Inc.[2] and the guidance of Mata v. Digital Recognition Network, Inc.,[3] concluding that the California Supreme Court would likely recognize violation of a consumer’s “right to know” as actionable harm under California’s ALPR law if presented with the question.

Continue Reading Federal Court Follows Bartholomew Reasoning in Denying Motion to Dismiss ALPR Lawsuit

In this episode of Consumer Counterpoint, Kristine and Paul discuss the recent decision out of the Seventh Circuit that held that text messages do not count as “telephone calls” for purposes of a private right of action under Section 227(c) of the Telephone Consumer Protection Act and what this may mean for pending litigation alleging DNC violations based on texting campaigns.

Watch the Quick Take Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

On July 21, 2026, the California Privacy Protection Agency, now branding itself publicly as CalPrivacy, announced that its Audits Division has launched its first formal privacy audit, focused on gig economy platforms operating in California. The audit is the first in a planned series of “sectoral audits” and will evaluate whether major gig platforms are complying with the California Consumer Privacy Act (CCPA), particularly with respect to consumers’ and workers’ rights to access and control personal information.

Although the audit is directed at app-based transportation, delivery, and task-service platforms, the broader message is important for any business collecting applicant, worker, contractor, geolocation, profiling, performance, biometric, communications data, or automated decision-making technology (ADMT) use in California. CalPrivacy’s focus on gig workers also reinforces a point that employers and workforce platforms should not underestimate: California privacy rights apply not only to traditional consumers, but also to employees, job applicants, and independent contractors.

Continue Reading California Privacy Regulator Launches First Sectoral Audit—Targets Gig Platforms

Episode 21 is now live. In this Consumer Counterpoint Quick Take, Kristine Argentine and Paul Yovanic discuss takeaways from a recent Ninth Circuit oral argument on arbitration provision enforceability.  

Watch Episode 21 Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

Thursday, August 6, 2026
2:00 p.m. to 3:00 p.m. Eastern
1:00 p.m. to 2:00 p.m. Central
12:00 p.m. to 1:00 p.m. Mountain
11:00 a.m. to 12:00 p.m. Pacific

REGISTER HERE

About the Decoding Data Privacy Series

Data privacy and cybersecurity have become critical business risks for companies as they increasingly rely on technology to collect, store, monitor, and manage employee and customer information. From biometric data, workplace monitoring tools, marketing-based communication systems and connected tracking technologies, and AI-enabled technologies to vendor management, cross-border data transfers, and cyber incident response, companies face a rapidly evolving patchwork of legal obligations and litigation risks.

The Decoding Data Privacy webinar series will provide practical guidance on navigating today’s most pressing privacy and cybersecurity challenges, helping organizations protect sensitive workforce and consumer data, mitigate risk, and stay ahead of emerging regulatory and enforcement trends.

About the Program

Session 1: Vendor Contracting at the Intersection of Employment, Privacy, and Commercial Litigation

Companies increasingly depend on third-party providers to support nearly every aspect of the employment and business lifecycle, from payroll and benefits administration to recruiting platforms, timekeeping systems, workforce, consumer, and website analytics tools, customer relationship management, marketing and emerging AI technologies. As these vendors gain access to sensitive employee and business information, contractual decisions can create significant exposure not only under employment, privacy, and cybersecurity laws, but also in commercial disputes arising from data breaches, service failures, indemnification obligations, and allocation of risk.

In this practical discussion of how vendor agreements can serve as both a compliance tool and a critical risk-management mechanism, our experienced practitioners examine the provisions that matter most when evaluating technology and service vendors and discuss how thoughtful contracting can help organizations mitigate regulatory exposure, prepare for cyber incidents, comply with privacy obligations, and strengthen their position when disputes arise.

Topics include:

  • Managing risk through indemnification, insurance, limitations of liability, and dispute resolution provisions
  • Privacy, cybersecurity, and compliance obligations in vendor agreements
  • Contractual considerations for data maintenance and access, cyber incidents, and vendor accountability
  • Biometric technologies and emerging workplace and marketing technologies offered by third party service partners that create heightened legal and litigation risk
  • Structuring vendor relationships to better protect employee and business data
  • Key considerations for payroll, benefits, recruiting, and timekeeping vendors
  • Lessons learned from privacy, cybersecurity, and commercial disputes involving third-party providers

Speakers

Kristine Argentine, Partner, Seyfarth Shaw LLP
Ada Dolph, Partner, Seyfarth Shaw LLP
Paul Yovanic, Partner, Seyfarth Shaw LLP
Ala Salameh, Associate, Seyfarth Shaw LLP

REGISTER HERE

If you have any questions, please contact Kate Stacey at kstacey@seyfarth.com and reference this event.

Learn more about our DATA Law and Consumer Class Actions practices.

To comply with State CLE Requirements, CLE forms requesting credit in IL or CA must be received before the end of the month in which the program took place. Credit will not be issued for forms received after such date. For all other jurisdictions forms must be submitted within 10 business days of the program taking place or we will not be able to process the request.

Our live programming is accredited for CLE in CA, IL, and NY (for both newly admitted and experienced).  Credit will be applied as requested, but cannot be guaranteed for TX, NJ, GA, NC and WA. The following jurisdictions may accept reciprocal credit with our accredited states, and individuals can use the certificate they receive to gain CLE credit therein: AZ, AR, CT, HI and ME. For all other jurisdictions, a general certificate of attendance and the necessary materials will be issued that can be used for self-application. CLE decisions are made by each local board, and can take up to 12 weeks to process. If you have questions about jurisdictions, please email CLE@seyfarth.com.

Please note that programming under 60 minutes of CLE content is not eligible for credit in GA. programs that are not open to the public are not eligible for credit in NC.

In this Consumer Counterpoint: Quick Take, Kristine Argentine and Paul Yovanic discuss California Senate Bill 690 and its proposed amendments to the California Invasion of Privacy Act (CIPA). They examine the bill’s latest effort to restrict private lawsuits involving alleged pen-register or trap-and-trace violations arising from websites and mobile applications, shift enforcement authority to the California Attorney General, and address certain pending claims retroactively. They also explore what the proposal could mean for businesses navigating the continuing wave of CIPA litigation.

Watch the Quick Take Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.

Episode 20 is now live. In this episode of Consumer Counterpoint, Kristine Argentine and Paul Yovanic provide a mid-year review on wiretapping and pixel tracking litigation under the California Invasion of Privacy Act and similar statutes, including recent court decisions and what to expect later this year.

Watch Episode 20 Here:

Subscribe to the Consumer Class Defense Blog today and get notified when each new vidcast goes live.