Updated October 6, 2026

SB 690: what California changed, and what it didn't.

On September 30, 2026 California's governor signed SB 690, the first real narrowing of the "website wiretapping" wave under the California Invasion of Privacy Act (CIPA). People keep asking whether it ended these claims. It ended one of the two theories behind them. The other one — the one ForensicConsent was built around — is untouched. Here's the plain version, with sources. This is an explainer from a software company, not legal advice.

The facts

What SB 690 does

  • Signed Sept 30, 2026. Operative Jan 1, 2027.
  • Removes the private right of action under Penal Code §638.51 — the "pen register / trap-and-trace" section — for conduct on a website, online application or mobile app. That was the theory that treated an ordinary pixel, cookie or analytics beacon as a device capturing "dialing and routing" information. Only the California Attorney General can enforce that section now.
  • Reaches back two years. It applies to pending claims in actions commenced within two years before the operative date. A demand letter that never became a filed action isn't an "action commenced."
  • The broad "commercial business purpose" exemption was stripped out in July 2026 before the bill passed. There is no general carve-out for businesses.

The part that matters

What SB 690 does not do

  • CIPA §631 and §632 are unchanged. Those are the interception and eavesdropping sections: a third party receiving the contents of a visitor's communication without consent. Session-replay scripts that record keystrokes, chat widgets that route the conversation through a vendor, and pixels that forward what someone typed into a form or search box all live here. Private plaintiffs can still sue, and the $5,000-per-violation figure in Penal Code §637.2 still applies.
  • The federal Wiretap Act and other states' wiretap laws are untouched. Pennsylvania, Washington, Florida and others have their own statutes; some already drive suits of their own.
  • EU and UK rules are unaffected. GDPR and the ePrivacy rules still require consent before non-essential trackers run. France's CNIL fined Shein €150M in September 2025 for cookies placed without consent.
  • The defense bar expects a pivot, not a pause. Firms covering the bill say plaintiffs' counsel will shift the same facts to §631 and §632. The governor's own signing message said CIPA "contains other decades-old statutes that are also susceptible to abuse" and asked the Legislature to keep going in 2027 — so this area will move again.

For your site

What this means in practice

The question used to be "how many scripts fire before consent?" After SB 690 the sharper question is "does anything capture what a visitor types, says or watches before they consent — and where does it go?"

Still live

Session replay (Hotjar, FullStory, Clarity, Quantum Metric), live-chat widgets, and any script that sends form or search input to a third party before consent. This is the §631 contents-capture pattern.

AG-only

A plain pixel or analytics beacon that only sends a page view and a device identifier. The pen-register theory over this is no longer a private claim in California. State privacy acts, GDPR and the Attorney General still apply.

Watch

Pixels on forms and search pages. Meta, TikTok and similar pixels can forward the typed contents — courts have treated that as interception, and that claim did not go away.

2027

More CIPA reform is expected. Dated, independently verifiable records of what your site did and when are the thing that stays useful no matter how the statute moves.

What we changed

How ForensicConsent reflects SB 690

  • Detection is unchanged. ForensicConsent always watched for replay, chat, pixel and fingerprint scripts that transmit before consent, and the chat "gotcha" test always checked whether typed input leaves the page. That is the §631 fact pattern.
  • The legal-exposure labels were re-based (extension 0.5.1, ruleset 2026.10.06). Session replay and chat are labelled as CIPA §631 contents capture. Pixels and analytics are labelled §631 only where contents or form data are sent, otherwise state privacy acts. Fingerprinting and cookies note that §638.51 is Attorney-General-only enforcement since SB 690. Nothing is presented as a private pen-register claim anymore.
  • The EU side is unchanged. Every finding still carries its GDPR / ePrivacy basis.
  • Still exposure, never a verdict. ForensicConsent reports what transmitted and when, with a tamper-evident, independently verifiable record. Whether any of it is a violation is a question for counsel.

See what your site sends before anyone clicks Accept.

Free to install. No account, no card. Detection runs in your browser.

Install ForensicConsent free