California SB 690 and CIPA Website Tracking Claims: What Changed, What Hasn't, and What Businesses Should Know
California Senate Bill 690 has moved significantly closer to becoming law, creating an important development for businesses facing CIPA website-tracking allegations involving pen-register and trap-and-trace theories.
But the practical takeaway is not that website-tracking risk has disappeared.
SB 690 addresses a specific category of claims. It does not make every CIPA theory disappear, resolve other privacy requirements, or eliminate the need to understand what tracking technologies are actually doing on a website.
For businesses that have already received a CIPA demand letter, are defending a website-tracking claim, or are reviewing their tracking environment with counsel, there is an important distinction to keep in mind:
The legal theory may change. The underlying technical facts still need to be established.
This article explains the current status of SB 690, what the enrolled bill would change, what it does not change, and why evidence about website tracking behavior can still matter.
Technical scope note: Auditzo provides technical website evidence, consent-state testing, and remediation-oriented observations. We do not provide legal advice, determine whether CIPA has been violated, evaluate the legal viability of a claim, or predict litigation outcomes. Qualified counsel should evaluate how SB 690 or any other legal development applies to a particular matter.
SB 690 Status as of September 9, 2026
California Senate Bill 690 has passed both houses of the California Legislature.
The Assembly passed the bill on August 28, 2026, and the Senate concurred in the Assembly amendments the same day. The bill was enrolled on August 31 and presented to the Governor on September 4, 2026.
As of September 9, the official California Legislature record continues to list SB 690 as an Active Bill - Enrolled, with its house location shown as the Governor.
That distinction matters.
SB 690 should not yet be described as enacted California law.
Businesses, attorneys, privacy professionals, and technical teams following an active matter should check the official California Legislature SB 690 status page for the latest status before relying on an article, social post, vendor communication, or other secondary source.
What Would SB 690 Change?
The enrolled bill would amend California Penal Code Section 637.2, which currently provides a civil remedy for violations of the relevant CIPA chapter.
For an alleged violation of Section 638.51 arising from conduct occurring on an internet website, online application, or mobile application, the enrolled language provides that an action against a private actor under Section 637.2 may be brought only by the California Attorney General.
In practical terms, if enacted in its enrolled form, SB 690 would materially change the private-action landscape for website and application claims based specifically on the Section 638.51 pen-register and trap-and-trace theory.
The enrolled text also includes a retroactivity provision applying the amendment to a pending claim in an action commenced within two years before the legislation's operative date.
The exact effect of those provisions on an existing demand, complaint, lawsuit, settlement discussion, or procedural strategy is a legal issue that should be evaluated by qualified counsel.
The official enrolled text of SB 690 should be reviewed when evaluating the scope of the proposed amendment.
What SB 690 Does Not Do
This is where businesses should be careful about headlines suggesting that SB 690 simply "ends CIPA website lawsuits."
That description is broader than the enrolled bill supports.
SB 690 amends Section 637.2 with respect to the specified Section 638.51 website and application claims.
It does not amend California Penal Code Section 631.
Section 631 uses different statutory language involving specified conduct concerning communications and can raise different legal and technical questions from a Section 638.51 pen-register or trap-and-trace theory.
The bill also should not be treated as resolving requirements that may arise independently under other privacy statutes, contractual arrangements, consent requirements, or other legal theories.
Which laws or theories apply to a particular website, business, claimant, or dispute is a question for qualified counsel.
SB 690 should therefore be analyzed claim by claim, not treated as a universal website-tracking exemption.
Why This Matters for Businesses That Already Received a CIPA Demand Letter
If your company has already received a CIPA website-tracking demand letter, SB 690 may be highly relevant to counsel's analysis.
But the first question is still:
What does the demand actually allege?
A letter focused specifically on Section 638.51 presents a different situation from one alleging Section 631, multiple CIPA provisions, or additional legal theories.
That is why businesses should avoid reducing the analysis to:
SB 690 passed the Legislature, so the demand no longer matters.
That conclusion goes further than the current procedural status and enrolled bill text support.
Counsel should first determine which claims are being asserted, what procedural posture exists, and how SB 690 may affect those claims if it becomes law.
Separately, technical teams may still need to establish what website behavior occurred.
If you are dealing with an existing demand, Auditzo's CIPA Demand Letter Technical Evidence Guide explains how to preserve the current website state, review supplied evidence, and translate allegations into testable technical questions.
Why Technical Website Evidence Still Matters
SB 690 addresses a legal remedy. It does not tell an attorney or business what the website actually did during a particular browsing session.
Those are separate questions.
A modern website may contain analytics tools, advertising pixels, tag managers, chat widgets, session technologies, ecommerce integrations, CRM scripts, consent tools, and other third-party components.
Determining whether one of those technologies was merely present, actually executed, generated a network request, transmitted observable values, or behaved differently based on consent requires technical investigation.
Depending on the matter, useful technical questions can include:
- Which third-party technologies were present?
- Which technologies actually executed during the tested session?
- Which external domains received browser requests?
- What observable parameters or payload fields were transmitted?
- Did relevant requests occur before any consent interaction?
- What changed after Accept?
- What changed after Reject or Decline?
- Did cookies or browser storage differ between consent states?
- Which user action preceded a particular request?
- Can the behavior identified in a demand letter still be reproduced?
- Has the website configuration changed since the alleged event?
These questions do not determine whether CIPA or another law was violated.
They establish a technical record that counsel, privacy teams, developers, and other qualified reviewers can evaluate in the context of the matter.
Detection Is Still Not the Same as Transmission
One recurring problem in website-tracking disputes is collapsing several different technical stages into one conclusion.
1. Technology Detection
A script, tag, cookie, integration, domain, or technology signature is identified.
Detection can establish the presence of a technology or technical indicator.
It does not necessarily establish what occurred during the relevant browsing session.
2. Execution
The relevant browser-side technology actually executes or initializes.
This is stronger behavioral evidence, but execution alone does not describe every communication that may result.
3. Network Transmission
The browser makes an observable request to an external or internal endpoint.
At this stage, a technical reviewer may be able to examine:
- destination
- timing
- HTTP method
- request structure
- observable parameters
- payload fields where visible
- initiator information
- consent and session context
4. Technical Interpretation
A reviewer evaluates what those artifacts demonstrate about observable browser behavior.
Limitations still matter. Browser-side evidence, for example, may not reveal every process that occurs after information reaches an external server.
5. Legal Interpretation
Qualified counsel evaluates technical findings against the statute, asserted theory, relevant authority, consent issues, procedural posture, defenses, exceptions, and other legally material facts.
These stages should not be treated as interchangeable.
The presence of a pixel does not, by itself, establish every factual or legal claim that could be made about that pixel.
What About Section 631 Website-Tracking Claims?
SB 690 does not amend Section 631.
Businesses should therefore not assume that a proposed change affecting private Section 638.51 actions automatically resolves allegations based on Section 631.
Section 631 uses different statutory language and may require counsel to evaluate different factual and legal questions.
From a technical perspective, this can make it important to understand exactly what happened during a particular interaction rather than relying only on a list of detected tracking technologies.
Depending on the allegation and agreed scope, a technical review may examine interactions such as:
- website searches
- lead-generation forms
- contact forms
- chat interactions
- checkout or shopping-cart events
- account or signup workflows
- appointment or quote requests
- analytics events
- advertising events
- session technologies
- third-party scripts triggered by a user action
The technical objective is to connect an interaction to observable browser behavior and supporting evidence.
User action -> Browser behavior -> Supporting artifact -> Technical interpretation
Qualified counsel determines the legal significance of that record.
Do Not Confuse Legislative Change With Website Remediation
Another mistake would be to interpret SB 690 as a reason to stop reviewing consent and tracking behavior.
The legislative development does not automatically answer whether a website's consent implementation works as intended.
A business may still need to know whether optional technologies activate before a consent choice, whether a Reject choice suppresses the expected requests, whether browser storage persists, or whether an integration operates outside the site's primary consent mechanism.
Those questions can remain relevant to privacy programs, other regulatory frameworks, client requirements, internal governance, vendor oversight, technical remediation, and counsel-directed review independently of the particular Section 638.51 private-action issue addressed by SB 690.
Where deeper behavioral testing is required, Auditzo's Manual Evidence Audit compares observable website behavior across defined sessions rather than relying only on a tracker inventory.
If Your Website Is Being Reviewed Now, Preserve the Current State
Website technology can change quickly.
A developer can republish a Google Tag Manager container. A consent rule can be modified. A Shopify or WordPress application can update. A marketing platform can change its implementation. A pixel can be removed or replaced.
Once that happens, a current test may no longer reproduce the environment that existed when a demand letter, complaint, or technical allegation was created.
Depending on the matter and counsel's direction, potentially relevant technical material can include:
- HAR or browser network captures
- timestamped screenshots
- screen recordings where appropriate
- cookie and browser-storage records
- tag-manager versions
- consent-management platform configuration
- available consent records
- deployment history
- integration settings
- relevant application or plugin versions
- relevant server or platform records where available
- technical evidence supplied with the demand or complaint
Not every matter requires every artifact.
The goal is not maximum data collection. The goal is relevant, traceable, and reproducible evidence.
For a deeper methodology, see Auditzo's Website Tracking Evidence Preservation Guide for Legal Review.
What Businesses Should Do While SB 690 Is Awaiting Governor Action
Businesses reviewing an active matter should keep the legal and technical workstreams distinct while allowing each to inform the other.
1. Confirm the Current Bill Status
SB 690 remains in an active legislative process. Do not rely on an older article, headline, social post, or vendor email as the definitive current status.
Check the official California Legislature record when the status matters to a live decision.
2. Have Counsel Review the Actual Allegations
Determine whether the matter concerns Section 638.51, Section 631, multiple theories, or another legal framework.
A technical auditor should not determine which legal theory succeeds.
3. Preserve Relevant Evidence Before Material Changes
Where preservation is appropriate, document the website's relevant current state before tracking or consent configurations are materially modified.
4. Establish What the Website Actually Does
Test the relevant pages, user journeys, consent states, requests, cookies, browser storage, and third-party connections under defined conditions.
5. Keep Remediation Separate From Historical Evidence
If changes are made, preserve the original evidence separately and maintain a clear record of what changed.
6. Re-Test After Remediation
Do not assume that changing a tag, CMP rule, application setting, or GTM configuration produced the intended technical result.
Use a fresh controlled session to verify the post-change behavior.
Auditzo's Post-Remediation Verification process is designed around this before-and-after distinction.
What If SB 690 Is Signed?
If SB 690 is signed in its enrolled form, businesses and counsel should review the final enacted text, operative timing, retroactivity language, and how those provisions apply to the particular matter.
The legal analysis may change.
The underlying technical history does not.
A change in legal theory does not change what the browser did during an earlier session.
If website-tracking behavior remains relevant to another legal theory, privacy requirement, internal compliance question, remediation decision, vendor investigation, or counsel review, reliable technical evidence can still be useful.
This article should also be reviewed again after any gubernatorial action because the current status described here is time-sensitive.
How Auditzo Supports CIPA-Related Technical Review
Auditzo provides technical website evidence support for businesses, law firms, privacy professionals, and technical teams reviewing website-tracking behavior.
Unlike a generic scanner-only approach, a matter-specific review can be designed around the actual technical questions raised by a demand, complaint, remediation effort, or counsel-directed investigation.
Depending on the agreed scope, a review may include:
- clean browser sessions
- initial-state observations
- Accept and Reject consent comparisons
- specific user-journey reproduction
- third-party request analysis
- HAR and browser network evidence
- cookies and browser storage
- timestamped screenshots
- review of supplied technical evidence
- finding-to-evidence references
- technical limitations
- remediation-oriented observations
- post-remediation verification
Auditzo does not decide whether SB 690 eliminates a claim, whether CIPA was violated, whether a demand should be settled, or whether litigation should proceed.
Our role is to establish what can be observed technically and organize that evidence so qualified counsel and technical teams have a clearer factual record.
Legal teams can review Auditzo's Technical Website Evidence Support for Law Firms. Businesses needing deeper human-reviewed testing can explore the Manual Evidence Audit.
Frequently Asked Questions About SB 690 and CIPA Website Tracking
Has California SB 690 Become Law?
No, not as of this article's September 9, 2026 review.
SB 690 has passed the California Legislature and was presented to the Governor on September 4, 2026. The official legislative record currently lists it as an active enrolled bill with the Governor.
Because the status can change, check the official SB 690 status page for subsequent action.
Would SB 690 Eliminate Private Section 638.51 Website Claims?
If enacted in its enrolled form, SB 690 would provide that an action under Section 637.2 against a private actor for an alleged Section 638.51 violation arising from conduct on an internet website, online application, or mobile application may be brought only by the California Attorney General.
How that provision affects a particular existing or future matter is a legal question for qualified counsel.
Does SB 690 Eliminate All CIPA Website-Tracking Claims?
No.
The enrolled bill specifically addresses the Section 637.2 remedy for the identified Section 638.51 website and application claims.
It does not amend Section 631 and should not be treated as a blanket resolution of other CIPA provisions or other legal requirements.
Does SB 690 Apply Retroactively?
The enrolled text states that the amendment applies retroactively to a pending claim in an action commenced within two years before the legislation's operative date.
How that language applies to a particular demand, complaint, lawsuit, or procedural posture should be evaluated by qualified counsel.
Should Businesses Stop Reviewing Website Tracking If SB 690 Is Signed?
No.
Website tracking behavior can remain relevant to other legal theories, privacy frameworks, consent requirements, contractual obligations, internal governance, vendor oversight, remediation, and technical risk management.
Separately from legal requirements, a business may simply need to know whether its website behaves as intended.
Does Finding Meta Pixel, Google Analytics, or Another Tracker Establish a CIPA Violation?
No.
Detection establishes that a technology or technical indicator was observed.
It does not automatically establish execution, network transmission, the complete contents of a request, or the legal significance of the observed behavior.
Can a Website Scan Tell Us What Was Transmitted?
An automated scan can help identify technologies, cookies, external domains, requests, and other technical signals.
A matter-specific investigation may require deeper human-reviewed testing, including HAR analysis, user-journey reproduction, request inspection, consent-state comparison, cookies, browser storage, and evidence supplied with the allegation.
Should I Remove Tracking Technologies Immediately After Receiving a CIPA Demand?
Auditzo does not make that legal or business decision.
From a technical evidence perspective, businesses and counsel should consider whether relevant current-state behavior needs to be documented before material configuration changes are made.
What If the Website Has Already Been Changed?
A current audit can establish what is observable now.
Historical conclusions may require earlier HAR files, screenshots, logs, configuration history, tag-manager versions, consent records, deployment history, or other timestamped evidence.
Current behavior should not be represented as proof of historical behavior unless the available evidence supports that conclusion.
Can Auditzo Determine Whether SB 690 Defeats Our Demand Letter or Lawsuit?
No.
That is a legal question for qualified counsel.
Auditzo can investigate and document website behavior, reproduce scoped interactions where reasonably possible, compare consent states, review supplied technical artifacts, and explain what the technical evidence does and does not establish.
Received a CIPA or Website-Tracking Demand?
Before changing the website or relying only on a generic tracker list, establish what the relevant website behavior actually was.
Start with Auditzo's CIPA Demand Letter Technical Evidence Guide to understand evidence preservation, allegation-specific testing, HAR review, consent-state comparison, and technical evidence organization.
If the matter requires human-reviewed browser testing, Auditzo can scope a Manual Evidence Audit around the specific URLs, technologies, workflows, consent states, and technical questions identified by the business or counsel.
Attorneys and legal teams can also review our Technical Website Evidence Support for Law Firms.
Legal rules can change. Reliable technical evidence still begins with establishing what the website actually did.
Table of Contents
- SB 690 Status as of September 9, 2026
- What Would SB 690 Change?
- What SB 690 Does Not Do
- What This Means If You Already Received a CIPA Demand Letter
- Why Technical Website Evidence Still Matters
- Detection Is Still Not the Same as Transmission
- What About Section 631 Website-Tracking Claims?
- Do Not Confuse Legislative Change With Website Remediation
- If Your Website Is Being Reviewed Now, Preserve the Current State
- What Businesses Should Do While SB 690 Is Awaiting Governor Action
- What If SB 690 Is Signed?
- How Auditzo Supports CIPA-Related Technical Review
- Frequently Asked Questions About SB 690 and CIPA Website Tracking
- Received a CIPA or Website-Tracking Demand?