/ 2 min read

California legislature amends CIPA to remove private right of action

The California legislature has passed a long-awaited amendment to the California Invasion of Privacy Act ("CIPA") removing the private right of action that has become big business for plaintiffs' firms and a handful of pro se professional plaintiffs. S.B. 690 was first introduced in early 2025 but stalled, only to see advancement in July of this year. The amendment makes it so that violations of CIPA concerning internet websites, online applications, and mobile applications can only be prosecuted by the California Attorney General. The amendment also has retroactive application to any pending claim in an action commenced within 2 years of the bill's operative date.

For years, CIPA claimants have been alleging that various advertising and analytics technologies placed on websites without their consent constitute illegal wiretaps, trap-and-trace devices, and pen registers under the law. Overtime, courts have become less receptive to these claims, but without legislative action or unanimity among courts, the claims have persisted. This trend has resulted in many businesses, including B2B businesses that do not have large amounts of regular consumer traffic, switching to a consent-based strategy for these technologies, despite otherwise stricter and more comprehensive privacy regimes such as the California Consumer Privacy Act only requiring businesses to provide an opt-out choice.

CIPA was not the only law, however, that these plaintiffs have pursued claims under with respect to website technologies, and businesses will still need to be vigilant over their website operations. Claimants have recently been alleging that placing technologies on a user's browser or device without consent violates the California Comprehensive Computer Data Access and Fraud Act ("CDAFA"), especially where a faulty cookie banner is involved. There has also been an uptick in theories under the federal Electronic Communications Privacy Act ("ECPA"), in which claimants allege certain uses of data broker technologies and technologies that create “communications” meet the crime-tort exception under the ECPA, allowing for a private right of action. While healthcare-related claims seem to have more success under the ECPA thus far, and courts are slowly applying skepticism to these claims as they develop, the potential class size under the ECPA should give businesses pause. 

In summary, assuming the California governor signs S.B. 690 into law, this amendment is welcome relief for businesses. However, websites and related technologies continue to be a source of litigation, and organizations must remain vigilant about their website operations.