California Legislature Looks to Rein In Certain CIPA Claims Through SB 690: Miller and Sperling Publish Bloomberg Law Analysis
Glaser Weil litigation partners Sarah G. Miller and Elizabeth Sperling have co-authored a new Bloomberg Law article, “California Bill Could Curb Privacy Lawsuits Hitting Businesses,” examining California Senate Bill 690 and its potential impact on the growing wave of privacy litigation targeting businesses nationwide.
As website-tracking and consumer privacy lawsuits continue to proliferate under California's Invasion of Privacy Act (CIPA), SB 690 represents one of the most significant legislative efforts to date to address claims arising from so-called "pen register" and "trap and trace" allegations. If enacted, the bill could substantially limit private lawsuits asserting that businesses unlawfully track IP addresses or browser activity through common website technologies.
Miller and Sperling explain that CIPA, originally enacted in 1967 to address telephone wiretapping, has increasingly been applied to modern website technologies, resulting in a surge of litigation against companies using tools such as analytics platforms, chat functions and other online tracking mechanisms. The authors note that inconsistent court rulings have created significant uncertainty for businesses, prompting numerous lawsuits and demand letters seeking quick settlements.
The article highlights several important developments and considerations, including:
- How SB 690 would narrow private enforcement
- The continued risk associated with Section 631(a) claims
- The significance of the bill's retroactivity provisions
- Why businesses should proactively audit their websites
- The importance of maintaining effective privacy notices, cookie banners and consent-management tools
- The potential for litigation to shift to other legal theories
While SB 690 could provide meaningful relief from certain categories of privacy litigation, Miller and Sperling caution that businesses should not view the legislation as a complete solution. Companies should continue evaluating their privacy compliance programs and website technologies to mitigate risk under both California and federal privacy laws.