Wiretapping change sparks big privacy fight in the Golden State
A bipartisan update to a California wiretapping law will eliminate the right to sue over internet-based surveillance, ending a key provision of a 57-year-old wiretapping law. Advocates say it is an overdue correction meant to prevent frivolous lawsuits, while privacy advocates call it a blow to digital consumer privacy rights.
The California Invasion of Privacy Act, originally passed in 1967, requires a court order for wiretapping, eavesdropping, interception or recording of telephone calls. Over time, courts extended the law to cover most internet-based communications as well, such as email and websites.
In 2015, lawmakers added a provision allowing residents to sue companies for unauthorized use of certain internet-tracking technologies, such as pen registers, with penalties up to $5,000 per violation, plus triple damages. Last week, Calif. Gov. Gavin Newsom signed SB 690 into law, that gave a private right to sue websites and mobile applications.
Newsom and sponsors of the law say the provision has spawned thousands lawsuits and demand letters against companies for using common internet-tracking tools, like browser cookies, that serve legitimate business purposes.
Pen registers and trap-and-trace devices are primarily used by law enforcement agencies—such as local police, the FBI, and the DEA—as well as national security organizations during active criminal and counterintelligence investigations. Authorized through a court order, investigators use pen registers to log outgoing metadata like dialed phone numbers, IP addresses, and timestamps (and trap-and-trace tools for incoming contacts) to map out a suspect’s communication network without listening to the content of the conversations.
“This measure addresses the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites that at times have tracked and shared the information of visitors to the site,” Newsom wrote in his signing statement. “I applaud the authors’ efforts and align myself with the goal of protecting small businesses from overzealous lawsuits based on a statute written without today’s complex technology landscape in mind.”
According to privacy attorneys at law firm Kelley Drye, the addition of the pen register and trap-and-trace statute in 2015 was meant to codify how law enforcement agencies could obtain court orders for phone metadata without violating CIPA.
Estimates of lawsuits filed under the provision vary widely. The law was widely supported by business groups like the Chamber of Commerce, which was one of hundreds of California groups that signed in support of the legislation last year.
The Alliance for Legal Fairness, a Virginia-based lobbying firm backing the legislative update, tracked approximately 600 lawsuits under the provision in 2025, according to written comments. Today, the group claims that number has “exploded” to more than 4,000.
According to Shruti Bhutani Arora and Christine Mastromonaco, privacy attorneys for the law firm Pillsbury, plaintiffs and prospective litigants have “sent tens of thousands of demand letters to businesses threatening class-action suits under the CIPA’s pen-register and trap-and-trace provisions for using everyday website tools like cookies, analytics software and pixels.”
A report from the California Assembly Committee on Privacy and Consumer Protection characterized the pen register provision as “the poster child for abusive lawsuits.”
“Enterprising plaintiffs’ attorneys have exploited the statute at scale to go after businesses using third-party software to enable advertising on their websites,” the committee wrote. “Because the potential liability can be staggering, businesses generally settle this litigation hastily, encouraging vexatious litigants to continue blasting out demand letters.”
Meanwhile, most major California labor unions opposed the law, as did the American Civil Liberties Union, the Consumer Federation of California, the Privacy Rights Clearinghouse, the Electronic Privacy Information Center and dozens of civil rights groups.
The committee report also noted opposition by “a broad array of privacy, civil society, legal and immigrant rights organizations.”
The Electronic Frontier Foundation in particular has fought the bill for years. Early versions of SB 690 would have exempted other privacy provisions from private lawsuits, but later versions narrowed the exemption to just pen registers and trap-and-trace devices.
Privacy groups argue the exemption will make it easier for companies to track, collect and sell consumer data to third parties, including data brokers, while making it harder for individuals to take legal action.
Hayley Tsukayama, director of state affairs at EFF, told CyberScoop that the bill “never should have been signed” and that the organization tried and failed to lobby Newsom to veto it.
“CIPA was originally intended to protect personal privacy against the threat of surveillance of private communications,” said Tsukayama in a statement. “But this ‘reform’ harms privacy by making it impossible for ordinary people to sue companies engaged in unlawful metadata surveillance. That’s especially scary as the federal government and other law enforcement agencies seek data from businesses or data brokers to target people based on their political beliefs, religious affiliations, or health decisions.”
California passed major privacy legislation in 2018, standing up the California Privacy Protection Agency to enforce digital privacy laws. It has some of the strictest data broker laws in the nation, requiring brokers to register with the government and provide consumers with easy, universal opt-out options for data collection.