09/01/2026
If you run basic website cookies, analytics, or a chat widget, you've probably been sweating California's wiretapping lawsuits. 😓 Statutory damages start at $5,000 per violation, and they can stack per visitor, per session. Most businesses settle rather than risk that math playing out in court.
Fisher Phillips attorney Usama Kahf testified to state lawmakers this summer: "With typical settlements at $15,000 to $25,000, more than half a billion dollars has been siphoned from businesses, non-profits, and public agencies."
Lawmakers just unanimously voted to kill a big chunk of these claims.
But that doesn’t mean C**A risk has disappeared. Private litigants can still sue under C**A. Here's what actually changed, and what to do before September 30.
SB 690 eliminates private lawsuits over "pen register and trap-and-trace" claims (C**A Section 638.51), the theory that your analytics tools function like illegal phone taps. Only the state Attorney General could bring those claims now, and it applies retroactively to cases filed since early 2025.
What it doesn't touch: Section 631 wiretapping claims. That's the provision behind most of the demand letters businesses are actually getting, and it's untouched. Litigation is already shifting toward session replay tools, chat features, and whether you got consent before third-party scripts fired.
Newsom has until September 30 to sign or veto the bill. Don't wait to find out if you're still exposed.
✅ Check your risk now: https://pvcy.me/4xx4NfQ