SACRAMENTO, Cal. — Governor Gavin Newsom has signed into law a bill to narrow the scope of the California Invasion of Privacy Act (CIPA), to prevent abusive lawsuits targeting online businesses, including adult websites.
As industry attorney Nick Zargarpour explained in a recent article for XBIZ, CIPA prohibits improper monitoring of someone’s communications without their consent or a court order, including by using trap-and-trace devices or “pen registers.”
Adult sites and others have experienced a wave of CIPA lawsuits accusing them of violating CIPA by planting trackers and cookies, and sharing information about site users, before obtaining those users’ permission. Some courts have ruled that CIPA does not apply to websites, but others have ruled that the law may apply and allowed plaintiffs to seek monetary settlements.
SB 690 narrows the scope of CIPA, so that only the state attorney general can sue for CIPA violations. It is partially retroactive, applying to some pending claims filed since January 1, 2025.
In his signing message to the state legislature, Newsom wrote: “This measure addresses the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites that at times have tracked and shared the information of visitors to the site. I applaud the author’s efforts and align myself with the goal of protecting small businesses from overzealous lawsuits based on a statute written without today’s complex technological landscape in mind.”
Newsom added that additional work on the issue is still needed.
“CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants,” the governor’s message notes. “I urge the Legislature to take this on next year to ensure a fair balance between protecting private information and preventing rapacious litigation.”
Attorney Corey Silverstein shared an update on the legislation, calling the change “significant” but cautioning adult businesses to continue scrutinizing technologies that could still fall under CIPA’s provisions, and to comply with other privacy statutes.
“The practical consequence is that businesses should stop treating every ordinary tracking technology as if it presents the same California CIPA risk,” Silverstein writes. “The correct analysis now turns much more heavily on what the technology actually collects, what it transmits, who receives the data, and for what purpose.”