California’s governor approved SB 690 on September 30, limiting who can sue under the state’s pen register provision when the conduct involves websites and apps. The bill was chaptered as Chapter 976 and filed with the Secretary of State the same day. It amends Penal Code Section 637.2.

Existing law bars a person from installing or using a pen register or a trap and trace device without a court order, and lets an injured person sue. Under Section 637.2, damages are the greater of $5,000 per violation or three times actual damages. The new subdivision (d) says an action against a private actor for a violation of Section 638.51 that is alleged to arise from conduct on an internet website, online application or mobile application may be brought only by the Attorney General. The limit applies retroactively to any pending claim in an action commenced within two years before the operative date. The bill also declares its provisions severable.

For marketing teams, the text answers one question and leaves others open. It removes the private right of action for that one section when the conduct is on a website or app. It does not change what Section 638.51 prohibits, since the bill amends only the section that sets who can bring the action, and the Attorney General can still sue. Subdivision (d) names only Section 638.51, so a team’s exposure under other sections of the chapter is a question for counsel.

Our read: tag and consent audits remain worth doing. A law that changes who can sue does not change what a tag does when a page loads. Teams should keep their inventory of third-party scripts current, and watch for the bill’s operative date, which the chaptered text does not state in the portion we reviewed. For related state-level changes see New Jersey Redefines Who Counts as a Data Broker and A Federal Bill Would Make AI Crawlers Identify Themselves.

Source: California Legislative Information, SB-690 Crimes: invasion of privacy (Chaptered)