SB 690 Ends Pixel Lawsuits, Chat Widget Claims Survive

Affiliate disclosure: This post contains affiliate links. If you buy through them, I may earn a commission at no extra cost to you. Full disclosure

Gov. Gavin Newsom signed SB 690 on September 30, ending private lawsuits over website pixels and cookies under California’s pen-register law.

If you run a store like the ones I teach at Ecommerce Paradise, this changes your legal exposure but not your tracking setup. The lawsuit theory that has hit thousands of site owners just lost its private plaintiffs. The theory aimed at chat widgets and session replay tools did not.

Below is what the bill does, how pixel suits climbed to nearly 4,000 claims, what the law fixes and what it leaves open, and a checklist to finish before it becomes operative on January 1, 2027. I’m not a lawyer, so treat this as reporting plus my opinion, and run your specifics past counsel.

Sell online and you can be sued, so form your LLC with Northwest Registered Agent, the best LLC formation service for ecommerce owners. Cheap formation sites that upsell you at renewal are the ones to dodge, and Northwest keeps your renewal price the same as year one. Form your LLC with Northwest →

Newsom Signs SB 690: Private Pixel and Cookie Suits End

Newsom signed Senate Bill 690 on September 30, the last day of his constitutional deadline, according to PPC Land. The bill removes the private right to sue under California Penal Code Section 638.51, the pen-register and trap-and-trace provision of the California Invasion of Privacy Act (CIPA), when the target is a website or app operator. Per PPC Land, enforcement passes exclusively to the California Attorney General starting January 1, 2027.

The governor’s signing message framed the target directly. The bill “addresses the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites,” according to the message as quoted by PPC Land.

The law reaches backward. Sidley Austin, in a client alert dated September 3, said the bill applies to pending claims filed within two years before January 1, 2027, so defendants in existing Section 638.51 cases can seek dismissal once it becomes operative. Another summary from TrueVault describes the window as claims filed after January 1, 2025, so the exact edges are worth confirming with a lawyer.

Fisher Phillips, in an October 1 analysis, reported that plaintiffs’ firms have signaled they will challenge the retroactive piece in court. Its analysis also puts the remaining exposure in numbers: of the 4,000-plus CIPA suits, roughly one-third involve only pen-register claims, and another third combine pen-register allegations with wiretapping claims.

That second group matters most. Procopio, in an October 1 alert, said the law preserves claims under Penal Code Section 631, including allegations involving pixels, session replay, chat tools, and third-party software development kits that intercept communications. Butler Snow likewise said private plaintiffs can still pursue wiretapping and eavesdropping theories, and Sidley added that federal Wiretap Act claims remain available as an alternative.

The governor is not done. PPC Land reported that Newsom signaled interest in future limits on the provisions that survived.

Why CIPA Pixel Lawsuits Hit Nearly 4,000 Before SB 690

The bill’s path was not smooth. Sidley reported that SB 690 was introduced in March 2025 in a broader form, with a “commercial business purpose” exemption that would have covered wiretapping and eavesdropping claims too. That version stalled. The 2026 rewrite narrowed the scope to pen-register and trap-and-trace claims only, and the legislature passed it with what Sidley called overwhelming bipartisan support on August 28, 2026.

The votes were lopsided. PPC Land lists a 35-0 Senate vote on June 3, 2025, a 66-0 Assembly vote on August 28, 2026, and a 40-0 Senate concurrence the same day, with no recorded opposition at any floor or committee vote.

Behind those votes sits a litigation wave. PPC Land reported that Section 638.51 claims grew from roughly 600 to nearly 4,000 after February 2025, with thousands of demand letters on top. The damages formula did not change: $5,000 per violation or three times actual damages. A coalition called Stop CIPA Shakedown Lawsuits, which counts small businesses, nonprofits, healthcare providers, local news outlets, farmers, and public agencies among its members, backed the bill.

The counterpoint is built into the reporting. Plaintiffs’ firms plan to fight the retroactivity, per Fisher Phillips, and TrueVault noted that plaintiffs’ strategies have shifted several times already and will likely shift again. None of the sources I reviewed quoted a consumer-side objection on the record, so I can’t tell you what the privacy plaintiffs’ bar says beyond its litigation posture.

I covered the browser-side version of the same tension when iOS 27 started blocking Trade Desk ads in Safari. Tracking is getting squeezed from the platform side and the courtroom side at once.

What SB 690 Does and Doesn’t Fix for Your Shopify Store

My read: this is relief for one claim type, not a green light for tracking.

Start with timing. The law becomes operative January 1, 2027, and the retroactivity is likely to be tested. Until a court rules, a demand letter that lands on your desk next month is still a real problem, so keep your records clean. That is my inference from the reporting, not a legal opinion.

Next, the chat widget. Plenty of store owners paste a live chat script on every page and never think about it again. If a plaintiff claims each conversation was intercepted, the arithmetic gets ugly fast. Hypothetical math: if a plaintiff alleged 10 intercepted chats and a court applied the $5,000 statutory figure to each, that is $50,000 before legal fees. I made those numbers up to show the shape of the risk, they are not from any case.

Here is how I’d sort stores by exposure, using my own rule of thumb rather than any legal threshold. If your analytics show almost no California sessions, put this on the back burner. If California is a meaningful slice of your traffic, say 5% or more, handle the checklist below this month. California is the largest state market in the country, so I’d assume you are in the second group until your analytics say otherwise.

Attorney General enforcement is a different animal, and this part is my read. A private plaintiff’s firm profits from volume, so it sends thousands of letters and settles cheap. A state agency picks cases that make headlines. I expect fewer pixel demand letters and a slower, more public process, which favors stores that can show they made a good-faith effort to disclose and get consent.

Three scenarios, with my own thresholds. Scenario one: California is under 2% of your sessions, you run a pixel and email tracking only, and you have no chat. Do the script inventory and move on. Scenario two: California is 5% or more, you run chat on every page, and your privacy policy was copied from a template. That store should fix disclosures within 30 days. Scenario three: you have already received a demand letter. Call a lawyer before you do anything else, because the retroactivity question is exactly what counsel will want to examine.

There is also a sales angle. High-ticket buyers want to talk to a human before spending $3,000 or $10,000, which is why I tell stores to keep a phone number and chat on the site. Ripping out chat to dodge a lawsuit theory would cost you more in lost sales than a disclosure banner costs in setup time.

Your tool stack decides the rest. A pixel-only store has less to worry about than one running chat, session replay, and third-party scripts. The scripts that deserve a second look are the ones that capture what a visitor types or does. That is why I keep pushing proper consent and policy setup with Termly instead of a copy-pasted privacy page.

Privacy is also one of several operational risks that can hurt a high-ticket store. If you have not built the other defenses yet, my guide to chargeback prevention for high-ticket stores belongs on the same to-do list. So does my warning about single-processor risk. Compliance work stacks up, and it is a pain in the butt when you are also running ads and talking to suppliers.

Entity structure matters here too. An LLC does not stop anyone from filing a claim, but it puts a legal wall between the business and your personal assets when you set it up and run it correctly. My walkthrough on forming an LLC with MyCompanyWorks covers the basics.

Pair it with my guide to getting a business address without renting an office. My business formation page lays out the options.

Stores that grow fast also grow their script count. Every new app, pixel, and AI shopping tool adds a data path. I flagged the same pattern when Meta’s Muse plugged into Shopify and Stripe.

It showed up again when Shopify let AI agents submit orders. If auditing all of that sounds like a second job, that is the problem my turnkey done-for-you service exists to solve, because my team builds the store and runs it so you are not reading terms of service at midnight.

Want my team to build and run your high-ticket store so you are not auditing pixels and chat scripts yourself? See the turnkey done-for-you service →

Your Pixel, Chat and Consent Checklist Before Jan. 1, 2027

Here are five things I’d do this month, in this order.

  1. Check your California traffic. Open the sessions-by-location report in your Shopify analytics and write down the California percentage, because that number sets how urgent everything below is.
  2. Inventory every script. In Shopify admin, open Settings and then Customer events, list every pixel and app script, and add the ones you installed outside Shopify, like heatmaps, session replay, and your email tool’s site tracking from Klaviyo. Anything nobody on your team can explain gets removed.
  3. Fix consent and your privacy policy. Set up an opt-in banner and a policy that matches the tools you actually run, which is what TrueVault recommends, using Termly if you want a tool to do the heavy lifting.
  4. Add a disclosure to chat. Check the settings in Tidio if that is your chat tool. If you run a helpdesk like Gorgias, check it too, and make sure visitors see a notice that conversations are recorded and processed by a vendor before they type.
  5. Get a lawyer’s eyes on it. If you do not have counsel on call, a plan like LegalShield gets you a lawyer to ask. You can also book a discovery call with me to talk through your store’s setup first.

Keep a dated record of every change you make. Screenshot the banner, save the policy version, and note the day you added the chat disclosure. If a letter ever arrives, a paper trail showing you acted in good faith gives your lawyer something to work with, and it takes about an hour to build.

If you receive a demand letter, do not pay it or ignore it. Send it to a lawyer the same day, since the retroactive window may let counsel get it dismissed.

Frequently Asked Questions

Does SB 690 stop all CIPA lawsuits?
No. It removes private suits under Section 638.51 only. Procopio and Butler Snow both say wiretapping claims under Section 631 remain, and those cover chat tools, session replay, and some pixels.

When does the law take effect?
PPC Land reports January 1, 2027, when Attorney General enforcement begins. Sidley says defendants can seek dismissal of qualifying pending cases once the law is operative.

I sell nationwide. Does this protect me everywhere?
No. It changes California law. Other states have their own privacy and wiretap statutes, and Sidley notes the federal Wiretap Act is still an alternative route, so a nationwide store should talk to counsel.

Do I still need a cookie consent banner?
TrueVault recommends opt-in consent for pixels and cookies plus a privacy policy that matches your real tools. I’d keep both. This is not legal advice, so confirm with your lawyer, and my Termly setup guide shows the mechanics.

Should I rip out my chat widget?
I wouldn’t. Phone and chat close high-ticket sales. Add a clear disclosure, review the vendor’s terms, and ask counsel about your setup. My post on collecting payments for phone and WhatsApp orders shows how stores handle those channels.

Does an LLC protect me from these lawsuits?
An LLC can separate business liabilities from your personal assets when it is formed and run properly, but it does not prevent someone from suing. If you have not formed one, my ZenBusiness walkthrough is another option to compare.

I’m new to high-ticket stores. Where do I start?
Read my guide on what high-ticket dropshipping is. Then grab my free niches list at ecommerceparadise.com/niches.

Want to compare notes on privacy and compliance with other store owners and me inside the community? Join the Skool community →

The legal side of running a store keeps changing, and I’ll keep flagging the changes that cost you real money. Subscribe to the YouTube channel for daily breakdowns. More breaking news coming through the day.

Related Articles

If this was useful, these go deeper:

Free 1,000+ high-ticket niches list

Still deciding what to sell?

Grab the free list of 1,000+ niches that work for high-ticket dropshipping, sorted by category.

Free. Unsubscribe any time.