In the final weeks of California’s 2026 legislative session, lawmakers passed a series of bills that stand to significantly reshape the state’s privacy and AI regulatory landscape. Of particular significance, Senate Bill 690 (SB 690) seeks to curtail one of the principal theories underlying the recent wave of California Invasion of Privacy Act (CIPA) litigation, which has swept across diverse industries to affect website operators ranging from consumer brands to financial services firms. The bill would eliminate private actions under CIPA’s pen register and trap-and-trace provision, leaving the California Attorney General as the sole party authorized to bring those civil claims. If enacted, SB 690 would also apply retroactively to any pending pen/trap claim in actions filed within two years before its operative date, potentially affecting certain website-tracking cases already in litigation.
The Legislature simultaneously passed two consequential amendments to the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA). Senate Bill 923 (SB 923) would expand the right to deletion, extending it to personal information collected from or about a consumer, regardless of its source. Meanwhile, Assembly Bill 1542 (AB 1542) would generally prohibit businesses, service providers, and contractors from selling or sharing sensitive personal information with third parties, subject to specified statutory provisions and a narrow express exception.
Additionally, the Legislature approved several measures affecting AI, most notably amendments to the California AI Transparency Act. If enacted, these amendments would significantly revise requirements for generative AI providers and large online platforms, including new obligations for the provenance, verification, and disclosure of AI-generated or AI-altered content. The proposed changes would expand the range of regulated entities and strengthen the infrastructure for identifying and managing AI content, with immediate and future compliance implications for businesses deploying AI technologies.
Each measure awaits action by Governor Gavin Newsom, who has until September 30, 2026 to sign or veto them. There is no pocket veto in California, meaning any measure left unsigned by this deadline automatically becomes law without the Governor’s signature. Governor Newsom has moved quickly on other fronts, recently signing into law separate AI auditing requirements and child safety measures targeting chatbots and social media platforms.
Together, these initiatives mark significant developments in California’s approach to data privacy and artificial intelligence, reinforcing the state’s role as a national bellwether for technology regulation.
CIPA Reform: SB 690 Would Limit Certain Website Tracking Actions
Enacted in 1967 amid growing Cold War anxieties over electronic surveillance, CIPA establishes the state’s framework for regulating wiretapping and eavesdropping.1 Its civil remedies provision allows any person injured by a violation to seek the greater of $5,000 per violation or three times the actual damages, and authorizes injunctive relief without requiring a showing of actual harm or threat thereof.2 These expansive remedies have prompted a surge of litigation asserting that widely used website technologies—such as pixels, cookies, analytics services, session-replay tools, and chat functionalities—run afoul of statutory provisions originally designed to address conventional forms of electronic surveillance.
The avalanche of CIPA litigation directed at website tracking technologies—pixels, cookies, analytics services, session-replay tools, and chat functionalities—has principally relied on three distinct statutory theories. Section 631 addresses wiretapping and the unauthorized interception or use of the contents or meaning of communications while they are in transit.3 Meanwhile, Section 632 covers the unauthorized use of an electronic amplifying or recording device to eavesdrop or record a confidential communication without the consent of all parties.4 Section 638.51 separately prohibits the installation or use of a pen register or trap-and-trace device without a court order, subject to statutory exceptions.5 In the digital context, plaintiffs have alleged that website technologies violate Section 631 by intercepting the contents of communications, Section 632 by unlawfully eavesdropping or recording a “confidential communication” with a defendant’s website, and Section 638.51 by capturing routing, addressing, or signaling information associated with those communications.
Limitation on Private Actions. SB 690 reaches only the pen register and trap-and-trace theory. Rather than amending that prohibition, the bill rewrites CIPA’s civil remedies provision to effectively strip private plaintiffs of the right to sue on that theory when the alleged conduct occurs on a website or app, leaving enforcement to the Attorney General.6 The amendment is both significant and targeted. It does not determine whether a particular pixel, cookie, analytics service, or other technology qualifies as a “pen register” or “trap-and-trace device.” Nor does it legalize the underlying conduct or create a substantive safe harbor for specific technologies. Section 638.51 would remain in effect, including its criminal penalty, while the Attorney General would have exclusive authority to bring the specified civil actions under Section 637.2 involving covered website and application conduct.
Retroactive Application. Importantly, SB 690 would apply retroactively to a pending claim in an action commenced within the two years preceding the legislation’s operative date.7 If enacted with a January 1, 2027 operative date, the provision would reach qualifying pending claims in actions commenced on or after January 1, 2025, in both state and federal court, though how courts apply it in any given case remains to be seen. While the retroactive application provision may itself become a subject of dispute, its severability clause ensures the remaining sections survive if any part is ruled invalid.8
Continuing CIPA Exposure. SB 690 would provide meaningful but limited relief, reflecting a more targeted approach to CIPA reform than prior proposals. Unlike earlier iterations, SB 690 does not create a general exception for conduct undertaken for a commercial business purpose, nor does it amend the definitions of “pen register” or “trap-and-trace-device,” or broadly exempt routine business uses of website technologies. Most importantly, it does not touch CIPA’s wiretapping and eavesdropping provisions or restrict private actions alleging that a website technology unlawfully intercepted or recorded the contents of a communication. Accordingly, a plaintiff unable to pursue a pen register or trap-and-trace claim may attempt to recast the same technology and data flow as unlawful wiretapping or eavesdropping under CIPA’s other provisions.
CCPA Amendments: Expanded Deletion Rights and Sensitive-Data Restrictions
The CCPA has also been in the Legislature’s crosshairs. In the session’s final days, the Legislature passed two notable amendments to the CCPA, both of which would strengthen consumer control over their personal information. SB 923 would extend consumers’ existing right to delete their personal information to include data that covered businesses did not directly collect. Separately, AB 1542 would restrict covered businesses from selling or sharing sensitive personal information altogether.
Expanded Deletion Right. SB 923 would close what its sponsors describe as a loophole in the CCPA’s existing deletion right.9 As currently drafted, that right does not require a business to delete personal information it collected from a third party, even though businesses routinely supplement their own consumer records with acquired data.10 The result is an inconsistency across the CCPA’s consumer rights: businesses already respond to access, correction, and opt-out-of-sale requests with respect to third-party-sourced information, but deletion requests reach only what the business collected directly. If enacted, SB 923 would extend the deletion right to personal information a business has collected about the consumer, regardless of source, bringing California in line with Delaware, Indiana, Maryland, and New Jersey.11 Existing CCPA exemptions—including for fraud prevention, peer-reviewed research, and compliance with legal obligations—would continue to apply. The bill also addresses a practical problem the expansion creates: a business that deletes every trace of a consumer cannot recognize that consumer if it later re-acquires the same data. SB 923 would expressly permit a business to maintain a suppression list, retaining a record of the deletion request and the minimum data necessary to ensure the information remains deleted.12 Finally, the bill would require online-only businesses that have a direct relationship with consumers to offer an online submission method, such as a web form, in addition to the email address existing law requires.13
Default Restriction on Sensitive Data. AB 1542 focuses on sensitive personal information. Rather than requiring consumers to invoke the CCPA’s right to limit certain uses and disclosures, the bill would prohibit businesses, service providers, and contractors from selling or sharing sensitive personal information with third parties, subject to specified exceptions.14 The CCPA already provides a notice-and-limitation framework that allows consumers to limit a business’s use of their sensitive personal information, and requires a business to provide consumer notice if it discloses sensitive personal information to a service provider or contractor for additional specified purposes. Under existing law, service providers do not directly receive limitation requests under this framework, and are only required to limit their use of sensitive personal information pursuant to a written contract with the business, in response to instructions from the business, and with respect to its relationship with that business.15 Nevertheless, neither this carveout nor that notice framework would permit service providers and businesses to evade the bill’s prohibition on the sale of sensitive information merely because of consumer inaction after the business provides notice of a sale. AB 1542’s restriction would apply regardless of whether a consumer has exercised the right to limit, effectively establishing a default restriction rather than an opt-out-based framework.
If enacted, both CCPA bills would require covered businesses to revisit their consumer rights procedures and their data transfer practices.
AI Legislation: Content Provenance and Verification Requirements
The Legislature simultaneously passed a broad package of measures addressing chatbots, employment, healthcare, digital replicas, and auditing. For businesses developing generative AI systems or operating large online platforms, Senate Bill 1000 (SB 1000) and Assembly Bill 2713 (AB 2713) are particularly significant. Together, the bills would amend the California AI Transparency Act (CAITA) to strengthen the infrastructure used to identify AI-generated or AI-altered content: SB 1000 would revise obligations for generative AI providers, while AB 2713 would revise how large online platforms detect, disclose, preserve, and allow users to inspect qualifying content-provenance information.16
Verification Tools and Expanded Coverage. CAITA, whose first phase of obligations became operative on August 2, 2026, already requires a covered generative AI provider to make an AI detection tool available to users at no cost. SB 1000 recasts that obligation, replacing the “AI detection tool” with a “disclosure verification tool.”17 The revised tool must allow users to assess whether covered image, video, or audio content was created or altered, except by minor modification, by the provider’s system and output detected system-provenance data. Significantly, SB 1000 also strikes the “over 1,000,000 monthly visitors or users threshold” from the definition of “covered provider,” substantially expanding the universe of regulated generative AI providers, and eliminates the existing requirement that a provider offer users the option to include a manifest, or visible, disclosure in covered content.18 The bill also requires that the latent disclosure embedded in covered content indicate whether the content was generated or modified by AI and imposes restrictions on personal information derived from users of the verification tool or from content processed by it.19 Because SB 1000 is an urgency measure requiring a two-thirds vote, it would take effect immediately upon enactment rather than on the following January 1.
Platform Provenance Obligations. CAITA’s obligations for large online platforms become operative on January 1, 2027. AB 2713 would broaden the detection provision to cover provenance data embedded into, attached to, or otherwise associated with content, while preserving an express limitation for provenance data, system-provenance data, and digital signatures that are not compliant or interoperable with widely adopted standards.20 To the extent technically feasible, large online platforms could not knowingly strip system-provenance data or digital signatures that comply with widely adopted specifications from content uploaded to, distributed on, or downloaded from the platform.21 Affected providers and platforms should evaluate whether their systems can generate, exchange, display, and preserve interoperable provenance information and whether their verification processes appropriately limit the collection and use of personal information.
Key Takeaways
- CIPA Section 638.51 Claims: Businesses confronting claims under CIPA section 638.51 related to website or application activity should promptly determine when the relevant actions were filed and evaluate the potential applicability of SB 690’s retroactivity provision. Notwithstanding the bill’s targeted relief, website operators should continue to review their use of tracking technologies, as Sections 631 and 632 remain unaffected.
- CCPA Compliance: Entities subject to the CCPA should review whether their existing deletion protocols cover information acquired from third-party sources, confirm that suppression records are appropriately limited, and assess whether current privacy request channels are compliant with new erasure measures. It is also advisable that businesses begin evaluating whether existing advertising, analytics, vendor, and data-broker arrangements involving the exchange of sensitive personal information could become prohibited under AB 1542’s proposed restrictions.
- Generative AI and Platform Obligations: Providers of generative AI and large online platforms should evaluate their implementation of content credentials, metadata, digital signatures, latent disclosures, and verification tools. Providers that have relied on CAITA’s monthly-user threshold should assess the consequences of its proposed removal.
***
Ropes & Gray will continue to monitor these measures and other developments in data privacy and AI law. For more information, please contact your Ropes & Gray relationship team or the authors of this Alert.
- Cal. Penal Code § 630 (2026).
- Cal. Penal Code § 637.2(a)–(c) (2026).
- Cal. Penal Code § 631(a).
- Cal. Penal Code § 632(a), (c).
- Cal. Penal Code § 638.51(a)–(b).
- SB 690 (2025–2026 Reg. Sess.) § 1(d)(1) (Cal. 2026) (amending Cal. Penal Code § 637.2).
- Id. at § 1(d)(2).
- Id. at § 2.
- SB 923 (2025–2026 Reg. Sess.) § 1; see also Press Release, Cal. Privacy Prot. Agency, California Legislature Advances Bill to Strengthen Deletion Rights (Aug. 28, 2026).
- Cal. Civ. Code § 1798.105(a).
- SB 923 § 2 (amending Cal. Civ. Code § 1798.105(a)) (extending the right to personal information the business has collected “from or about” the consumer).
- SB 923 § 2.
- Id. at § 3.
- For example, AB 1542 would permit a commercial credit-reporting agency to sell a consumer’s Social Security number to the extent the agency uses the number solely to identify the consumer’s relationship to a business the consumer owns. See AB 1542 (2025–2026 Reg. Sess.).
- Cal. Civ. Code § 1798.121(c).
- SB 1000 (2025–2026 Reg. Sess.); AB 2713 (2025–2026 Reg. Sess.). The California AI Transparency Act is codified at Cal. Bus. & Prof. Code § 22757 et seq.
- SB 1000 § 3.
- Id. at §§ 2, 4.
- Id. at §§ 3–4.
- AB 2713 (amending Cal. Bus. & Prof. Code § 22757.3.1).
- Id.
Stay Up To Date with Ropes & Gray
Ropes & Gray attorneys provide timely analysis on legal developments, court decisions and changes in legislation and regulations.
Stay in the loop with all things Ropes & Gray, and find out more about our people, culture, initiatives and everything that’s happening.
We regularly notify our clients and contacts of significant legal developments, news, webinars and teleconferences that affect their industries.



