Blog Post

California SB 690 Highlights Why AdTech Governance Can’t Keep Chasing the Next Law

The privacy enforcement environment in California continues to evolve, with ongoing areas of uncertainty. The result is a set of moving adtech compliance goalposts for organizations operating in the state and other states engaging in similar enforcement activities. Organizations must begin to look at ways to evolve their governance programs away from reacting to each new regulatory and legal development and toward a more resilient posture.

A prime example of the ongoing ambiguity in the current landscape is in the recent amendments to California’s SB 690, drafted to eliminate the private right of action for certain pen register and trap-and-trace claims under the California Invasion of Privacy Act. On August 28, 2026, the legislature sent SB 690 to California Gov. Gavin Newsom; he has until the end of September to sign or veto the bill. 

For organizations facing the growing wave of website tracking litigation and a steady stream of demand letters, this legislation may initially appear as a reprieve. However, it should not be mistaken for a broader retreat in litigation risk, because even if signed, additional exposures remain. 

In their current form, the proposed SB 690 changes would:

  • Restrict the private right of action for alleged §638.51 violations arising from conduct on websites, online applications or mobile applications by private actors.
  • Reserve civil actions under §637.2 for those covered claims to the California attorney general.
  • Apply restrictions retroactively to pending claims in actions commenced within two years before the bill’s operative date.

Even if signed into law, SB 690 amendments would not repeal or otherwise eliminate the underlying prohibitions in §638.51. Nor would they eliminate private claims under the California Invasion of Privacy Act alleging the unauthorized interception of communications or other claims under CIPA §§632 or 632.7. Generally, these amendments would not end website-tracking litigation or create a commercial-purpose exemption or substantive safe harbor for pixels and other tracking technologies.

The litigation landscape is evolving, not slowing

So, while SB 690 could narrow one legal theory, it would not change the principal technical questions surrounding website and mobile application data flows that are expected to continue driving the privacy litigation landscape: What technologies executed? What data was transmitted? Under what consent conditions? To whom? 

Rather than abating, pixel tracking litigation is becoming broader and more technical, expanding to mobile apps (in addition to websites), testing new theories and combinations of laws. Plaintiffs continue to look for alternative legal theories to bring their demands, and lately appear to leverage other state interception statutes and federal law, including claims brought in other jurisdictions.

At the same time, demand letters and complaints are becoming more sophisticated. Allegations frequently reference browser network captures, request payloads, JavaScript execution, cookie identifiers, consent timing and vendor-specific endpoints. Organizations should expect plaintiffs to pursue overlapping claims across multiple jurisdictions based on similar technical website or mobile app behavior. This litigation landscape evolution calls for strong governance and privacy enabling technologies to sustain attacks on privacy compliance. 

Mature adtech governance equates to litigation readiness

Organizations should view SB 690 as an opportunity to strengthen their technical litigation readiness through mature governance, implementation assessments and defensible evidence. Below are core governance questions companies should be ready to answer:

  • Can we demonstrate what technologies execute under every consent state?
  • Can we explain exactly what information leaves the browser and where it goes?
  • Can we reconstruct historical implementations if challenged?
  • Can we produce technically defensible evidence before remediation changes the environment?
  • Can we demonstrate that consent choices are consistently honored across downstream vendors?
  • Can we demonstrate that we continuously identify unauthorized trackers (piggybacking or shadow tags) that are injected by our primary vendors without our knowledge?
  • Do our contracts specifically prohibit these vendors from using this data for cross-context behavioral advertising or their own machine-learning models?

Establishing the capabilities within these questions minimize compliance risk, accelerate investigations and provide outside counsel with the factual foundation needed to promptly evaluate allegations and develop defense strategy. Unlike traditional privacy assessments that focus primarily on policies, inventories and disclosures, implementation assessments should extend beyond scanning for cookies or validating banner deployment. Effective assessments validate behavior across browsers, devices, mobile applications, authenticated experiences and multiple consent states to identify gaps before they become litigation issues. More, they help preserve technically defensible evidence that may later support investigations, litigation or regulatory inquiries, acting as the bridge between governance and litigation readiness.

Historically, organizations often commissioned technical investigations after receiving a demand letter or a class action lawsuit. A recurring theme in discussions with defense counsel and at industry conferences is that organizations facing website-tracking demand letters often choose early settlements rather than commissioning comprehensive technical investigations and remediation. The immediate cost of resolving a demand letter can appear lower than undertaking a detailed assessment of the adtech ecosystem. While that approach may resolve an individual matter, it does not strengthen governance or an organization’s ability to respond to future claims. This shift, from reactive investigation to proactive technical readiness, may ultimately prove more significant than any single legislative amendment.

Looking ahead

Plaintiffs are unlikely to abandon tracking litigation and are more likely to prompt new avenues to pursue litigation. Areas that may come into play include:

  • CIPA §631: Claims may focus on the alleged interception of content, such as searches, chats, form entries, appointment details and authenticated activity instead of routine metadata.
  • Consent and disclosure failures: Plaintiffs may target pre-consent firing, ineffective “reject all” or Global Privacy Control signals, tracker misclassification and discrepancies between notices and actual data flows.
  • Sensitive digital experiences: Health care, financial, youth, employment, video and authenticated journeys will remain attractive because they support stronger allegations of privacy harm.
  • Session replay: Claims could emphasize captured keystrokes, searches, field entries and user identity, particularly where the activity involves sensitive content.
  • Other state wiretap laws: Plaintiffs are expected to continue testing Florida, Pennsylvania and other state statutes, although their consent rules, standing requirements and defenses vary.
  • Electronic Communications Privacy Act: Plaintiffs may allege that inaccurate privacy disclosures, defective consent banners or underlying privacy violations trigger the federal law’s crime tort exception.
  • Layered alternative claims: Complaints are likely to increasingly combine wiretap allegations with Video Privacy Protection Act, California Comprehensive Data Access and Fraud Act, privacy tort, contract, consumer-protection and industry-specific claims.

Rather than relying on scalable metadata-based claims, plaintiffs are expected to put a greater emphasis on allegations involving intercepted content, identifiable users, sensitive digital experience, failed consent, misleading disclosures and downstream advertising use. Privacy enforcement will continue to evolve and the statutes will inevitably change. As the goalposts move, organizations with a mature adtech governance program will be better positioned to respond to incoming litigation and regulatory  scrutiny with confidence. 

The views expressed herein are those of the author(s) and not necessarily the views of FTI Consulting, its management, its subsidiaries, its affiliates, or its other professionals.