In this article

Sign up for our newsletter

Share this article

If you've spent any part of the last two years fielding a demand letter over your website's cookies, pixels, or analytics tools, this week's news is for you. On Friday, California's legislature passed SB 690 without a single "no" vote, taking aim at one specific legal theory behind that wave of California Invasion of Privacy Act lawsuits: the idea that those tools function as illegal "pen registers" or "trap and trace" devices.

I've talked to more than a few founders and privacy leads over the past few years who got hit with one of these letters and had no idea what a "pen register" even was. But CIPA lawsuits have cast common web tracking tools as the regulated devices used to log dialed phone numbers–the original technologies that CIPA was intended for.

Does this mean CIPA lawsuits are going away forever? Will serial CIPA litigants be cursed so that their socks are always wet? No and no, sadly.

This bill leaves CIPA's wiretapping provision completely untouched, so the bulk of CIPA lawsuits are unaffected. SB 690 only takes away one specific tool in the CIPA litigation toolkit, and reduces potential exposure by that much as well.

Governor Newsom has until September 30 to sign it, veto it, or let it become law without his signature, and given that this thing cleared the legislature unanimously, I'd bet on a signature.

Best,

Arlo

Resource Listing - State of US Privacy Enforcement

Highlights From Osano

New From Osano

Engineering Blog: Show, Don't Tell: How We Ship Internal Ideas at Osano

In the first of our new engineering blog series, we cover the new internal platform we built to make sharing AI-assisted tools, prototypes, and proofs of concept easier--especially for non-engineers. Meet Archie.

Read more

Release Notes: August

What’s new in Osano this month? Check out our release notes to find out the latest.

Read more

In Case You Missed It…

Blog: What Is CIPA, and Why Is Your Website Getting Sued?

The California Invasion of Privacy Act (CIPA) is a serious thorn in the side of businesses that thought they were protected from privacy law. Even if you’re compliant with the CCPA, why is your business still at risk of CIPA lawsuits? Find out in our blog.

Read more



Top Privacy Stories of the Week

California Moves to Shut Down a Wave of Website-Tracking Lawsuits

California's legislature passed SB 690 without a single "no" vote, cutting off one of the most-used legal theories behind the flood of website-tracking lawsuits filed against ordinary businesses over the past two years. The bill eliminates the private right of action for "pen register" and "trap-and-trace" claims under the California Invasion of Privacy Act. CIPA's wiretapping provision, which is behind the bulk of current claims, remains untouched, so the litigation wave recedes rather than disappears. The bill is awaiting Governor Newsom’s signature

Read more

California Closes a Loophole in the Right to Delete

California's CCPA has always had a gap in its right to delete: businesses only had to erase data they collected directly from a consumer, not data bought about that person from a third party. SB 923 closes that gap, requiring deletion of all non-exempt personal information a business holds regardless of source. The bill now heads to Governor Newsom for signature.

Read more

Missouri's Age-Verification Law For Adult Sites Takes Effect

Missouri's new age-verification law for adult websites took effect Friday, requiring sites to verify a user is 18 or older through a third party before granting access, while barring that third party from retaining any identifying information. Critics argue the law pushes traffic toward unmoderated sites overseas that don't take down illegal content. Missouri now joins more than two dozen states with some version of this requirement on the books.

Read more

CalPrivacy Fines Another Unregistered Data Broker

CalPrivacy fined Virginia-based SalesIntel Research $36,400 for operating as a data broker without registering by the 2025 deadline, the latest in a string of enforcement actions the agency has brought against unregistered brokers. SalesIntel sells access to more than 200 million professional contacts and 54 million mobile numbers, and one of its products "de-anonymizes" website traffic, matching anonymous visitors to names, direct phone numbers, and verified emails. Beyond the fine, the decision requires SalesIntel to post privacy-rights metrics on its website and start processing deletion requests through California's DROP platform.

Read more

Australia Proposes a GDPR-Style Overhaul of Its Privacy Act

Australia's government released the draft for additional Privacy Act reforms, and it's a big one: roughly 40 proposed changes that would move the country's privacy framework much closer to the GDPR. The draft introduces a controller/processor model, a 72-hour breach notification requirement to the OAIC, expanded categories of sensitive information covering precise geolocation and genomic data, and a new right to erasure for personal information held by large digital platforms.

Read more

Like What You See in the Privacy Insider newsletter?

There's more to explore:

🛠️ The Osano Engineering Blog

Learn what we're building, why, and how! New posts released monthly here.

📱 The Osano Subreddit

Join our official subreddit to stay up to date on the latest news, analysis, guidance, and content from Osano!

📖 The Privacy Insider: How to Embrace Data Privacy and Join the Next Wave of Trusted Brands

The book inspired by this newsletter: Osano CEO, Arlo Gilbert, covers the history of data privacy and how companies can start building a privacy program from the ground up. More details here.

If you’re interested in working at Osano, check out our Careers page! 

Get a demo of Osano today
Share this article