Photo of Vincent Smolczynski

California lawmakers have sent Senate Bill 690 to Governor Gavin Newsom, teeing up a narrowing of website-tracking litigation under the California Invasion of Privacy Act (CIPA), who has until September 30 to sign or veto the legislation. If signed, the bill would eliminate private lawsuits asserting website-based “pen register” and “trap and trace” claims under Section 638.51 of CIPA. For businesses that have received demand letters or are defending lawsuits premised on routine website technologies—such as cookies, pixels, analytics tools, or similar tracking technology—the bill would offer relief from certain types of claims asserted under CIPA. Additionally, the bill would apply retroactively to pending claims in actions commenced within two years before its operative date, which is expected to be January 1, 2027, if the bill becomes law. 

The Impetus

The legislation responds to a surge of CIPA claims built on a statute originally designed for telephone-era wiretapping, not modern website traffic. Because CIPA carries statutory damages that can reach at least $5,000 per violation without proof of actual harm, even ordinary commercial web practices have created substantial litigation leverage for plaintiffs to demand large sums from website owners. SB 690 targets that specific theory by removing the private right of action for Section 638.51 claims.

Continue Reading California SB690 – A Bill That Significantly Narrows Website Tracking Claims – Sent to Governor’s Desk

Senior United States District Judge William H. Orrick, sitting in the Northern District of California, denied a motion to dismiss last week in an Automated License Plate Recognition (“ALPR”) matter, McGinty v. Reimagined Parking LLC, d/b/a Imperial Parking.[1] Judge Orrick held that the plaintiff plausibly alleged actionable harm based on his “right to know” about the use of ALPR systems in two garages. The order follows Bartholomew v. Parking Concepts, Inc.[2] and the guidance of Mata v. Digital Recognition Network, Inc.,[3] concluding that the California Supreme Court would likely recognize violation of a consumer’s “right to know” as actionable harm under California’s ALPR law if presented with the question.

The decision is significant because it marks the first time a federal judge adopted the state-court trajectory created in Bartholomew and Mata. Bartholomew treated the alleged failure to make required ALPR disclosures in an ALPR Privacy Policy as an actionable injury to a consumer’s right to know under the law. Though Mata did not deal with the failure to present an ALPR Privacy Policy, the decision in Mata did offer further guidance on how courts should analyze asserted ALPR harms.

Continue Reading Federal Court Follows Bartholomew Reasoning in Denying Motion to Dismiss ALPR Lawsuit

On July 20, 2026, the California Court of Appeal, Fourth Appellate District issued a notable decision in Mata v. Digital Recognition Network, Inc.,[1] which addresses the standing requirements for private claims under California’s Automated License Plate Recognition (“ALPR”) law. At the heart of the decision lies the question whether a violation of the

Automated License Plate Reader (ALPR) technology is facing increasing legal scrutiny as courts, regulators and individuals attempt to examine and expose the various ways in which license plate data is captured, collected, shared and used. Recent disputes over ALPR technology have shifted away from issues of public safety and toward whether the private sector businesses and governmental organizations, among others, that utilize ALPR adequately disclose its use and sharing, as well as implement proper safeguards around this potentially sensitive, location-based personal information.

1. Private Sector’s Failure to Disclose Use of ALPR Technology Can Be Sufficient to Constitute Harm to Consumers

The private sector’s use of ALPR technology is facing challenges and possible legal exposure. In February of this year, California’s First Appellate District addressed the requirements imposed by the state’s ALPR Law in Bartholomew v. Parking Concepts, Inc., and in particular addressed what constitutes sufficient “harm” under the law to state a claim.1,2 In that matter, the plaintiff alleged that a parking garage owned and operated by Parking Concepts collected his license plate data without making a privacy policy regarding the collection publicly available. First, the Court determined that the parking garage camera system constituted a ALPR system under the law – that is, that it was “a searchable computerized database resulting from the operation of one or more mobile or fixed cameras combined with computer algorithms to read and convert images of registration plates and the characters they contain into computer-readable data.” But more importantly, the Court concluded that using ALPR technology without a publicly disclosed privacy policy stating when and how ALPR is collected and used violates an individual’s “right to know” of the activity, which is sufficient to allege harm under the law.

Continue Reading Automated License Plate Reader Technology Raises Concerns Over Private Sector Compliance and Government Overreach

On Friday, October 17, 2025, U.S. District Court Judge Vince Chhabria issued a biting Order granting defendant Eating Recovery Center, LLC’s (“ERC”) motion for summary judgment on the plaintiff Jane Doe’s California Invasion of Privacy Act (CIPA) claims, a law enacted in 1967 to address the increasing use of wiretapping to eavesdrop on private phone

On June 3, 2025, the California Senate unanimously passed Senate Bill 690 (SB 690), a bill that seeks to add a “commercial business purposes” exception to the California Invasion of Privacy Act (CIPA).

After multiple readings on the Senate floor, SB 690 passed as amended, and will now proceed to the California State Assembly. SB

On May 19, 2025, the California Senate Appropriations Committee, which handles budgetary and financial matters, held a hearing on California Senate Bill 690 (SB 690).  The proposed bill would amend the California Invasion of Privacy Act (CIPA) by adding an exception to the statute which has the effect of permitting use of tracking technologies for

California Senate Bill 690 (SB 690), introduced by Senator Anna Caballero, is continuing to proceed through the California state legislative process. The proposed bill would amend the California Invasion of Privacy Act (CIPA) by adding an exception to the statute which has the effect of permitting use of tracking technologies for “commercial business purposes.” CIPA

Seyfarth Synopsis: In a significant decision for website operators, the Massachusetts Supreme Judicial Court clarified that tracking users’ web activity does not constitute illegal wiretapping under the state’s Wiretap Act. The court found that person-to-website interactions fall outside the Act’s scope, which focuses on person-to-person communications. However, the court emphasized that other privacy laws could still apply to such tracking practices. This ruling may influence how similar cases proceed nationwide and signals to the Massachusetts legislature that any broader restrictions on web tracking require explicit statutory action.

Continue Reading Tracking Users’ Web Browsing Activity Does Not Constitute Illegal Wiretapping under Massachusetts Law

The California Privacy Protection Agency (“CPPA”) issued and discussed draft regulations on Cybersecurity Audits and Risk Assessments late in the summer. The CPPA Board plans to discuss the draft regulations at its upcoming December 8th public meeting, along with a presentation on the regulations. 

Continue Reading CPPA Considers Next Set of CPRA Regulations Covering Cybersecurity Audits and Risk Assessments