
This story was originally published by CalMatters. Sign up for their newsletters.
In May, Gytahnna Loffgren opened her mail to find her family’s small solar panel installation company was being sued for over $35,000 because its website’s practices allegedly violated state privacy laws.
“We were completely blindsided,” Loffgren told CalMatters. “I’ve never been sued before… you instantly feel like you’ve done something terribly wrong.”
The suit against Loffgren stems from the California Invasion of Privacy Act, a wiretapping statute written for the era of landlines that is increasingly wielded against websites for California’s small businesses.
The California Legislature on Friday passed a bill to curb such suits, sending the measure to Gov. Gavin Newsom. On the surface, the legislation looks like a bipartisan rescue mission for overwhelmed local business owners, who say they are being shaken down by a cottage industry of opportunistic lawyers. But look closer, opponents say, and the legislation is a masterclass in Sacramento astroturfing.
Senate Bill 690 is backed by a who’s who of Silicon Valley, with Meta, the parent company of Facebook and Instagram, among the most involved in a list of tech giants that also includes Amazon, Google, and X. On the other side of the fight are some of the biggest names in national privacy advocacy, including the ACLU, Tech Oversight Project, and National Consumer Law Center.
The privacy advocates warn that SB 690 acts as a Trojan horse, shaped by Big Tech lobbyists who have fashioned legitimate small-business outrage into a powerful political weapon. In its final, amended form, the bill strips away individual consumers’ rights to sue companies for tracking device violations, handing exclusive enforcement powers to an under-resourced attorney general. Opponents also say the bill’s retroactivity clause could quietly sink landmark privacy cases against Silicon Valley giants.
A spokesperson for SB 690’s author, Merced Democratic Sen. Anna Caballero, told CalMatters that the goal of the bill was always to address what she viewed as “frivolous litigation.”
“Our bill accomplishes what we were able to achieve this year and reflects where we could come to a consensus,” Caballero’s spokesperson said. “We recognize there is more work to do, and the Legislature will likely need to revisit this issue in a future session to address the remaining concerns.”
The anatomy of a CIPA lawsuit
CIPA was originally written in 1967 to catch phone-line eavesdroppers. In 2015, the bill was amended to prohibit any unauthorized entity from installing or using a “pen register” or a “trap and trace device,” which record routing, addressing, or signaling information, without a court order or consent.
That amendment unleashed a flood of lawsuits, as lawyers argued modern website tracking tools act as digital “pen registers” by logging, without user consent, information on IP addresses, which are used to route information online. In the last four years, attorneys representing small companies targeted by the suits say more than 4,000 claims have been filed, with thousands more demand letters sent, hammering local businesses with costly legal threats over routine use of web identification technologies like cookies and analytics trackers.
“This is modern ambulance chasing, but it’s worse because at least with ambulance chasing, someone was harmed,” said Jim Monagle, an attorney for Mullen Coughlin, referring to the stereotype of an unethical personal injury lawyer soliciting clients immediately after an accident while they’re still receiving medical care.
Monagle has represented healthcare clients against the type of lawsuits faced by Loffgren and other business owners. “In these cases, nobody’s really screaming out about the fact that a portion of their IP address was turned into a different unique IP to figure out whether or not they’ve been to the website before and if they come back. It doesn’t affect anyone,” he added.
CIPA’s danger to businesses, and profitability for trial lawyers, lies in its mandatory $5,000 penalty per violation. Plaintiffs don’t need to prove actual harm; simply visiting a site with certain tracking cookies can trigger the fine. For a small business with even modest web traffic, common add-ons like Google Analytics or the Meta Pixel can create massive legal exposure, forcing owners to pay thousands of dollars in settlements just to survive.
And the risk isn’t limited to small businesses. Earlier this year, the Los Angeles Times agreed to a $3.85 million class-action settlement over similar website tracking claims, and Big Tech companies like Amazon and Meta routinely face CIPA-related data privacy claims that bog them down in costly legal battles and expose them to millions of dollars of liability. Both companies, and many other tech giants, are actively fighting class action lawsuits related to CIPA claims.
CIPA has long faced criticism for being applied to internet-era cases, and federal judges are feeling the strain of the law’s scope. U.S. District Judge Vince Chhabria, in an October 2025 order siding with a business sued under CIPA, called the 1967 law a “total mess” that has gotten “bigger and bigger” when applied to modern web technology. Urging lawmakers to “erase the board entirely and start writing something new,” Chhabria, whose district oversees cases in the Bay Area, called on the Legislature to step in.
But while proponents of SB 690 claim the bill answers that call — and argue existing privacy rules like the California Consumer Privacy Act offer enough protection — some legislative analysts disagree. A report for the Assembly Public Safety Committee warned that the California Consumer Privacy Act , signed into law in 2018, isn’t a true safety net because it doesn’t allow individuals to sue over routine tracking, leaving consumer protection entirely dependent on an attorney general’s office that lacks the staff to police every website in California.

The architect and the ‘astroturf’ strategy
Behind the campaign to pass SB 690 is an underground river of corporate money, made difficult to trace by California’s lobbying disclosure laws. State regulations require organizations to report their quarterly lobbying expenditures, but don’t require them to break down how much is earmarked for specific bills, obscuring financial specifics in the event a firm lobbies on more than one issue, which they frequently do.
One notable exception to this opacity is the Alliance for Legal Fairness, created in 2024 by a prominent privacy attorney and lobbyist, Andrew Kingman, for the sole purpose of reforming CIPA and, later, passing SB 690. Operating out of his law firm, Mariner Strategies, Kingman serves as general counsel for both the Alliance and the State Privacy and Security Coalition — a powerhouse industry group backed by tech titans like Amazon, Meta, Google, and Mastercard that works to influence similar data privacy bills around the country.
Across just two legislative quarters this year, Kingman’s Alliance funneled over $234,000 exclusively into pushing the CIPA reform bill through the Capitol.
To build momentum for the measure, Kingman’s coalition combed court records for small-business owners affected by the CIPA lawsuits, recruiting them to testify in Sacramento. Supporters argue the bill restores common-sense boundaries, noting that even advocacy groups that oppose SB 690 use similar analytics on their websites. Opponents, however, view it as corporate cover: by placing struggling Main Street shops at the center of the fight, Big Tech gets to dismantle consumer lawsuit rights while keeping its own branding off the front lines.
The financial backing behind the bill extends beyond a single group. A roster of corporate heavyweights, from platforms like Meta, X Corp, and Amazon to consumer giants like Chipotle, Mastercard, and Chick-fil-A, collectively poured millions into Sacramento lobbying while the bill made its way through the legislature, with hundreds of thousands of dollars allocated toward influencing SB 690’s specifics.
Matt Schwartz, a policy analyst for Consumer Reports, told CalMatters his organization has seen Kingman spearhead a similar playbook in “dozens and dozens” of states’ data privacy fights, adding that the strategy makes it hard for lawmakers, much less the average citizen, to understand who’s really behind the effort to roll back privacy protections.
“These Big Tech companies rarely come into state legislatures with lobbyists saying that they’re from Meta or Google or Amazon and testify at the committee level with those affiliations out front,” Schwartz said. “Their own brand as giant companies might be too toxic to be out front, so they use smaller organizations as the mouthpiece. At the end of the day, it distorts the process — and it makes it almost impossible for lawmakers to see who’s actually pulling the strings until it’s too late.”
Kingman declined to comment on the record regarding allegations that his coalition serves as a proxy for Big Tech interests.
The fine print: exclusive AG enforcement and retroactivity
As introduced, the bill offered a sweeping exemption shielding commercial web tools from wiretapping and tracking claims under CIPA. Facing pushback from labor and privacy groups, the bill’s author, Caballero, narrowed the bill, dropping the wiretap protections and focusing strictly on pen-register claims — which track metadata like IP addresses rather than communication content.
Over the course of the bill’s revisions, Caballero also introduced a retroactivity clause, and changed its enforcement provisions, which opponents see as major wins for Big Tech. Privacy groups also warn that carving out metadata creates a dangerous loophole.
“California should be leading on tech regulation, but SB 690 does the exact opposite; it makes it easier for companies to spy on us,” Jenna Sherman, a campaign director at the women’s advocacy group Ultraviolet, told CalMatters.
Ultraviolet became involved in the fight against the bill in part because its two-year retroactivity clause could have major implications on landmark privacy cases, including the decision in Frasco v. Flo Health Inc., in which a San Francisco jury unanimously found Meta liable for collecting, in violation of CIPA, intimate reproductive health data, like details about their menstrual cycles and sexual activity, from users of the Flo Health app without their consent.
Meta, which a judge signaled may face damages of up to $8 billion in the case, has appealed the decision. Representatives for the company declined to comment when reached by CalMatters.
Placing sole enforcement of CIPA in state hands would have kept plaintiffs from bringing the case in the first place, lawyers for the plaintiffs told CalMatters.
That is precisely what worries privacy advocates. If SB 690 becomes law, the five-year battle fought by the Flo Health plaintiffs won’t stand as a landmark precedent for data privacy, and it could become the last time everyday Californians were able to force Big Tech to answer to a jury.



