Bill to Curb California Wiretapping Lawsuits Makes Progress: 5 Takeaways from FP’s Testimony Before the State Legislature
California businesses have already paid more than half a billion dollars to settle lawsuits over ordinary website cookies, and the tally climbs each day this problem goes unaddressed. That’s the message Fisher Phillips Privacy and Cyber Co-Chair Usama Kahf delivered on July 1 when he testified before the California Assembly Privacy Committee in support of SB 690, a bill designed to curb what supporters call a “shakedown” of businesses under the state’s decades-old wiretapping law. At the end of the hearing, the committee voted to advance the bill, giving businesses a reason for some optimism. Here are five takeaways from the hearing, the committee vote, and what’s to come next.
1. The Numbers Behind the “Shakedown” Are Staggering
Kahf told committee members that Fisher Phillips alone has handled roughly 250 matters involving businesses that complied with the California Consumer Privacy Act (CCPA), yet were still sued for using standard website tools like analytics and cybersecurity software. Statewide, he testified, opportunistic plaintiffs have filed more than 3,800 lawsuits under the California Invasion of Privacy Act (CIPA). And for every lawsuit filed, plaintiffs and their attorneys are sending an estimated 10 to 15 additional demand letters or arbitration claims that never reach the public record. (You can track the lawsuits on FP’s Digital Wiretapping Litigation Map.)
With typical settlements running $15,000 to $25,000, Kahf estimated the total drain on California businesses at over half a billion dollars, flowing largely to a small handful of plaintiffs’ firms. The targets, he emphasized, aren’t all Fortune 500 companies or Big Tech. They’re small employers (such as your local non-chain coffee shops, plumbers, HVAC providers, construction contractors, or flower shops), nonprofits, schools, public agencies, hospitals, local newspapers, and even B-2-B companies that do not sell or provide goods and services to individual consumers or the public at large.
2. There’s No Real Harm, Just a Technical Trigger
The core of Kahf’s testimony is that these lawsuits don’t allege any actual injury. Instead, they target ordinary technology – like cookies used for analytics or basic cybersecurity – and treat a technical violation as grounds for a payout. Plaintiffs argue that penalties under the wiretapping provision can stack at $5,000 per third-party cookie, per visitor, per session on the website, which means damages can escalate quickly even when a business uses common, widely available tools in good faith and in full compliance with the CCPA, the only law on the books with specific regulations addressing use of cookies on websites.
This is why a wide range of community interests testified in favor of SB 690 along with Kahf. Dozens of businesses, community activists, nonprofits, and industry associations showed up to express support, including Jeff Glasser, General Counsel of the LA Times, who also testified alongside Kahf and Senator Caballero in support of the bill.
3. One Litigant’s Story Shows How Far Things Have Gone
Kahf’s most striking example involved Vivek Shah, a self-represented plaintiff who spent seven years in federal prison for an extortion-related felony before turning to CIPA claims. In the two months before the hearing, Kahf testified, Shah sent an estimated tens of thousands of demand letters, mostly asserting claims under Section 631, CIPA’s wiretapping provision, rather than the “pen register” provision that SB 690 has been narrowed down to address. Fisher Phillips alone has fielded over 80 matters involving this single plaintiff. As Kahf testified, Shah demands a payment, doesn’t negotiate, and many businesses settle simply because litigation would cost more than the demand itself. You can read more about Shah’s demand letters here (along with a plan to respond if your business receives such a letter).
When a committee member asked Kahf about the scope of the situation during Q&A, he didn’t pull punches. He pointed out that the technology driving these claims, like Google Analytics, is so common that it’s running on the websites of committee members – and even the hearing’s opposition witnesses. He said he’d checked one opposition witness’s site himself that day and found his own data being shared with Facebook. His point: the businesses being targeted aren’t uniquely careless. They’re using the same tools nearly everyone else uses, which is exactly why the volume of claims has exploded.
4. SB 690 Solves Part of the Problem, Not All of It
The version of SB 690 that advanced on July 1 looks different from the bill as originally introduced (which you can read about here). After months of negotiation with privacy advocates who worried the original language would let large tech companies escape accountability, the bill’s author, Senator Anna Caballero, agreed to narrow its scope. As amended, SB 690 now removes the private right of action only for claims under CIPA’s “pen register” provision, the metadata-tracking tool provision, and would apply retroactively to lawsuits filed on or after January 1, 2025, that are still pending when the bill would take effect.
That means Section 631, the wiretapping provision Kahf identified as the source of most current abuse, including by the serial-plaintiff he described, is not addressed by the bill as amended. Businesses and nonprofits should understand that even if SB 690 passes in its current form, cases alleging both pen register and wiretapping violations (a common pairing) won’t simply disappear. Businesses facing pen-register-only claims may see relief, but the wiretapping exposure Kahf spent much of his testimony describing would remain on the table, and it is common for plaintiffs to pivot to other claims when one door is shut.
5. The Bill Still Has a Path to Travel, and So Do Website Operators
SB 690 next heads to the Assembly Appropriations Committee for an August hearing, and several Democratic lawmakers who voted to advance the bill asked Caballero to keep working with opponents before it reaches the Assembly floor. Privacy advocates, including labor leader Dolores Huerta and groups like TechEquity, expressed concern over the retroactivity provision and are continuing to review the amended language.
Meanwhile, a business coalition called Stop CIPA Shakedown Lawsuits has criticized the amendments for not going far enough, since they leave Section 631 exposure untouched.
For website operators, there are two practical takeaways:
Businesses can watch SB 690’s progress through August and weigh in through industry coalitions if they want the wiretapping provision addressed before a final vote. Reach out to our FP Government Relations team or our FP Gov group to have your voice heard.
At the same time, waiting on legislation isn’t a strategy on its own. You may want to have your counsel review your website’s tracking technology, consent mechanisms, and vendor relationships now, given that thousands of demand letters are still going out regardless of where the bill ends up. Here are five specific steps you can take now.
Conclusion
Fisher Phillips will continue to track SB 690 as it moves through the Legislature. To stay current on CIPA developments, legislative progress, and other California privacy litigation trends, subscribe to Fisher Phillips’ Insights. If you have questions about CIPA compliance or exposure, reach out to your Fisher Phillips attorney, the authors of this Insight, or any member of the firm’s Consumer Privacy Team, or our Digital Wiretapping Litigation Team.

