California Just Took Away the Lawsuit Everyone Was Worried About. It Left the Two That Actually Fit Your Virtual Try-On.

VisionCarePro by

If you sell eyewear online and you have had a demand letter in the last two years, there is a good chance it quoted a statute you had never heard of, about a device invented for telephone exchanges.

The letter said your website used a pen register. It meant your analytics pixel, or your session replay tool, or — increasingly — your virtual try-on. It demanded five thousand dollars per visitor. And the reason it was so cheap to send is that the provision it relied on did not require the sender to prove that anybody had read anything. It only required a device that captured routing or addressing information, which is a description of approximately every script on the modern internet.

On 30 September 2026, California took that letter away. It took away only that letter.

What was signed, and how little of it there is

SB 690 (Caballero) was signed by the Governor on 30 September 2026, appearing in the signed list of the Governor's legislative update of that date under the description “Crimes: invasion of privacy”. It is the last day of the session's signing window, which is worth noticing: this bill went to the wire.

The bill amends one section of the Penal Code — section 637.2 — and adds no new sections. Section 637.2 is not a prohibition. It is the provision that gives private individuals the right to sue over the prohibitions in the California Invasion of Privacy Act. SB 690 adds a subdivision (d) to it, and here it is in full:

(d) (1) An action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.

(2) The amendments to this section by Senate Bill No. 690 of the 2025–26 Regular Session apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.

That is the whole of it. Two sentences, in the remedies section, naming one prohibition.

Read what it does not say. It does not say that running a tracker on your storefront is lawful. It does not amend section 638.51, which still prohibits exactly what it prohibited last week. It does not create an exemption, a safe harbour, a defence, or a compliance standard. The conduct is unchanged and still unlawful; the Attorney General may still bring an action over it. What was removed is a remedy, from one class of plaintiff, under one section, for conduct in one place.

The three limbs, and which one went

CIPA is not a single rule. For website-tracking purposes it has three doors, and California closed one of them to private plaintiffs.

Provision What a plaintiff has to show Private suit after SB 690
§ 638.51 — pen register / trap and trace That a device or process recorded routing, addressing or signalling information. No need to prove anyone captured the contents of anything. Gone, for conduct on a website or app, against a private actor. Attorney General only.
§ 631 — wiretapping Reading, or attempting to read, the contents or meaning of a message or communication in transit, without consent. Untouched.
§ 632 — eavesdropping Intentionally recording a confidential communication without the consent of all parties. Untouched.

Everything outside CIPA is untouched as well, and it is a long list: the federal Electronic Communications Privacy Act, the Video Privacy Protection Act, California's own Comprehensive Computer Data Access and Fraud Act, the CCPA and CPRA, common law privacy claims, and the unfair competition statute. A California statute amending a California remedies provision does nothing to any of them.

Why the limb that went is the wrong one for an eyewear store

This is the part that is specific to this industry, and it is the reason the relief is thinner here than it looks in the headlines.

Section 638.51 became the plaintiffs' bar's favourite because it let them skip the hard element. Proving that a third-party script intercepted the contents of a communication is difficult when the script is collecting an IP address, a referrer header and a scroll depth. Calling the same script a pen register was easy, because routing and addressing information is all it collects. The provision was a workaround for a proof problem.

An eyewear storefront does not have that proof problem. It has the opposite.

A virtual try-on tool activates the customer's camera, captures their face, and in almost every commercial implementation transmits that image or a derived mesh of it to a third-party vendor's servers. A prescription form collects sphere, cylinder, axis, addition and pupillary distance. Whatever else may be arguable about those data flows, nobody is going to struggle to characterise them as contents. They are the most content-like thing on the site.

So the limb California just removed from private hands is the limb a plaintiff suing over your try-on tool needed least, and the two limbs left standing are the ones that fit it best. For an ordinary analytics pixel, SB 690 is real and substantial relief. For the one feature on an eyewear site that handles a photograph of the customer's face, it is close to no relief at all. That reading is ours, offered as analysis; no court has considered how SB 690 interacts with a camera-based try-on tool, because the ink is not dry.

It is worth adding what the statutory-damages arithmetic looks like on the doors that are still open. Section 637.2 awards the greater of five thousand dollars per violation or three times actual damages, and it expressly does not require the plaintiff to have suffered actual damage. That number did not change. Only the list of sections it can be attached to by a private plaintiff got one shorter.

The bill that was introduced would have done much more

SB 690 as introduced in March 2025 was a different animal. It proposed a “commercial business purpose” exemption that would have removed private actions under CIPA's wiretapping and eavesdropping provisions as well as the pen register provision — in other words, all three doors. That version did not advance, and when the bill was revived it was cut back to the single subdivision quoted above.

This matters for reading the commentary. A good deal of analysis written in 2025 describes SB 690 as gutting CIPA website-tracking litigation, and that analysis was accurate about the bill it was written about. It is not accurate about the statute that was signed. If you are relying on a note about this bill, check whether it postdates the amendments.

The retroactivity clause has no date in it

Subdivision (d)(2) is the most commercially interesting sentence in the bill, and it is built on a date the bill never states.

It applies the amendment retroactively to “any pending claim in an action commenced within two years before the operative date of that legislation”. The operative date is not in the text. SB 690 contains no urgency clause and specifies no effective or operative date, so it takes effect under the ordinary rule for statutes passed in a regular session: 1 January 2027. Commentators give that date, and it follows from the absence of an urgency clause rather than from anything in the bill.

Run the arithmetic and the reach-back window opens on 1 January 2025. That is where the figure in the law firm notes comes from. It is a calculation off a date supplied by background constitutional law, not a provision you can point at.

Two consequences follow, and the second one is rarely mentioned.

A pending section 638.51 claim in an action commenced on or after 1 January 2025 is caught. If you are a defendant in one of those, the claim is on borrowed time.

An action commenced before that date is, on the face of the clause, outside the window. The subdivision reaches claims in actions “commenced within two years before” the operative date. An action filed in 2023 or early 2024 was not commenced within that window. Whether the oldest cases therefore keep their pen register claim while newer ones lose theirs is a question the text raises and does not answer, and we have not found a source that addresses it. If your exposure is in an older case, that is a question for your counsel rather than an assumption either way.

The other half of 30 September: the smart glasses bill was vetoed

The same legislative update carried a second item that reaches this industry, and it went the other way.

SB 1130 (Gómez Reyes), “Invasion of privacy: wearable recording devices”, was vetoed. It appears in the vetoed list of the 30 September update. Press reporting of the veto says the Governor's objection was that the bill's definition of a wearable recording device was too broad.

What it would have done, had it been signed, is worth recording because this will be back. From 2028 it would have required manufacturers of smart glasses and other wearable recording devices to include a visible indicator showing when recording is in progress, and banned the sale of technology designed to conceal such an indicator, with penalties reported at up to $2,500 for non-compliant manufacturers and up to $1,500 or imprisonment for individuals recording secretly in private places such as changing rooms and consulting rooms.

For a store that lists camera-equipped frames, the practical position is unchanged: there is no Californian recording-indicator mandate, and the design requirement that would have arrived in 2028 does not exist. The duties that do attach when you sell and glaze that hardware are a separate question, and a live one — putting prescription lenses into a pair of smart glasses can make you the manufacturer under rules that have nothing to do with this veto. A changing room in an optician's practice is also still a place where recording somebody has consequences; what fell away is a bespoke statute, not the general law.

What has not changed, and it is the part most likely to be misread

The single most important sentence in this article is this one: SB 690 is a California statute and it does nothing whatever to Illinois.

The exposure that has driven the virtual try-on litigation is not primarily CIPA. It is the Illinois Biometric Information Privacy Act, which carries its own per-person statutory damages and does not require any showing of harm, and which the Seventh Circuit has been steadily opening up. We wrote about what happened to the try-on exemption that merchants had been relying on when that shield came off. Nothing signed in Sacramento on 30 September touches it. Texas and Washington are likewise unaffected.

If the operational conclusion anyone draws from this week's news is “we can stop worrying about the try-on consent flow”, the news has been read in exactly the wrong direction.

Six things to do

1. If you are a defendant in a pending CIPA pen register case, tell your counsel today. Subdivision (d)(2) is retroactive and it may dispose of the claim. This is the one item on the list with a cash value attached and a clock on it.

2. Do not touch your consent banner or your try-on consent flow. They were built for sections 631 and 632, for BIPA, and for the CCPA. All of those survive intact. Relaxing a consent flow because of SB 690 is the single most expensive mistake available this quarter.

3. Separate your try-on vendor from your analytics vendors in your own records. They now sit in materially different legal positions. The pixel got relief; the camera did not. If one line in your vendor list covers both, split it.

4. Check what your try-on vendor transmits, and whether it leaves your domain. This was always the question. It is now the only question on the California side, because the contents-free route is closed and the contents route is open. Ask the vendor in writing what is sent, to whom, and whether anything is retained.

5. Re-read any 2025 memo you were given about SB 690. If it describes a commercial business purpose exemption covering wiretapping and eavesdropping claims, it describes a bill that was not enacted.

6. Leave the prescription capture alone. Sphere, cylinder, axis and PD are plainly contents, they are collected on your own domain with the customer typing them in deliberately, and consent there is about as clear as consent gets. It is the least exposed surface in this entire article.

The line moved, but not under your feet

There is something unusual about this one, set against everything else this industry has had to absorb this year.

Every other rule we have written about draws its line somewhere in the merchant's own conduct or inventory. Whether the frame is a medical device. What you did to it when you glazed it. Where your checkout actually renders. Where you are established. What your own terms and conditions happened to promise. In each case you could look at your own operation and work out which side of the line you were on, and in each case you could move.

California alone now gives you three live examples of the difference. It has told you what to disclose about the AI model in your video ad from 1 January, a duty that turns entirely on what you made and published. It is in court over what you may print on a glasses case, a duty that turns on the object. And now it has changed who may sue you over a script, while leaving the script exactly where it was. The first two ask what you did. The third asks who is standing opposite you.

SB 690 is not like that. Your conduct is not the variable. The script on your storefront does precisely what it did on 29 September, it is precisely as lawful or unlawful as it was, and the Attorney General can still come after it. What changed is who holds the right to sue. It is the first rule in this series where the merchant's behaviour is not the thing being measured at all — which is also why it is so easy to mistake for permission. A remedy was withdrawn. No duty was lifted.

That distinction is the one to keep. California has made it dramatically harder for a private plaintiff to monetise a pixel. It has not said a word about what you may do with a photograph of your customer's face.

Frequently asked questions

I am not in California. Does this help me?

If you were facing, or feared, a CIPA pen register claim, yes — those claims are brought in California courts over conduct on websites available to Californians, and private plaintiffs lose that route. If your concern was Illinois biometric exposure, or the federal wiretap statute, or the CCPA, this does nothing for you.

Can I remove my cookie consent banner now?

No, and nothing in SB 690 suggests otherwise. Consent is what defends sections 631 and 632 claims, which are untouched, and consent requirements under the CCPA and CPRA are unaffected. The banner is load-bearing for the doors that are still open.

Does the Attorney General actually bring these cases?

Not established. The amendment preserves the Attorney General's action and the published material we could find does not indicate any enforcement history or stated intention under section 638.51. The honest position is that private litigation was the practical risk and it is now narrower; what replaces it, if anything, is unknown.

What counts as a “private actor”?

The term is used in the new subdivision and we did not find a definition for it in section 637.2. The evident sense is a defendant other than a government body, which is what matters for a merchant. We are flagging it rather than asserting it.

My try-on runs entirely in the customer's browser and sends nothing out. Where does that leave me?

In the best position available, and that was true before this bill. An interception claim under section 631 needs a third party reading a communication in transit. A tool that does its work on the device and transmits nothing is a much harder target. If your vendor tells you this is how their tool works, get it in writing and keep it.

Does this affect the AI Act obligations on my try-on in Europe?

Not at all — different continent, different mechanism. The EU transparency duties work through the provider and deployer roles rather than through a private damages claim; we cover how that split lands on an eyewear store's try-on separately.

Is there anything in SB 690 about session replay specifically?

No. The subdivision names only section 638.51 and describes conduct “occurring on an internet website, online application, or mobile application”. Session replay tools were frequently sued under both the pen register provision and section 631; only the first of those routes is closed to private plaintiffs.

What is the chapter number?

Not established at the time of writing. The Governor's legislative update of 30 September 2026 records the signature; the chaptering details were not available in any source we could read. The signature date and the bill text are what this article relies on.


This article is general information about regulatory developments, not legal advice. SB 690 was signed on 30 September 2026, has not yet taken effect, and no court has interpreted it. The reading offered here about how the surviving CIPA provisions apply to camera-based virtual try-on tools is our analysis and not a settled question, and the treatment of actions commenced before the retroactivity window is an open question we have flagged rather than answered. Whether and how any of this reaches you depends on your tooling, your vendors, your consent flows and where your customers are. Take advice on your own position, and if you are in live litigation take it now rather than from an article.

VisioncarePro adds structured prescription capture and lens selection to any Shopify product page. The customer types their own prescription, on your domain, deliberately — which is the cleanest consent posture of any data collection in an eyewear store. Free to install.

Install VisioncarePro free on the Shopify App Store →


Sources: California SB 690 (Caballero), 2025–26 Regular Session, amending section 637.2 of the Penal Code — bill text read directly, including the full text of new subdivision (d)(1) and (d)(2) quoted above, confirmed on two separate readings, and the absence of any urgency clause, any specified operative date, any additional code section and any “commercial business purpose” provision in the enacted text · Office of the Governor of California, “Governor Newsom issues legislative update 9.30.2026”, gov.ca.gov, read directly: SB 690 in the signed list, described as “SB 690 by Senator Anna Caballero (D-Merced) — Crimes: invasion of privacy”, and SB 1130 in the vetoed list, described as “SB 1130 by Senator Eloise Gómez Reyes (D-Colton) — Invasion of privacy: wearable recording devices” · California Penal Code sections 637.2 (statutory damages of the greater of $5,000 per violation or three times actual damages, with no requirement of actual damage), 638.51, 631 and 632 · Goodwin, “California Curbs CIPA Pen Register Suits — But the Website Tracking Litigation Wave Isn't Over”, September 2026, for the 1 January 2027 operative date, the absence of a safe harbour and the list of surviving theories · Sidley, “California's SB 690 Clears the Legislature”, September 2026, for the bill's amendment history and the abandoned commercial business purpose exemption · Kelley Drye, Ad Law Access, on the retroactive application to claims filed within two years before the operative date · ABC News wire report of the SB 1130 veto, for the Governor's stated objection to the breadth of the definition and the bill's 2028 indicator requirement, $2,500 manufacturer penalty and $1,500 individual penalty. Chapter number and chaptering date for SB 690: not established.

RuffRuff Apps RuffRuff Apps by Tsun