Industry story
California SB-690 Keeps Private Right of Action for Online Tracking
data-brokers identity litigation privacy
The California legislature passed a compromise version of SB-690 that preserves private right of action under the California Invasion of Privacy Act (CIPA) — meaning individual citizens, not just regulators, can sue companies over online data collection practices. This shifts the compliance burden from satisfying bureaucratic rules to satisfying juries, since courts and not agencies will now be the primary arbiters of acceptable data practices. The article argues this is net positive for smaller, customer-centric companies and negative for Big Tech, whose data practices (e.g., pervasive tracking pixels and third-party data sharing) are the same ones juries are most likely to reject. Over 4,000 CIPA lawsuits have already been filed, mostly against legitimate mid-sized businesses rather than large platforms, highlighting the immediate legal exposure.
Analysis
Showing the shorter version.
California's legislature passed a compromise version of SB-690 that keeps the private right of action under CIPA (the California Invasion of Privacy Act), meaning individual citizens, not just the attorney general, can sue over pixels, tags, and third-party data sharing. Over 4,000 suits are already filed. The targets so far are mid-sized businesses, not Meta or Google.
That last point matters. Meta and Google have privacy counsel, mature consent flows, and lobbying muscle. The plaintiffs' bar goes where it finds a jury-unfriendly tracking footprint and a defendant who'll settle to avoid discovery. Mid-sized publishers and e-commerce operators fit that description. They carry the same cookie-syncing and retargeting infrastructure as the giants, without the legal reserves to defend it.
The immediate operational job is audit and triage. Every tag management system, every third-party JavaScript inclusion is now potential plaintiff evidence. The near-term work is emergency consent-layer reviews, legal holds on analytics vendor contracts, and defunding retargeting pixels that were already marginal on ROAS. The trap is that "just remove the pixel" sounds cheap until you realize how much measurement infrastructure goes dark with it. Defund your tracking and your attribution collapses right when you need to defend budget. Distinguishing the junk pixels you can kill tomorrow from the measurement backbone you actually depend on is the real work.
There's a second cost most teams haven't modeled yet: privacy insurance underwriters will re-price coverage before most ad ops teams finish their audits. That repricing lands whether or not you've fixed anything, so get a quote now.
On the budget side, follow the money. A private right of action at scale makes first-party data and provable consent a legal defense, not a compliance checkbox. Clean-room and consent infrastructure vendors, LiveRamp, InfoSum, Optable, and Habu, get a multi-year tailwind. Mid-market advertisers stop treating CIPA as a line item and start treating it as a build-versus-buy decision on their identity stack. Spend flows toward walled gardens that can absorb litigation risk and toward publishers who can certify consent provenance. The SSP and data-broker middle tier loses, because they carry the tracking footprint juries hate and none of the legal cover.
The one real uncertainty: CIPA's wiretapping theory is still contested in the circuit courts. Appellate rulings could narrow the actionable surface before any compliance buildout pays back. If that happens, everyone who rushed to rip out infrastructure overspent.
Our call: LiveRamp or another publicly traded consent or clean-room identity vendor names CIPA litigation exposure as a demand driver on an earnings call by Q2 2027 reporting (ending August 2027). Confidence is medium. The tailwind is real, the suits are in flight, and management teams reliably fold a live regulatory threat into their demand narrative once it shows up in pipeline. The risk is timing: if appellate courts narrow the wiretapping theory first, the sales story softens before it reaches a transcript.
California just handed every citizen a private right to sue over online tracking. The legislature passed a compromise version of SB-690 that keeps the private right of action under CIPA, the California Invasion of Privacy Act. Translation: individuals, not just the attorney general, can drag you into court over pixels, tags, and third-party data sharing. Over 4,000 CIPA suits are already filed, and the targets so far are mid-sized legitimate businesses, not Meta or Google.
What's actually being decided: whether the arbiter of "acceptable" data practices moves from regulators writing rules to juries reacting to your tag manager. Hard to undo, at least for the plaintiffs' bar side: once a private right of action is on the books and 4,000 suits are in flight, that machinery does not get unwound. The compliance side is easier to undo, because appellate courts could still narrow what CIPA's wiretapping theory actually reaches. What sets the deadline: nothing fixed. But every quarter you run marginal retargeting pixels is a quarter of accumulating discovery exposure.
The Skeptic
The article's framing is that this hurts Big Tech. That's backwards. Meta and Google have armies of privacy counsel, mature consent flows, and the lobbying muscle to shape whatever safe-harbor rulemaking emerges. The 4,000 suits already filed landed on mid-sized businesses, because that's where the plaintiffs' bar finds a jury-unfriendly tracking footprint and a defendant who'll settle to avoid discovery. That's a plaintiffs'-bar revenue model, not a well-targeted consumer protection. And CIPA's wiretapping theory is still contested in the circuit courts. There's a real chance appellate rulings narrow the actionable surface before anyone's expensive compliance buildout pays back. For an informed outsider: the law meant to punish the giants mostly clobbers the companies in the middle who can least afford it.
The Operator
Tuesday morning, this is an audit and triage job. Every tag management system, every pixel in the catalog, every third-party JavaScript inclusion is now potential plaintiff evidence. Day 30 is emergency consent-layer reviews. Day 90 is legal holds on your analytics vendor contracts and quiet defunding of retargeting pixels that were already marginal on ROAS. The second-order effect nobody's modeling: cyber and privacy insurance underwriters re-price coverage before most ad ops teams finish their audits. Mid-sized publishers and e-commerce operators eat this asymmetrically. They generate the same jury-unfriendly tracking footprint as Meta, without Meta's legal reserves. "Just remove the pixel" sounds cheap until you watch how much measurement infrastructure collapses with it.
The Market Analyst
Follow the budget. A private right of action at scale makes first-party data and consent-based identity a strategic necessity, not a nice-to-have. Clean-room and consent infrastructure vendors, LiveRamp, InfoSum, Optable, Habu, get a two-to-three-year tailwind. Mid-market advertisers stop treating CIPA as a compliance line and start treating it as a build-versus-buy decision on their identity stack. That flips spend two ways: toward walled gardens that can indemnify or absorb litigation cost, and toward publishers who can credibly certify where consent came from. The SSP and data-broker middle tier is the loser here, because they carry the cookie-syncing footprint juries hate and none of the legal cover. For a general reader: the fear of a jury trial pushes money toward the few players who can promise the data was collected cleanly.
The CFO
The line item people see is legal spend and settlements. The real cost is measurement collapse. Defund your retargeting pixels and your third-party tracking, and your attribution goes dark right when you need to defend budget. That's the trap: the cheap move to dodge a lawyer letter also blinds you to what's working. Factor in the insurance re-pricing the Operator flagged, and your cost of carrying a tracking-heavy stack just went up on two lines at once, premiums and reserves. Payback on a clean-room build is 18 to 24 months, and it only pencils if jury standards stabilize enough that "we did it right" is a real defense. If standards stay chaotic, you're spending to reduce exposure you can't fully price.
The Customer / End User
Here the customer is two different people. The consumer gets a weapon, and 4,000 filings say plenty are willing to use it, though most of that is plaintiffs'-bar volume, not grassroots outrage. The advertiser client is the one to watch. A mid-market brand running Tatari-style measurement or standard retargeting didn't ask for this and mostly doesn't understand its exposure yet. When they do, the demand isn't "help me track more." It's "prove to me your stack won't get me sued." That reframes the whole vendor pitch. Consent provenance becomes a sales requirement, and the vendor who can certify it wins the RFP over the one with better reach.
The tensions
Two real disagreements sit under this.
First, who actually gets hurt. The Skeptic says the middle tier eats it while Big Tech lawyers its way through and shapes the eventual safe harbor. The Market Analyst partly agrees but sees the same pressure pushing budget toward walled gardens and clean rooms, which is a slower, structural win for a specific set of vendors. Both can be right: the middle tier loses, and the money it loses flows to the giants and the consent-infrastructure players.
Second, whether "remove the pixel" is cheap or catastrophic. The article's quote treats cutting tracking scripts as a straightforward web project and a long-term win. The Operator and CFO say that's where your measurement infrastructure lives, and pulling it blinds you. The compromise resolves toward: removing junk pixels is cheap, removing your measurement backbone is not, and telling them apart is the actual work.
What it hinges on
Two beliefs decide this. One, whether appellate courts narrow CIPA's wiretapping theory before the compliance buildout pays back. If they narrow it hard, everyone who rushed to rip out infrastructure overspent. Two, whether jury standards for "acceptable data practice" stabilize fast enough that a clean-room investment is a real legal defense and not just a hope.
The council leans one way with conviction: the near-term winners are the consent and clean-room infrastructure vendors, and the near-term losers are the ad-tech middle layer that carries the tracking footprint without the legal reserves. That's the same pattern regulatory pressure always creates. It sends money toward whoever can certify compliance and away from whoever can't afford to defend it.
Before committing real budget: verify your actual exposure by cataloging which pixels drive measurement you'd defend in front of a jury versus which are marginal retargeting you can kill tomorrow. De-risk by pricing the insurance re-rating now, before your audit finishes, because that repricing lands whether or not you've fixed anything.
Prediction: At least one publicly traded consent or clean-room identity vendor (LiveRamp the most likely, as the largest public pure-play) will name CIPA litigation exposure or private-right-of-action risk as a demand driver on an earnings call by the Q2 2027 reporting season, ending in August 2027.
Confidence: Medium — the tailwind is real, but timing to an earnings mention is loose.
Why: SB-690 keeps a private right of action alive with over 4,000 suits already filed, which turns first-party data and provable consent from optional into a legal defense. Vendors that certify consent provenance sell directly against that fear, and management teams reliably fold a live regulatory threat into their demand narrative once it starts showing up in pipeline. The opposite outcome, silence, is less likely because a public vendor with a litigation-driven tailwind has every incentive to name it for investors, and CIPA is concrete enough to cite. The risk to the call is timing: if appellate courts narrow the wiretapping theory first, the sales story softens before it reaches a transcript.
Revisit by 2027-08-31: We're right if a public consent or clean-room identity vendor cites CIPA or California private-right-of-action litigation as a demand or pipeline driver on an earnings call by the end of Q2 2027 reporting. We're wrong if none does by then.
Also covered this issue
-
German Court Rules Meta Liable for Scam Ads Under DSA Framework
digiday
A German court ruled algorithmic ranking strips platforms of the DSA's neutrality defense, exposing every ad distributor to liability for what it amplifies.
-
John Nardone of JWX: Viant Measurement 'Absolutely Not' Independent
adotat
Viant's claim to measure the market—not just its own buys—now carries a conflict-of-interest charge that could become contract language in fall upfronts.
Comments