New Ruling Could Stop Privacy Suits Over IP Addresses
Online users in California benefit from stronger privacy protections under the California Invasion of Privacy Act (CIPA) and the California Consumer Privacy Act (CCPA). Originally introduced in 1967 to prevent unauthorized surveillance, CIPA has become a legal battleground over website tracking and the collection of users' personal information, including IP addresses.

Posted on Justia.com, plaintiff Dawn Fergosa is suing Mashable in 2025 for using trackers on its website and “unlawfully recorded users’ IP addresses and device identifiers and transmitted that data to third parties for advertising and profiling.” The ruling allegedly violates CIPA and the Pen Register Act.
LA Times, Reddit, and InMobi were also sued by various individuals under CIPA. The lawsuits have not reached a final decision, but the courts allowed them to proceed after denying the defendants’ motions to dismiss.
Potential Changes on IP Address Collection Ruling
While these litigations are ongoing, a ruling from California’s Court of Appeal and Legislature could make these litigations moot or unnecessary.
According to Blank Rome, a tentative ruling was reached last August 21, 2026, about the website’s collection of IP addresses. Specifically, the CIPA’s provision does not cover the collection of this type of information. The reasoning for not including IP addresses as part of CIPA is as follows:
“Traditionally, these devices capture information identifying the destination of an outgoing communication, whereas a visitor’s IP address generally identifies the origination of the communication.”
In addition to the California Court of Appeal's tentative ruling, the California Legislature has passed SB 690, which would limit who can file CIPA claims. It only needs the Governor’s signature to become state law.
According to California's Official Legislative Website, the bill would “authorize only the Attorney General to bring that action for a violation…if the action is alleged to arise from conduct occurring on an internet website, online application, or mobile application. The bill would provide that this limitation applies retroactively to any pending claim in an action commenced within 2 years before the operative date of the bill.”
Privacy Protection Still Exists
These latest updates may make it seem like California is relaxing its privacy protections, especially regarding IP addresses. However, the latest ruling only limits those who can file CIPA claims. Private individuals are restricted from filing lawsuits against websites and online services. The Attorney General, however, can still file cases against websites if they violate CIPA.
Aside from CIPA, California residents also have stronger online privacy protections under the CCPA. It has stricter requirements, as websites must clearly tell users what information they collect. They must also inform users how their data is shared and provide an option to opt out. Like CIPA, the CCPA restricts individuals from filing lawsuits for certain violations.
This doesn’t mean an individual could take a website to court for privacy violations. Consumers can still sue websites under the CCPA if there is a data leak.
California residents can still submit a complaint to the California Privacy Protection Agency if they believe a business has violated their privacy rights. The Attorney General would then review these complaints and take appropriate action against websites for any violation.

Comments