Axel PR
Signals

Is Website Visitor Identification Legal? What Changed in 2026

Person-level visitor identification can be run lawfully, but the rules moved in 2026. Here is what changed in California, what did not, and the setup that keeps a small business on the right side of it.

· 8 min read

Key takeaways

  • Visitor identification can be run lawfully with clear notice, an updated privacy policy, consent where required, honored opt-outs, and careful follow-up.
  • California SB 690, signed September 30, 2026 and operative January 1, 2027, ends private lawsuits under the state's pen-register provision over websites and apps. Only the Attorney General can bring those claims.
  • SB 690 does not touch the wiretap section of the California Invasion of Privacy Act, which is the theory that fits identity-resolution pixels most closely, so private suits on that theory remain possible.
  • Under California law and about a dozen other state privacy laws, sharing visitor data with an identity provider can be a sale or sharing that visitors may opt out of, including through browser signals such as Global Privacy Control.
  • An identified visitor did not ask you to call. Email them, show them ads, or call by hand after a Do Not Call check. Never robocall, AI-call, or mass-text an identified visitor.

What is person-level visitor identification?

First, the line that matters most: this is general information for business owners, not legal advice. Privacy law is changing quickly, and courts in different states disagree. Confirm anything that affects your business with counsel.

Company-level identification tells you which business a visitor works for, usually from the network they browse on. Person-level identification goes further: a script on your site sends signals about the visit to an identity provider, which matches the visitor to a person it already knows and returns a name, an email address, and sometimes a phone number and location. That second kind is what most small-business tools sell, and it is the kind privacy law cares about most.

What did California SB 690 change?

For several years, plaintiffs filed thousands of demand letters and lawsuits under the California Invasion of Privacy Act (CIPA), arguing that website trackers were illegal pen registers or wiretaps. Statutory damages of $5,000 per violation made the claims expensive to defend even when they were weak.

SB 690, signed on September 30, 2026, takes the pen-register and trap-and-trace provision out of private hands for websites and apps: from January 1, 2027, only the California Attorney General can sue a business over that provision for conduct on a website or app, and the change reaches suits filed on or after January 1, 2025. An earlier draft would have exempted all tracking done for a commercial business purpose. That broader exemption was removed before the bill passed.

What did SB 690 not change?

The wiretap section of CIPA still allows private suits. Its theory is that a third party listened in on the contents of a communication without consent. A pixel that sends page addresses, form activity, or other content to a vendor that resolves the visitor to a named person is closer to that theory than a simple analytics tag that records an IP address. Claims over recording calls, and federal wiretap and unfair competition claims, are also unaffected.

In practice, that means the safest setup for visitors in California is the same as it was before SB 690: tell visitors what you do, and load the identification script only after they agree.

Is sharing visitor data a sale under privacy law?

Often, yes. Under the California Consumer Privacy Act, making personal information available to a third party for something of value is a sale, and disclosing it for cross-context behavioral advertising is sharing. An identity provider that adds what it learns to its own graph is not acting as your service provider, so passing it visitor data is usually treated as a sale or sharing.

That brings three duties: say so in your privacy policy, give visitors a way to opt out (a link titled Do Not Sell or Share My Personal Information, or Your Privacy Choices), and honor browser opt-out signals such as Global Privacy Control. About a dozen states now require businesses to honor those signals, and the list grows each year.

What about health, legal, and financial sites?

Be most careful here. Washington's My Health My Data Act treats information that suggests a person is seeking health care, including inferences from browsing, as consumer health data. Collecting it needs consent, selling it needs a signed authorization, and consumers can sue. Many operators simply do not run person-level identification on health-related pages, and we recommend the same. Pages about financial hardship, children, or legal trouble deserve the same caution.

Can you call or text an identified visitor?

Identification gives you contact details, not consent. Treat identified visitors as cold contacts.

  • Email is allowed under CAN-SPAM with a clear sender, an honest subject, a physical address, and a working unsubscribe
  • Calls by hand are possible after checking the National Do Not Call Registry, the state lists that apply, and your own do-not-call list, inside legal calling hours
  • Autodialed calls, prerecorded or AI-voice calls, and marketing texts need prior express written consent, which an identified visitor has not given
  • Never tell someone you know what they read on your site. It is unsettling, and it is how a follow-up becomes a complaint

A practical setup for small businesses

  • Update your privacy policy to describe identity resolution, what is collected, who receives it, and how to opt out
  • Add a consent notice, and load the identification script only after a visitor accepts, at least for California and Washington visitors
  • Honor Global Privacy Control and opt-out requests, and pass them to your vendor
  • Exclude health and other sensitive pages from identification
  • Follow up with email and ads first, and manual calls only after a Do Not Call check
  • Choose a vendor that publishes its data-use rules, registers where data brokers must register, and supports opt-outs
  • Review the setup with counsel once a year, because this area moves fast

Frequently asked questions

Is website visitor identification legal?

It can be run lawfully with clear notice, an updated privacy policy, consent where required, honored opt-outs, and careful follow-up. The main risks are California wiretap claims, state privacy laws that treat the data flow as a sale, and health data laws. This is general information, not legal advice.

Did SB 690 make website tracking legal in California?

No. Signed September 30, 2026 and operative January 1, 2027, it ends private suits under CIPA's pen-register provision for websites and apps, leaving those claims to the Attorney General. Private wiretap claims under the same law remain possible.

Do I need a cookie banner for visitor identification?

A consent notice that loads the script only after the visitor agrees is the safer setup, especially for California and Washington visitors, and your privacy policy must describe the practice either way.

Can I text people my website identified?

Not for marketing without prior express written consent naming your business. Email and manual calls after a Do Not Call check are the appropriate channels.

Only pay for calls that meet the intent.

Submit an inquiry and we'll show you the exclusive call volume, pricing, and dispute process for your industry.