CIPA & Wiretap Litigation

What is Pen Register?

A pen register is defined by California Penal Code section 638.50(b) as a device or process that records dialing, routing, addressing, or signaling information for outgoing communications without capturing their contents — a telephone-era concept plaintiffs now invoke against website analytics and advertising trackers.

Historically, a pen register was a physical device attached to a phone line that logged the numbers a suspect dialed. Because it captured metadata rather than conversation content, courts treated it differently from a wiretap — but legislatures still required a court order to use one. The federal Pen Register Act (18 U.S.C. section 3121 and following) and California Penal Code sections 638.50-638.53 both regulate pen registers on that model.

California's definition is written broadly: a 'device or process' that records dialing, routing, addressing, or signaling information transmitted by an instrument from which a wire or electronic communication is sent. Plaintiff attorneys seized on the words 'or process' to argue that JavaScript trackers — which record a visitor's IP address, URLs visited, device characteristics, and similar routing or signaling information — are software pen registers installed on the visitor's browser without a court order, violating section 638.51.

The 2023 Greenley v. Kochava decision, which held that a mobile SDK could plausibly be a pen register 'process,' opened the floodgates. Pen-register and trap-and-trace claims are typically pleaded together, and both ride on CIPA's civil remedy of $5,000 per violation with no proof of actual harm required.

Section 638.51 contains a consent exception: a provider may use such a device 'if the consent of the user of that service has been obtained.' That makes prior consent — trackers held until the banner is answered — the cleanest technical defense, independent of how any particular court reads the statute.

Why it matters for eCommerce

For an online store, every pre-consent analytics call, ad pixel, and fingerprinting script is raw material for a pen-register demand letter. These letters are cheap to send and name real technologies found on your actual site, so the credible response is architectural: scan the storefront to inventory what fires before consent, then gate it.

Frequently asked questions

Why are website trackers being called pen registers?
California defines a pen register as a 'device or process' that records routing, addressing, or signaling information. Plaintiffs argue tracking scripts fit because they collect IP addresses, page URLs, and device signals. Courts are split on the theory, but the statutory-damages exposure makes the claims attractive to file regardless.
What is the penalty for a pen register violation under CIPA?
Civil exposure runs through Penal Code section 637.2: $5,000 per violation or three times actual damages, whichever is greater, with no actual harm required. Multiplied across a class of website visitors, claimed damages escalate quickly.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Scan your site for pre-consent trackers

← Back to all glossary terms