CIPA & Wiretap Litigation

What is Trap and Trace Device?

A trap and trace device is defined by California Penal Code section 638.50(c) as a device or process that captures incoming electronic impulses identifying the source of a communication — a definition plaintiffs now apply to website trackers that collect visitor IP addresses and device identifiers.

The term comes from telephone surveillance: a trap and trace device captures information about incoming calls (who is calling you), while its sibling, the pen register, records information about outgoing calls. Both capture dialing, routing, addressing, or signaling information — metadata about the communication — but not its contents. Law enforcement needs a court order to use either one, under California Penal Code section 638.52 and the federal Pen Register Act.

California Penal Code section 638.51 makes it unlawful for anyone to install or use a pen register or trap and trace device without a court order, subject to exceptions — the most important being consent of the user. Violations feed into CIPA's civil remedy: $5,000 per violation under section 637.2, with no requirement of actual damages.

Starting around 2022, plaintiff firms began arguing that common web technologies — analytics scripts, advertising pixels, fingerprinting libraries — are 'trap and trace devices' because they capture the visitor's IP address, device details, and other signaling information that identifies the source of the communication. A federal court's 2023 ruling in Greenley v. Kochava, which held that a software SDK could qualify as a pen register, gave the theory momentum, and thousands of demand letters followed.

Courts remain split on whether the statute reaches website trackers, and several California decisions have rejected the theory. But because consent is an explicit statutory exception, the reliable mitigation does not depend on winning that argument: capture consent before any tracker that collects identifying information fires.

Why it matters for eCommerce

Trap-and-trace demand letters are aimed disproportionately at online stores, because a typical storefront loads a dozen third-party scripts that collect IP addresses and device signals on the first pageview — before any consent banner is answered. The claimed exposure is $5,000 per violation. Gating those scripts behind consent converts the strongest version of the claim into a non-starter.

Frequently asked questions

What is the difference between a trap and trace device and a pen register?
Direction. A pen register records dialing, routing, addressing, or signaling information for outgoing communications; a trap and trace device captures the same category of information for incoming communications, identifying the source. Web-tracking lawsuits often plead both theories together.
Is using analytics on my website really a trap and trace violation?
That is contested. Some California courts have let trap-and-trace claims against website trackers proceed past early motions; others have dismissed them as misreading a telephone-surveillance statute. Because section 638.51 contains a consent exception, obtaining consent before trackers fire is the dependable safeguard either way.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

See PieEye Trap and Trace Shield

← Back to all glossary terms