By Steve Levine · Updated July 2, 2026 · 7 min read
A pen register is a device or process that records the outgoing dialing, routing, addressing, or signaling information of a communication — classically, the numbers a telephone dialed. A trap and trace device captures the same information for incoming communications. California Penal Code § 638.51 (part of CIPA) bars installing or using either without a court order, subject to exceptions including user consent. Since Greenley v. Kochava (S.D. Cal. 2023) read the statute's “device or process” language to potentially cover tracking software, plaintiffs have filed a wave of class actions alleging that website trackers collecting IP addresses and device data are unauthorized digital pen registers. Courts have split on the theory — it is developing, contested law — but CIPA's $5,000-per-violation statutory damages keep the filings coming.
Free settlement alerts
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Traditionally, a pen register is a device that records the outgoing dialing, routing, addressing, or signaling information of a communication — classically, the phone numbers dialed from a particular line — without capturing the contents of the conversation. A trap and trace device is its mirror image: it captures the originating number and similar information for incoming communications. Both were law-enforcement surveillance tools regulated by statutes requiring a court order before use.
California Penal Code § 638.51, part of the California Invasion of Privacy Act, makes it unlawful to install or use a pen register or trap and trace device without first obtaining a court order, subject to exceptions — including where the provider obtains the consent of the user. California defines a pen register as a 'device or process' that records outgoing routing, addressing, or signaling information, and plaintiffs argue the word 'process' reaches modern tracking software.
In Greenley v. Kochava, Inc. (S.D. Cal. 2023), a federal district court declined to dismiss a § 638.51 claim against a mobile data broker, reasoning that the statute's 'device or process' language could plausibly cover software embedded in apps that collects device and identifying data. The decision was the first prominent ruling to read California's pen-register law to reach tracking software, and it triggered a wave of web-tracking pen-register class actions. It is one district court's ruling at the pleading stage, not binding precedent.
Plaintiffs allege that tracking technologies — advertising pixels such as the TikTok pixel, analytics scripts, and device-fingerprinting tools — act as digital pen registers by capturing visitors' IP addresses, device identifiers, and browsing metadata, which they characterize as 'routing, addressing, or signaling information,' without a court order or the visitor's consent. These are contested allegations; courts have split on whether the statute reaches website tracking at all, and many cases have been dismissed while others have been allowed past the pleading stage.
Plaintiffs invoke CIPA's private right of action, Cal. Penal Code § 637.2, which authorizes the greater of $5,000 per violation or three times actual damages, plus injunctive relief, without requiring proof of a dollar loss. Those are amounts a court may award if a violation is proven — the pen-register web-tracking theory remains developing, contested law, and no appellate court has definitively endorsed it.
HOT