A pen register is a device or process that records the dialling, routing, addressing or signalling information of an outgoing communication, but not what the communication says. It exists in law because legislators wanted a lighter regime for collecting the envelope of a communication than for its contents. Since 2023 the term has acquired a second life in California, where plaintiffs argue that tracking pixels, software development kits (SDKs) and analytics scripts on websites are pen registers installed without a court order.

How a pen register works

On a landline, a telephone company attached equipment at its central office to the target's line and recorded each outgoing number, often with time and duration. No audio was captured. A companion tool, the trap and trace device, did the reverse: it captured the incoming signals identifying who was calling the target.

Federal law defines both functionally. Under 18 U.S.C. 3127(3), a pen register is "a device or process which records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted", excluding "the contents of any communication". A trap and trace device captures information "reasonably likely to identify the source" of a communication. The word "process" matters: it means software can qualify.

Under 18 U.S.C. 3123(a)(1), a court must issue an ex parte order if a government lawyer certifies that the information likely to be obtained is relevant to an ongoing criminal investigation. That is the lowest threshold in the Electronic Communications Privacy Act (ECPA), well below the probable cause required for a wiretap. Providers are exempt when billing, running their networks, preventing fraud or acting with consent.

California copied this architecture. Penal Code section 638.50 defines a pen register in near-identical words, and section 638.51 bars anyone from installing or using one "without first obtaining a court order". A criminal violation carries a fine of up to $2,500, up to a year in county jail, or both. The provision that turned the statute into a litigation engine sits elsewhere: section 637.2 of the California Invasion of Privacy Act (CIPA) lets any person injured by a violation of the chapter sue for $5,000 per violation or three times actual damages, whichever is greater, without proving financial harm.

On a website, the plaintiffs' theory runs as follows. A third-party script sends the visitor's IP address, device characteristics, cookie identifiers or a fingerprint to an advertising or analytics company. That transmission, the argument goes, is "addressing" or "signalling" information, the script is a "process", and the site operator has installed it without a court order.

Origin and evolution

The name is older than the telephone: Samuel Morse's 1840 telegraph patent described a register that marked paper tape with a pen, and the term later attached to machines recording dial pulses.

The constitutional foundation came on June 20, 1979. In Smith v. Maryland, Baltimore police asked the telephone company to install a pen register on the home line of Michael Lee Smith, a robbery suspect harassing the victim by telephone. The Supreme Court ruled 5-3, in an opinion by Justice Harry Blackmun, that this was not a search under the Fourth Amendment because Smith had "voluntarily conveyed numerical information to the telephone company". The ruling became the anchor of the third-party doctrine, which holds that information handed to a business carries no reasonable expectation of privacy.

Because the Constitution did not require a warrant, Congress filled the gap with a statute. The Pen Register Act, Title III of ECPA, was enacted on October 21, 1986, and made unauthorised use a federal misdemeanour. On October 26, 2001, section 216 of the USA PATRIOT Act rewrote the definition to add "routing" and "addressing" information and the word "process", extending it to internet communications.

California was a late adopter. Assembly Bill (AB) 929, carried by Assemblymember Ed Chau and approved on August 13, 2015, took effect on January 1, 2016. Its committee analysis states that "California does not have a state statute authorizing the use of pen registers or trap and trace devices". The bill was framed entirely as a law enforcement measure.

From telephone lines to tracking pixels

The turn came on July 27, 2023. In Greenley v. Kochava, a federal court in the Southern District of California rejected the argument that section 638.51 covers only physical machines attached to phone lines. Given the "vague and inclusive" definition, the court said, a pen register could include software "that identifies consumers, gathers data, and correlates that data through unique fingerprinting". Kochava, an Idaho mobile measurement and location data company, separately settled a Federal Trade Commission case in May 2026.

Earlier CIPA suits had relied on section 631, the wiretapping clause, which requires interception of the contents of a communication. A pen register claim avoids that burden because it concerns only metadata. By March 2024, one firm alone had filed more than 120 suits, according to K&L Gates. Section 638.51 filings rose from about 600 to nearly 4,000 after February 2025, alongside thousands of demand letters.

Complaints now routinely pair the two theories. A March 12, 2026 suit accused Ace Hardware of firing Google Analytics and a Bazaarvoice pixel after visitors rejected cookies, pleading section 638.51 beside the federal Wiretap Act. An April 6, 2026 class action alleged that a LinkedIn script probed browsers for more than 6,000 Chrome extensions and included a pen register count.

Why it matters for marketers

The exposure attaches to ordinary infrastructure: a site tag that loads an advertising platform's library on every page transmits an IP address and identifiers by design. If each page view is a violation, $5,000 multiplied across a class of California visitors produces sums out of proportion to any harm alleged, which pushes most cases towards settlement.

Courts have not agreed. Los Angeles Superior Court judges dismissed pen register claims in Licea v. Hickory Farms on March 13, 2024, Sanchez v. Cars.com on January 27, 2025, and Aviles v. LiveRamp a day later, reasoning that the statute targeted telephone surveillance and that visitors expect to disclose IP addresses. On December 10, 2025, Judge Teresa Beaudet wrote in Rodriguez v. Ink America that CIPA "did not, and does not, criminalize the process by which websites communicate with users who choose to access them". Federal judges went the other way. In October 2024, Judge Rita Lin let Shah v. Fandom proceed over IP addresses shared with third-party trackers. Two Southern District rulings on October 1 and November 21, 2025 found that the Meta Pixel could meet the statutory definition, according to Troutman Pepper.

Limitations and disputes

Critics make three objections. The first is textual: an IP address is literally addressing information, but so is a postal address, and Cory Andrews of the Washington Legal Foundation, a business-aligned litigation group, argues that a literal reading would capture phone books and street signs. The second concerns direction. A pen register records outgoing destinations, yet many complaints rest on a visitor's IP address, which identifies a source. The third is the service provider exception, which some judges have read to cover tools used to operate a website.

Plaintiffs reply that the definition was deliberately widened beyond telephones in 2001 and that California copied the wider wording, a reading the Greenley court accepted. Consent, the obvious defence, is weakened when scripts fire before a banner choice is made, which the FTI paper distributed by IAB identifies as the core argument in demand letters.

Not the same as

Trap and trace device. The mirror image of a pen register: it captures incoming signals identifying the source of a communication. Website complaints often plead both, and the Variety Media tentative ruling turned on which of the two an IP address represents.

Wiretap. A wiretap intercepts contents, such as the words of a call or the text typed into a form. CIPA section 631 and the federal Wiretap Act govern it. A pen register by definition excludes contents.

Session replay. Session replay is a product category, not a legal term. Scripts record clicks, scrolling and keystrokes to reconstruct a visit. Because they can capture form inputs, they are usually litigated as wiretaps under section 631, as PPC Land's explainer on real user monitoring describes.

Recent developments

Governor Gavin Newsom signed SB 690 on September 30, 2026, the last day of his window. From January 1, 2027, only the Attorney General may sue over section 638.51 conduct on websites and apps, and the change reaches pending claims filed within the preceding two years. Introduced by Senator Anna Caballero on February 21, 2025, the bill passed the Assembly 66-0 on August 28, 2026. Section 638.50 and the criminal penalty are unchanged.

The relief is partial. An Interactive Advertising Bureau (IAB) paper by FTI Consulting argued on October 1, 2026 that wiretap claims under section 631 remain open. A suit over ChatGPT queries sent to Meta and Google relied on sections 631 and 632 without a pen register count, and a federal jury had already found Meta liable under CIPA in August 2025 over Flo app data.

The appellate question is also unsettled. On August 21, 2026, the Second Appellate District issued a tentative ruling in Variety Media v. Superior Court rejecting the telephone-only reading but finding an IP-address theory deficient. On October 1, 2026, the court withdrew the submission and asked whether SB 690 makes the case moot, with resubmission set for October 15, 2026, according to Jones Walker. As of October 2026, no California appellate court has issued a binding opinion on whether a website tracker is a pen register.

Timeline

  • 1840: Samuel Morse's telegraph patent describes a register that marks paper tape with a pen, the origin of the term.
  • June 20, 1979: Supreme Court rules 5-3 in Smith v. Maryland that pen register use is not a Fourth Amendment search.
  • October 21, 1986: Electronic Communications Privacy Act enacted; Title III creates the federal Pen Register Act.
  • October 26, 2001: USA PATRIOT Act section 216 extends the definition to routing and addressing information and to any "process", covering internet traffic.
  • August 13, 2015: California AB 929, authorising state pen register orders, is approved.
  • January 1, 2016: California Penal Code sections 638.50 to 638.53 take effect.
  • July 27, 2023: Greenley v. Kochava holds that SDK software can be a pen register under CIPA.
  • March 13, 2024: Licea v. Hickory Farms dismisses a website pen register claim in Los Angeles Superior Court.
  • October 2024: Shah v. Fandom allows an IP-address pen register claim to proceed in federal court.
  • January 27, 2025: Sanchez v. Cars.com dismisses a pen register claim without leave to amend.
  • February 21, 2025: SB 690 introduced in the California Senate.
  • June 3, 2025: Senate passes SB 690 35-0.
  • October 1 and November 21, 2025: Southern District of California rulings find the Meta Pixel can meet the pen register definition.
  • December 10, 2025: Rodriguez v. Ink America grants judgment on the pleadings against a pen register claim.
  • March 12, 2026: Ace Hardware sued with a section 638.51 count over post-opt-out tracking.
  • April 6, 2026: LinkedIn sued over browser extension scanning, including a pen register claim.
  • August 21, 2026: Second Appellate District issues tentative ruling in Variety Media v. Superior Court.
  • August 28, 2026: Assembly passes SB 690 66-0; Senate concurs 40-0.
  • September 30, 2026: Governor Newsom signs SB 690.
  • October 1, 2026: Variety Media court withdraws submission to consider mootness.
  • January 1, 2027: SB 690 becomes operative, ending private section 638.51 suits over websites and apps.

Summary

Who. Law enforcement agencies obtain pen register orders from courts, and telephone and internet providers install the tools. In California's website litigation, plaintiffs' firms sue site operators and ad tech vendors such as Meta, Google and Kochava; the Attorney General will be the sole civil enforcer for websites and apps from 2027.

What. A pen register is a device or process that records the dialling, routing, addressing or signalling information of an outgoing communication without capturing its contents. California's CIPA bars its use without a court order and, through section 637.2, has allowed private suits for $5,000 per violation.

When. The constitutional rule dates from Smith v. Maryland in June 1979, the federal statute from October 1986 and its internet extension from October 2001. California's version took effect in January 2016, the website theory gained traction after Greenley v. Kochava in July 2023, and SB 690 ends private website claims on January 1, 2027.

Where. Federally, across the United States under 18 U.S.C. 3121 to 3127. The website litigation is concentrated in California state and federal courts, with similar wiretap theories tested in other states.

Why. The concept was created to regulate the collection of communication metadata at a lower threshold than wiretapping. Its application to tracking pixels matters because the same definitions arguably cover everyday advertising and analytics code, exposing businesses to statutory damages that bear little relation to demonstrated harm.