Checklist

Pen register vs trap and trace: what does that mean for website tracking?

Start a free audit

Pen register and trap and trace are often one theory family in website-tracking talk. Open the CIPA map, then still record Fresh and Reject. Not legal advice.

In brief

People searching pen register vs trap and trace want a vocabulary check before a CIPA page. Website-tracking commentary names those phrases as one addressing-style theory family, separate from wiretap theories about content. The full map is on the CIPA theory page. SB 690 news is on its own page. Still record Fresh and Reject. A free US-baseline scan is not an EU or California legal conclusion. This page is not a second CIPA theory rewrite and not legal advice.

Not legal advice

This FAQ explains how public commentary groups pen register and trap and trace language for website-tracking searches, and how that phrase relates to the live theory map. It is not legal advice, not a second CIPA theory rewrite, not a case prediction, and not counsel on a demand letter or complaint. Readers with California exposure should talk to their own counsel. Observation of storefront cookies and requests is not a CIPA risk score.

Last updated September 29, 2026. This page does not paste statutory text and does not invent holdings, fine amounts, or vote counts. The CIPA theory page owns the pen-register and trap-and-trace versus wiretap map. The SB 690 page owns the news slice.

Short answer

In public commentary on website-tracking lawsuits, pen register and trap and trace are frequently named together as one addressing, routing, or signaling-style theory family. People often discuss that family under CIPA pen-register and trap-and-trace talk, including section 638.51-style claims. That family is distinct from wiretap and eavesdropping-style theories about the content of communications.

The two phrases are usually one family in that talk. Open the CIPA theory page for the map. Open the SB 690 page for the news slice and confirm the live bill status.

Theory labels do not replace a storefront check. Still capture what loads before Accept and after Reject. This page is a literal-query bridge. It is not a second CIPA theory rewrite and not legal advice. Observation is not counsel permission.

Vocabulary card

Use these labels as search language. This table does not quote the code.

Search phrases, the high-level focus in website-tracking commentary, and where to read more.
Phrase in alertsPlain-English focusWhere to read more
Pen register / trap and trace, often named togetherAddressing, routing, or signaling-style information alleged in website-tracking talkCIPA theory page
Wiretap / eavesdropping theoriesContent of communications allegedCIPA theory page
SB 690 news sliceMainly certain private pen-register website claims. Confirm the live bill page.SB 690 page

Still measure the storefront

A theory vocabulary and a runtime record answer different questions. Clean profiles, labeled states, and saved requests are the record. The checklist, the before-Accept audit, and the Reject leftovers guide hold the longer method.

  1. Use a clean profile. Load the storefront once. Do not click Accept. Label the pack Fresh.
  2. Capture cookies and Network rows for marketing and analytics hosts. Example of an ops note, not a legal exhibit: Fresh shows a marketing host before any banner click.
  3. Open a new clean profile. Click Reject All. Navigate once more. Label the pack Reject and recapture cookies and Network.
  4. Keep the evidence pack: request, cookie, and screenshot, tied to the state label.
  5. Hand findings to engineering when they own the tag, or to counsel when they ask. This page does not draft counsel edits.
  6. If the banner text and the Network row disagree, open the CMP claims page. If Reject still shows the host, open the Reject leftovers guide.

When hand-built packs get slow

Building Fresh and Reject packs across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios, including GPC when that claim matters, only for those regional paths. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not score CIPA risk, does not install a CMP, and does not issue a certificate.

FAQ

Pen register vs trap and trace: what does that mean for website tracking?

In public commentary they are often named together as one addressing, routing, or signaling-style theory family. The CIPA theory page maps that family against wiretap theories. This page is the short query bridge.

Are pen register and trap and trace two opposite claims?

Website-tracking talk usually treats them as one family. This page does not invent a courtroom split. Read the code pages and the CIPA theory page before you describe a complaint.

Where is the full CIPA theory comparison?

On the CIPA pen-register versus wiretap page. This FAQ only bridges the literal search phrase to that map. It is not a second CIPA theory rewrite.

Does SB 690 end all website-tracking theories?

No. The SB 690 page covers the news slice for certain private pen-register website claims. Confirm the live bill page. The CIPA theory page notes that wiretap theories are a different story.

What should operators still do?

Run Fresh and Reject runtime checks. The pre-consent checklist, the before-Accept audit, and the Reject leftovers guide are the method. Keep the evidence pack.

Is this legal advice?

No. These are technical observations and a vocabulary map. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

Pen register and trap and trace are often one theory family in website-tracking commentary. The full map is on the CIPA theory page. Fresh and Reject still belong on the storefront. This page is not legal advice and not a second CIPA theory rewrite. Observation is not counsel permission. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the CIPA theory page for the map, the SB 690 page for the news slice, and the checklist plus the before-Accept and Reject guides when you need the storefront record.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Pen register vs trap and trace FAQ | ConsentProbe