文章

What is the difference between CIPA pen-register and wiretap theories for website tracking?

开始免费审计

Plain-English map of CIPA pen-register and wiretap website theories, what SB 690 covers, and which storefront checks to keep. Not legal advice.

In brief

In website-tracking lawsuits under California's Invasion of Privacy Act, plaintiffs often plead two theories. Pen-register and trap-and-trace claims, often discussed under section 638.51, focus on addressing, routing, or signaling information. Wiretap and eavesdropping claims, often discussed under sections 631 and 632, focus on communications content. Public reporting on SB 690 centers on private enforcement of certain pen-register website claims. Operators still need evidence of what loads before consent and after Reject. This page is a high-level map, not legal advice.

Not legal advice

This page maps two CIPA website-tracking theories in plain English. It is not legal advice, not a case prediction, not counsel on a demand letter or complaint, and not a reading of how any court will rule.

Section numbers below are names people use in alerts, not pasted statutory text. Open the code, the enrolled bill, or a firm alert you can cite. Readers with California exposure should talk to their own counsel. A ConsentProbe report is not a CIPA legal opinion.

Short answer

The same pixel or session tool can show up under more than one label. Pen-register and trap-and-trace style claims, commonly discussed under section 638.51, focus on alleged recording of routing, addressing, or signaling information. Wiretap and eavesdropping style claims, commonly discussed under sections 631 and 632, focus on alleged interception of communications content.

Public reporting on SB 690 has centered on private enforcement for certain pen-register website claims. That reporting does not rewrite every wiretap theory. The SB 690 guide holds the timeline. Operators still need a record of what loads before Accept and after Reject.

Two theories, one storefront

An alert often uses one of these labels and assumes you already know which theory is in play. Pixels, click IDs, chat widgets, and session replay can appear under either label. The label is the pleading. The browser record is separate: a cookie, a request, a script, a screenshot of the banner state.

The pre-consent audit checklist is the pass order: a fresh load, storage, Reject All plus one navigation, and an accept baseline.

Pen-register and trap-and-trace theory

In plain English, this style of claim is about capturing addressing, routing, or signaling information: how traffic is directed, which identifiers travel with a request, which hosts it touches. Public chatter describes pixels, analytics IDs, and URL metadata as the things plaintiffs try to call a pen-register-style device. That is a description of the chatter, not a case holding.

The section people name is Penal Code section 638.51. Read it on the Legislature's site. This page does not paste the section or invent a quotation. Sidley, Fenwick, and Taft alerts linked from the SB 690 guide discuss how website claims have been pleaded under that section. Open those alerts for their wording.

Public commentary after SB 690 has focused on private plaintiffs and section 638.51-style website claims. Who may sue, if the bill becomes law, belongs on the SB 690 guide. This page only needs the split: that news slice is about one theory, not the whole Act.

Wiretap and eavesdropping theory

In plain English, this style of claim is about intercepting or recording the content of a communication: what was said, what was typed, what a session-replay or chat tool is alleged to have captured as content. People often name sections 631 and 632. Those are names. The elements live in the code and in counsel's reading.

Session replay, chat transcripts, and form contents are the examples alerts use when they contrast this theory with pen-register talk. The same tool can be discussed under either label, depending on the pleading. The label helps you read the alert. It does not list the scripts your theme loaded.

The SB 690 guide does not say that every CIPA website theory vanished. Public firm alerts described there say private wiretap theories would remain if the bill becomes law. A pen-register bill moving is not a reason to tell a team that wiretap claims ended.

Side-by-side, for operators

Use the table to keep the two conversations apart. It is descriptive. It is not a list of defenses, and it does not state fines, damages, or outcomes.

Pen-register talk versus wiretap talk for website tracking. Plain English only. Not a legal element chart.
AnglePen-register / trap-and-trace (often section 638.51 talk)Wiretap / eavesdropping (often section 631 / 632 talk)
Rough focusAddressing, routing, or signaling-style informationContent of a communication
How it shows up in website-tracking chatterPixels, IDs, and URL or routing metadata alleged as pen-register-likeSession replay, chat, or form contents alleged as interception
SB 690, per the SB 690 guide and public alertsMain news slice for private enforcement of certain website pen-register claimsNot the same story. Do not claim wiretap claims ended
What operators can still measureWhich third parties load, which cookies or storage they set, and when they fireThe same runtime surfaces. A labeled evidence pack stays useful

What SB 690 does and does not settle

SB 690 is one enforcement slice. The timeline and the September 22, 2026 status check live on the SB 690 guide. Confirm the live status page before you describe the bill as law. This page, written September 23, 2026, does not add a signature or a veto.

  • The Legislature passed SB 690 on August 28, 2026. Passage is not enactment.
  • The SB 690 guide records a September 22, 2026 check of the official status page: enrolled, House location Governor, presented to the Governor on September 4, 2026, with no signature and no veto in the history actions that page showed.
  • Public reporting describes a sign or veto window through about September 30, 2026. Open the status page again before you brief a team.
  • Public alerts describe the enrolled limit as private enforcement of certain section 638.51 website and app claims. They do not describe a rewrite of sections 631 and 632.
  • If that private pen-register path narrows, storefront testing remains an operations task. A change in who may file one kind of claim does not turn tags off.

What to still measure

The pre-consent audit checklist has the full pass table. Use a clean profile, the same URL, and a note of region. Label every file by state.

  1. Fresh visit: do not click Accept. Record cookies, storage, third-party ad and analytics requests, and a screenshot of the banner.
  2. Reject All, or the closest control (Decline, Essential only): click it, navigate once, and record the same surfaces. Compare that run with Accept.
  3. Accept All, in a new clean profile: record the same surfaces so you have a baseline for what the tags do after a choice.
  4. Optional California path: if you claim to honor Global Privacy Control, compare GPC off with GPC on. The GPC test guide shows how to confirm Sec-GPC: 1. SB 690 does not perform that comparison.
  5. Strip query values that carry identifiers before you share the pack.

Evidence pack fields

A usable pack names the URL, the timestamp, browser and profile notes, the consent-state label, a cookie table, key request URLs, screenshots, and an optional HAR snippet with secrets removed. A banner photo shows that a control existed. It does not show whether a marketing host still loaded after Reject.

ConsentProbe maps findings to a request, a cookie, or a screenshot after a saved run. A free US-baseline visit stores one non-California technical record so you can learn the report shape. It is not a California legal conclusion and not a CIPA risk score. Paid California scenarios compare GPC off with GPC on. Paid EU scenarios are a different pack. Read the free versus paid guide before you quote a region.

FAQ

What is a CIPA pen-register theory for websites, in one sentence?

A claim style that treats certain website tracking as capturing dialing, routing, addressing, or signaling-type information under CIPA pen-register and trap-and-trace provisions. The elements belong to counsel and to the code.

How is that different from a wiretap theory?

Wiretap and eavesdropping-style claims focus on alleged interception or recording of communications content. People name different sections, and the elements differ.

Did SB 690 end all CIPA website lawsuits?

No. Public reporting centers on narrowing private enforcement for certain pen-register website claims. Read the SB 690 guide and talk to counsel. Do not treat a pen-register bill as the end of wiretap theories.

If the litigation theory changes, should I still audit cookies?

Yes. Operations still need evidence of pre-consent and post-reject behavior. The pre-consent audit checklist is the pass order.

Does ConsentProbe decide if I am liable under CIPA?

No. ConsentProbe records technical browser evidence. Legal conclusions need your counsel. A report is not a CIPA opinion.

What should I send counsel after an alert?

State-labeled cookie tables, request lists, screenshots, and timestamps. A banner photo without those layers leaves the handoff thin.

Limits of this page

This article explains, at a high level, how public commentary and lawsuit pleadings have framed website-tracking claims under California's Invasion of Privacy Act, especially pen-register and trap-and-trace theories versus wiretap and eavesdropping theories. It is not legal advice, not a case prediction, not counsel on any demand letter or complaint, and not a reading of how any court will rule.

A ConsentProbe report is not a CIPA legal opinion. Free US-baseline output is not a California conclusion. Readers with California exposure should talk to their own counsel, and they should re-check the official SB 690 status page before they describe the bill as law.

Related guides

Read the SB 690 guide for the bill timeline, the pre-consent checklist for the pass order, and the reject and pre-Accept guides when you need the browser steps in more detail.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

CIPA 笔录与窃听理论对照 | ConsentProbe