文章
What is the difference between CIPA pen-register and wiretap theories for website tracking?
Plain-English map of CIPA pen-register and wiretap website theories, what SB 690 covers, and which storefront checks to keep. Not legal advice.
In brief
In website-tracking lawsuits under California's Invasion of Privacy Act, plaintiffs often plead two theories. Pen-register and trap-and-trace claims, often discussed under section 638.51, focus on addressing, routing, or signaling information. Wiretap and eavesdropping claims, often discussed under sections 631 and 632, focus on communications content. Public reporting on SB 690 centers on private enforcement of certain pen-register website claims. Operators still need evidence of what loads before consent and after Reject. This page is a high-level map, not legal advice.
Not legal advice
This page maps two CIPA website-tracking theories in plain English. It is not legal advice, not a case prediction, not counsel on a demand letter or complaint, and not a reading of how any court will rule.
Section numbers below are names people use in alerts, not pasted statutory text. Open the code, the enrolled bill, or a firm alert you can cite. Readers with California exposure should talk to their own counsel. A ConsentProbe report is not a CIPA legal opinion.
Short answer
The same pixel or session tool can show up under more than one label. Pen-register and trap-and-trace style claims, commonly discussed under section 638.51, focus on alleged recording of routing, addressing, or signaling information. Wiretap and eavesdropping style claims, commonly discussed under sections 631 and 632, focus on alleged interception of communications content.
Public reporting on SB 690 has centered on private enforcement for certain pen-register website claims. That reporting does not rewrite every wiretap theory. The SB 690 guide holds the timeline. Operators still need a record of what loads before Accept and after Reject.
Two theories, one storefront
An alert often uses one of these labels and assumes you already know which theory is in play. Pixels, click IDs, chat widgets, and session replay can appear under either label. The label is the pleading. The browser record is separate: a cookie, a request, a script, a screenshot of the banner state.
The pre-consent audit checklist is the pass order: a fresh load, storage, Reject All plus one navigation, and an accept baseline.
Pen-register and trap-and-trace theory
In plain English, this style of claim is about capturing addressing, routing, or signaling information: how traffic is directed, which identifiers travel with a request, which hosts it touches. Public chatter describes pixels, analytics IDs, and URL metadata as the things plaintiffs try to call a pen-register-style device. That is a description of the chatter, not a case holding.
The section people name is Penal Code section 638.51. Read it on the Legislature's site. This page does not paste the section or invent a quotation. Sidley, Fenwick, and Taft alerts linked from the SB 690 guide discuss how website claims have been pleaded under that section. Open those alerts for their wording.
Public commentary after SB 690 has focused on private plaintiffs and section 638.51-style website claims. Who may sue, if the bill becomes law, belongs on the SB 690 guide. This page only needs the split: that news slice is about one theory, not the whole Act.
Wiretap and eavesdropping theory
In plain English, this style of claim is about intercepting or recording the content of a communication: what was said, what was typed, what a session-replay or chat tool is alleged to have captured as content. People often name sections 631 and 632. Those are names. The elements live in the code and in counsel's reading.
Session replay, chat transcripts, and form contents are the examples alerts use when they contrast this theory with pen-register talk. The same tool can be discussed under either label, depending on the pleading. The label helps you read the alert. It does not list the scripts your theme loaded.
The SB 690 guide does not say that every CIPA website theory vanished. Public firm alerts described there say private wiretap theories would remain if the bill becomes law. A pen-register bill moving is not a reason to tell a team that wiretap claims ended.
Side-by-side, for operators
Use the table to keep the two conversations apart. It is descriptive. It is not a list of defenses, and it does not state fines, damages, or outcomes.
| Angle | Pen-register / trap-and-trace (often section 638.51 talk) | Wiretap / eavesdropping (often section 631 / 632 talk) |
|---|---|---|
| Rough focus | Addressing, routing, or signaling-style information | Content of a communication |
| How it shows up in website-tracking chatter | Pixels, IDs, and URL or routing metadata alleged as pen-register-like | Session replay, chat, or form contents alleged as interception |
| SB 690, per the SB 690 guide and public alerts | Main news slice for private enforcement of certain website pen-register claims | Not the same story. Do not claim wiretap claims ended |
| What operators can still measure | Which third parties load, which cookies or storage they set, and when they fire | The same runtime surfaces. A labeled evidence pack stays useful |
What SB 690 does and does not settle
SB 690 is one enforcement slice. The timeline and the September 22, 2026 status check live on the SB 690 guide. Confirm the live status page before you describe the bill as law. This page, written September 23, 2026, does not add a signature or a veto.
- The Legislature passed SB 690 on August 28, 2026. Passage is not enactment.
- The SB 690 guide records a September 22, 2026 check of the official status page: enrolled, House location Governor, presented to the Governor on September 4, 2026, with no signature and no veto in the history actions that page showed.
- Public reporting describes a sign or veto window through about September 30, 2026. Open the status page again before you brief a team.
- Public alerts describe the enrolled limit as private enforcement of certain section 638.51 website and app claims. They do not describe a rewrite of sections 631 and 632.
- If that private pen-register path narrows, storefront testing remains an operations task. A change in who may file one kind of claim does not turn tags off.
What to still measure
The pre-consent audit checklist has the full pass table. Use a clean profile, the same URL, and a note of region. Label every file by state.
- Fresh visit: do not click Accept. Record cookies, storage, third-party ad and analytics requests, and a screenshot of the banner.
- Reject All, or the closest control (Decline, Essential only): click it, navigate once, and record the same surfaces. Compare that run with Accept.
- Accept All, in a new clean profile: record the same surfaces so you have a baseline for what the tags do after a choice.
- Optional California path: if you claim to honor Global Privacy Control, compare GPC off with GPC on. The GPC test guide shows how to confirm
Sec-GPC: 1. SB 690 does not perform that comparison. - Strip query values that carry identifiers before you share the pack.
Evidence pack fields
A usable pack names the URL, the timestamp, browser and profile notes, the consent-state label, a cookie table, key request URLs, screenshots, and an optional HAR snippet with secrets removed. A banner photo shows that a control existed. It does not show whether a marketing host still loaded after Reject.
ConsentProbe maps findings to a request, a cookie, or a screenshot after a saved run. A free US-baseline visit stores one non-California technical record so you can learn the report shape. It is not a California legal conclusion and not a CIPA risk score. Paid California scenarios compare GPC off with GPC on. Paid EU scenarios are a different pack. Read the free versus paid guide before you quote a region.
FAQ
What is a CIPA pen-register theory for websites, in one sentence?
A claim style that treats certain website tracking as capturing dialing, routing, addressing, or signaling-type information under CIPA pen-register and trap-and-trace provisions. The elements belong to counsel and to the code.
How is that different from a wiretap theory?
Wiretap and eavesdropping-style claims focus on alleged interception or recording of communications content. People name different sections, and the elements differ.
Did SB 690 end all CIPA website lawsuits?
No. Public reporting centers on narrowing private enforcement for certain pen-register website claims. Read the SB 690 guide and talk to counsel. Do not treat a pen-register bill as the end of wiretap theories.
If the litigation theory changes, should I still audit cookies?
Yes. Operations still need evidence of pre-consent and post-reject behavior. The pre-consent audit checklist is the pass order.
Does ConsentProbe decide if I am liable under CIPA?
No. ConsentProbe records technical browser evidence. Legal conclusions need your counsel. A report is not a CIPA opinion.
What should I send counsel after an alert?
State-labeled cookie tables, request lists, screenshots, and timestamps. A banner photo without those layers leaves the handoff thin.
Limits of this page
This article explains, at a high level, how public commentary and lawsuit pleadings have framed website-tracking claims under California's Invasion of Privacy Act, especially pen-register and trap-and-trace theories versus wiretap and eavesdropping theories. It is not legal advice, not a case prediction, not counsel on any demand letter or complaint, and not a reading of how any court will rule.
A ConsentProbe report is not a CIPA legal opinion. Free US-baseline output is not a California conclusion. Readers with California exposure should talk to their own counsel, and they should re-check the official SB 690 status page before they describe the bill as law.
Related guides
Read the SB 690 guide for the bill timeline, the pre-consent checklist for the pass order, and the reject and pre-Accept guides when you need the browser steps in more detail.
- What does California SB 690 change for website tracking lawsuits?
- Pre-consent audit checklist: what to verify before Accept
- Pre-Consent Cookie Audit: A Storefront Checklist
- Reject All Still Tracking: What to Check After You Say No
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- What is Global Privacy Control, and how do you test it on a storefront?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
- California Legislative Information — Penal Code section 638.51
- California Legislative Information — Penal Code section 631
- California Legislative Information — SB 690 status
- California Legislative Information — SB 690 enrolled text
- Sidley Austin — SB 690 clears the Legislature, September 2026
- ConsentProbe methodology
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。