Skip to main content

What Is Trap and Trace Under CIPA? A Website Technical Review Guide

Under California Penal Code Section 638.50, a trap-and-trace device is a device or process that captures incoming electronic or other impulses containing routing, addressing, or signaling information reasonably likely to identify the source of a wire or electronic communication, but not the contents of the communication.

A pen register is defined separately. It records or decodes dialing, routing, addressing, or signaling information transmitted from the instrument or facility from which a wire or electronic communication is sent, again excluding communication contents.

Section 638.51 generally restricts the installation or use of a pen register or trap-and-trace device without a qualifying court order, subject to listed service-provider purposes and user consent. Whether ordinary website technologies such as analytics scripts, pixels, cookies, software development kits, and browser requests fall within these definitions remains disputed and fact-specific.

This guide explains the statutory distinction, why applying it to websites is difficult, what technical website evidence may help counsel investigate, and what an automated or manual website review cannot legally determine.

By Auditzo Updated October 05, 2026

Key point: An IP address, cookie, pixel, browser request, or third-party endpoint does not automatically become a pen register or trap-and-trace device merely because it can be observed in website evidence. Statutory coverage requires legal analysis of the technology, direction of information, data involved, parties, purpose, consent, exceptions, and relevant authority.

October 2026 update — California SB 690: Governor Gavin Newsom approved SB 690 on September 30, 2026. The enacted bill amends Penal Code Section 637.2, the civil-remedies provision, so that an action against a private actor for an alleged Section 638.51 violation arising from conduct on an internet website, online application, or mobile application may be brought under Section 637.2 only by the California Attorney General. The enacted text also contains a retroactivity provision for specified pending claims.

Important: SB 690 does not amend Section 638.51 itself and does not amend Section 631. The change concerns who may bring the specified Section 638.51 website/app action under Section 637.2, not a technical declaration that website tracking is lawful or that browser evidence no longer matters. The law is expected to take effect January 1, 2027 under California's general effective-date rule for regular-session statutes without an urgency clause.

What Is a Trap-and-Trace Device?

California Penal Code Section 638.50(c) defines a trap-and-trace device by reference to the capture of incoming electronic or other impulses that identify the originating number or other routing, addressing, or signaling information reasonably likely to identify the source of a wire or electronic communication.

The definition expressly excludes the contents of the communication.

In its traditional telephone context, the concept generally involved identifying the source of communications arriving at a particular line. Applying that definition to websites is harder because a browser session can involve many interconnected systems:

  • The visitor’s browser
  • The website’s origin server
  • A content-delivery network
  • A consent-management platform
  • A tag-management system
  • Analytics or advertising vendors
  • Embedded video, chat, map, payment, or social-media services
  • Additional redirects and server-to-server systems

The legal question is not simply whether information moved across the internet. Counsel may need to determine which device or process allegedly performed the capture, what information it captured, in which direction the information moved relative to the relevant instrument or facility, and whether the information was content or non-content information.

Review the official definition in California Penal Code Section 638.50.

What Is a Pen Register?

California Penal Code Section 638.50(b) defines a pen register as a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted.

Like the trap-and-trace definition, it excludes the contents of a communication.

The definition also excludes certain devices or processes used by a provider or customer of a wire or electronic communication service for billing, communications-service records incidental to billing, cost accounting, or similar ordinary-course purposes described in the statute.

Why the word “process” matters

The statutory definition is not limited to a particular physical device. It refers to a “device or process.” Plaintiffs in website cases have relied on that wording when arguing that software-based tracking processes may fall within the provision.

Defendants have raised competing arguments based on:

  • The structure and legislative history of the California provisions
  • The references to telephone lines in related court-order procedures
  • The meaning of electronic communication
  • The difference between website operation and regulated surveillance
  • Statutory exceptions
  • Consent
  • The type and sensitivity of information collected
  • Whether the alleged process captured information beyond what was necessary to communicate with the website

Auditzo does not resolve these statutory-construction questions. It can help document the underlying website behavior for counsel’s analysis.

Pen Register vs Trap and Trace

The direction described in the statute is the central distinction.

Comparison of a pen register and trap-and-trace device under CIPA, showing outgoing information versus incoming source information.
The statutory distinction focuses partly on direction: a pen register concerns information transmitted from the relevant instrument or facility, while trap and trace concerns incoming information identifying a communication source.
Review Area Pen Register Trap-and-Trace Device
Statutory direction Information transmitted from the relevant instrument or facility Incoming impulses identifying the source of a communication
Information described Dialing, routing, addressing, or signaling information Originating number or other routing, addressing, or signaling information reasonably likely to identify the source
Communication contents Excluded from the definition Excluded from the definition
Traditional analogy Information identifying outgoing telephone connections Information identifying the source of incoming telephone connections
Website-review caution An outgoing browser request is not automatically a statutory pen-register event. A cookie, response, IP address, or incoming browser event is not automatically a statutory trap-and-trace event.

Why simple website equivalents are misleading

It is unsafe to claim:

  • Every outbound HTTP request is a pen register
  • Every cookie is a trap-and-trace device
  • Every IP address is incoming routing information
  • Every analytics script performs both functions
  • Every pre-consent third-party request establishes a Section 638.51 violation

Browser communications often include a request and response sequence. A third-party script may also load additional resources, set or read browser storage, generate identifiers, trigger redirects, or send later events.

The legal characterization depends on the particular process being examined and the perspective from which direction is assessed. That characterization should be made by qualified counsel, not inferred automatically from a scanner label.

What Does CIPA Section 638.51 Say?

California Penal Code Section 638.51(a) states that, except as provided in subdivision (b), a person may not install or use a pen register or trap-and-trace device without first obtaining a court order under the related provisions.

Subdivision (b) lists circumstances in which a provider of electronic or wire communication service may use a pen register or trap-and-trace device. These include certain uses to:

  • Operate, maintain, and test a wire or electronic communication service
  • Protect the provider’s rights or property
  • Protect users from abuse or unlawful use of the service
  • Record whether a communication was initiated or completed for specified protection against fraudulent, unlawful, or abusive use
  • Act where the user’s consent has been obtained

The existence of these exceptions does not automatically answer whether a website operator, technology vendor, analytics provider, or other party qualifies for a particular exception.

That analysis may require examination of:

  • The role of each party
  • The service being provided
  • The purpose of the technology
  • The information collected
  • Whether collection was necessary for the asserted purpose
  • Whether consent was obtained
  • What the visitor was told
  • When the relevant process operated

Review the current statutory text in California Penal Code Section 638.51.

Legal boundary: A website audit can document observable behavior relevant to an exception analysis. It cannot determine that an exception legally applies or does not apply.

Why Application to Websites Remains Unsettled

Sections 638.50 and 638.51 use technology-neutral terms such as “device or process,” “electronic communication,” and “routing, addressing, or signaling information.” They also sit within a statutory scheme containing references and procedures historically associated with telephone communications and law-enforcement orders.

That creates several unresolved questions when the alleged technology is a commercial website script rather than a traditional telephone-surveillance device.

Questions courts and counsel may consider

  • Does the statutory definition extend to ordinary internet communications?
  • Is the alleged website technology the relevant device or process?
  • Which party installed or used it?
  • What communication is being examined?
  • Did the process record outgoing information or capture incoming information?
  • Was the information routing, addressing, or signaling information?
  • Did it include communication contents?
  • Was the information required for basic website operation?
  • Did the technology collect additional identifiers, behavioral data, or other values?
  • Did a first party or third party receive the information?
  • Did the user consent?
  • Does a statutory exception apply?
  • Does the claimant have the required standing or legally protected interest?

Different courts have approached these questions differently. A decision permitting a claim to continue at an early procedural stage does not necessarily mean a final violation has been established. A dismissal in another case does not necessarily create a universal exemption for all website technologies.

The correct takeaway is not that website pixels are always covered or never covered. The area remains dependent on the particular allegations, technology, information, parties, jurisdiction, and procedural posture.

Current Legal Status and SB 690 Update

California's treatment of website-based pen-register and trap-and-trace claims changed materially in September 2026.

SB 690 was signed on September 30, 2026

Governor Gavin Newsom approved Senate Bill 690 on September 30, 2026. The chaptered bill amends Penal Code Section 637.2, California's civil-remedies provision for CIPA claims.

For an action against a private actor alleging a violation of Section 638.51 arising from conduct on an internet website, online application, or mobile application, the amended Section 637.2 provides that the action may be brought under that section only by the California Attorney General.

The enacted text also states that the amendment applies retroactively to specified pending claims in actions commenced within two years before the operative date of the legislation.

What SB 690 does not change

  • It does not amend the text of Penal Code Section 638.51.
  • It does not amend the pen-register and trap-and-trace definitions in Section 638.50.
  • It does not amend CIPA Section 631.
  • It does not convert every website tracker, pixel, cookie, or browser request into lawful conduct.
  • It does not make technical evidence irrelevant to counsel, remediation teams, regulators, or other privacy theories.

Because the enacted bill contains no urgency clause or later operative date in its text, it is expected to take effect on January 1, 2027 under California's general rule for statutes enacted during a regular session. Counsel should confirm the operative date and the effect on any particular pending or future matter.

Practical takeaway: SB 690 changes the civil-enforcement path for the specified Section 638.51 website and app claims against private actors. It does not replace the need to understand what a website actually transmitted, stored, loaded, or changed across defined visitor and consent states.

For a focused explanation of the enacted legislation, see California SB 690 and CIPA Website Tracking Claims.

Website Technologies That May Require Review

A CIPA-oriented website review may examine technologies that create, transmit, receive, store, or disclose information during a visitor session.

Examples of website technologies that may require CIPA-oriented technical review, including analytics, advertising pixels, chat tools, video embeds, consent platforms, cookies, and browser storage.
A CIPA-oriented technical review may examine analytics, pixels, embedded services, consent platforms, cookies, and storage, but the presence of a technology does not establish statutory coverage or a violation.

Analytics technologies

  • Page-view analytics
  • Event tracking
  • Conversion measurement
  • Attribution tools
  • Session analytics
  • Performance monitoring

Advertising and audience technologies

  • Advertising pixels
  • Retargeting tags
  • Audience-matching tools
  • Advertising identifiers
  • Demand-side or supply-side integrations
  • Data-management or identity-resolution services

Embedded services

  • Chat systems
  • Video players
  • Maps
  • Social-media widgets
  • Payment services
  • Appointment or scheduling tools
  • Form and lead-generation tools

Browser and infrastructure technologies

  • Cookies
  • Local storage
  • Session storage
  • Tag managers
  • Consent-management platforms
  • Content-delivery networks
  • Fraud-prevention tools
  • Security services
  • Server-side tagging

The presence of one of these technologies does not establish that it is a pen register, trap-and-trace device, wiretap, unlawful tracker, data broker, or legal violation.

The technical review should document what the technology was observed doing within the defined session.

Why Data-Flow Direction Matters

A website visit commonly involves several directional exchanges.

Three-stage website data-flow diagram showing a browser request, server response, and follow-up script activity involving browser storage and later events.
A single website journey may include an outgoing browser request, an incoming server response, and later script activity, so direction and session context should be reviewed together.

Browser request

The browser may send information such as:

  • Destination hostname
  • URL path
  • Query parameters
  • Referrer information
  • Browser or device information
  • Cookie values
  • Language settings
  • Event names
  • Client-generated identifiers

Server or vendor response

The responding system may return:

  • HTML
  • JavaScript
  • Images or other resources
  • Redirect instructions
  • Set-Cookie headers
  • Configuration values
  • Tracking or session identifiers

Later browser activity

A loaded script may subsequently:

  • Read browser storage
  • Create a new identifier
  • Collect a page or event value
  • Send another request
  • Load an additional vendor
  • Communicate with a first-party or third-party endpoint

Because one page journey may involve all three stages, broad labels such as “outgoing tracker” or “incoming cookie” may be insufficient.

A useful technical record identifies:

  • The initiating event
  • The source and destination
  • The request and response sequence
  • The observed fields
  • The related browser-storage change
  • The consent state
  • The timing
  • The responsible or associated technology where identifiable

Qualified counsel can then evaluate how, if at all, the observed sequence relates to the statutory direction requirements.

Content vs Routing, Addressing, and Signaling Information

Both statutory definitions exclude the contents of a communication. That makes the distinction between content and non-content information potentially important.

In a browser environment, a technical capture may contain:

  • IP addresses
  • Hostnames
  • Request URLs
  • URL paths
  • Query strings
  • Header values
  • Referrer values
  • Cookie names and values
  • Device or browser characteristics
  • Account or session identifiers
  • Page titles
  • Search terms
  • Form-related values
  • Event labels

It is not safe for a technical report to classify every one of these fields universally as either communication content or non-content metadata.

The classification may depend on:

  • The communication being defined
  • The function of the field
  • The surrounding request
  • The information encoded in the value
  • The factual allegations
  • The applicable legal authority

For example, a URL may contain basic routing information, but it may also reveal a page path, search term, product, account action, or other substantive context.

Auditzo can document the observable field and where it appeared. Counsel should determine its legal classification and significance.

Technical Evidence That May Support Review

A technical evidence package may help counsel understand what occurred in a defined website session.

Diagram of technical evidence that may support a CIPA-oriented website review, including an environment record, screenshots, HAR network evidence, cookies, browser storage, and an evidence index.
A scoped technical review may combine environment records, screenshots, browser-network evidence, cookie and storage observations, and an evidence index to explain observable website behavior.

Environment record

This may document:

  • Date and time
  • Time zone
  • Browser and version
  • Operating system
  • Device or viewport
  • Visitor region
  • Session preparation
  • Reviewed pages
  • Actions performed

Screenshots

Screenshots may show:

  • The reviewed page
  • The consent interface
  • The visible consent state
  • A form, chat, video, or embedded service
  • The timing or sequence of reviewer actions

A screenshot provides visual context. It does not independently prove that a particular network transmission occurred.

HAR or browser-network evidence

A browser-network record may help document requests and responses observed during the defined session, including:

  • Hostnames
  • Request URLs
  • Methods
  • Timing
  • Headers
  • Redirects
  • Selected request or response fields

A HAR file should not be described as a complete capture of every network event, server-side process, decrypted payload, or downstream use of information.

Cookie and storage records

These may document:

  • Cookie names
  • Cookie domains
  • Expiration and attributes
  • Values or redacted value patterns
  • Local-storage keys
  • Session-storage keys
  • Differences between defined consent states

DNS or hostname information

DNS or hostname records may help identify domains contacted or resolved during a session. They do not independently establish:

  • What complete information was transmitted
  • Who ultimately controlled the destination
  • Whether the destination is legally a data broker
  • Whether a cross-border transfer occurred
  • Whether Section 638.51 applies

Finding-to-artifact traceability

Each material finding should connect to the relevant page, session, timestamp, screenshot, request, cookie or storage record, and stated limitation.

For deeper evidence handling guidance, read:

Questions for a Website Technical Review

A useful CIPA-oriented technical review starts with questions, not predetermined legal conclusions.

Technology identification

  • Which script, SDK, tag, pixel, cookie, or process is under review?
  • Was it loaded directly by the website or through another service?
  • Which first-party and third-party domains were involved?
  • Can ownership or operational control be established from reliable sources?

Information flow

  • What caused the request or storage event?
  • What system initiated it?
  • What was the source?
  • What was the destination?
  • Was there a response, redirect, or follow-up request?
  • Which fields were observable?

Session context

  • Which page was reviewed?
  • What actions were performed?
  • What browser and region were used?
  • Was the visitor logged in?
  • Was the browser state clean or returning?
  • What consent state applied?
  • When did the event occur?

Purpose and control

  • Was the technology necessary for the requested website function?
  • Was it used for analytics, advertising, fraud prevention, security, personalization, or another purpose?
  • Did the website operator select or configure the technology?
  • Did a third party independently determine additional processing?

Limitations

  • Were payload fields encrypted or unavailable?
  • Were server-side events outside the capture layer?
  • Was only one browser or region tested?
  • Could campaigns, personalization, or A/B tests affect the result?
  • Does the evidence show observable transmission but not later use?

The technical record should answer what can be answered and clearly label what remains unknown.

Consent and Statutory Exceptions

Section 638.51(b)(5) refers to use where the consent of the user of the service has been obtained. Consent can therefore be relevant to counsel’s analysis.

A website technical review may document:

  • Whether a consent interface was present
  • Whether it appeared before or after selected requests
  • The visible choices offered
  • The default settings
  • Initial or no-interaction behavior
  • Reject-state behavior
  • Accept-state behavior
  • Whether preferences persisted
  • Whether technologies differed between sessions

That technical record does not independently determine:

  • Whether consent was legally required
  • Whether the relevant user consented
  • Whether notice was sufficiently clear
  • Whether consent was informed, specific, voluntary, or otherwise valid
  • Whether consent covered the particular process
  • Whether another exception applies

Privacy policy is not the same as tested consent behavior

A privacy policy may describe intended practices. It does not by itself demonstrate what the website did during a particular browser session or whether the user made an affirmative choice.

Similarly, the presence of a consent banner does not prove that selected technologies were blocked, allowed, categorized, or reconfigured correctly.

Where consent-state evidence is required, a scoped Manual Evidence Audit is more appropriate than an initial automated scan.

Section 638.51 vs CIPA Section 631

Section 638.51 and Section 631 address different statutory concepts.

Section 638.51 concerns the installation or use of a pen register or trap-and-trace device as defined in Section 638.50, subject to statutory provisions and exceptions.

Section 631 contains separate language concerning conduct such as tapping, making unauthorized connections, reading, attempting to read, learning the contents or meaning of communications under specified circumstances, and aiding or conspiring in such conduct.

A technical artifact may be relevant to more than one legal theory, but the elements should not be combined.

For example:

  • A request being visible does not automatically establish interception.
  • A non-content identifier does not automatically establish communication content.
  • A third-party destination does not automatically establish unauthorized participation.
  • A pre-consent event does not automatically satisfy every CIPA theory.

Auditzo may conduct a CIPA-oriented technical review covering observable requests, consent states, cookies, storage, and third-party technologies. It does not determine which CIPA section applies or whether its elements are satisfied.

For more information, review Auditzo’s CIPA Section 638.51 website technical review.

Automated Audit vs Manual Evidence Audit

Review Area Automated Website Audit Scoped Manual Evidence Audit
Purpose Initial technical visibility and triage Human-reviewed investigation of defined technical questions
Initial page-load observation Yes, within the configured automated window Yes, across agreed pages and sessions
Consent-button interaction No Accept or Reject interaction May include Initial, Reject, Accept, and custom preference states where scoped
Human verification No Yes
Representative journeys Limited to the automated configuration Defined according to the agreed scope
Request-level review Automated observations and findings Human-reviewed request analysis where included
Raw evidence files No downloadable raw-evidence package May include agreed screenshots, HAR, network, cookie, storage, and supporting files
Statutory classification Not provided Not provided
Legal conclusion No No

An automated audit can identify technologies or activity requiring further investigation. It should not label a website technology as a legally established pen register, trap-and-trace device, or CIPA violation.

Review the website privacy audit plan comparison before selecting the appropriate review path.

What Auditzo Can and Cannot Determine

Auditzo can document

  • Defined pages and website journeys
  • Browser and environment conditions
  • Initial and agreed consent states
  • Observable first-party and third-party requests
  • Request timing
  • Hostnames and selected request fields
  • Cookies and browser-storage behavior
  • Consent-interface behavior
  • Technology and vendor observations
  • Finding-to-artifact references
  • Technical limitations
  • Potential areas for remediation or further review

Auditzo does not determine

  • Whether a process is legally a pen register
  • Whether a process is legally a trap-and-trace device
  • Whether communication content was intercepted
  • Whether a user legally consented
  • Whether a statutory exception applies
  • Whether Section 631, 638.51, or another provision applies
  • Whether an IP address or identifier creates a legally protected interest
  • Whether a private right or remedy is available
  • Whether evidence is admissible
  • Whether a violation occurred
  • Whether a party is liable
  • Whether a claim or defense will succeed

Auditzo’s role: Auditzo provides technical observations and documented evidence for legal, privacy, and technical review. It does not provide legal advice, certify CIPA compliance, determine statutory violations, or predict litigation outcomes.

Review the complete Auditzo audit scope and limitations.

CIPA Section 638.51 Technical Review Checklist

Scope

  • Are the reviewed domains and pages identified?
  • Are the relevant technologies named?
  • Are the visitor journeys and actions defined?
  • Are the browser, region, and session conditions recorded?
  • Are material exclusions disclosed?

Technology and parties

  • Which script, SDK, tag, pixel, cookie, or process is under review?
  • Who appears to provide or control it?
  • Was it loaded directly or through another tag?
  • Which first-party and third-party endpoints were involved?

Data flow

  • What initiated the communication?
  • What was the source and destination?
  • Which request and response fields were observable?
  • Were redirects or follow-up requests present?
  • Were cookies or storage values read or written?

Direction and classification

  • What is the relevant instrument or facility?
  • What information was transmitted from it?
  • What information arrived at it?
  • Was the information routing, addressing, signaling, content, or another type?
  • Is the report separating technical description from legal classification?

Consent and timing

  • Was a consent interface visible?
  • When did it appear?
  • What happened before any interaction?
  • What changed after Reject?
  • What changed after Accept?
  • Did stored preferences affect the session?

Purpose and exceptions

  • What stated or observable function did the technology perform?
  • Was it related to operation, security, fraud prevention, analytics, advertising, or another purpose?
  • Was more information collected than appeared necessary for that function?
  • Has counsel assessed the statutory exceptions?

Evidence quality

  • Are screenshots linked to the relevant session?
  • Are network entries connected to the page and consent state?
  • Are cookies and storage records identified?
  • Does every material finding reference supporting artifacts?
  • Are limitations clearly stated?

Legal boundaries

  • Does the report avoid declaring a CIPA violation?
  • Does it avoid calling every tracker a pen register or trap-and-trace device?
  • Does it distinguish Sections 631 and 638.51?
  • Does it reserve statutory interpretation for counsel?
  • Does it avoid promising admissibility or litigation outcomes?

This checklist supports technical investigation. It is not a legal-elements checklist, compliance certification, or substitute for advice from qualified counsel.

CIPA Section 638.51 website technical review checklist covering scope, technology, data flow, consent, evidence quality, and legal boundaries.
A CIPA-oriented review should examine scope, technology, data flow, consent context, evidence quality, and legal boundaries without replacing matter-specific legal analysis.

Frequently Asked Questions

What is trap and trace?

Under California Penal Code Section 638.50, a trap-and-trace device captures incoming electronic or other impulses containing information reasonably likely to identify the source of a wire or electronic communication, while excluding communication contents.

What is a trap-and-trace device under CIPA?

It is the device-or-process concept defined in Section 638.50(c). Whether a particular website script, pixel, cookie, analytics tool, or SDK falls within that definition is a disputed legal question requiring matter-specific analysis.

What is CIPA Section 638.51?

Section 638.51 generally restricts installing or using a pen register or trap-and-trace device without the specified court order, subject to the service-provider purposes and user-consent provisions listed in subdivision (b).

What is the difference between a pen register and trap and trace?

A pen register concerns dialing, routing, addressing, or signaling information transmitted from the relevant instrument or facility. A trap-and-trace device concerns incoming impulses containing information reasonably likely to identify the source of a communication. Both definitions exclude communication contents.

Can a website pixel be a pen register?

Some claimants have argued that website pixels or similar software processes satisfy the definition, while defendants and some courts have taken narrower positions. The issue remains disputed and depends on the technology, information, parties, statutory interpretation, exceptions, consent, and relevant authority.

Does collecting an IP address automatically violate CIPA Section 638.51?

No. The observation that an IP address was transmitted or received does not independently establish that a statutory pen register or trap-and-trace device was installed or used, that no exception applied, or that a violation occurred.

Are cookies trap-and-trace devices?

Not automatically. A cookie is a browser-storage mechanism. A technical review can document when it was set, read, changed, or transmitted. Counsel must determine whether the associated process has any legal significance under Section 638.51.

Does tracking before consent prove a CIPA violation?

No. Pre-interaction activity may be relevant to consent and technical behavior, but it does not independently establish statutory coverage, invalid consent, absence of an exception, a violation, or liability.

Is a privacy policy enough to establish consent?

A privacy policy can provide notice about described practices, but a technical review cannot determine from the policy alone whether the relevant user legally consented to a particular process. Counsel should evaluate the notice, interface, timing, user actions, and applicable law.

What website evidence may help a CIPA review?

Depending on scope, useful technical material may include an environment record, screenshots, browser-network evidence, cookies, storage comparisons, request extracts, consent-state comparisons, evidence indexes, and documented limitations.

Is CIPA Section 638.51 the same as Section 631?

No. They contain different language and address different legal concepts. Technical evidence may be relevant to both, but their elements should not be combined.

Did SB 690 end CIPA website tracking claims?

No broad conclusion like that is appropriate. SB 690 amends Penal Code Section 637.2 so that the specified action against a private actor for an alleged Section 638.51 violation arising from website, online-application, or mobile-application conduct may be brought under that section only by the California Attorney General. It does not amend Section 638.51 itself, and it does not amend Section 631. Matter-specific legal effect should be evaluated by qualified counsel.

Can Auditzo confirm a pen-register or trap-and-trace violation?

No. Auditzo documents observable website behavior and technical evidence. Qualified counsel determines statutory classification, legal coverage, consent, exceptions, violations, liability, and evidentiary use.

Can an automated scan test Accept and Reject behavior?

No. Auditzo’s automated audits provide initial technical visibility without human verification or Accept and Reject interaction. A scoped Manual Evidence Audit may include separate consent-state testing where agreed.

Request a Scoped CIPA-Oriented Technical Review

Law firms, privacy teams, website operators, and technical teams can use Auditzo to investigate observable website behavior relevant to CIPA-oriented review.

A scoped Manual Evidence Audit may include:

  • Defined pages and visitor journeys
  • Browser and region records
  • Initial, Reject, Accept, or custom preference states
  • Screenshots
  • Browser-network review
  • Cookie and storage comparisons
  • Third-party endpoint observations
  • Finding-to-artifact traceability
  • Technical limitations
  • Remediation-oriented observations

Discuss a scoped Manual Evidence Audit or review Auditzo’s website privacy evidence support for law firms.

For initial visibility into cookies, technologies, storage, and third-party requests, teams can run an automated website audit.

Scope reminder: Auditzo provides technical observations for legal, privacy, and technical review. It does not provide legal advice, classify a technology conclusively as a pen register or trap-and-trace device, certify CIPA compliance, determine a violation, guarantee admissibility, or predict legal outcomes.

Official Sources and Further Reading

This article provides general technical information and summarizes the statutory text and current review context as of October 5, 2026. It is not legal advice and should not replace current statutory research, case-law analysis, procedural advice, or matter-specific guidance from qualified counsel.

Share: