Insight

What is a Pen Register? Definition, Law, and Website Tracking Risk (2026)

Insight Published 15 min read
"What Is Pen Register" text alongside a grayscale photo of a person writing in a notebook at a desk with a judge's gavel and scales of justice, introducing the topic of pen registers.

A technology invented to record telegraph pulses is now the legal theory behind thousands-of-dollars-per-violation lawsuits against ordinary websites. 

Federal and California laws both restrict the use of pen registers, and there have now been thousands of pen register and trap-and-trace claims. The technologies involved are common in most marketing setups, including analytics tags, advertising pixels, session replay tools, and chat widgets.

What usually follows is a demand letter and a question harder than the legal one: Is the site actually doing what the letter claims, and can anyone prove it?

Key takeaways

  • A pen register records dialing, routing, addressing, and signaling (DRAS) metadata. It never captures the content of communications.
  • Trap and trace works the other way around: it captures incoming data to identify the source.
  • No warrant or probable cause is required. A relevance certification is enough, orders are sealed, and targets are never notified.
  • California’s CIPA § 638.51 applies the pen register ban to private parties. That’s the basis for lawsuits over ordinary website trackers.
  • Damages run $5,000 per violation under § 637.2, counted per visitor.
  • Consent timing decides most cases. A pixel that fires before an affirmative opt-in sits inside the plaintiffs’ theory; one that fires after sits outside it.
  • Audit what data leaves your site, not just which tags load. Request-level evidence is what answers or rebuts a demand letter.

Every modern fight over the term starts with the statute’s exact words. Under 18 U.S.C. § 3127(3), a pen register is:

“a device or process which records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, provided, however, that such information shall not include the contents of any communication…”

Four elements do the work. 

  1. “Device or process” means that software can qualify. Courts often focus on the word “process” when applying this term to website trackers.
  2. “Records or decodes” covers passive capture. 
  3. “Dialing, routing, addressing, or signaling information,” often called DRAS, is the addressing layer: where a communication is sent, where it comes from, and the signals that set it up.
  4. “Not the contents” sets a clear boundary. If the substance of the communication is captured, it becomes a wiretap issue. There is an exception for billing and cost-accounting devices used in regular business, and California law is similar.

Why “pen”? A 186-year-old name

The name survives from the hardware era. Samuel F. B. Morse’s 1840 telegraph patent (U.S. Patent 1,647, June 20, 1840) described a register marking signals onto paper tape with “a fountain pen, pencil or other marking instrument”; where the record was made in ink, the device became a “pen register.”

Such registers stayed in telephone-company use into the 1960s, earning the plainer synonym “dialed number recorder” (DNR). The label changed; the function never did, which is why a term born on telegraph tape can be aimed, two centuries later, at a tracking pixel.


What information do pen registers and trap-and-trace devices collect

Both federal and California laws define pen registers by the types of data they collect, not by specific technologies. This makes the rules easy to apply to new tools.

ContextCapturedNot captured
TelephoneNumbers dialed and received; time of call; duration; whether it was answeredThe conversation itself
InternetIP addresses; port and protocol; routing and addressing metadata; referrer strings; email header informationMessage bodies; page content; email subject lines
MobileCell-site location information; device identifiers; timing dataCall or message content
Web tracking (contested)Cookie IDs; device and browser fingerprints; advertising identifiers; IP addressesWhether some of this is “content” rather than addressing data is actively litigated

Metadata isn’t the consolation prize it sounds like. A pattern of contacts maps a network in a way one intercepted conversation can’t. As a Texas prosecutors’ guide puts it, once a suspect’s phone is identified, a pen register “can provide the identities of potential co-conspirators.” Who contacted whom, how often, in what order. That’s the value, not a fallback from something better.

The same property is what makes visitor data worth collecting on a website. The value isn’t in reading what someone typed. It’s in knowing which addresses they contacted, in what sequence, tied to something that identifies them next time.

The line is blurrier than the statute makes it sound. Several categories sit awkwardly across it:

  • Post-cut-through dialed digits. The numbers you press after a call connects. Structurally, they’re dialed digits. Functionally, they may be a banking PIN or a prescription number, which is to say content.
  • URLs captured through traffic analysis. A web address is an address, but example.com/search?q= followed by a query term carries the substance of what someone asked.
  • Real-time cell location, which pen/trap capability can resolve to within a few meters. Routing data that describes where a person physically is.

This makes website cases difficult. The original rules were made for technology where the envelope and the letter were separate. On the modern web, that separation often does not exist.


How a pen register works

The point where data is captured has changed three times. Each change broadened the definition, even though the law was not rewritten.

Three-panel infographic showing the evolution of pen register surveillance: from a physical device on a phone line, to a carrier network setting, to browser-based tracking where search terms and addressing information are combined into a single data stream.

Version one was mechanical. A physical instrument wired to a specific telephone line, marking dial pulses onto paper tape as they passed. Tone dialing eventually made the mechanism obsolete, and the term came to cover anything that could record the digits.

Version two lives at the carrier. Modern pen/trap capability is not a box on your line but a configuration change at a service provider. This is why § 3124 obliges providers to assist in executing an order. Collection happens inside the network rather than on the target’s device and runs forward from installation instead of reaching back into stored records.

The target isn’t told. Orders are entered ex parte and sealed, and § 3123(d) directs the assisting provider not to disclose the existence of the device or of the investigation to the subscriber or to anyone else. Nothing physical to install, and nothing to find. Invisibility to the person being observed isn’t a side effect of the design. It is the design.

Moving the capture point to the carrier had a second effect nobody legislated. The carrier keeps the records.

A pen register runs forward. The database it runs against doesn’t. In September 2013, the New York Times revealed Hemisphere, an arrangement giving the DEA and other federal and local agencies access to AT&T call detail records reaching back to 1987, with roughly four billion added daily. That data is the same category a pen register captures: numbers dialed and received, time, date, duration, sometimes location. Access ran through administrative subpoenas, which law enforcement issues itself without court oversight, rather than through § 3123 orders.

The point isn’t drug enforcement. It’s structural. Once data sits with an intermediary, what governs reaching it is that intermediary’s arrangements, not the rule written for the original capture.

Version three runs in a browser. Which is where the argument now sits.

The mechanical detail that matters most is in § 3121(c). A law enforcement agency using a pen register:

Notice the law does not separate the envelope from the contents. Instead, it requires the technology collecting the data to make that distinction. On a phone line, this is simple because dialed numbers and conversations are separate signals.

A script running in a browser cannot separate these signals. If a tag captures a full URL, it also captures anything included in that URL, such as a search term. This is not an intentional loophole but simply what happens when rules made for phone lines are used on the web.


Pen register vs. trap and trace vs. wiretap (vs. subpoena vs. warrant)

Direction and content separate these tools. Pen registers and trap-and-trace devices look forward and stop at metadata. Subpoenas look backward at existing records, search warrants reach existing content, and wiretaps look forward and capture content.

ToolLegal standardData capturedContents?Prospective or retrospectiveDurationNotice to target
Pen registerCourt order on a certification of relevance to an ongoing criminal investigation; court “shall” issue (§§ 3122(b)(2), 3123(a))Outgoing DRAS metadataNoProspective – records from installation forwardUp to 60 days, renewable in 60-day extensions (§ 3123(c))None; order sealed (§ 3123(d))
Trap and traceSame as pen register (one application, one order)Incoming DRAS metadata identifying the sourceNoProspectiveUp to 60 days, renewable (§ 3123(c))None; sealed (§ 3123(d))
Wiretap (Title III)Probable cause plus necessity – other procedures tried and failed or unlikely to work (§ 2518)Contents of communications (plus metadata)YesProspectiveUp to 30 days per order, with minimization (§ 2518(5))Inventory notice after surveillance, generally within 90 days (§ 2518(8)(d))
SubpoenaVaries by jurisdiction and instrument; generally no prior finding of probable causeExisting records held by a third partyDepends on the records soughtRetrospectiveOne-time productionOften none to the account holder, depending on the instrument
Search warrantProbable cause, approved by a judgeEvidence described in the warrant, including contentYesRetrospective – items existing at executionShort execution windowAt execution

Under 18 U.S.C. § 3127(4), a trap-and-trace device “captures the incoming electronic or other impulses which identify the originating number or other dialing, routing, addressing, and signaling information reasonably likely to identify the source of a wire or electronic communication.”

A Title III wiretap requires probable cause and proof that other methods have failed or would be too risky (§ 2518(1)(c), (3)). The pen/trap law requires none of this. Pen registers are less expensive to monitor than wiretaps. There is no exclusionary rule, no duty to minimize, and no notice because metadata is not considered content.

Infographic comparing metadata and content collection: a pen register captures communication metadata (phone numbers, IP addresses, email headers, timestamps), while a wiretap captures the actual content of calls, emails, and messages.

A pen register reads the outside of the envelope. A wiretap opens it.


What the law says?

Federal authority lives in Chapter 206 of Title 18, enacted as part of the Electronic Communications Privacy Act (ECPA) in 1986. Section 3121 prohibits installing or using a pen register without a court order, with exceptions for providers running and testing their own services and where the user has consented. 

A pen register does not require a warrant. Under § 3122(b)(2), the applicant certifies that the information is “relevant to an ongoing criminal investigation,” and the court must enter the order. This is not probable cause but a certification. A pen register or trap and trace order is good for 60 days but may be extended for another 60 days upon a showing of good cause.

In Smith v. Maryland, 442 U.S. 735 (1979), the Supreme Court held that pen register use isn’t a Fourth Amendment search because a caller voluntarily conveys dialed numbers to the phone company. Carpenter v. United States (2018) narrowed that reasoning for cell-site location without overruling Smith.

It’s important to note that privacy protection for routing data comes from laws, not the Constitution. Legislatures decide the rules and can change them. That’s why a single state law can drive the surge in pen register cases, and why California’s SB 690 could change things without a court decision.

In 2001, Section 216 of the USA PATRIOT Act (Pub. L. 107–56, 115 Stat. 290) widened the definition to reach internet traffic, substituting the DRAS language and inserting “or process” after “device” wherever it appeared.

California went further, adding Penal Code § 638.50 and § 638.51 through AB 929, effective January 1, 2016. That date gets misreported constantly. The California Invasion of Privacy Act (CIPA) dates to 1967, but the pen register provisions are recent and track the post-PATRIOT federal text almost word for word. They reach private parties, not just the government. Violations support a private right of action under § 637.2 at the greater of $5,000 per violation or treble actual damages. And the consent exception at § 638.51(b)(5) is the user’s consent, not the operator’s.

§ 638.51 is often described as carrying “$2,500 per violation.” That’s the criminal fine under § 638.51(c). The civil exposure comes from § 637.2, and it’s $5,000.

From telegraph tape to tracking pixels: 186 years of pen-register law.

From telegraph tape to tracking pixels: 186 years of pen-register law.


What a pen register claim costs

Section 637.2 sets statutory damages at $5,000 per violation; no actual harm is required. That figure is fixed by statute, not indexed to inflation: the Legislature set it in 1992 (AB 2465, raising the original 1967 amount from $3,000), and it has not moved since; the words “per violation” were added only in 2016 (AB 1671, effective January 1, 2017). 

Plaintiffs frame each affected California visitor as at least one violation. A site with 10,000 California visitors faces $50 million in theoretical exposure. 


What counts as a pen register on a website

Whether a tool is involved doesn’t depend on its name or vendor. It’s about what data it sends, when it sends it, and who receives it. These are facts you can check, not just legal opinions.

The four-condition test

Drawn from the statutory language. Any technology on your site can be run through it.

  1. Does it record or decode information? (“records or decodes” are the statutory verbs)
  2. Is that information dialing, routing, addressing, or signaling data, as distinct from contents?
  3. Is it transmitted by an instrument or facility from which a communication originates, meaning a visitor’s browser or device?
  4. Did it operate without the user’s prior consent and outside any statutory exception?

Four yeses put a tool inside the argument the plaintiffs are making. Common categories tend to score like this.

TechnologyRecords/decodesCaptures DRASFrom user’s deviceTypically fires pre-consentIn scope
Advertising pixelsYesYes – IP, cookie IDsYesOftenLikely
Mobile & web SDKsYesYes – device IDsYesOftenLikely
Session replayYesYes, plus arguably contentYesOftenLikely
CDPs / identity resolutionYesYes – built to correlate identityYesVariesLikely
Chat & support widgetsYesYes – IP, session dataYesFrequentlyPossible
Tag managersContainer, but loads all of the aboveIndirectlyYesBy designPossible, and systemic

Note what condition 4 does. It’s the only one that’s a question about your configuration rather than about the tool. The same pixel firing after an affirmative opt-in sits in a completely different posture than one firing on page load. It also sets a higher bar for a consent banner than a banner alone can clear. One that announces agreement rather than requiring it, or that logs a preference while tags keep firing underneath, doesn’t produce the consent the exception needs. 


What a pen register visibility audit needs to show you

Just listing the tags on your site isn’t a real audit. An inventory only shows which vendors are present, not what data they actually receive.

The real risk is in the data being sent, and you can’t see that just by looking at your tag manager. A proper audit should answer these nine questions:

  • What leaves, not just what loads. Capture the outbound requests and read their contents. The gap between “we use an ad exchange” and “we send that exchange the visitor’s IP bound to a persistent ID” is the entire case.
  • Which fields, in what form. For each recipient: IP? A device or user identifier? Email, phone, other PII, raw or hashed or encoded? Hashing isn’t a defense you can assert if you can’t see whether it happened.
  • Who the recipient is, by function. A hostname isn’t enough: First-party CDN, analytics, identity-resolution broker, RTB exchange. The last two are what turn an ordinary request into a pen register question.
  • When it fired, relative to consent. Did the request go out before the banner was shown or accepted? Only timing-aware capture can show that, and it’s the fact most of this litigation turns on.
  • Whether identifiers persist. Is the IP or PII paired with a stable identifier that follows the user across sites and sessions? That pairing is what elevates addressing to signaling.
  • Whether your disclosures match your traffic. “We do not share personal information,” sitting above an IP-transmitting pixel, is the plaintiff’s first exhibit.
  • Coverage of the whole journey. Homepage, search, forms, checkout, and logged-in areas load different tags. Auditing the landing page misses where the sensitive flows are.
  • Evidence, not a dashboard. The output should be the actual request, reproducible. If you can’t show the wire, you can’t rebut the claim.
  • Change over time. Tags arrive quietly through tag managers and partner integrations. A one-time audit ages the moment a new vendor is dropped in.

This level of detail lets your privacy, security, or risk team answer the question, “Are we exposed?” with real evidence instead of just guessing.

Next steps

Look at your site the way a plaintiff’s expert does. Run an audit before you get a demand letter that prices the answer for you. If you can’t clearly answer what is firing on your site and where the data goes after it leaves, request a demo.


FAQs

What is the difference between a pen register and a trap-and-trace device? 

A pen register records the routing and addressing information of outgoing communications, such as numbers dialed and IP addresses contacted. A trap-and-trace device captures the same categories from incoming communications to identify their source. Neither captures the contents. They’re defined at 18 U.S.C. § 3127(3) and (4).

How much can a pen register lawsuit cost a business?

The statutory floor is $5,000 per violation. Plaintiffs frame each affected California visitor as at least one violation.

Does a pen register require a warrant? 

No. Federal law requires a court order on a lower standard than probable cause: a government attorney certifies that the information is relevant to an ongoing criminal investigation, and the court enters the order. This flows from Smith v. Maryland (1979), which held pen register use is not a Fourth Amendment search.

Yes, when authorized. Federal law prohibits installing or using one without a court order, subject to statutory exceptions, and California’s § 638.51 imposes a parallel prohibition that also reaches private parties. Unauthorized use is what creates liability.

What type of evidence can be obtained through a pen register? 

Numbers dialed and received, call timing and duration, IP addresses and routing metadata, and device identifiers. It cannot capture the contents of any communication. That exclusion is written into both the federal and California definitions.

Can a website be a pen register? 

Courts are split. Some have held that trackers capturing IP addresses and device identifiers qualify as a “process” under CIPA § 638.51. Others reject the analogy where only routine routing data was collected. Note also that Greenley v. Kochava, the decision plaintiffs rely on most, involved the SDK provider rather than a website using one. Appellate cases are pending.

Why is it called a pen register? 

Early devices recorded dialed digits as pen marks on a strip of moving paper, descended from telegraph registers. The hardware is long obsolete; the term survived. Law enforcement often uses the related term “dialed number recorder,” or DNR.

How long does a pen register order last? 

Up to 60 days under federal law, under 18 U.S.C. § 3123(c), with extensions available in additional 60-day increments.


DISCLAIMER: This article is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.


Reference

Cite this page

Dany Mirza. “What is a Pen Register? Definition, Law, and Website Tracking Risk (2026).” Melurna, September 2, 2026. https://www.melurna.com/blog/what-is-a-pen-register/