直 Japanese PDF Font
  • Our Professionals
  • Our Work
  • Our Insights
  • Offices
  • Firm
  • Careers
Finnegan
  • Articles & Books
    • Ad Law Buzz Blog
    • At the PTAB Blog
    • European IP Blog
    • Federal Circuit IP Blog
    • INCONTESTABLE® Blog
    • Prosecution First Blog
  • Events & Webinars
  • IP Updates
  • Podcasts
    • AI + Finnegan
    • AI + Copyright
    • AI + Patent
    • AI + Privacy
    • AI + Trade Secrets
    • AI + Trademark
  • Unified Patent Court (UPC) Hub

Article

Blaker v. NetScout Systems: A Narrow Reading of the Pen Register and Trap and Trace Provisions of the California Invasion of Privacy Act in California State Court

July 29, 2026

By Lynn Parker Dupree; Baiyu Zhu

  1. Statute Limited to Telephone Communications: A California state court held that California Penal Code § 638.51 does not apply to software used on commercial websites, finding that the statute’s pen register and trap-and-trace provisions were intended for telephone communications rather than internet-based technologies.

  2. Legislative Context Drives Interpretation: The court cross referenced the procedure provisions of the statute, which attach pen registers and trap-and-trace devices to a “telephone line,” concluding that the legislature did not intend the law to govern website SDKs and other online tracking technologies.

  3. Businesses Gain a Potential Defense: While the treatment is these claims is still in flux, the decision provides companies facing CIPA claims involving website SDKs and similar tracking technologies with a potential argument that California’s pen register and trap-and-trace provisions do not apply to commercial websites.

Background and Statutory Context

On May 27, 2026, the Superior Court of California held that subdivision (a) of California Penal Code § 638.51 does not apply to software on commercial websites. Plaintiff Brian Blaker sued Defendant NetScout, Inc., alleging the Defendant had violated § 638.51 of the California Invasion of Privacy Act by implementing a software development kit (SDK) on its website.[1]

Section 638.51(a) of the California Invasion of Privacy Act generally prohibits a person from installing or using a “pen register” or “trap and trace device” without first obtaining a court order. Section 638.50 defines a pen register as a “device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, but not the contents of a communication.” It defines a trap and trace device as a “device or process that captures the incoming electronic or other impulses that identify the originating number or other dialing, routing, addressing, or signaling information reasonably likely to identify the source of a wire or electronic communication, but not the contents of a communication.” Blaker argued that NetScout’s website SDK fell within those definitions.

The Court’s Reasoning

The main issue before the Court was whether the definitions of “pen register” and “trap and trace device” are limited to telephone lines, or if they also encompass software and internet websites. The Court observed that, although §§ 638.50 and 638.51 do not expressly limit the definitions to telephone lines, the surrounding statutory scheme does.

Specifically, the Court focused on § 638.52(d), which governs court orders authorizing pen registers or trap-and-trace devices. That section of the statute repeatedly used the language “the telephone line to which the pen register or trap and trace device is to be attached.” The Court reasoned that the repeated references to “telephone line” showed that the legislature intended the statutory scheme to apply to telephonic communications and not to internet websites. The Court asserted that if the legislature had intended otherwise, it would have so stated explicitly, as the internet was widespread when these provisions were enacted in 2015. Eventually, the Court concluded that the statute does not apply to software on Defendant’s commercial website.

What Does This Mean for Business?

The Court’s decision provides a defense-friendly interpretation of an SDK’s application to the trap-and-trace provisions of the California Invasion of Privacy Act (CIPA) in state court. In recent years, plaintiffs have increasingly attempted to apply older privacy statutes, including CIPA, to common website technologies such as SDKs, pixels, web beacons, and analytics tools. For companies facing similar claims in California, the ruling potentially offers a useful roadmap.

However, the treatment of pen register claims is still in flux, as the Blaker ruling is not a binding decision from an appellate court, and lower courts’ rulings on the application of § 638.51 are split. See, e.g, Greenley v. Kochava, Inc., 684 F.Supp.3d 1024, 1050 (S.D. Cal. 2023) (reasoning that “pen register” may take “the form of software” and allowing the claim to survive the motion to dismiss). The court’s legislative analysis in Blaker extended beyond the definitional analysis and prohibitive section analysis in Kochava to include the cross-referenced procedure provisions of the statute, leading to a different interpretation and providing an argument that the scope of the law should not be expanded to websites absent clearer legislative direction.

Endnotes

[1] Blaker v. NetScout Systems, Inc., 2026 WL 1709143 (Cal Sup. Ct. 2026).

Tags

privacy policy

Related Practices

Diligence, Licensing, and Opinions

Privacy

Related Industries

AI, Electronics, and Information Technology

Electronic Devices and Components

Related Offices

Palo Alto, CA

Washington, DC

Related Professionals

Lynn Parker Dupree
Partner
Washington, DC
+1 202 408 4462
Email
Baiyu Zhu
Associate
Palo Alto, CA
+1 650 849 6652
Email

Copyright © Finnegan, Henderson, Farabow, Garrett & Dunner, LLP. This article is for informational purposes, is not intended to constitute legal advice, and may be considered advertising under applicable state laws. This article is only the opinion of the authors and is not attributable to Finnegan, Henderson, Farabow, Garrett & Dunner, LLP, or the firm’s clients.

Related Insights

Hybrid Conference

Intellectual Property Law Institute 2026 – California

October 19-20, 2026

San Francisco

Articles

California Brings First CCPA and Delete Act Enforcement Action Against Data Broker

September 4, 2026

Lecture

Introduction to U.S. Judicial System and Litigation

August 25, 2026

Tokyo

Articles

Privacy Law Mid-Year Update: Key EU and UK Data Protection Decisions

August 13, 2026

Articles

Court Upholds MillerKnoll Ownership of Iconic Bubble Lamp Design

August 13, 2026

Articles

How Low Can You Go? Courts Lower Marking Defense Burden, Raising Patent Damages Risks

June 29, 2026

Federal Circuit IP Blog

Federal Circuit Holds Defend Trade Secrets Act Claim Untimely Filed

June 22, 2026

Articles

The SECURE Data Act: A Federal Privacy Framework Moves Forward

June 16, 2026

Articles

The TAKE IT DOWN Act Is Now in Full Effect: What Platforms Need to Know

June 16, 2026

Due to international data regulations, we’ve updated our privacy policy. Click here to read our privacy policy in full.

  • Privacy
  • Disclaimer
  • Legal Notices
  • Fraud Alert
  • EEO Statement
  • Cookies
  • Contact Us

© 2026 Finnegan, Henderson, Farabow, Garrett & Dunner, LLP