CIPA Section 631 vs 638.51: The Two Provisions Plaintiffs Use
Most CIPA website suits cite Penal Code §631, but a second theory under §638.51's pen-register language is increasingly common. Here's how the two provisions differ and why it matters.
Most coverage of CIPA website litigation talks about “CIPA” as if it were one claim. In practice, plaintiffs’ firms are working from at least two distinct provisions of the statute, built on two different legal theories, and the difference matters for understanding what kind of tracker behavior each one targets.
Section 631: the wiretapping / interception theory
This is the provision behind the bulk of the litigation we’ve covered elsewhere in this series, see our overview of what CIPA is. The theory is that a third-party tool (a chat widget, session-replay script, or similar) is functionally “listening in” on a website communication and relaying its contents to another party without consent, analogous to tapping a phone line. This is the theory behind session-replay and chat-widget suits specifically, because those tools capture something closer to the actual “content” of a visitor’s interaction with the page.
Section 638.51: the pen-register / trap-and-trace theory
This is a different, newer wave of claims, built on a different part of the statute entirely. §638.51 was originally about devices that record the numbers dialed or the routing information of a communication, the “who’s calling whom,” not the content of the call itself. Applied to websites, the theory argues that tools capturing routing-type information, IP addresses, device identifiers, or similar metadata used to identify and track a visitor, function as an unauthorized “pen register,” even when they aren’t capturing the substance of what a visitor said or did.
This distinction matters because it broadens the type of tool that can be targeted. A §631 claim generally needs a tool that captures something resembling message content. A §638.51 claim can target tools that only ever touch identifying and routing metadata, which describes a much larger share of standard marketing and analytics infrastructure, not just session replay and chat.
Enzuzo
Because §638.51 claims can target metadata-only tools, not just content-capturing ones, a consent platform that gates all non-essential trackers by default, not just the obviously conversational ones, covers both theories at once.
Why both theories point to the same fix
Despite targeting different technical behavior, both provisions turn on the same underlying fact pattern: was the tool operating and transmitting data before the visitor consented. We cover this timing question specifically in our piece on the millisecond problem. A consent management setup that blocks all non-essential scripts, content-capturing and metadata-only alike, until an affirmative consent decision addresses the mechanical trigger for both theories simultaneously, even though the underlying legal arguments differ.
What this means for your own risk assessment
If you’ve only been thinking about CIPA risk in terms of “do I run a chat widget or session replay,” it’s worth widening that lens. Standard analytics and ad tools that only ever touch routing-type metadata aren’t automatically safe from a §638.51 theory, even though they’d be a weaker target under a pure §631 interception theory. Our CIPA risk checker covers the tracker categories relevant to both provisions.
This is an educational overview of two distinct statutory provisions, not legal advice. How courts apply either section to a specific fact pattern is unsettled and evolving. Consult a privacy attorney for guidance on your specific tracking setup.