ConsentPixel – Privacy · Verified

✓ Defendant win · Dismissed with prejudice

Blaker v. NetScout Systems, Inc.

A Los Angeles judge threw out a CIPA "pen register" class action over a third-party website SDK — ruling, in a first-of-its-kind decision, that CIPA's pen-register and trap-and-trace provisions were written for telephones, not websites. Here's the full breakdown: the technology, the theory, how the court reasoned, and what it means for your site.

ConsentPixel Research Published July 7, 2026 10 min read CIPA §638.51 · pen register
⚖️ Case snapshot
Court
L.A. County Superior Court, Stanley Mosk Courthouse, Dept. 733 (Judge Gary D. Roberts)
Case No.
25STCV31283
Filed
October 27, 2025
Status (as of Jul 2026)
Dismissed May 27, 2026 — no leave to amend
Tracking tech
Third-party SDK supplied by X Corp. (f/k/a Twitter)
Defendant
NetScout Systems, Inc. — network performance & security

What the case is about

Plaintiff Brian Blaker sued NetScout Systems, Inc. over the tracking technology on its website. According to the complaint, NetScout had deployed a third-party software development kit (SDK) supplied by X Corp. (the company formerly known as Twitter), and that SDK captured data from visitors the instant they landed on the site. Blaker's framing was vivid: he alleged that "the surveillance begins the instant a visitor's browser connects to the website."[1]

The mechanics are worth stating precisely, because the whole case turns on them. The complaint alleged that the SDK captured "electronic impulses" — things like the visitor's IP address, device fingerprint, and browser/routing data — and that, while an SDK on its own might be innocuous, the information aggregated here created a "highly unique digital fingerprint" capable of reliably identifying and tracking individual visitors. Each visit, Blaker argued, and the automatic activation of the tracking that came with it, was a separate CIPA violation.[5]

The legal hook was California Penal Code §638.51 — the provision of the California Invasion of Privacy Act (CIPA) that governs "pen registers" and "trap and trace devices," normally reserved for law-enforcement surveillance and generally requiring a court order. In plain terms, the theory was that a routine analytics/identification SDK on a commercial website is the digital equivalent of attaching a pen register to a telephone line. It's the same §638.51 theory driving a large share of the 2026 CIPA litigation wave.[2]

The legal theory — and the statute it leans on

To see why the claim failed, you have to look at what a "pen register" originally was. Historically, pen registers were physical hardware devices used by law enforcement to record the outgoing numbers dialed from a specific telephone line; a "trap and trace device" did the reverse, capturing the originating data of incoming calls. California folded these concepts into CIPA in 2015 — decades after the statute's 1967 origins in telephone wiretapping.

Cal. Penal Code §638.51(a) — the prohibition

"...a person may not install or use a pen register or a trap and trace device without first obtaining a court order..." The definitions it borrows turn on capturing the dialing, routing, addressing, or signaling information of a communication — not its contents.

You can see the plaintiff's angle immediately. The words "routing, addressing, or signaling information" sound like they could describe what an analytics SDK does when it captures an IP address, a device identifier, or similar metadata. Plaintiffs across California have built entire class actions on exactly that textual hook: if a pixel or SDK captures "addressing" data, the argument goes, it is a pen register or trap-and-trace device, and every unconsented visit becomes a statutory violation carrying CIPA's damages.

Why §638.51 is the plaintiff's favourite theory. Unlike the §631 wiretapping theory — which requires showing a third party actually intercepted the contents of a communication in real time — the pen-register / trap-and-trace theory only requires capture of routing and addressing data, a much lower bar that ordinary analytics seem to clear. That asymmetry is why so many 2026 complaints, including Blaker's, lead with §638.51.[2]

Why Judge Roberts rejected it

The court didn't accept the textual stretch. Facing what he expressly treated as an issue of first impression — with neither side presenting binding California authority on whether these provisions reach website technologies — Judge Gary D. Roberts turned to statutory construction and legislative intent. He found multiple indicators that §638.51 was designed for telephonic surveillance: the statute repeatedly references a "telephone line," it uses telephony-specific terms like "dialing" and "routing," and its companion provision, §638.52, is built entirely around a court-order process for authorizing pen registers on phone lines. Read as a whole, the framework simply does not fit software running on a commercial website.[1]

CIPA's pen register and trap-and-trace provisions apply to telephone communications, not to software operating on commercial websites.

— The court's core holding, as reported across firm analyses of the May 27, 2026 order (25STCV31283)

The defense's real achievement, several firms noted, was rhetorical as much as legal: rather than letting the case dissolve into a dense technical debate about data architecture, NetScout reframed the SDK as ordinary, ubiquitous web infrastructure and gave the judge a clean conceptual category — telephone statute, telephone problem — into which to place the technology. When a court is confused by technology, it tends to default to caution and let a case proceed; NetScout removed the confusion.[3]

Dismissed with prejudice — why "no leave to amend" matters

NetScout challenged the complaint by demurrer — California's procedural equivalent of a motion to dismiss — arguing the pleading failed as a pure question of law: the plaintiff had not alleged use of a "pen register" or "trap and trace device" within the meaning of CIPA, because those terms are tied to telephones, not SDKs on websites. The court agreed, and the manner of dismissal is what makes the ruling so useful to defendants.

The court sustained the demurrer without leave to amend. Ordinarily a plaintiff gets at least one chance to re-plead and fix defects. Here, the court reasoned that amendment would be futile: the problem was not sloppy drafting but the limited scope of the statute itself. Since §638.51 does not reach website software, no rewritten complaint could cure the defect. At oral argument, plaintiff's counsel indicated she wished to supplement on the law rather than amend the facts pleaded — which the court held was not a proper basis for granting leave. Dismissal was therefore with prejudice.[1]

Statute = telephone "telephone line," "dialing," §638.52 court-order process Doesn't reach SDKs website software isn't a §638.51 device Amendment futile → dismissed with prejudice, no leave Because the defect was the statute's scope — not the pleading — no rewritten complaint could cure it.
The logic in three steps. The provisions are structurally telephonic; a website SDK isn't a §638.51 device; and because that's a limit on the statute — not a drafting error — leave to amend would have been pointless.

That "with prejudice, without leave" posture is what defense counsel will find most portable. It converts the ruling from "this particular complaint was weak" into "this theory doesn't fit this statute" — a merits holding that other defendants can cite, not just a pleading technicality the next plaintiff can draft around.

Where it stands (as of July 2026)

The case is dismissed with prejudice. On May 27, 2026, Judge Roberts sustained NetScout's demurrer without leave to amend in the Los Angeles County Superior Court (Central District, Stanley Mosk Courthouse, Department 733), case number 25STCV31283. The underlying action was filed October 27, 2025.[6] Multiple firms have described the decision as a "first-of-its-kind" ruling that could reshape how California courts treat website-tracking claims under the pen-register theory.[4]

A note on sourcing. The facts here come from the court's minute order (via Trellis) and the Los Angeles Superior Court docket, plus firm analyses from Loeb & Loeb, Taft, Robinson+Cole, Mac Murray & Shuster, and Briones PC — all listed in Sources below. Where secondary summaries differ on details, we've deferred to the court record and the primary docket.

How Blaker fits the 2026 landscape

Blaker is not an isolated ruling — it's part of a genuine 2026 shift. Across California, a growing line of decisions has refused to stretch CIPA's phone-era surveillance provisions to cover routine website cookies, pixels, and SDKs. Reading them together shows both the pattern and its limits:

CaseCourtWhat it held
Blaker v. NetScout (this case)L.A. Superior (state)CIPA's pen-register / trap-and-trace provisions cover telephones, not website SDKs. Demurrer sustained; dismissed with prejudice, no leave to amend.
Rounds v. DDIC.D. Cal. (federal)Cookies aren't a §638.51 trap-and-trace device; no violation meant no jurisdiction over the out-of-state defendant. Dismissed, no leave.[7]
Rodriguez v. Ink AmericaL.A. Superior (state)Pen-register theory dismissed with prejudice; CIPA can't criminalise what the CCPA already regulates.[7]

The through-line is judicial skepticism that these decades-old provisions were ever meant to reach the ordinary metadata a website exchanges with a visitor who chose to load the page. Blaker is a particularly clean articulation of that skepticism — a state court dismissing on the statute's scope alone, with prejudice.

But read the trend honestly. This is a trial-court decision, not binding appellate precedent. As the court itself acknowledged, it was an issue of first impression with no controlling authority — which means other judges remain free to disagree, and plaintiffs will keep filing §638.51 claims while the question works its way toward appellate review. The defense tide is real, but it is not a settled rule you can bank on.[4]

Why this case matters for website operators

For website owners, Blaker hands defense counsel fresh, citable authority for one of the most frustrating features of CIPA litigation: that even weak pen-register claims used to survive the pleading stage long enough to generate settlement pressure. A dismissal with prejudice at demurrer gives defendants a clean, early exit — a way to challenge these claims before litigation costs pile up.[4]

But it's essential to read the ruling for exactly what it decides — and what it doesn't. Blaker turned on the §638.51 pen-register / trap-and-trace theory. It says nothing about:

  • The §631 wiretapping theory, which targets the real-time interception of communication contents (not just routing data) — a live and much harder-to-dismiss theory, especially for session-replay tools.
  • Session-replay on checkout, login, or form pages, where tools capture exactly what a visitor types into sensitive fields — the highest-risk configuration in CIPA litigation, untouched by this ruling.
  • The pre-consent firing gap — trackers that fire before a visitor is given any choice — which sinks sites regardless of how the pen-register question is resolved.
  • Other layered theories plaintiffs are already pivoting to — the Unfair Competition Law, California's "Shine the Light" law, and traditional privacy torts — none addressed here.
The trap to avoid: "A court said an SDK isn't a pen register, so I'm fine" is the wrong lesson. Blaker narrows one theory, in one forum, at the trial-court level. The most common CIPA exposure — trackers firing before a visitor consents, and session-replay capturing what people type on sensitive pages — is completely untouched by this decision. Courts also still expect transparent disclosures and respect for opt-out signals under the CCPA/CPRA.

What this means for your site

The durable lesson from Blaker isn't "relax." It's that your actual risk depends on what your trackers do and when they fire — not on the label a plaintiff attaches or how one court rules. A favourable Superior Court decision won't help you if your site fires Meta Pixel, GA4, or a session-replay tool before a visitor consents; that's a different theory, a different fact pattern, and a materially worse position to be in.

The reliable protection is the same no matter which way the case law swings: don't let non-essential third-party trackers run before consent, keep session-replay off sensitive pages, and keep a record proving consent was obtained. That is precisely what ConsentPixel is built to do — block third-party trackers until a visitor opts in, fire Google Consent Mode v2 signals correctly, and log every consent decision in an immutable record — so your compliance posture doesn't hinge on a court's mood or a plaintiff's choice of forum.

And notice how this whole dispute began: with a third-party SDK on the defendant's site, doing more than the operator may have fully appreciated. In many CIPA cases, the site owner didn't realise exactly what a given pixel or SDK was doing, or when it fired. That's why the first, cheapest step is simply seeing what actually runs on your pages — and whether any of it fires before consent.

Worried your site has this exposure?

Scan free in about 10 seconds to see every tracker firing on your site — including the ones loading before consent, the gap this ruling doesn't protect. It's the same scan a plaintiff firm would run.

Scan your site free →

No account needed · then start a 14-day free trial, no credit card, from $8.99/mo

Frequently asked questions

What was Blaker v. NetScout Systems about?
Plaintiff Brian Blaker alleged that NetScout's website deployed a third-party SDK supplied by X Corp. (formerly Twitter) that captured visitors' IP address, device fingerprint, and routing data to identify and track them — which he claimed was an unauthorized "pen register" or "trap and trace device" under California Penal Code §638.51 (part of CIPA). The Los Angeles County Superior Court dismissed the claim on May 27, 2026.
Why did the court dismiss the case?
Judge Gary D. Roberts held that CIPA's pen-register and trap-and-trace provisions apply to telephonic communications, not to software such as an SDK running on a commercial website. Because that's a limit on the statute's scope rather than a fixable pleading defect, amendment would have been futile — so the demurrer was sustained without leave to amend, dismissing the case with prejudice.
Does this mean SDKs and cookies are legal and CIPA doesn't apply to my site?
No. Blaker is a trial-court decision on one theory (§638.51 pen register / trap-and-trace). It's persuasive, not binding, so other California courts can disagree, and it says nothing about the §631 wiretapping theory, session-replay on checkout pages, or trackers firing before consent — which remain the most common sources of CIPA exposure. CCPA/CPRA obligations are also unaffected. This is general information, not legal advice.
What is a "pen register" or "trap and trace device" under CIPA?
Under California Penal Code §638.51 (with definitions from §638.50), these are devices or processes that capture the dialing, routing, addressing, or signaling information of a communication — but not its contents. The provisions were written for telephone surveillance and normally require a court order. Plaintiffs have argued tracking SDKs, pixels, and cookies qualify; courts are divided, and Blaker is one of several 2026 rulings holding they do not.
What's the practical takeaway for website owners?
Don't rely on favourable case law to protect you — rely on your configuration. Block non-essential third-party trackers until a visitor consents, keep session-replay off sensitive pages, honor opt-out signals like GPC, and maintain a record of consent decisions. That posture protects you regardless of how any individual CIPA ruling comes out.

Sources

  1. Trellis — Minute Order / Demurrer Ruling, Brian Blaker v. NetScout Systems, Inc., 25STCV31283 (L.A. Super. Ct. May 27, 2026). Court record: sustained without leave to amend; Dept. 733, Judge Gary D. Roberts; counsel of record.
  2. The National Law Review — "CIPA Win: California Superior Court Sustains Dismissal of Website Tracking Claims". Summarises the §638.51/§638.52 statutory-construction reasoning and the X Corp. SDK allegations.
  3. Loeb & Loeb LLP — "Decoding the Code: How Simple, Rigorously Accurate Advocacy May Have Broken the CIPA Litigation Impasse". Analysis of the defense framing and the "telephone statute" holding.
  4. Mac Murray & Shuster LLP — "A California Court Just Handed Website Operators a Win on CIPA". Covers the early-exit significance and the persuasive-not-binding limits.
  5. Taft — "Changing Tides: A Los Angeles Court Delivers a Major CIPA Defense Win". Details the plaintiff's allegations (X/Twitter SDK, "highly unique digital fingerprint," per-visit violations) and the layered follow-on theories.
  6. Docket Alarm — BRIAN BLAKER VS NETSCOUT SYSTEMS, INC., 25STCV31283 (L.A. Super. Ct.). Docket: filed Oct. 27, 2025.
  7. Briones PC — "CIPA Web-Tracking Claims Crushed in NetScout Ruling". Judge Roberts's statutory-text analysis; related 2026 pen-register/trap-and-trace rulings.
  8. Additional reporting: Robinson+Cole, "Big Win for Companies Facing CIPA Website Tracking Lawsuits" (Case No. 25STCV31283, May 27, 2026).

Sources accessed and summarised July 2026. Case status is current as of the publication date and may change as litigation proceeds.

Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above. Status is stated as of July 7, 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.

Scroll to Top