Blaker v. NetScout Systems, Inc.
A Los Angeles judge threw out a CIPA "pen register" class action over a third-party website SDK — ruling, in a first-of-its-kind decision, that CIPA's pen-register and trap-and-trace provisions were written for telephones, not websites. Here's the full breakdown: the technology, the theory, how the court reasoned, and what it means for your site.
What the case is about
Plaintiff Brian Blaker sued NetScout Systems, Inc. over the tracking technology on its website. According to the complaint, NetScout had deployed a third-party software development kit (SDK) supplied by X Corp. (the company formerly known as Twitter), and that SDK captured data from visitors the instant they landed on the site. Blaker's framing was vivid: he alleged that "the surveillance begins the instant a visitor's browser connects to the website."[1]
The mechanics are worth stating precisely, because the whole case turns on them. The complaint alleged that the SDK captured "electronic impulses" — things like the visitor's IP address, device fingerprint, and browser/routing data — and that, while an SDK on its own might be innocuous, the information aggregated here created a "highly unique digital fingerprint" capable of reliably identifying and tracking individual visitors. Each visit, Blaker argued, and the automatic activation of the tracking that came with it, was a separate CIPA violation.[5]
The legal hook was California Penal Code §638.51 — the provision of the California Invasion of Privacy Act (CIPA) that governs "pen registers" and "trap and trace devices," normally reserved for law-enforcement surveillance and generally requiring a court order. In plain terms, the theory was that a routine analytics/identification SDK on a commercial website is the digital equivalent of attaching a pen register to a telephone line. It's the same §638.51 theory driving a large share of the 2026 CIPA litigation wave.[2]
The legal theory — and the statute it leans on
To see why the claim failed, you have to look at what a "pen register" originally was. Historically, pen registers were physical hardware devices used by law enforcement to record the outgoing numbers dialed from a specific telephone line; a "trap and trace device" did the reverse, capturing the originating data of incoming calls. California folded these concepts into CIPA in 2015 — decades after the statute's 1967 origins in telephone wiretapping.
"...a person may not install or use a pen register or a trap and trace device without first obtaining a court order..." The definitions it borrows turn on capturing the dialing, routing, addressing, or signaling information of a communication — not its contents.
You can see the plaintiff's angle immediately. The words "routing, addressing, or signaling information" sound like they could describe what an analytics SDK does when it captures an IP address, a device identifier, or similar metadata. Plaintiffs across California have built entire class actions on exactly that textual hook: if a pixel or SDK captures "addressing" data, the argument goes, it is a pen register or trap-and-trace device, and every unconsented visit becomes a statutory violation carrying CIPA's damages.
Why Judge Roberts rejected it
The court didn't accept the textual stretch. Facing what he expressly treated as an issue of first impression — with neither side presenting binding California authority on whether these provisions reach website technologies — Judge Gary D. Roberts turned to statutory construction and legislative intent. He found multiple indicators that §638.51 was designed for telephonic surveillance: the statute repeatedly references a "telephone line," it uses telephony-specific terms like "dialing" and "routing," and its companion provision, §638.52, is built entirely around a court-order process for authorizing pen registers on phone lines. Read as a whole, the framework simply does not fit software running on a commercial website.[1]
CIPA's pen register and trap-and-trace provisions apply to telephone communications, not to software operating on commercial websites.
— The court's core holding, as reported across firm analyses of the May 27, 2026 order (25STCV31283)The defense's real achievement, several firms noted, was rhetorical as much as legal: rather than letting the case dissolve into a dense technical debate about data architecture, NetScout reframed the SDK as ordinary, ubiquitous web infrastructure and gave the judge a clean conceptual category — telephone statute, telephone problem — into which to place the technology. When a court is confused by technology, it tends to default to caution and let a case proceed; NetScout removed the confusion.[3]
Dismissed with prejudice — why "no leave to amend" matters
NetScout challenged the complaint by demurrer — California's procedural equivalent of a motion to dismiss — arguing the pleading failed as a pure question of law: the plaintiff had not alleged use of a "pen register" or "trap and trace device" within the meaning of CIPA, because those terms are tied to telephones, not SDKs on websites. The court agreed, and the manner of dismissal is what makes the ruling so useful to defendants.
The court sustained the demurrer without leave to amend. Ordinarily a plaintiff gets at least one chance to re-plead and fix defects. Here, the court reasoned that amendment would be futile: the problem was not sloppy drafting but the limited scope of the statute itself. Since §638.51 does not reach website software, no rewritten complaint could cure the defect. At oral argument, plaintiff's counsel indicated she wished to supplement on the law rather than amend the facts pleaded — which the court held was not a proper basis for granting leave. Dismissal was therefore with prejudice.[1]
That "with prejudice, without leave" posture is what defense counsel will find most portable. It converts the ruling from "this particular complaint was weak" into "this theory doesn't fit this statute" — a merits holding that other defendants can cite, not just a pleading technicality the next plaintiff can draft around.
Where it stands (as of July 2026)
The case is dismissed with prejudice. On May 27, 2026, Judge Roberts sustained NetScout's demurrer without leave to amend in the Los Angeles County Superior Court (Central District, Stanley Mosk Courthouse, Department 733), case number 25STCV31283. The underlying action was filed October 27, 2025.[6] Multiple firms have described the decision as a "first-of-its-kind" ruling that could reshape how California courts treat website-tracking claims under the pen-register theory.[4]
How Blaker fits the 2026 landscape
Blaker is not an isolated ruling — it's part of a genuine 2026 shift. Across California, a growing line of decisions has refused to stretch CIPA's phone-era surveillance provisions to cover routine website cookies, pixels, and SDKs. Reading them together shows both the pattern and its limits:
| Case | Court | What it held |
|---|---|---|
| Blaker v. NetScout (this case) | L.A. Superior (state) | CIPA's pen-register / trap-and-trace provisions cover telephones, not website SDKs. Demurrer sustained; dismissed with prejudice, no leave to amend. |
| Rounds v. DDI | C.D. Cal. (federal) | Cookies aren't a §638.51 trap-and-trace device; no violation meant no jurisdiction over the out-of-state defendant. Dismissed, no leave.[7] |
| Rodriguez v. Ink America | L.A. Superior (state) | Pen-register theory dismissed with prejudice; CIPA can't criminalise what the CCPA already regulates.[7] |
The through-line is judicial skepticism that these decades-old provisions were ever meant to reach the ordinary metadata a website exchanges with a visitor who chose to load the page. Blaker is a particularly clean articulation of that skepticism — a state court dismissing on the statute's scope alone, with prejudice.
Why this case matters for website operators
For website owners, Blaker hands defense counsel fresh, citable authority for one of the most frustrating features of CIPA litigation: that even weak pen-register claims used to survive the pleading stage long enough to generate settlement pressure. A dismissal with prejudice at demurrer gives defendants a clean, early exit — a way to challenge these claims before litigation costs pile up.[4]
But it's essential to read the ruling for exactly what it decides — and what it doesn't. Blaker turned on the §638.51 pen-register / trap-and-trace theory. It says nothing about:
- The §631 wiretapping theory, which targets the real-time interception of communication contents (not just routing data) — a live and much harder-to-dismiss theory, especially for session-replay tools.
- Session-replay on checkout, login, or form pages, where tools capture exactly what a visitor types into sensitive fields — the highest-risk configuration in CIPA litigation, untouched by this ruling.
- The pre-consent firing gap — trackers that fire before a visitor is given any choice — which sinks sites regardless of how the pen-register question is resolved.
- Other layered theories plaintiffs are already pivoting to — the Unfair Competition Law, California's "Shine the Light" law, and traditional privacy torts — none addressed here.
What this means for your site
The durable lesson from Blaker isn't "relax." It's that your actual risk depends on what your trackers do and when they fire — not on the label a plaintiff attaches or how one court rules. A favourable Superior Court decision won't help you if your site fires Meta Pixel, GA4, or a session-replay tool before a visitor consents; that's a different theory, a different fact pattern, and a materially worse position to be in.
The reliable protection is the same no matter which way the case law swings: don't let non-essential third-party trackers run before consent, keep session-replay off sensitive pages, and keep a record proving consent was obtained. That is precisely what ConsentPixel is built to do — block third-party trackers until a visitor opts in, fire Google Consent Mode v2 signals correctly, and log every consent decision in an immutable record — so your compliance posture doesn't hinge on a court's mood or a plaintiff's choice of forum.
And notice how this whole dispute began: with a third-party SDK on the defendant's site, doing more than the operator may have fully appreciated. In many CIPA cases, the site owner didn't realise exactly what a given pixel or SDK was doing, or when it fired. That's why the first, cheapest step is simply seeing what actually runs on your pages — and whether any of it fires before consent.
Worried your site has this exposure?
Scan free in about 10 seconds to see every tracker firing on your site — including the ones loading before consent, the gap this ruling doesn't protect. It's the same scan a plaintiff firm would run.
Scan your site free →No account needed · then start a 14-day free trial, no credit card, from $8.99/mo
Frequently asked questions
What was Blaker v. NetScout Systems about?
Why did the court dismiss the case?
Does this mean SDKs and cookies are legal and CIPA doesn't apply to my site?
What is a "pen register" or "trap and trace device" under CIPA?
What's the practical takeaway for website owners?
Sources
- Trellis — Minute Order / Demurrer Ruling, Brian Blaker v. NetScout Systems, Inc., 25STCV31283 (L.A. Super. Ct. May 27, 2026). Court record: sustained without leave to amend; Dept. 733, Judge Gary D. Roberts; counsel of record.
- The National Law Review — "CIPA Win: California Superior Court Sustains Dismissal of Website Tracking Claims". Summarises the §638.51/§638.52 statutory-construction reasoning and the X Corp. SDK allegations.
- Loeb & Loeb LLP — "Decoding the Code: How Simple, Rigorously Accurate Advocacy May Have Broken the CIPA Litigation Impasse". Analysis of the defense framing and the "telephone statute" holding.
- Mac Murray & Shuster LLP — "A California Court Just Handed Website Operators a Win on CIPA". Covers the early-exit significance and the persuasive-not-binding limits.
- Taft — "Changing Tides: A Los Angeles Court Delivers a Major CIPA Defense Win". Details the plaintiff's allegations (X/Twitter SDK, "highly unique digital fingerprint," per-visit violations) and the layered follow-on theories.
- Docket Alarm — BRIAN BLAKER VS NETSCOUT SYSTEMS, INC., 25STCV31283 (L.A. Super. Ct.). Docket: filed Oct. 27, 2025.
- Briones PC — "CIPA Web-Tracking Claims Crushed in NetScout Ruling". Judge Roberts's statutory-text analysis; related 2026 pen-register/trap-and-trace rulings.
- Additional reporting: Robinson+Cole, "Big Win for Companies Facing CIPA Website Tracking Lawsuits" (Case No. 25STCV31283, May 27, 2026).
Sources accessed and summarised July 2026. Case status is current as of the publication date and may change as litigation proceeds.
Disclaimer: This page is for general informational purposes only and is not legal advice. Case details are drawn from public court records and the legal reporting listed above. Status is stated as of July 7, 2026 and litigation can change. ConsentPixel — Privacy · Verified is not a law firm and does not provide legal counsel. For advice on your specific situation, consult a qualified privacy attorney.