Under the Stored Communications Act (SCA), “content” means the actual substance of a communication, the message itself, such as an email body, a chat transcript, or a voicemail recording. “Non-content” data is everything else: subscriber information, IP addresses, timestamps, and other metadata. The distinction matters because the SCA generally prohibits disclosure of content without a warrant or user consent, while non-content data can often be disclosed under a lower legal threshold, such as a subpoena.
Misunderstanding this distinction when responding to subpoenas or law enforcement requests can lead to compliance errors, privacy violations, and legal liability. This guide breaks down the definitions, provides examples of each category, and outlines what legal process is required to compel disclosure.
Already dealing with a subpoena or data request? [Let’s start the conversation →]
What Is the Stored Communications Act (SCA)?
Congress enacted the Stored Communications Act, 18 U.S.C. § 2701 et seq., as Title II of the Electronic Communications Privacy Act (ECPA) of 1986. The law serves two purposes: protecting the privacy of stored electronic communications, and establishing lawful procedures for government entities and civil litigants to access that data.
Businesses that qualify as an Electronic Communication Service (ECS) or a Remote Computing Service (RCS) are subject to the SCA. ECS providers store digital communications for others, such as email and messaging services. RCS providers offer storage on behalf of users, such as cloud storage or virtual server hosting.
The SCA prohibits ECS and RCS providers from disclosing the content of electronic communications without user consent, unless a specific exception applies.
(For a deeper dive into the SCA generally, see What Is the Stored Communications Act? Understanding the SCA & Subpoena Compliance.)
Not sure if the data you’re being asked for is “content” or “non-content”?
Getting this distinction wrong can mean unlawfully disclosing protected communications or unnecessarily withholding data you’re required to produce. Let’s chat and review your specific request and tell you where you stand.
Schedule a call or just reach out.
What Counts as “Content” Under the SCA
“Content” refers to the substance, purport, or meaning of a communication. Under 18 U.S.C. § 2510(8), content is defined as any wire, oral, or electronic communication that includes information concerning the substance, purport, or meaning of that communication.
Courts have defined content as the intended message conveyed by a communication, distinct from record information about the communication’s characteristics. This line traces back to Theofel v. Farey-Jones, 359 F.3d 1066 (9th Cir. 2004), one of the Ninth Circuit’s earliest and most-cited rulings on what qualifies as content in stored email, and was reaffirmed a decade later in In re Zynga Privacy Litigation, 750 F.3d 1098 (9th Cir. 2014).
Examples of content under the SCA:
- Email subject lines and bodies: The subject line, if it conveys substantive information, the body, and any attachments. See Xie v. Laii, Case No. 19-mc-80287-SVK (N.D. Cal. 2019) (holding that an email subject line is content because it reveals the substance of the communication).
- Instant messages and chat: The actual text of a conversation, and any links or files exchanged within it.
- Voicemails and audio files: The audible message itself.
- Private documents and files: Files stored in cloud services (Google Docs, Dropbox, Salesforce CRM notes) that contain substantive or private communication.
- Photos and videos: When exchanged as a form of communication or when they convey substantive meaning.
- Passwords: Some courts treat passwords as content. See In re Ex Parte Application of Path Network, Inc., 703 F. Supp. 3d 1046 (N.D. Cal. 2023) (holding that passwords are a form of information that may relate to the substance of a communication).
A Case to Watch: Snap, Inc. v. Superior Court
A pending case before the California Supreme Court could reshape how courts determine who is protected under the SCA in the first place. In Snap, Inc. v. Superior Court of San Diego County (S286267), a California appellate court ruled that Snapchat’s and Meta’s business models, which involve accessing and monetizing stored user content for advertising, place them outside SCA protection entirely. Under that theory, a provider that routinely accesses content for commercial purposes could be compelled to disclose it through a subpoena rather than the warrant the SCA typically requires for content.
Snap and Meta appealed, arguing the ruling would strip SCA protections from a broad range of modern communications platforms, not just social media apps. The case drew amicus support from the Electronic Frontier Foundation, the Center for Democracy and Technology, and Mozilla, as well as the U.S. Chamber of Commerce. The California Supreme Court agreed to hear the case, briefing concluded in 2025, and a decision is still pending.
For businesses operating as ECS or RCS providers, the outcome matters. If the appellate court’s “business model” theory is upheld, providers whose revenue depends on accessing user data, not just storing it, may need to reassess whether SCA content protections apply to them at all.
What Counts as “Non-Content” Data Under the SCA
“Non-content” data relates to account activity without revealing the substance of any communication. It is often referred to as metadata, or data about the data. See Google v. United States, Misc. Case No. 23-67 (D.D.C. 2025) (noting that subpoenas may require a provider to disclose basic subscriber information such as name, address, payment information, session times, and IP addresses).
Examples of non-content data under the SCA:
- Subscriber information: Name, physical address, billing address, account number, payment method, and date the account was opened.
- Connection and session data: IP addresses used to log in or send messages, login and logout times, session duration, and device type. See In re Mert Karaman v. Turkcell Communication, 2023 WL 8242122 (N.D. Cal. 2023).
- Routing information: Email header information (excluding the subject line), and the source and destination of data packets. See Xie v. Laii, 2019 WL 7020340 (N.D. Cal. 2019) (permitting disclosure of email headers).
- Time and date stamps: When a communication was sent, received, or accessed.
- Volume of data: The size of a file, not its content.
- Transactional records: User activity logs, messaging logs, data transfer volume, and associated network addresses.
Metadata disputes come up often in litigation too, not just subpoena compliance. See our related piece, Metadata: Can’t Always Get What You Want, Sometimes You Get What You Need, for how courts treat metadata production requests under Rule 34.
What Legal Process Is Required to Disclose Content vs. Non-Content Data
The SCA generally prohibits ECS and RCS providers from voluntarily disclosing content, but the exact process required depends on who is requesting the data and what type of data is at issue. Government entities are often entitled to more information, through a lower evidentiary bar, than private civil litigants. For a step-by-step breakdown of the full response process, see our Complete Guide to Subpoena Compliance.
Civil Subpoenas
Courts issue subpoenas at the request of parties involved in civil litigation.
- Content is generally off-limits: An ECS or RCS provider cannot disclose the content of communications, such as the text of an email, in response to a civil subpoena alone.
- Non-content data is generally permissible: A provider may disclose non-content data, such as subscriber information or IP addresses, in response to a civil subpoena. See Google v. United States, Misc. Case No. 23-67 (D.D.C. 2025).
Not sure if the data you’re being asked for is content or non-content? Getting this distinction wrong can mean unlawfully disclosing protected communications, or unnecessarily withholding data you’re required to produce. Schedule a call or just reach out and we’ll review your specific request and tell you where you stand.
Governmental Requests (Law Enforcement/Administrative) and Court Orders:
These are issued by government agencies, including law enforcement, grand juries, or administrative bodies.
For content of communications:
- Warrant: Required to obtain content stored by an ECS provider for 180 days or less. This is the highest legal standard, mirroring the requirements for a physical search.
- Court order under 18 U.S.C. § 2703(d): Required for content stored by an ECS provider for longer than 180 days, or content held by an RCS provider regardless of age. This order requires specific and articulable facts showing reasonable grounds to believe the information sought is relevant and material to an ongoing criminal investigation.
- Subpoena alone is generally insufficient: See In the Matter of the Search of Content Stored at Premises Controlled by Google Inc., Case No. 16-mc-80263-RS (N.D. Cal. 2017) (holding that only basic subscriber information can be obtained by administrative subpoena).
For non-content data:
Government entities can typically obtain non-content data, such as subscriber name, address, payment information, session times, and IP addresses, through a less stringent process than that required for civil litigants, such as a grand jury or administrative subpoena. See Google v. United States, Misc. Case No. 23-67 (D.D.C. 2025).
The Emergency Exception
The SCA includes a limited exception for emergencies. If there is immediate danger of death or serious physical injury, an ECS or RCS provider may voluntarily disclose content or non-content data if there are reasonable grounds to believe the emergency exists. This exception is narrow and should be handled with immediate legal review.
User Consent
If the subscriber or user provides explicit, informed consent to disclosure, the provider is generally permitted to release the data.
Proactive Steps for SCA Compliance
Proactive preparation is a business’s best defense when a subpoena for customer information arrives. Documented internal procedures can prevent errors stemming from content versus non-content disclosure decisions.
- Maintain a data retention policy: Know what customer data your business collects, where it’s stored, who is responsible for it, and how long it’s retained.
- Centralize intake and tracking: Designate a single point of contact, such as Legal, Data Security, or Compliance, for receiving and logging all data requests and subpoenas.
- Identify your SCA classification: Determine whether your business functions as an ECS provider, an RCS provider, or both.
- Review your terms of service and privacy policy: Confirm they accurately reflect your data handling practices and align with your SCA obligations.
- Determine if the data type is properly requested: Review the subpoena to determine whether it seeks content or non-content data, and whether the request permits disclosure under the SCA.
- Verify legal process and service: Confirm the subpoena, court order, or data request meets the SCA’s requirements for the type of data sought and the issuing authority.
- Object to the request if necessary: You may have grounds to challenge a subpoena that is overly broad, lacks a proper legal basis, or improperly seeks cost-shifting. See You Subpoenaed My Documents, Shouldn’t You Pay for Them? for how courts have handled compliance cost disputes.
- Understand your duty to notify: Some state laws, contracts, or your own privacy policies may require notifying users when their data is sought, even where the SCA itself does not.
- Consult legal counsel: The SCA is complex and its application varies with the facts and evolving case law, including the pending Snap decision discussed above. When in doubt, consult legal help before responding to a subpoena for digital data.
A dedicated compliance workflow makes a real difference here. In one recent engagement, we helped a client clear a 20-subpoena backlog in two weeks using attorney-led review paired with AI-enabled intake and triage. Read the case study to see how it worked.
How to Work With Us or Learn More
Work with our team. If you’d like to discuss our Subpoena Response and Compliance Services and how we can streamline your subpoena response and data request workflows, reach out here.
Explore more subpoena compliance resources. Check out our Complete Guide to Subpoena Compliance or Subpoena Compliance Services: A Comprehensive Guide for Businesses for a deeper walkthrough of the intake, review, and production process. If you’re weighing a Fifth Amendment objection, see Can Your Client Claim the Fifth to Avoid a Document Subpoena?
Frequently Asked Questions
What is content under the Stored Communications Act? Content under the SCA is the substance of a communication, meaning the actual message conveyed. This includes email bodies and subject lines, chat text, voicemail recordings, and private files or documents that convey substantive information.
Is an email subject line considered content under the SCA? Yes. Courts have held that an email subject line is content under the SCA when it reveals information about the substance of the communication, as in Xie v. Laii (N.D. Cal. 2019).
Is an IP address considered content or non-content data? An IP address is non-content data under the SCA. It is treated as connection and session information rather than the substance of a communication, and is generally accessible under a lower legal threshold than content.
Can a business disclose the content of communications in response to a civil subpoena? Generally, no. An ECS or RCS provider cannot disclose the content of communications in response to a civil subpoena alone. Non-content data, such as subscriber information, can typically be disclosed in response to a civil subpoena.
What legal process is required for the government to obtain the content of communications? A warrant is required to obtain content stored for 180 days or less. For content stored longer, or held by a remote computing service, a court order under 18 U.S.C. § 2703(d) is typically required. An administrative subpoena alone is generally not sufficient to obtain content.
Can a user consent to disclosure of their communications under the SCA? Yes. If the user or subscriber provides explicit, informed consent, a provider is generally permitted to disclose the content of their communications.




