Contact Us Now

Have a questions? Let us know below and we will be in touch ASAP!

What is the Stored Communications Act? Understanding the SCA & Subpoena Compliance

The digital age long ago transformed how businesses operate and store information. From hosting information on cloud-based or internal servers, electronic data is the lifeblood of modern business. But with digital transformation comes legal complexity–especially when responding to subpoenas for electronic communications.

What many businesses might not realize is that customer data could be subject to a specific legal framework limiting disclosure of stored electronic communications – the Stored Communications Act (SCA). Failure to comply with the SCA when responding to subpoenas can lead to significant legal and financial repercussions, reputational damage, and even loss of customer trust.

When law enforcement serves a warrant or a civil litigant serves a subpoena seeking your company’s electronically stored information, is your organization prepared to properly respond?

This article covers the requirements of the Stored Communications Act, providing a foundational overview of its purpose, key definitions, and how it impacts your company’s subpoena compliance obligations. Understanding the requirements of the SCA is paramount to protecting your business and your customers’ sensitive information.

Understanding the Basics of the Stored Communications Act

Congress enacted the Stored Communications Act, 18 U.S.C. 2701, et seq, as Title II of the Electronic Communications Privacy Act (ECPA) of 1986. The primary purpose of the SCA is twofold: 1) to protect the privacy of stored electronic communications; and 2) outline the lawful procedures for government entities and civil litigants to access this data.

The ostensible goal of the ECPA is to extend wiretap restrictions to computer transmission of electronic data. The original wiretap statute was the Omnibus Crime Control and Safe Streets Act of 1968. With the prevalence of computer use by the 1980s, the original law became outdated and needed to be revised.

The SCA protects disclosure of digital and electronic communications. Or, as defined by the statute, “any transfer of signs, signals, writing, images, sounds, data, or intelligence of any nature transmitted in whole or in part by a wire, radio, electromagnetic, photoelectronic or photooptical system” held by third-party technology providers. 

The SCA Applies to “Electronic Communication Service Providers” and “Remote Computing Service Providers”

Whether the Stored Communication Act applies to a subpoena or data request depends on the type of organization to which it is directed. Specifically, the SCA applies to two types of service providers: Electronic Communication Service (ECS) Providers and Remote Computing Service (RCS) Providers:

Electronic Communication Service Providers: An ECS provider is any service that offers users the ability to send or receive wire or electronic communications.

    • Examples: Email providers (e.g., Gmail, Microsoft 365), instant messaging services (e.g., Slack, WhatsApp), telecommunication companies, and Internet Service Providers (ISPs)

Remote Computing Service Providers: An RCS provider offers computer storage or processing services by means of an electronic communication system. These are typically services that store data for later retrieval or processing.

      • Examples: Cloud storage providers (e.g., Dropbox, Google Drive), online cloud computing services (e.g., Microsoft Azure, Amazon S3), and virtual server hosting.

It’s crucial to understand that a single entity can function as both an ECS and an RCS provider, depending on the specific service or data in question. See e.g. Low v. LinkedIn Corp., 900 F. Supp. 2d 1010, 1023 (N.D. Cal. 2012)(Noting that companies can be both ECS and RCS providers). For instance, an email provider stores emails (RCS function) but also facilitates their sending and receiving (ECS function). An organization’s role as an ECS or RCS provider dictates its legal obligations under the SCA.

Content vs. Non-Content Data – Generally, Content Data May Not Be Produced

Once it is determined that a business is an Electronic Communication Service or Remote Computing Service provider, the next question is: what can be turned over when responding to a subpoena or law enforcement request for information?

The short answer is, sometimes, not much. The starting point under the SCA is that turning over the contents of electronic communications is prohibited unless the user consents or there is an exception under the SCA permitting disclosure.

Understanding the difference between the “content” of a communication and its “non-content” or “transactional” portions is key to SCA compliance. This difference determines the legal process required for lawful disclosure.

“Content” of a Communication: This refers to any information concerning the substance or meaning of a communication. It’s the actual message being conveyed.

    • Examples: The text of an email, the audio of a voicemail, the back and forth of a chat message, attached files, or the subject line of an email if it conveys substantive meaning.

    • Privacy Protection: Content data receives the highest level of privacy protection under the SCA.

“Non-Content” or “Transactional” Data: This encompasses information that describes a communication or account activity but does not reveal its substance. It is Metadata about the communication.

    • Examples: Sender and receiver email addresses, IP addresses used to send or access communications, timestamps (date and time communication was sent or received), size of a file, routing information, login/logout times, and subscriber account information .

    • Privacy Protection: Non-content data generally has a lower level of privacy protection compared to content.

Understanding the distinction between content and non-content data is vital for businesses responding to subpoenas. The type of data requested in a third-party subpoena directly dictates the specific legal process required for a lawful disclosure. Misclassifying data can lead to improper disclosure or, conversely, unlawful withholding.

How the Stored Communications Act Impacts Subpoena Response and Compliance

The SCA generally prohibits ECS and RCS providers from voluntarily disclosing the content of stored electronic communications. As noted above, disclosure is only permitted under specific exceptions. This ensures that individuals’ digital privacy is safeguarded against arbitrary access.

Understanding what disclosures are permissible under the SCA is complex, as the required legal process varies depending on who is issuing the request and what type of data is being sought. For instance, the government is often entitled to more information than a private civil litigant.

Civil Subpoenas:

These are issued by courts upon the request of parties involved in civil litigation.

    • Disclosure of the Content of Communications Prohibited: Generally, an ECS or RCS provider cannot disclose the content of communications in response to a civil subpoena (e.g., the actual text of an email).

    • Disclosure of Non-Content Data Permissible: Non-content data (e.g., subscriber information, IP addresses) may be disclosed by an ECS or RCS provider in response to a civil subpoena. See, e.g. Google v. United States,  Misc. Case No. 23-67 (D. D.C. 2025) (Noting that [the  SCA] provides a sliding scale of protections and data requests by subpoena “require a service provider to disclose certain basic subscriber information and content.”)

Governmental Requests (Law Enforcement/Administrative) and Court Orders:

These are issued by government agencies, including law enforcement (e.g., FBI, grand juries, or administrative bodies).

    • For “Content” of Communications:
        • Warrant: A probable cause search warrant is generally required for the content of communications stored by an ECS provider for 180 days or less. This is the highest legal standard, mirroring the requirements for physical searches.

        • Court Order (18 U.S.C. § 2703(d)): For the content of communications stored by an ECS provider older than 180 days, or by an RCS provider (regardless of age), a specific court order issued under 18 U.S.C. § 2703(d) is typically required. This order demands “specific and articulable facts showing that there are reasonable grounds to believe that the contents of a wire or electronic communication, or the records or other information sought, are relevant and material to an ongoing criminal investigation.”

    • For “Non-Content” Data:
        • Government entities can often obtain non-content data (e.g., subscriber name, address, payment information, session times, IP addresses) with a less stringent legal process than that required for civil litigants, such as a grand jury subpoena or administrative subpoena.  See Google v. United States,  Misc. Case No. 23-67 (D. D.C. 2025) (“the Government may by ‘subpoena’ require a service provider to disclose certain basic subscriber information and content.”)

    • Emergency Disclosure: The SCA includes a limited exception for emergency situations. If there is an immediate danger of death or serious physical injury, an ECS or RCS provider may voluntarily disclose content or non-content data if there are reasonable grounds to believe the emergency exists. This is a narrow exception and should be handled with extreme caution and immediate legal review.

User Consent as an Exception:

If the subscriber or user of the electronic communication service or remote computing service provides explicit, informed consent to the disclosure, then the provider is generally permitted to release the data.  

Subpoena Response Best Practices for SCA Compliance

Proactive preparation is advisable when dealing with subpoenas for digital data. Developing internal subpoena compliance and data request procedures can save your business from costly errors and legal entanglements.

Implement a Robust Subpoena Response Protocol:

    • Develop a Clear Data Retention Policy: Understand what electronic data your business collects, where it’s stored (on-premise, cloud, third-party services), who owns it, and for how long it is retained. This knowledge is key to quickly and accurately responding to data requests.
    • Centralized Intake and Tracking: Designate a specific individual or department (e.g., Legal, Data Security, Compliance) as the sole point of contact for receiving and logging all legal requests.
    • Identify Your Organization’s SCA Classification: Clearly determine if your business functions as an ECS provider or an RCS provider (or both). This is the first step in understanding your obligations under the Stored Communications Act.
    • Understand Your Terms of Service/Privacy Policy: Regularly review and update your company’s terms of service and privacy policy to ensure they accurately reflect your data handling practices and align with your SCA obligations. Transparency with users can be a significant asset.
    • Determine if Data Type is Properly Requested: Review the subpoena or data request to ascertain whether it is for “content” or “non-content.” Then determine if the nature of the request permits its disclosure under the SCA (i.e. if content of communication is requested, was the request made by warrant or with the informed consent of a participant?).
    • Verify Legal Process: Examine the subpoena, court order or data request to ensure it meets the SCA’s specific requirements for the type of data requested and the issuing authority.
    • Challenge the Request if Necessary: You may have grounds to object to a subpoena or challenge the request (e.g., if it’s overly broad or lacks proper legal basis).
    • Duty to Notify: While required under the SCA in certain situations, but not in others, some state laws, contractual agreements, or even your own privacy policies may impose a duty to notify users when their data is being sought via legal process.
    • Consult Legal Counsel or Other Experts: The SCA is complex, and its application can vary based on specific facts and evolving case law. When in doubt – or whenever a subpoena for digital data is received consult legal help, or other experts to assist with the handing of subpoenas.  Mishandling information subject to the SCA can be significantly more costly than planning ahead.

How to Work With Us or Learn More

Work with our Company: If you would like to discuss our Subpoena Response and Compliance Services and how we can work together to streamline your subpoena response and data request workflows, please reach out here.

Check out our Subpoena Resources Page: If you are interested in learning more about subpoena compliance, regulations and laws related to data requests like the Stored Communication Act or how to leverage subpoena software, check out our Subpoena Compliance Articles Page.

Percipient Logo

Streamline your Subpoena Response Workflow

Get in touch with us to learn more about our Subpoena Response and Compliance Services

Related Posts

Percipient helps legal teams efficiently and accurately handle legal matters with human in the loop technology.

Services
  • Contract Review
  • Managed Review
  • Subpoena Compliance
  • EDiscovery & Digital Forensics
Resources
  • Articles
  • Technically Legal Podcast
Company
  • About us
  • Privacy Policy

© Percipient LLC. All Rights Reserved.