What is the Stored Communications Act?

Written by 
Published on:
March 10, 2026
Updated on:
April 23, 2026

Enacted in 1986 and embedded within the broader Electronic Communications Privacy Act, the SCA remains one of the most consequential digital privacy statutes on the books. As data breaches multiply and corporate surveillance expands, understanding this law has never mattered more. Contact our lawyers to discuss related cases.

What Is the Stored Communications Act?

The Stored Communications Act governs how electronic communications held in storage can be accessed and used. The law prohibits unauthorized access to emails, private messages, voicemails, and other communications that are stored with a third-party service provider like Gmail, iCloud, Slack, or your internet service provider.

Congress crafted the SCA to fill the gap of transmitted communications and give stored digital communications a shield against both government overreach and private misconduct.

Who Does the SCA Cover?

The statute applies primarily to Electronic Communication Services (ECS) and Remote Computing Services (RCS). An ECS provides users the ability to send or receive electronic communications. Your email provider is the classic example. An RCS stores or processes data on behalf of users. Cloud storage platforms like Dropbox or Google Drive fit squarely in this category.

The SCA imposes obligations on both types of providers, restricting when and how they can hand over your data. Crucially, it also creates liability for anyone who accesses that stored data without lawful authorization.

What Does the SCA Actually Prohibit?

The SCA makes it unlawful to intentionally access a facility through which an electronic communication service is provided, and thereby obtain or prevent authorized access to stored electronic communications. It also prohibits service providers from voluntarily disclosing the contents of stored communications to parties not entitled to receive them. On the civil side, victims of SCA violations may recover:

  • Actual damages suffered as a result of the violation
  • Statutory damages of no less than $1,000 per violation
  • Punitive damages where the defendant acted with a culpable mental state
  • Attorney's fees and litigation costs

Common Real-World SCA Violations

Despite its age, the SCA regularly surfaces in modern disputes. The following scenarios represent the most common contexts in which SCA claims arise today:

  • Employer Access to Employee Communications Employers who access workers' personal email accounts, private messages, or cloud storage without explicit authorization frequently run afoul of the SCA. Courts have consistently held that a company's ownership of a device does not automatically confer the right to access personal accounts accessed through it.
  • Data Broker and Third-Party Disclosures When service providers share the contents of stored communications with data brokers or analytics firms without proper user consent, they may be violating the SCA's disclosure provisions.
  • Government Overreach Without Proper Legal Process Law enforcement agencies must follow strict procedures before compelling a provider to disclose the contents of stored communications. Accessing stored data through improper subpoenas or informal pressure on providers can constitute an SCA violation.
  • Domestic and Intimate Partner Surveillance Installing spyware or accessing an ex-partner's email account without consent are actionable under the SCA. Courts have awarded significant damages in these cases.

The SCA and Corporate Data Practices

Companies that aggregate communications data or share communication contents through API integrations face genuine SCA exposure, particularly when their terms of service fail to clearly authorize such uses.

Courts have grappled with whether reading email content for advertising targeting constitutes "access" under the statute, and whether automated scanning differs legally from human review. These questions remain actively litigated, making legal counsel essential for anyone navigating an SCA dispute.

Why Choose The Lyon Firm for Your SCA Case?

Data privacy law is the foundation of many of our cases. The Lyon Firm has built its reputation by aggressively protecting individuals and businesses whose digital privacy rights have been violated, and the Stored Communications Act is a cornerstone of that work.

When you retain The Lyon Firm, you gain a legal team that combines deep statutory knowledge with litigation experience in both federal and state courts. We know how privacy cases are won and lost and the theories most likely to move a jury or secure a favorable settlement.

Frequently Asked Questions About the Stored Communications Act

Does the SCA protect my text messages?

Text messages stored by your carrier or on a cloud backup service can fall under SCA protection. However, messages still being transmitted in real-time are governed by a separate provision of the Electronic Communications Privacy Act known as the Wiretap Act. Courts continue to refine where the line between "in transit" and "in storage" falls for modern messaging platforms, making case-specific analysis critical.

Can I sue my employer under the SCA for reading my personal emails?

If your employer accessed your personal email account without your authorization, that access may constitute an SCA violation. The key legal questions are whether the account qualifies as an electronic communication service and whether your employer had actual authorization.

What is the statute of limitations for an SCA claim?

The SCA provides a two-year statute of limitations, running from the date on which the claimant first discovered the violation.

Does the SCA apply to social media messages?

Courts have increasingly held that private messages sent through social media platforms can fall within the SCA's scope, since those platforms qualify as electronic communication service providers.

What's the difference between the SCA and CCPA?

The SCA is a federal criminal and civil statute specifically targeting unauthorized access to stored communications. The CCPA (California) is a broader consumer data protection framework governing how businesses collect and share personal data. Many of The Lyon Firm's cases involve overlapping claims under multiple statutes, which is why comprehensive legal analysis matters from the outset.

What evidence do I need to bring an SCA case?

Successful SCA claims typically require evidence establishing: (1) that the defendant intentionally accessed a facility providing an electronic communication service; (2) that the access was unauthorized or exceeded authorization; and (3) that stored communications were obtained, altered, or blocked as a result. The Lyon Firm works with technical experts to build the evidentiary record necessary to support your claim.

Contact Us

Request a Free Consultation

Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there:

  • It begins with a few simple questions about your situation.
  • From there, a member of our legal team reviews your case.
  • Together, we’ll chart the path forward, helping you take the next step toward resolution.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.