
Enacted in 1986 and embedded within the broader Electronic Communications Privacy Act, the SCA remains one of the most consequential digital privacy statutes on the books. As data breaches multiply and corporate surveillance expands, understanding this law has never mattered more. Contact our lawyers to discuss related cases.
The Stored Communications Act governs how electronic communications held in storage can be accessed and used. The law prohibits unauthorized access to emails, private messages, voicemails, and other communications that are stored with a third-party service provider like Gmail, iCloud, Slack, or your internet service provider.
Congress crafted the SCA to fill the gap of transmitted communications and give stored digital communications a shield against both government overreach and private misconduct.
The statute applies primarily to Electronic Communication Services (ECS) and Remote Computing Services (RCS). An ECS provides users the ability to send or receive electronic communications. Your email provider is the classic example. An RCS stores or processes data on behalf of users. Cloud storage platforms like Dropbox or Google Drive fit squarely in this category.
The SCA imposes obligations on both types of providers, restricting when and how they can hand over your data. Crucially, it also creates liability for anyone who accesses that stored data without lawful authorization.
The SCA makes it unlawful to intentionally access a facility through which an electronic communication service is provided, and thereby obtain or prevent authorized access to stored electronic communications. It also prohibits service providers from voluntarily disclosing the contents of stored communications to parties not entitled to receive them. On the civil side, victims of SCA violations may recover:
Despite its age, the SCA regularly surfaces in modern disputes. The following scenarios represent the most common contexts in which SCA claims arise today:
Companies that aggregate communications data or share communication contents through API integrations face genuine SCA exposure, particularly when their terms of service fail to clearly authorize such uses.
Courts have grappled with whether reading email content for advertising targeting constitutes "access" under the statute, and whether automated scanning differs legally from human review. These questions remain actively litigated, making legal counsel essential for anyone navigating an SCA dispute.
Data privacy law is the foundation of many of our cases. The Lyon Firm has built its reputation by aggressively protecting individuals and businesses whose digital privacy rights have been violated, and the Stored Communications Act is a cornerstone of that work.
When you retain The Lyon Firm, you gain a legal team that combines deep statutory knowledge with litigation experience in both federal and state courts. We know how privacy cases are won and lost and the theories most likely to move a jury or secure a favorable settlement.
Does the SCA protect my text messages?
Text messages stored by your carrier or on a cloud backup service can fall under SCA protection. However, messages still being transmitted in real-time are governed by a separate provision of the Electronic Communications Privacy Act known as the Wiretap Act. Courts continue to refine where the line between "in transit" and "in storage" falls for modern messaging platforms, making case-specific analysis critical.
Can I sue my employer under the SCA for reading my personal emails?
If your employer accessed your personal email account without your authorization, that access may constitute an SCA violation. The key legal questions are whether the account qualifies as an electronic communication service and whether your employer had actual authorization.
What is the statute of limitations for an SCA claim?
The SCA provides a two-year statute of limitations, running from the date on which the claimant first discovered the violation.
Does the SCA apply to social media messages?
Courts have increasingly held that private messages sent through social media platforms can fall within the SCA's scope, since those platforms qualify as electronic communication service providers.
What's the difference between the SCA and CCPA?
The SCA is a federal criminal and civil statute specifically targeting unauthorized access to stored communications. The CCPA (California) is a broader consumer data protection framework governing how businesses collect and share personal data. Many of The Lyon Firm's cases involve overlapping claims under multiple statutes, which is why comprehensive legal analysis matters from the outset.
What evidence do I need to bring an SCA case?
Successful SCA claims typically require evidence establishing: (1) that the defendant intentionally accessed a facility providing an electronic communication service; (2) that the access was unauthorized or exceeded authorization; and (3) that stored communications were obtained, altered, or blocked as a result. The Lyon Firm works with technical experts to build the evidentiary record necessary to support your claim.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: