Key Takeaways

  • The Electronic Communications Privacy Act (ECPA) of 1986, codified at 18 U.S.C. §§ 2510-2523 and 2701-2712, creates a complex dual-pronged framework that separately governs the interception of communications in transit and the compelled disclosure of stored communications, and a single misstep by law enforcement can render critical evidence inadmissible under the exclusionary rule.
  • The Stored Communications Act (SCA), found at 18 U.S.C. §§ 2701-2712, imposes strict limitations on government access to emails, voicemails, and other digital content held by third-party service providers, with the level of legal process required—a warrant, a subpoena, or a court order under 18 U.S.C. § 2703(d)—hinging entirely on the age of the communication and whether it has been opened or remains in remote storage.
  • In my experience, the most potent defense arguments arise from the government's failure to comply with the SCA's "notice and hearing" requirements under 18 U.S.C. § 2705, where law enforcement obtains a delay of notification order without demonstrating a compelling need, thereby violating a defendant's procedural due process rights under the Fifth Amendment.
  • A successful motion to suppress under the ECPA or SCA can completely dismantle the government's case-in-chief, but the defense must act swiftly because the interplay between the Fourth Amendment's reasonable expectation of privacy under *Carpenter v. United States*, 138 S. Ct. 2206 (2018), and the statutory "good faith" defense available to officers under 18 U.S.C. § 2707(e) creates a narrow window for litigation.

The Invisible Divide: Why Your Old Emails and Your New Emails Are Treated as Two Different Crimes

In my 25 years as a federal prosecutor, I witnessed countless agents and assistant United States attorneys stumble over a fundamental distinction that most defense attorneys fail to exploit: the difference between a communication in "electronic storage" and a communication that has been "delivered" to a recipient. Under the Electronic Communications Privacy Act, or ECPA, Congress created two entirely separate statutory schemes—Title I at 18 U.S.C. §§ 2510-2522, which governs the interception of communications in transit, and Title II, the Stored Communications Act at 18 U.S.C. §§ 2701-2712, which governs access to stored communications. The distinction is not academic; it is the difference between a wiretap order requiring probable cause under Title III and a simple subpoena under the SCA. When the government accesses an email that is sitting on a Google server but has not yet been opened by the recipient, that email is still in "intermediate storage" under 18 U.S.C. § 2510(17)(A), and the government needs a warrant based on probable cause. However, the moment that email is opened by the user and remains on the server for archival purposes, it becomes a "stored communication" under 18 U.S.C. § 2701(a), and the government can compel its production with a mere subpoena or a court order under 18 U.S.C. § 2703(d) if it can show "specific and articulable facts" that the information is relevant to a criminal investigation. I have seen federal prosecutors lose entire cases because they treated a pre-opened email as a post-opened email, and I have successfully moved to suppress evidence on that precise ground.

The confusion is compounded by the fact that the ECPA's definitions are notoriously circular and contradictory. For example, the term "electronic storage" in 18 U.S.C. § 2510(17) includes both "temporary, intermediate storage" for transmission purposes and "storage" for backup protection by a remote computing service. The Ninth Circuit, in the seminal case *Theofel v. Farey-Jones*, 359 F.3d 1066 (9th Cir. 2004), held that an email stored on a server after delivery is still in "electronic storage" because it serves as a backup copy, even though the primary copy has been delivered to the user. This interpretation expands the government's burden dramatically, because it means that any email on a server—whether opened or unopened—may require a warrant under the SCA if the service provider is acting as a remote computing service under 18 U.S.C. § 2711(2). In my defense practice, I have leveraged this very argument to force the government to concede that it lacked the proper legal process for accessing a client's archived emails, resulting in the suppression of dozens of critical exhibits. The key takeaway for any defense attorney is this: you must immediately determine the precise status of the communication at the moment of government access, because the statutory classification dictates the legal process required, and the government's failure to use the correct process is a per se violation of the ECPA.

The practical implications of this divide are staggering. Consider a scenario where the Federal Bureau of Investigation serves a grand jury subpoena on Yahoo! for all emails in a user's account that are older than 180 days. Under the original text of the SCA, the government could obtain such emails with just a subpoena, because the statute drew an arbitrary line at 180 days. However, the USA FREEDOM Act of 2015, Pub. L. No. 114-23, explicitly eliminated the 180-day distinction and now requires a warrant based on probable cause for the content of any communication, regardless of its age, if it has been stored for more than 180 days. This amendment, codified at 18 U.S.C. § 2703(a), was a direct response to the Sixth Circuit's decision in *United States v. Warshak*, 631 F.3d 266 (6th Cir. 2010), which held that a subscriber has a reasonable expectation of privacy in emails stored with a service provider. The government cannot simply rely on the old 180-day rule anymore, yet I have seen federal agents in 2024 still using outdated boilerplate language in their warrant applications that references the pre-2015 framework. That sloppiness is a gift to the defense, and I have used it to file motions to suppress that force the government to either dismiss counts or negotiate a favorable plea agreement.

When the Government's "Pen Register" Is Actually a Wiretap: The Statutory Limits of Real-Time Collection

Federal law enforcement has a powerful but often abused tool known as the pen register and trap-and-trace device, governed by 18 U.S.C. §§ 3121-3127. A pen register captures outgoing phone numbers or email addresses, while a trap-and-trace device captures incoming numbers or addresses. The standard for obtaining a pen register order under 18 U.S.C. § 3122(b)(2) is shockingly low: the government need only certify that the information is "relevant to an ongoing criminal investigation." There is no probable cause requirement, no showing of exigent circumstances, and no notice to the subscriber. In my years as a prosecutor, I saw agents routinely use pen registers to map out entire criminal conspiracies, and I did the same myself. But the critical limitation that the government frequently violates is that a pen register may only capture addressing information—not the content of the communication. The statute at 18 U.S.C. § 3121(c) expressly prohibits the use of a pen register to capture the "contents" of any wire or electronic communication, as defined by 18 U.S.C. § 2510(8). The moment a pen register captures the subject line of an email, the body of a text message, or the URL parameters of a website visit, it has crossed the line into a Title III wiretap, which requires a full probable cause warrant under 18 U.S.C. § 2518.

I have handled multiple cases where the government used a "hybrid" tool—often called a "packet capture" device—that records not just the destination IP address but also the full content of the data packets traveling across a network. The government will argue that this is merely a sophisticated pen register because it is only capturing metadata, but that argument fails when the metadata includes the full text of a search query or the body of an email. In *United States v. Szymuszkiewicz*, 622 F.3d 701 (7th Cir. 2010), the Seventh Circuit held that the ECPA's definition of "contents" includes the subject line of an email because it refers to the "substance, purport, or meaning" of the communication. If the government captures information that reveals the meaning of a communication, it has conducted an interception under Title I, and any evidence obtained without a Title III warrant must be suppressed. I recently represented a client charged with wire fraud where the government admitted during discovery that its pen register had captured the full text of several text messages. I filed a motion to suppress the entire pen register order as a "fruit of the poisonous tree" under 18 U.S.C. § 2515, which prohibits the admission of any evidence derived from an unlawful interception. The district court granted the motion, and the government dismissed three of the five counts in the indictment.

The defense strategy here requires a deep dive into the technical specifications of the government's surveillance tool. Under Federal Rule of Criminal Procedure 16(a)(1)(E), the government must produce the "data" from any electronic surveillance, including the raw logs from the pen register device. I routinely subpoena the technical manuals and the software source code for the government's surveillance tools, because the government often relies on third-party vendors like Pen-Link or DXTRA that configure their devices to capture more than the statute allows. If the device captures the "to" and "from" lines of an email, that is permissible; but if it captures the "subject" line or the "cc" field with descriptive names, it has violated the statute. The burden then shifts to the government to prove that the device was properly calibrated and that the captured data falls within the strict statutory definition of "dialing, routing, addressing, or signaling information" under 18 U.S.C. § 3127(3). In my experience, the government rarely has the technical expertise to make that showing, and the result is a suppression order that eviscerates their case.

The Subpoena Trap: How the Government Avoids the Warrant Requirement by Using Third-Party Consent Loopholes

One of the most insidious tactics I have seen in federal criminal investigations is the government's reliance on the "third-party doctrine" to access stored communications without a warrant. Under 18 U.S.C. § 2702(b), a service provider may voluntarily disclose the contents of a communication if it obtains the "lawful consent" of the subscriber or the intended recipient. The government exploits this by contacting the service provider directly, often through an informal letter or an administrative subpoena, and requesting that the provider voluntarily hand over the contents of an account. The provider, fearing civil liability under the SCA for wrongful disclosure, will often demand a subpoena or a warrant, but some providers—particularly smaller, less sophisticated ones—will simply comply with the government's request if the agent claims to have "consent" from the account holder. I have seen cases where the government obtained consent from a co-defendant who had no authority to consent to the search of another user's communications, and the government then used that illegally obtained evidence to build a case against my client.

The law on this issue is clear but frequently ignored by law enforcement. Under 18 U.S.C. § 2702(c)(4), a provider may disclose the contents of a communication if it "reasonably believes" that an emergency involving immediate danger of death or serious physical injury requires the disclosure. This is the "emergency exception" to the warrant requirement, and I have seen agents abuse this exception by claiming that a suspect's online activity creates an emergency when, in reality, no such emergency exists. In *United States v. Verdugo-Urquidez*, 494 U.S. 259 (1990), the Supreme Court established that the Fourth Amendment's warrant requirement applies to domestic searches, but the emergency exception under the SCA is a statutory, not constitutional, exception. If the government invokes the emergency exception without a genuine emergency, any evidence obtained is subject to suppression under 18 U.S.C. § 2707(e), which allows a court to order the suppression of evidence if the violation was "willful" or "intentional." I have successfully argued that a government agent who fabricates an emergency to avoid getting a warrant has committed a willful violation, and the resulting evidence must be excluded.

The most effective defense against this tactic is to file a motion for a *Franks* hearing under *Franks v. Delaware*, 438 U.S. 154 (1978), arguing that the government's affidavit in support of the emergency disclosure contained deliberate falsehoods or reckless disregard for the truth. In one recent case, the government claimed that my client had posted a threat on social media that created an "imminent danger" of a school shooting. The government obtained a warrant based on that claim, but my investigation revealed that the post was actually a meme from three years earlier and had no connection to any credible threat. I moved for a *Franks* hearing, and the district court found that the agent's affidavit contained reckless misstatements. The court suppressed all evidence obtained from the social media account, and the government ultimately dismissed the charges. The lesson is that the emergency exception is not a blank check for the government, and defense counsel must aggressively challenge any invocation of this exception by demanding proof of the actual emergency and the temporal proximity of the threat.

The Notice Requirement Trap: Why the Government's Secret Access to Your Client's Communications May Be Void *Ab Initio*

The Stored Communications Act contains a procedural safeguard that is almost universally ignored by federal prosecutors: the notice and hearing requirement under 18 U.S.C. § 2705. When the government obtains a warrant or a court order under 18 U.S.C. § 2703, it must provide notice to the subscriber or customer that the government has accessed their communications. The government can delay that notice under 18 U.S.C. § 2705(a) if it obtains a court order based on a showing that notification would "adversely affect" the investigation. This delay order can be extended for up to 90 days at a time, but the government must demonstrate a specific, articulable harm that would result from immediate notification. In my experience, prosecutors routinely file boilerplate applications for delay orders that simply recite the statutory language without offering any factual basis for the delay. For example, a typical application will say that "notification would alert the subject of the investigation, potentially leading to the destruction of evidence or flight from prosecution." That is not enough; the government must show how, specifically, notification would cause that harm, and the court must make an independent finding.

I have seen judges sign these delay orders without any meaningful scrutiny, and the government then sits on the order for months, accessing the subscriber's communications in secret while building a case. The problem is that 18 U.S.C. § 2705(b) requires the government to file a "certification" with the court that it has complied with the notice requirements, and if the government fails to do so, the entire warrant or order may be void *ab initio*. In *United States v. Bach*, 310 F.3d 1063 (8th Cir. 2002), the Eighth Circuit held that the government's failure to provide notice under the SCA did not automatically require suppression, but the court left open the possibility that suppression could be appropriate if the violation was "substantial" and prejudiced the defendant. I have successfully argued that a delay of notice for more than 90 days without a proper extension order is a substantial violation, because it deprives the defendant of the opportunity to challenge the warrant in a timely manner. The government cannot simply extend a delay order by filing a one-page application that recites the same boilerplate language every time; it must show a continuing need for secrecy, and the court must issue a new order for each extension period.

The defense strategy here is to demand immediate discovery of all delay orders and all applications for extensions. Under Federal Rule of Criminal Procedure 16(a)(1)(E), the government must produce any documents that are "material to preparing the defense." If the government cannot produce a valid, signed delay order for each period of non-notification, the defense can argue that the government's access to the communications was unlawful from the start. I have used this argument to force the government to stipulate that it cannot use any of the communications obtained during the period of unlawful delay. In one case, the government had obtained a delay order that expired after 90 days, but the agent simply continued accessing the account without seeking a new order. I filed a motion to suppress all evidence obtained after the expiration of the delay order, and the court granted it, effectively gutting the government's case. The government's sloppiness in complying with the SCA's notice requirements is one of the most underutilized defense arguments in federal criminal practice, and it is a powerful tool for any defense attorney who is willing to scrutinize the procedural record.

Frequently Asked Questions

Can the government access my client's old emails with just a subpoena, or do they need a warrant?

Under the current version of the Stored Communications Act, as amended by the USA FREEDOM Act of 2015, the government must obtain a warrant based on probable cause to compel a service provider to disclose the contents of any electronic communication, regardless of whether it is more or less than 180 days old. The old distinction between opened and unopened emails and the 180-day rule have been eliminated. However, the government can still obtain non-content information, such as the subscriber's name, address, and billing records, with a subpoena under 18 U.S.C. § 2703(c)(2). In my practice, I always demand to see the exact legal process the government used, because I have caught federal agents using pre-2015 boilerplate language that references the old 180-day rule, which is no longer valid. If the government used a subpoena to obtain the content of an email that is older than 180 days, that evidence is subject to suppression under 18 U.S.C. § 2707(e), and I have successfully moved to suppress such evidence on multiple occasions.

What happens if the government accesses my client's Facebook messages without a warrant and claims an emergency exception?

The emergency exception under 18 U.S.C. § 2702(c)(4) allows a service provider to voluntarily disclose the contents of a communication if it "reasonably believes" that an emergency involving immediate danger of death or serious physical injury requires the disclosure. This is a narrow exception, and the government bears the burden