Back to Frameworks

US Stored Communications Act (18 USC 2701-2713)

United States (federal)
vUnited States Code 2024 edition (govinfo), chapter 121 as last amended by Pub. L. 115-141 (CLOUD Act, 2018); no later amendment to 2701 to 2713 found
3 domains
12 controls

The federal Stored Communications Act: no unauthorized access to a communication service to obtain stored email or messages (employers may authorize access to the systems they provide, and users to their own messages); limits on public providers disclosing contents and customer records; provider duties to preserve, back up, keep government demands confidential and answer them wherever data is stored. 18 U.S.C. 2701 to 2713.

Verified

US Stored Communications Act (18 USC 2701-2713) is a compliance framework from United States (federal) with 3 domains and 12 controls. The largest domains are Provider duties on government process – US Stored Communications Act (18 USC 2701-2713) (6 controls), Access to stored communications – US Stored Communications Act (18 USC 2701-2713) (3 controls), Provider disclosure limits – US Stored Communications Act (18 USC 2701-2713) (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (3)

Access to stored communications – US Stored Communications Act (18 USC 2701-2713)

3 controls
Controls in the Access to stored communications – US Stored Communications Act (18 USC 2701-2713) domain of US Stored Communications Act (18 USC 2701-2713) — 3 controls
CodeTitle
us-stored-communications-act-18-usc-2701-2713::2701(a)2701(a) Do not access a communication service facility without authorization to reach stored communications
us-stored-communications-act-18-usc-2701-2713::2701(c)(1)2701(c)(1) Authorization by the service provider: access to the employer's own communication service
us-stored-communications-act-18-usc-2701-2713::2701(c)(2)2701(c)(2) Authorization by the user for that user's own communications

Provider disclosure limits – US Stored Communications Act (18 USC 2701-2713)

3 controls
Controls in the Provider disclosure limits – US Stored Communications Act (18 USC 2701-2713) domain of US Stored Communications Act (18 USC 2701-2713) — 3 controls
CodeTitle
us-stored-communications-act-18-usc-2701-2713::2702(a)(1)2702(a)(1) Public ECS providers: do not divulge stored communication contents
us-stored-communications-act-18-usc-2701-2713::2702(a)(2)2702(a)(2) Public RCS providers: do not divulge contents carried or maintained for customers
us-stored-communications-act-18-usc-2701-2713::2702(a)(3)2702(a)(3) Public providers: do not give customer records to a governmental entity except as allowed

Provider duties on government process – US Stored Communications Act (18 USC 2701-2713)

6 controls
Controls in the Provider duties on government process – US Stored Communications Act (18 USC 2701-2713) domain of US Stored Communications Act (18 USC 2701-2713) — 6 controls
CodeTitle
us-stored-communications-act-18-usc-2701-2713::2703(f)2703(f) Preserve records and evidence on a governmental request for 90 days, renewable
us-stored-communications-act-18-usc-2701-2713::2704(a)2704(a) Create and keep a backup copy when a subpoena or order requires it
us-stored-communications-act-18-usc-2701-2713::2705(b)2705(b) Do not notify anyone of a warrant, subpoena or order while a preclusion order is in force
us-stored-communications-act-18-usc-2701-2713::2709(a)2709(a) Comply with FBI national security letters for subscriber and toll records
us-stored-communications-act-18-usc-2701-2713::2709(c)2709(c) Do not disclose that the FBI sought or obtained records when a nondisclosure certification applies
us-stored-communications-act-18-usc-2701-2713::27132713 Preserve and disclose regardless of where the data is stored

What is US Stored Communications Act (18 USC 2701-2713) and who does it apply to?

US Stored Communications Act (18 USC 2701-2713) is a compliance framework from United States (federal) with 3 domains and 12 controls. The federal Stored Communications Act: no unauthorized access to a communication service to obtain stored email or messages (employers may authorize access to the systems they provide, and users to their own messages); limits on public providers disclosing contents and customer records; provider duties to preserve, back up, keep government demands confidential and answer them wherever data is stored. 18 U.S.C. 2701 to 2713. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does US Stored Communications Act (18 USC 2701-2713) actually require?

US Stored Communications Act (18 USC 2701-2713) has 12 controls organised across 3 domains. The largest domains are Provider duties on government process – US Stored Communications Act (18 USC 2701-2713) (6 controls), Access to stored communications – US Stored Communications Act (18 USC 2701-2713) (3 controls), Provider disclosure limits – US Stored Communications Act (18 USC 2701-2713) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of US Stored Communications Act (18 USC 2701-2713) do I already cover?

US Stored Communications Act (18 USC 2701-2713) does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement US Stored Communications Act (18 USC 2701-2713)?

Start your US Stored Communications Act (18 USC 2701-2713) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Stored Communications Act (18 USC 2701-2713) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 12 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 849 frameworks.

Get Started Free →

Free forever — no credit card required