11.3 Electronic Data, Social Media & Communications Account Records
Key Takeaways
- The Stored Communications Act (18 U.S.C. § 2702) bars providers from disclosing the contents of stored communications, and California's O'Grady v. Superior Court (2006) 139 Cal.App.4th 1423 holds that a civil subpoena cannot compel a provider to produce email content.
- Penal Code § 502, California's Comprehensive Computer Data Access and Fraud Act, criminalises knowingly accessing a computer, system, or data without permission — using a subject's password, even one supplied by a spouse, is the classic violation.
- Penal Code § 638 makes it an offence to purchase, sell, or obtain by fraud or deceit any telephone calling pattern record, punishable by a fine up to $2,500 and/or a year in county jail, and § 638(b) makes information so obtained inadmissible.
- Penal Code § 638.51 bars any person from installing or using a pen register or trap and trace device without a court order, with a fine not exceeding $2,500 for a violation.
- Publicly visible social media content is lawfully collected; creating a false identity to gain access is pretexting that risks Penal Code § 502, breach of the platform's terms, and the dishonesty grounds in BPC § 7561.1.
Electronic Data, Social Media & Communications Account Records
Core Regulatory Standard: Knowledge statement K46 asks for the laws regarding accessing electronic data, social media, and phone accounts. The organising idea is a three-tier model: open material anyone can see, provider-held material only the provider or a court can release, and device or account material that requires the owner's genuine authority. Crossing a tier without lawful authority is not a civil misstep in California; it is a crime under Penal Code § 502, Penal Code § 638, or both.
The Three Tiers
+---------------------------------------------------------------------------+
| TIER 1 OPEN SOURCE Public profiles, public posts, indexed pages, |
| court and property records, public registries |
| -> Collect freely; preserve properly |
+---------------------------------------------------------------------------+
| TIER 2 PROVIDER-HELD Email contents, direct messages, cloud files, |
| call detail records, subscriber data |
| -> Provider consent, party consent, or court |
+---------------------------------------------------------------------------+
| TIER 3 DEVICE/ACCOUNT Phones, laptops, cloud accounts, password-gated |
| areas |
| -> Owner's genuine authority, or forensic order |
+---------------------------------------------------------------------------+
Tier 1 — Open Source: Lawful, but Preserve It Properly
Anything genuinely public may be collected. The professional risk here is evidentiary, not criminal. A screenshot pasted into a report is weak; a defensible capture records the full URL, the capture date and time with time zone, the capturing tool or method, and a hash of the saved file, and is supported by a declaration under Code of Civil Procedure § 2015.5. Authentication then runs through Evidence Code § 1400, and California courts have been demanding about social media authentication because content is trivially fabricated.
Two limits apply even in Tier 1:
- Aggregation is not neutral. Compiling scattered public data into a dossier that reveals a protected person's location can facilitate stalking and is the precise harm the intake screening in Content Area 2A exists to catch.
- Do not confuse "publicly viewable" with "publicly posted." Content visible only because a friend of the subject has lax settings, or because you were logged in as someone the subject accepted, is not open source.
Tier 2 — Provider-Held Content: The Stored Communications Act Wall
The Stored Communications Act (18 U.S.C. §§ 2701–2712) does two things that matter to investigators. Section 2701 criminalises intentionally accessing a facility through which an electronic communication service is provided without authorisation, or exceeding authorisation, to obtain stored communications. Section 2702 prohibits providers from knowingly divulging the contents of communications, with narrow exceptions including the lawful consent of the originator or intended recipient.
California case law makes the practical consequence explicit. In O'Grady v. Superior Court (2006) 139 Cal.App.4th 1423, the Court of Appeal held that the SCA barred enforcement of a civil subpoena seeking the contents of stored email from a service provider. The takeaway is blunt: you cannot subpoena Google, Meta, or a carrier for message content in a civil case. The lawful routes are:
- Consent of a party to the communication — most commonly, the client produces their own account contents.
- Discovery from the opposing party, who can be compelled to produce their own messages.
- A court order in a criminal matter, obtained by law enforcement.
Non-content records — subscriber identity, IP logs, call detail — sit on a slightly different footing under § 2703, but civil litigants still generally cannot reach them directly from the provider.
Telephone Records: Penal Code § 638
California enacted a dedicated statute after the phone-record pretexting scandals of the mid-2000s. Penal Code § 638(a) punishes any person who purchases, sells, offers to purchase or sell, or conspires to purchase or sell any telephone calling pattern record or list without the written consent of the subscriber, and any person who procures or obtains through fraud or deceit such a record — by a fine not exceeding $2,500, imprisonment in county jail not exceeding one year, or both, rising to $10,000 for a prior conviction. Section 638(b) makes personal information so obtained inadmissible in any judicial, administrative, legislative, or other proceeding except in a prosecution for violating the section.
That statute closes the door on the entire "phone records available, no questions asked" corner of the vendor market. Buying call detail from a data broker who cannot show subscriber written consent exposes the purchaser, not merely the seller.
Pen Registers and Trap-and-Trace: Penal Code § 638.51
Penal Code § 638.51(a) provides that, except for specified provider self-help uses in subdivision (b), a person may not install or use a pen register or a trap and trace device without first obtaining a court order under § 638.52 or § 638.53. The provider exceptions cover operating and testing the service, protecting the provider's rights or property, protecting users from abuse, recording completion to prevent fraud, and use with the consent of the user. A violation is punishable by a fine not exceeding $2,500. Nothing in the section creates a private investigator route.
Tier 3 — Devices and Accounts: Penal Code § 502
California's Comprehensive Computer Data Access and Fraud Act, Penal Code § 502, is broader than the federal Computer Fraud and Abuse Act (18 U.S.C. § 1030) and is the statute an investigator is most likely to trip over. Section 502(c) makes it an offence knowingly and without permission to access, copy, use, alter, damage, or delete any data, computer, computer system, or computer network, and separately to provide or assist in providing a means of access. Section 502(e) creates a civil action for compensatory damages, injunctive relief, and — where the violation is wilful and oppressive, fraudulent, or malicious — punitive damages and attorney's fees.
The recurring fact patterns:
| Scenario | Analysis |
|---|---|
| Spouse supplies the other spouse's email password and asks you to log in | The account holder has not given permission. Access is "without permission" as to that holder; § 502 exposure plus SCA § 2701 exposure. |
| Client owns the company; asks you to review an employee's work email | Generally lawful where the employer owns the system and has a policy putting employees on notice; document the ownership and the policy. |
| Client hands you the subject's unlocked phone found in a shared home | Ownership, not physical possession, controls. Absent the owner's authority, do not access. |
| Spyware or a keylogger installed on the subject's device | § 502, plus Penal Code § 632 if it captures audio, plus civil liability. Never. |
| Wi-Fi credential guessing or shoulder-surfed passwords | Access without permission. |
Social Media: Pretexting and the Represented-Party Rule
Creating a fictitious profile to send a friend request to a subject is the most commonly asked social media question, and the answer has four independent problems:
- Access without permission. The subject grants access to the persona, not to you. Where the persona is the mechanism of access, § 502 is squarely in play.
- Terms of service. Every major platform prohibits false identities; the breach supports both a § 502 "without permission" argument and a credibility attack on the investigator at trial.
- Professional-conduct spillover. Where a lawyer directs the work, California Rule of Professional Conduct 4.2 bars communication with a represented party about the subject of the representation, and Rule 5.3 and Rule 8.4(a) extend responsibility to the lawyer's non-lawyer agents. An investigator's friend request to a represented plaintiff can disqualify counsel.
- Evidentiary cost. Evidence gathered through a false persona invites a motion in limine and hands opposing counsel a character attack that outlasts the exhibit.
Lawful alternatives: collect what is public; obtain content from the client's own accounts; obtain it in discovery from the opposing party; and where the subject's own posts are the target, preserve the public versions promptly, because deletion is common once litigation is anticipated.
Case Example: The Helpful Password
Scenario: A client in a dissolution matter gives the investigator her husband's email password, saying "it's our family account, I've always known it." The investigator logs in from the office and downloads three months of messages showing a hidden bank account. The client asks that the messages go into the report.
Analysis. The account holder is the husband; his lack of diligence in changing a password is not permission. Logging in is knowingly accessing a computer system and data without permission under Penal Code § 502(c), exposing the investigator to criminal liability and to a civil action under § 502(e) including punitive damages and fees. It is also intentional access to a facility providing electronic communication service to obtain stored communications under SCA § 2701. Delivering the messages to the client compounds the problem, and putting them in a report offered to a court risks the report being excluded and the client's case being tainted.
The compliant version. The hidden account is discoverable by lawful means: a judgment-debtor-style examination is unavailable pre-judgment, but formal discovery, a deposition subpoena for the husband's own records, and forensic accounting of joint filings all reach the same fact. Advise counsel; do not log in.
A client in a family law matter provides the investigator with the opposing spouse's email password and asks the investigator to review the account. What is the correct analysis?
An investigator wants email content from a subject's Gmail account in a civil case. Which route is lawful?
A vendor offers to sell an investigator a subject's mobile call detail records, with no subscriber authorisation. Under California law, what is the consequence of buying them?
An investigator creates a fictitious social media profile and sends a friend request to a represented plaintiff in pending litigation. Which consequence does NOT follow?