Texas unlawful access to stored communications — Penal Code § 16.04
Unlawful access to stored communications under Texas Penal Code § 16.04 is a Class A misdemeanor — intentionally accessing (or exceeding your authorization to access) a facility that stores wire or electronic communications, and thereby obtaining, altering, or blocking a message in electronic storage. It becomes a state jail felony when done to obtain a benefit or to harm another.
Free, Confidential Case Review
Tell us what happened. A defense attorney reviews every submission — usually within an hour, day or night.
Classification: Class A misdemeanor at the base grade; state jail felony if committed to obtain a benefit or with intent to harm another
Punishment range: up to 1 year in county jail and a fine up to $4,000 (Class A); 180 days to 2 years in a state jail and a fine up to $10,000 (state jail felony)
The controlling statute
Section 16.04 sits in Chapter 16 of the Penal Code — Criminal Instruments, Interception of Wire or Oral Communication, and Installation of Tracking Device. It is the state-law twin of the federal Stored Communications Act, 18 U.S.C. § 2701, and it borrows that statute’s structure almost word for word. Section 16.04(a) provides:
“A person commits an offense if the person obtains, alters, or prevents authorized access to a wire or electronic communication while the communication is in electronic storage by: (1) intentionally obtaining access without authorization to a facility through which a wire or electronic communications service is provided; or (2) intentionally exceeding an authorization for access to a facility through which a wire or electronic communications service is provided.” — Tex. Penal Code § 16.04(a)
Two things separate this offense from every other privacy crime in the code. First, the target is a communication that is at rest — sitting in “electronic storage” — not one being captured live off the wire. Second, the crime is committed against a facility through which a service is provided, meaning a provider’s system, not the device in your hand. Section 16.04 does not define its own terms; like the rest of Chapter 16, it draws them from the electronic-surveillance provisions the Legislature placed in the Code of Criminal Procedure (now Chapter 18A, formerly Article 18.20), and subsection (d) cross-references Chapter 18B for lawful, court-authorized access.
What conduct does § 16.04 actually criminalize?
The statute reaches two distinct paths to the same result: an outsider who breaks in, and an insider who goes too far. Under (a)(1), a person with no right of entry intentionally gets into the provider’s facility. Under (a)(2), a person who does have some authorization intentionally exceeds it. Either way, the person must thereby obtain, alter, or prevent authorized access to a stored message.
In everyday terms, that covers logging into someone else’s webmail with a guessed or stolen password, using a former employer’s credentials to pull messages after access was revoked, resetting a partner’s account to read stored texts or direct messages, or an employee with limited system rights reaching into a mailbox they were never assigned. What it does not cover is the far more common scenario of picking up an unlocked phone and scrolling through it: as the Fifth Circuit has explained under the federal analog, data an individual keeps on a personal handset or hard drive generally is not held “in electronic storage” by a service-provider facility at all.1 That distinction narrows § 16.04 in a way many people, and some charging instruments, overlook.
Classification & punishment range
Grading is a simple two-step. The base offense is a Class A misdemeanor. It climbs one level — to a state jail felony — only when the State proves an additional aggravating purpose: the access was committed to obtain a benefit, or with intent to harm another. That aggravator is what turns snooping into a felony, and it is usually where the fight is.
| Conduct | Grade | Punishment range |
|---|---|---|
| Base offense — unauthorized access, or exceeding authorization, to a stored-communications facility — § 16.04(a),(b) | Class A misdemeanor | Up to 1 year in county jail + fine up to $4,000 (Penal Code § 12.21) |
| Committed to obtain a benefit, or with intent to harm another — § 16.04(c) | State jail felony | 180 days to 2 years in a state jail + fine up to $10,000 (Penal Code § 12.35) |
| Statute text & ranges last verified | July 2026, against Tex. Penal Code § 16.04 and Penal Code ch. 12 | |
The felony bump matters far beyond the label. “To obtain a benefit” sweeps in economic motives — pulling a competitor’s emails, harvesting account data, reading a spouse’s messages to gain leverage in a divorce or custody fight. “With intent to harm another” can turn an ugly breakup into a state jail felony when the messages are accessed to embarrass, stalk, or retaliate. Because the base and enhanced grades share the same access conduct, contesting the purpose is often the whole difference between a misdemeanor and a felony record.
Elements the State must prove
Every element must be proved beyond a reasonable doubt. Section 16.04 is easy to charge loosely and hard to prove precisely, because each element carries a technical requirement the State frequently glosses over.
- 1. A stored wire or electronic communication
- The object must be a communication — an email, text, voicemail, or direct message — that exists in “electronic storage,” meaning temporary storage incidental to transmission or a provider’s backup copy. A file the defendant created, or data resting on someone’s own device, is a different thing.
- 2. A facility through which a service is provided
- The access must be into provider-side infrastructure — a mail server, a carrier system, a messaging platform’s account storage. Under the federal analog, a personal phone or laptop is not a “facility” merely because it lets you use communication services.1
- 3. Access without authorization, or exceeding authorization
- This is the entry element. Courts construing the same language treat it as illegal entry — getting into data or a place you have no right to be — not the misuse of information you were allowed to see.3
- 4. Intentional conduct
- Each mode of (a) requires that the access, or the exceeding of authorization, be done intentionally. Accidental logins, cached sessions, or a good-faith belief in permission attack this element.
- 5. A prohibited result
- The person must thereby obtain, alter, or prevent authorized access to the stored communication. Getting in is not enough by itself; the statute ties liability to what the access accomplished.
- The felony aggravator — § 16.04(c)
- To raise the offense to a state jail felony, the State must additionally prove the conduct was committed to obtain a benefit or with intent to harm another. Absent that proof, the offense stays a Class A misdemeanor.
Stored access vs. wiretap interception (§ 16.02)
Section 16.04 is constantly confused with its neighbor, unlawful interception under § 16.02. They protect the same privacy interest at two different moments. Interception is live capture — grabbing a call or message during transmission through a device. Section 16.04 is access to a message at rest — reaching into storage after the transmission is over. The two cannot both describe the same act.
The line comes straight from how courts read the federal scheme these statutes track. Seizing or reading an email that is already sitting in storage, unread, is not an “intercept” at all, because an intercept requires acquisition contemporaneous with transmission; once the message is at rest, the stored-communications rules govern instead.2 That is why charging the wrong statute is a live defense issue: if the State pleads interception for conduct that was really stored access — or the reverse — the proof will not match the pleading. We keep the lanes separate, and we hold the State to the one it chose. For the live-capture offense and tracking-device conduct, see our dedicated page on § 16.02 interception and tracking devices.
How Texas and Federal Courts Have Interpreted § 16.04
Reported Texas decisions construing § 16.04 by name are scarce — the offense is charged far less often than it is committed. But because the section is a near-verbatim adoption of the federal Stored Communications Act, Fifth Circuit and federal interpretations of that statute are the controlling interpretive guide, and the Texas Court of Criminal Appeals has mapped the framework for Chapter 16’s sibling statute. Four decisions anchor the analysis.
The reach of “facility” and “electronic storage.” In Garcia v. City of Laredo, the Fifth Circuit held that the Stored Communications Act “does not apply to data stored in a personal cell phone,” because such a device is not a “facility through which an electronic communication service is provided,” and “information that an individual stores to his hard drive or cell phone is not in electronic storage under the statute.”1 The court set the prima facie test: the defendant must have gained unauthorized access to a provider’s facility and thereby reached a communication while in electronic storage. For the defense, Garcia is the strongest tool on the page — it forces the State to identify a real provider facility and a message genuinely in storage, not just data on a phone someone picked up.
Stored is not intercepted. In Steve Jackson Games, Inc. v. United States Secret Service, the Fifth Circuit held that seizing electronic mail that had been sent but not yet retrieved — sitting in storage — “does not constitute an ‘intercept’” under the Wiretap Act, because “the definition of ‘electronic communication’ does not include electronic storage of such communications,” and Congress “did not intend for ‘intercept’ to apply to ‘electronic communications’ when those communications are in ‘electronic storage.’”2 This is the case that draws the § 16.04 / § 16.02 boundary and defeats a mischarged interception theory.
Exceeding authorization means illegal entry, not misuse. In Cousineau v. Microsoft Corp., the court explained that “exceeding authorized access” occurs “when a party accesses information that the party has no authority to see, or information that is stored in a place where the party has no authority to be” — the Act “outlaws illegal entry, not larceny.”3 The court also agreed that a personal device is not a “facility” simply because it enables communication services. That gives the § 16.04(a)(2) prong a real limit: a person who was allowed to view data does not commit the offense merely by later using it in an unwanted way.
The Texas framework for Chapter 16. In Long v. State, the Court of Criminal Appeals addressed the sibling interception statute and confirmed that § 16.02 “does not define many of the terms of the offense; rather, it specifically incorporates the definitions found in” the Code of Criminal Procedure’s electronic-surveillance chapter, and that Chapter 16 concerns itself with “the capture, not the content, of the communication.”4 The same cross-referenced definitions — “electronic communication,” “electronic storage,” “user” — supply the meaning of § 16.04’s terms, so the State cannot prove the offense without proving those defined elements.
Defense strategies
L and L Law Group builds § 16.04 defenses on the statute’s own technical limits and on the federal case law construing its language:
- No provider “facility.” If the messages were read off a personal phone or laptop rather than pulled from a provider’s system, Garcia supplies a direct argument that the stored-communications theory does not fit the facts.1
- Not in “electronic storage.” Already-delivered, opened, and locally saved content may fall outside the statutory definition of electronic storage — a fact question that can defeat the charge.
- Authorization. Section 16.04(d) makes it a defense that the access was authorized by the service provider, by the user, or by the communication’s addressee or intended recipient. Shared accounts, saved passwords, and prior consent are litigated here.
- Access vs. misuse. Under Cousineau, a person entitled to see the data has not “exceeded authorization” simply by using it — the offense targets crossing into data you had no right to enter.3
- Intent. The access must be intentional. Cached logins, mistaken identity of an account, or a genuine belief in permission negate the required mental state.
- No benefit, no intent to harm. Where the State reaches for the felony grade, the defense forces proof of the § 16.04(c) aggravator — without it, the case is a Class A misdemeanor.
- Attribution and forensics. These cases turn on logs, IP records, and device forensics. Who actually logged in, from what device, and whether the records reliably identify the accused are all contestable.
- Wrong statute. If the conduct was live capture, it belongs under § 16.02, not § 16.04 — and a mismatch between pleading and proof is grounds to attack the charge.
Defense theories are fact-specific. Our developing hub on Texas criminal defense strategies collects the cross-cutting approaches — suppression, forensic challenges, and grade reductions — that recur across computer and communications cases.
§ 16.04 vs. breach of computer security & the federal SCA
The same episode can trigger overlapping statutes, and the charging choice shapes the exposure. Breach of computer security under § 33.02 reaches accessing a computer, network, or system without the owner’s effective consent; § 16.04 reaches accessing a communications facility to get at a stored message. Reading a partner’s texts directly off a phone may fit § 33.02’s device-access theory even where Garcia takes it outside § 16.04.
Federal exposure is the other half of the picture. Because § 16.04 mirrors 18 U.S.C. § 2701, the very same conduct can draw federal charges — often alongside the Computer Fraud and Abuse Act — particularly where an account provider crosses state lines. Anyone facing a state stored-communications case should be evaluated for parallel federal risk. We handle both state and federal criminal defense, and matters where the access was tied to financial gain frequently overlap with white-collar and fraud allegations.
Key Legal Terms
- Electronic Storage
- Temporary, intermediate storage of a communication incidental to its transmission, and any storage kept by a service for backup protection. A message a provider holds pending delivery, or as a backup, is in electronic storage; content saved onto a personal device generally is not.
- Facility (through which a service is provided)
- Provider-side infrastructure that supplies a wire or electronic communications service — a mail server, carrier system, or messaging platform’s account storage. A personal phone or computer is not a facility just because it enables use of those services.
- Without Authorization / Exceeding Authorization
- The two ways to commit the offense: an outsider who enters a facility with no right at all, or an insider with some access who intentionally goes beyond it. Courts treat this as illegal entry, not the later misuse of data a person was allowed to see.
- Benefit (§ 1.07(a)(7))
- Anything reasonably regarded as economic gain or advantage, including a benefit to a person in whose welfare the beneficiary is interested. Access committed “to obtain a benefit” raises § 16.04 to a state jail felony.
- Stored Communications Act (18 U.S.C. § 2701)
- The federal statute § 16.04 is patterned on. Federal interpretations of its “facility,” “electronic storage,” and “exceeds authorization” language are the leading guide to how the Texas offense is construed.
Frequently Asked Questions
Is unlawful access to stored communications a felony in Texas?
What is the difference between § 16.04 and wiretapping under § 16.02?
Can I be charged for reading my spouse’s texts or email?
What do “facility” and “electronic storage” mean here?
Is it a defense that I was authorized to access the account?
What makes the offense a state jail felony instead of a misdemeanor?
Does § 16.04 apply to social media or cloud accounts?
Can the same conduct be charged under both § 16.04 and breach of computer security?
Can a § 16.04 charge be expunged or sealed?
References & Authoritative Sources
- Garcia v. City of Laredo, 702 F.3d 788 (5th Cir. 2012) — Stored Communications Act does not reach data on a personal cell phone; defines “facility” and “electronic storage.”
- Steve Jackson Games, Inc. v. United States Secret Service, 36 F.3d 457 (5th Cir. 1994) — stored, unretrieved email is not “intercepted”; distinguishes the Wiretap Act from the Stored Communications Act.
- Cousineau v. Microsoft Corp., 6 F. Supp. 3d 1167 (W.D. Wash. 2014) — “exceeding authorized access” is illegal entry, not misuse of data one was entitled to see.
- Long v. State, 535 S.W.3d 511 (Tex. Crim. App. 2017) — Chapter 16 incorporates the Code of Criminal Procedure’s electronic-surveillance definitions and protects the capture of communications.
- Tex. Penal Code § 16.04 — Unlawful Access to Stored Communications
- Tex. Penal Code § 16.02 — Unlawful Interception of Communications
- 18 U.S.C. § 2701 — Federal Stored Communications Act
- Tex. Penal Code ch. 12 — Punishments
- Texas Courts
- Texas State Law Library
About the Authors
Reggie London
Co-Founding Partner · Texas Bar No. 24043514
Reggie London co-founded L and L Law Group and handles federal and complex felony matters, including computer and communications cases. Licensed in Texas; admitted to the Northern and Eastern Districts of Texas.
Njeri London
Co-Founding Partner · Texas Bar No. 24043266
Njeri London co-founded L and L Law Group with a focus on DWI, family-violence, and privacy-related offenses. Licensed in Texas; admitted to the Northern and Eastern Districts of Texas.
Charged under § 16.04? Talk to L and L Law Group.
Co-founding partners Reggie London and Njeri London ensure attorney-level review at every stage. Free consultation. Frisco, Texas.
Call (972) 370-5060