FCC Proposal to Revise Data Breach Definition for Telecommunications Providers

Source Node: 2004201

The Federal Communications Commission (FCC) recently proposed a revision to the definition of a data breach for telecommunications providers. This proposal is intended to provide greater clarity and consistency in the way telecommunications providers report and respond to data breaches.

The current definition of a data breach is based on the Federal Trade Commission’s (FTC) definition, which states that a data breach is an “unauthorized acquisition of sensitive information.” The FCC’s proposed revision would expand this definition to include any “unauthorized access, use, or disclosure of customer proprietary network information (CPNI).” CPNI is defined as any information that a telecommunications provider obtains from customers in the course of providing services.

Under the proposed revision, telecommunications providers would be required to report any data breach involving CPNI to the FCC within seven days of discovering the breach. The FCC would then investigate the breach and determine if any corrective action is necessary. The proposed revision also requires telecommunications providers to notify affected customers of any data breach within 30 days of discovering the breach.

The proposed revision is intended to provide greater clarity and consistency in the way telecommunications providers report and respond to data breaches. By expanding the definition of a data breach to include CPNI, the FCC hopes to ensure that telecommunications providers are taking appropriate steps to protect customer data. Additionally, the proposed notification requirements will help ensure that affected customers are notified in a timely manner.

The FCC is currently seeking public comment on the proposed revision. If approved, the revised definition of a data breach would apply to all telecommunications providers, including wireless, wireline, cable, satellite, and VoIP providers. The FCC is expected to make a final decision on the proposed revision in the coming months.

Time Stamp:

More from Cyber Security / Web3