FCC Proposes Rule to Clarify Data Breach Definition for Communications Carriers

Source Node: 2004051

The Federal Communications Commission (FCC) recently proposed a new rule to clarify the definition of a data breach for communications carriers. This proposed rule is intended to help communications carriers better understand their obligations under the Communications Act of 1934 and the FCC’s regulations.

The proposed rule would define a data breach as “the unauthorized acquisition of, access to, or use of customer proprietary network information (CPNI) or confidential information that is stored, maintained, or transmitted by a communications carrier.” CPNI is defined as “information that relates to the quantity, technical configuration, type, destination, location, and amount of use of a telecommunications service subscribed to by any customer of a telecommunications carrier, and that is made available to the carrier by the customer solely by virtue of the carrier-customer relationship.”

Under the proposed rule, communications carriers would be required to notify customers and the FCC in the event of a data breach. The notification must include information about the nature of the breach, the type of information affected, and steps customers can take to protect themselves. The notification must also include contact information for the carrier’s customer service department.

The proposed rule also requires communications carriers to take reasonable steps to protect customer information from unauthorized access or use. These steps may include implementing security measures such as encryption, authentication, and access control. Additionally, carriers must have procedures in place to detect and respond to data breaches.

The proposed rule is intended to help ensure that communications carriers are aware of their obligations under the Communications Act and the FCC’s regulations. It will also help customers understand their rights and responsibilities when it comes to protecting their data. The FCC is currently accepting comments on the proposed rule until August 28th.

Time Stamp:

More from Cyber Security / Web3