FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)
FCC CPNI: Data Breach Notification (64.2011)
FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) CPNI-64.2011: Notification of CPNI security breaches (47 CFR 64.2011)
Section 64.2011 establishes the data breach notification regime: (a) DEFINITION OF BREACH - 'a person, without authorisation or exceeding authorisation, has intentionally gained access to + use + disclose CPNI' (the FCC 2024 amendment expanded this to include 'inadvertent + accidental' breaches in certain circumstances). (b) LAW ENFORCEMENT NOTIFICATION - within 7 BUSINESS DAYS of REASONABLE DETERMINATION OF A BREACH the carrier must electronically notify the United States Secret Service (USSS) + the Federal Bureau of Investigation (FBI) through the CENTRAL REPORTING FACILITY at https://www.cpnireporting.gov + the FCC. (c) CUSTOMER NOTIFICATION TIMING - the carrier MUST NOT notify customers OR disclose the breach publicly until 7 business days have passed AFTER the law enforcement notification UNLESS law enforcement requests an extension. (d) NOTIFICATION CONTENT - notifications must include the date of the breach + a description of CPNI affected + the carrier's contact information + steps that customers may take to protect their personal information. (e) RECORDKEEPING - carriers must maintain a record of any breaches discovered + notifications made for a minimum of 2 YEARS including all reports for that breach + the date of discovery + the steps taken to remedy the breach.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 45 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.