FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)
FCC CPNI: Safeguards on Use and Disclosure (64.2009-64.2010)

FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) CPNI-Vendor: Third party and joint venture CPNI restrictions (47 CFR 64.2007 + 64.2009)

CPNI rules apply to third parties + joint ventures + independent contractors that the carrier permits to access CPNI. Specific requirements: (a) Section 64.2007 OPT-IN required for joint venture + independent contractor use of CPNI for marketing not specifically related to the customer's existing service; (b) Section 64.2007 OPT-OUT may be sufficient for affiliated communications-related services entities; (c) Section 64.2009 SAFEGUARDS - carrier must extend CPNI safeguards to third parties through CONTRACTUAL FLOW-DOWN + monitoring + audit rights; (d) third-party vendor agreements must include CPNI confidentiality + use restrictions + breach notification flow-down to the carrier + audit rights; (e) third-party operational independence does NOT diminish carrier responsibility - the carrier remains fully accountable for CPNI under Section 222 even where access is via contractor / vendor / agent. The 2024 FCC enforcement actions against Verizon + AT&T + T-Mobile + Sprint for sale of customer location data via third-party data brokers (Securus + Securus Plus + LocationSmart + 3Cinteractive + 5Mile) demonstrated systemic third-party CPNI failures + resulted in hundreds of millions of dollars in fines.

Other controls in FCC CPNI: Safeguards on Use and Disclosure (64.2009-64.2010)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.