FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)
The US Federal Communications Commission (FCC) Customer Proprietary Network Information (CPNI) rules (47 CFR Part 64, Subpart U) protect the confidentiality of customer telecommunications data. Updated in 2023 to include a comprehensive data breach notification rule. CPNI includes: call records, services purchased, network usage information, and device information. The 2023 FCC Data Breach Notification Rule requires carriers to notify the FCC within 30 days, consumers without unreasonable delay, and FBI/Secret Service for breaches affecting 500+ customers. Applies to all telecommunications carriers, VoIP providers, and TRS providers.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Breach Notification Requirements
| Code | Title |
|---|---|
| 64.2011(a) | Definition of Breach |
| 64.2011(b) | Law Enforcement Notification |
| 64.2011(c) | Customer Notification |
| 64.2011(d) | Notification Content |
Recordkeeping and Compliance
| Code | Title |
|---|---|
| RK-1 | Breach Records |
| RK-2 | Annual CPNI Certification |
| RK-3 | Officer Certification |
| RK-4 | Supervisory Review Records |
Safeguards and Authentication
| Code | Title |
|---|---|
| 64.2010(a) | Safeguards on Disclosure |
| 64.2010(b) | Telephone Authentication |
| 64.2010(c) | Online Account Access |
| 64.2010(d) | In-Store Authentication |
| 64.2010(e) | Password and Account Protection |
Scope and Definitions
Defines nursing personnel as all categories of persons providing nursing care and services, wherever they work.
| Code | Title |
|---|---|
| 64.2001 | Basis and Purpose |
| 64.2003 | Definitions |
| 64.2004 | Customer Approval Mechanisms |
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| ILO-C149-01 | Article 1 — Definition of nursing personnel covering all categories providing nursing care and services |
Use and Disclosure of CPNI
| Code | Title |
|---|---|
| 64.2005 | Use Without Customer Approval |
| 64.2007 | Approval Required for Use |
| 64.2008 | Notice Requirements for Use |
| 64.2009 | Safeguards Required for Use |
Maps to 535 other frameworks
Frequently Asked Questions
What is FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)?
FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) is a compliance framework from United States (FCC) with 5 domains and 24 controls. The US Federal Communications Commission (FCC) Customer Proprietary Network Information (CPNI) rules (47 CFR Part 64, Subpart U) protect the confidentiality of customer telecommunications data. Updated in 2023 to include a comprehensive data breach notification rule. CPNI includes: call records, services purchased, network usage information, and device information. The 2023 FCC Data Breach Notification Rule requires carriers to notify the FCC within 30 days, consumers without unreasonable delay, and FBI/Secret Service for breaches affecting 500+ customers. Applies to all telecommunications carriers, VoIP providers, and TRS providers. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) have?
FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) has 24 controls organised across 5 domains. The largest domains are Scope and Definitions (7 controls), Safeguards and Authentication (5 controls), Breach Notification Requirements (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) map to?
FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) maps to 535 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (33% coverage), ISO/IEC 27400:2022 (33% coverage), GLI-33 — Gaming Laboratories International Event Wagering Systems (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) compliance?
Start your FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required