DA 23-93 Enforcement Advisory No. 2023-01 February 1, 2023 FCC ENFORCEMENT ADVISORY TELECOMMUNICATIONS CARRIERS AND INTERCONNECTED VOIP PROVIDERS MUST FILE ANNUAL REPORTS CERTIFYING COMPLIANCE WITH COMMISSION RULES PROTECTING CUSTOMER PROPRIETARY NETWORK INFORMATION ANNUAL CPNI CERTIFICATIONS DUE MARCH 1, 2023 Filing of Annual Customer Proprietary Network Information (CPNI) Certifications for Calendar Year 2022 EB Docket No. 06-36 The FCC’s Enforcement Bureau reminds telecommunications carriers and interconnected Voice over Internet Protocol (VoIP) providers of their obligation to file their annual certification documenting compliance with the Customer Proprietary Network Information (CPNI) rules by March 1, 2023. This Enforcement Advisory highlights certain obligations under the CPNI rules. Failure to receive this notice does not absolve a provider of the obligation to meet the requirements of the Communications Act of 1934, as amended, or the Commission’s rules and orders. Companies should read the full text of the relevant CPNI rules at 47 CFR § 64.2001 et seq. The protection of CPNI is of paramount importance, as it includes sensitive personal information that carriers collect about their customers during the course of their business relationship (e.g., telephone numbers of calls made and received; the frequency, duration, location, and timing of such calls; and any services purchased by the consumer, such as call waiting and voicemail). The Commission’s rules seek to ensure that CPNI is adequately protected from unauthorized access, use, or disclosure. Failure to file a timely and complete certification calls into question whether a company has complied with the rules requiring it to protect the privacy and security of its customers’ sensitive information. Telecommunications carriers and interconnected VoIP providers can satisfy their certification filing obligation in several ways, as described in Attachment 1. Because the CPNI rules provide important consumer protections, the Commission has taken enforcement action against telecommunications carriers and interconnected VoIP providers that failed to comply with the requirements, and we intend to continue to enforce the rules. Companies are reminded that failure to comply with the CPNI rules, including the annual certification requirement, may subject them to enforcement action, including monetary forfeitures of up to $237,268 for each violation or each day of a continuing violation, up to a maximum of $2,372,677. 47 U.S.C. § 503(b)(2)(B); see also 47 CFR § 1.80(b)(2); Amendment of Section 1.80(b) of the Commission’s Rules, Adjustment of Civil Monetary Penalties to Reflect Inflation, Order, DA 22-1356, 88 Fed. Reg. 783 (Dec. 23, 2022). False statements or misrepresentations to the Commission may be punishable by fine or imprisonment under Title 18 of the U.S. Code. Attachments: (1) Frequently Asked Questions; (2) CPNI Certification Template; (3) Text of the CPNI rules. Issued by: Chief, Enforcement BureauATTACHMENT 1 2 FREQUENTLY ASKED QUESTIONS The following frequently asked questions are addressed in this Enforcement Advisory: § What are the CPNI rules, and where can I find them? § Who is required to file? § Is there an exemption for small companies? § What must be included in the annual certification filing? § When are companies required to file the annual certification? § Is this the same as my form 499 filing or my USF filing? § What format should I use for my CPNI certification? § How do I file the CPNI certification? § What if I have questions? What are the CPNI rules, and where can I find them? Protection of CPNI is a fundamental obligation under section 222 of the Communications Act of 1934, as amended (Communications Act or Act). Consumers are understandably concerned about the privacy and security of the sensitive, personal data that their telecommunications carriers collect in the provision of service. In recognition of these concerns, the Commission issued rules requiring carriers and interconnected VoIP providers to establish and maintain systems designed to ensure that they adequately protect their subscribers’ CPNI. Those rules also require carriers and interconnected VoIP providers to, among other things: (1) obtain customers’ approval to use, disclose, or permit access to their CPNI for marketing or other purposes; 47 CFR § 64.2007. (2) notify customers of their right to restrict the use of their CPNI; Id. § 64.2008. (3) take reasonable measures to discover and protect against attempts to gain unauthorized access to CPNI; Id. § 64.2010(a). (4) notify law enforcement and affected customers of a breach of CPNI. Id. § 64.2011. In addition, all companies subject to the CPNI rules must file an annual certification documenting their compliance with the rules, and documenting any complaints or problems. Id. § 64.2009(e). Companies must file these certifications with the Commission annually, on or before March 1. Id. The CPNI rules are found at 47 CFR § 64.2001 et seq. A copy of the current version of the certification portion of the rules is attached to this Enforcement Advisory. To ensure that you are aware of any changes to the rules, you are advised always to check the current version of the Code of Federal Regulations, which can be found at the Government Printing Office website, here: https://www.ecfr.gov. Who is required to file? Telecommunications carriers and interconnected VoIP providers must file a CPNI certification each year. § A “telecommunications carrier” is “any provider of telecommunications services,” except an aggregator. 47 U.S.C. § 153(51). Section 226 of the Act defines an aggregator as “any person that, in the ordinary course of its operations, makes telephones available to the public or to transient users of its premises, for interstate telephone calls using a provider of operator services.” 47 U.S.C. § 226(a)(2). The Communications Act defines telecommunications service as “the offering of telecommunications for a fee directly to the public, or to such classes of users as to be effectively available directly to the public, regardless of the facilities used.” 47 U.S.C. § 153(53). § Some examples of “telecommunications carriers” that must file an annual certification are: local exchange carriers (LECs) (including incumbent LECs, rural LECs, and competitive LECs), interexchange carriers, commercial mobile radio services (CMRS) providers, resellers, prepaid telecommunications providers, and calling card providers. This list is not exhaustive. § “Interconnected VoIP providers” are companies that provide a service that: “(1) enables real-time, two-way voice communications; (2) requires a broadband connection from the user’s location; (3) requires Internet protocol-compatible customer premises equipment (CPE); and (4) permits users generally to receive calls that originate on the public switched telephone network and terminate calls to the public switched network.” 47 CFR § 9.3. Is there an exemption for small companies? No, there is no exemption for small companies. The annual certification filing requirement applies regardless of the size of the company. What must be included in the annual certification filing? The annual certification filing must include all of the elements listed below: § A compliance certificate signed by an officer of the company. § A statement by the officer in the compliance certificate that he or she has personal knowledge that the company has established operating procedures that are adequate to ensure compliance with the CPNI rules. § A written statement accompanying the certification explaining how the company’s operating procedures ensure that it is or is not in compliance with the CPNI rules. § An explanation of any actions taken against data brokers. § A summary of all consumer complaints received in the prior year concerning unauthorized release of CPNI. See Attachment 2 for a suggested template that can be used to prepare the certification filing. In reviewing prior years’ filings, we have found the following deficiencies: § Some companies have failed to have the officer signing the certification affirmatively state that he or she has personal knowledge that the company has established operating procedures that are adequate to ensure compliance. An officer of the company must sign the compliance certificate. § Some companies have failed to provide a statement accompanying the certification explaining how their operating procedures ensure that they are or are not in compliance with the rules. Stating that the company has adopted operating procedures without explaining how compliance is being achieved does not satisfy this requirement. § Some companies have failed to state clearly whether any actions were taken against data brokers in the prior year. If there were no such actions, the company must include an affirmative statement of that fact to make clear that it has provided the required information. § Some companies have failed to state clearly whether any customer complaints were received in the prior year concerning the unauthorized release of CPNI. If there were no such complaints, the company must include an affirmative statement of that fact to make clear that it has provided the required information. To help companies ensure that their certifications contain all of the required information, we are providing a suggested template, attached to this Enforcement Advisory. When are companies required to file the annual certification? The 2023 annual certification filing (for calendar year 2022) is due no later than March 1, 2023. Is this the same as my Form 499 filing or my USF filing? No. The annual CPNI certification filing is different from FCC Form 499 filings and USF filings. What format should I use for my CPNI certification? A suggested template is attached to this Enforcement Advisory. See Attachment 2. This template was designed to ensure that companies will comply with the annual certification filing requirement of 47 CFR § 64.2009(e) if they complete it fully and accurately. Use of this template is not mandatory, and companies may use any format that fulfills the requirements of the rule. If you elect to use the suggested template, we encourage you to review the template carefully and to ensure that all fields are fully and accurately completed before submission. How do I file the CPNI certification? 1. Certifications may be filed using the Commission’s Electronic Comment Filing System (ECFS) or the Commission’s web-based application. To file a certification using ECFS, visit https://www.fcc.gov/ecfs/filings. Filings submitted through ECFS must reference EB Docket No. 06-36 in the “proceeding” field. Companies must file a separate certification for each affiliate in possession of a unique 499 filer ID number. For the Commission’s web-based application specifically designed for this purpose, visit http://apps.fcc.gov/eb/CPNI/. Instructions are provided at the website. 2. Do not send copies of certifications to the Enforcement Bureau or to any individuals within the Enforcement Bureau unless such filing is a requirement of a consent decree with the Enforcement Bureau. People with Disabilities: To request materials in accessible formats for people with disabilities (braille, large print, electronic files, audio format), send an e-mail to fcc504@fcc.gov or call the Consumer & Governmental Affairs Bureau at 202-418-0530 (voice), 202-418-0432 (tty). What if I have questions? For further information regarding the annual certification filing, contact any of the following individuals in the Telecommunications Consumers Division, Enforcement Bureau: shana.yates@fcc.gov, michael.epshteyn@fcc.gov, kimbarly.taylor@fcc.gov, or james.graves@fcc.gov. ATTACHMENT 2 6 Annual 47 CFR § 64.2009(e) CPNI Certification Template EB Docket 06-36 Annual 64.2009(e) CPNI Certification for [Insert year] covering the prior calendar year [Insert year] 1. Date filed: [Insert date] 2. Name of company(s) covered by this certification: [Insert company name] 3. Form 499 Filer ID: [Provide filer ID number(s)] 4. Name of signatory: [Insert name] 5. Title of signatory: [Insert title of corporate officer] 6. Certification: I, [insert name of officer signing certification], certify that I am an officer of the company named above, and acting as an agent of the company, that I have personal knowledge that the company has established operating procedures that are adequate to ensure compliance with the Commission’s CPNI rules. See 47 CFR § 64.2001 et seq. Attached to this certification is an accompanying statement explaining how the company’s procedures ensure that the company is in compliance with the requirements (including those mandating the adoption of CPNI procedures, training, safeguards, recordkeeping, and supervisory review) set forth in section 64.2001 et seq. of the Commission’s rules. The company [has/has not] taken actions (i.e., proceedings instituted or petitions filed by a company at either state commissions, the court system, or at the Commission against data brokers) against data brokers in the past year. [NOTE: If you reply in the affirmative, provide an explanation of any actions taken against data brokers.] The company [has/has not] received customer complaints in the past year concerning the unauthorized release of CPNI. [NOTE: If you reply in the affirmative, provide a summary of such complaints. This summary must include the number of complaints, broken down by category or complaint, e.g., instances of improper access by employees, instances of improper disclosure to individuals not authorized to receive the information, or instances of improper access to online information by individuals not authorized to view the information.] The company represents and warrants that the above certification is consistent with 47 CFR § 1.17, which requires truthful and accurate statements to the Commission. The company also acknowledges that false statements and misrepresentations to the Commission are punishable under Title 18 of the U.S. Code and may subject it to enforcement action. Signed _____________________________ [Signature of an officer, as agent of the carrier] Attachments: Accompanying Statement explaining CPNI procedures Explanation of actions taken against data brokers (if applicable) Summary of customer complaints (if applicable) ATTACHMENT 3 47 CFR § 64.2009 Safeguards required for use of customer proprietary network information. (a) Telecommunications carriers must implement a system by which the status of a customer's CPNI approval can be clearly established prior to the use of CPNI. (b) Telecommunications carriers must train their personnel as to when they are and are not authorized to use CPNI, and carriers must have an express disciplinary process in place. (c) All carriers shall maintain a record, electronically or in some other manner, of their own and their affiliates' sales and marketing campaigns that use their customers' CPNI. All carriers shall maintain a record of all instances where CPNI was disclosed or provided to third parties, or where third parties were allowed access to CPNI. The record must include a description of each campaign, the specific CPNI that was used in the campaign, and what products and services were offered as a part of the campaign. Carriers shall retain the record for a minimum of one year. (d) Telecommunications carriers must establish a supervisory review process regarding carrier compliance with the rules in this subpart for outbound marketing situations and maintain records of carrier compliance for a minimum period of one year. Specifically, sales personnel must obtain supervisory approval of any proposed outbound marketing request for customer approval. (e) A telecommunications carrier must have an officer, as an agent of the carrier, sign and file with the Commission a compliance certificate on an annual basis. The officer must state in the certification that he or she has personal knowledge that the company has established operating procedures that are adequate to ensure compliance with the rules in this subpart. The carrier must provide a statement accompanying the certificate explaining how its operating procedures ensure that it is or is not in compliance with the rules in this subpart. In addition, the carrier must include an explanation of any actions taken against data brokers and a summary of all customer complaints received in the past year concerning the unauthorized release of CPNI. This filing must be made annually with the Enforcement Bureau on or before March 1 in EB Docket No. 06-36, for data pertaining to the previous calendar year. (f) Carriers must provide written notice within five business days to the Commission of any instance where the opt-out mechanisms do not work properly, to such a degree that consumers' inability to opt-out is more than an anomaly. (1) The notice shall be in the form of a letter, and shall include the carrier's name, a description of the opt-out mechanism(s) used, the problem(s) experienced, the remedy proposed and when it will be/was implemented, whether the relevant state commission(s) has been notified and whether it has taken any action, a copy of the notice provided to customers, and contact information. (2) Such notice must be submitted even if the carrier offers other methods by which consumers may opt-out. 7