The U.S. Court of Appeals for the Sixth Circuit recently issued a decision in Ohio Telecom Association et al. v. FCC, upholding the FCC’s 2024 data breach reporting requirements for telecommunications carriers and relay service providers.
Background
The 2024 rule requires carriers to report breaches involving either Customer Proprietary Network Information (CPNI) or Personally Identifiable Information (PII) – including social security numbers, login credentials and biometric data. It replaced older rules by:
- Expanding coverage to PII (not just CPNI)
- Removing the mandatory waiting period before notifying customers
- Adding a “good faith” exception for disclosures
Industry groups challenged the rule, arguing the FCC lacked authority under the Communications Act of 1934 and the rule violated the Congressional Review Act (CRA) by being “substantially the same” as a 2016 FCC order repealed by Congress.
Court’s Decision
The Sixth Circuit rejected both arguments. The court held that while certain sections of the Communications Act only relate to CPNI, the FCC may regulate PII-related practices under broader grants of authority under the Communications Act. The FCC, according to the court, could regulate any practice with a close and clear connection to a carrier’s provision of services – practices that directly implicate a carrier’s furnishing of communication services. The court held the failure to report a data breach can qualify as an unreasonable “practice” connected to providing telecom services and was within the FCC’s authority. On a more procedural basis, the court also found the 2024 rule materially different from the 2016 order, so the CRA’s “substantially the same” prohibition did not apply.
Significance for Telecom and Relay Providers
This ruling affirms the FCC’s ability to regulate breach reporting for a broad range of customer data – not just CPNI. The decision signals § 201(b) remains a flexible enforcement tool for the FCC, even in areas where Congress has enacted more specific privacy provisions.
Key Takeaways
- Carriers and relay service providers must comply with the 2024 breach notification rule. Entities must notify Federal agencies of a reportable breach as soon as practicable, but no later than seven business days, after reasonable determination of the breach.
- Compliance programs should address both CPNI and PII, with prompt breach detection and reporting procedures.
- The FCC’s interpretation of its authority under § 201(b) could open the door to further privacy and security requirements beyond those explicitly stated in § 222.
If you have questions about how this decision affects your organization’s obligations, or if you need assistance updating your incident response and breach reporting policies, please contact a member of our Cybersecurity and Data Privacy team.