Communications Act Section 222 (Customer Proprietary Network Information) and CPNI Rules
CPNI
Communications · Location · Breach notification
Section 222 requires carriers to protect the confidentiality of customer proprietary network information, such as call details and location, and limits its use without customer approval. FCC rules require authentication before disclosing call detail records and breach reporting to the Secret Service and FBI. A broader 2024 FCC breach rule covering personally identifiable information was upheld by a Sixth Circuit panel in August 2025, but en banc rehearing was granted on July 31, 2026 and the amended 47 CFR 64.2011 is not yet in effect.
- Where
- Federal
- Citation
- 47 U.S.C. 222; 47 CFR 64.2001-64.2011
- Status
- In force
- In force since
- 1996-02-08
- Last amended
- 2008-07-23
- Enforced by
- Federal Communications Commission
- People can sue
- Limited
- Penalties
- FCC forfeitures under the Communications Act; damages actions against common carriers are available under 47 U.S.C. 206-207.
- Applies to
- Telecommunications carriers
- Interconnected VoIP providers (by FCC rule)
Practices it requires
- Use, disclose, or permit access to individually identifiable CPNI only to provide the service from which it is derived, or with customer approval or as required by law.47 U.S.C. 222(c)(1)
- Wireless location information requires the customer's express prior authorization, subject to emergency exceptions.47 U.S.C. 222(f)
Security duties
- Take reasonable measures to discover and protect against attempts to gain unauthorized access to CPNI, including authentication before disclosing call detail records and SIM change/port-out protections.47 CFR 64.2010
Breach duties
- Report CPNI breaches to the U.S. Secret Service and FBI within seven business days and generally wait seven business days before notifying customers.47 CFR 64.2011(a)-(b)
- Notify the FCC, Secret Service and FBI, and customers of breaches of CPNI and other covered data, including inadvertent disclosures (2024 amendments).47 CFR 64.2011 (as amended, 89 FR 9968) · Only if: Pending Office of Management and Budget approval and en banc review in Ohio Telecom Ass'n v. FCC (6th Cir.)
Sources
- Official text
- 47 U.S.C. 222 (OLRC)
- 47 CFR 64.2011 (eCFR)
- FCC, Data Breach Reporting Requirements, 89 FR 9968 (Feb. 12, 2024)
- Washington Legal Foundation case page, Ohio Telecom Ass'n v. FCC (en banc grant July 31, 2026)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The en banc grant date is from an amicus's case page, not the court docket | 64.2010 SIM-swap/port-out amendments (2023-2024) were not read | 47 U.S.C. 206-207 not fetched
Research reference, not legal advice.