Customer Proprietary Network Information: FCC Compliance GuideCustomer proprietary network information (CPNI) is the carrier-held usage, service, and billing data about your customers, and federal law requires you to treat it as regulated data with specific safeguards, notice obligations, and annual certification duties. If you are a telecommunications carrier or interconnected VoIP provider, three actions reduce your enforcement risk immediately:
- Confirm your authentication procedures do not rely on biographical data such as the last four digits of a Social Security number or a mother's maiden name.
- Verify that your outbound marketing campaigns have documented supervisory approval and that records are retained for at least one year.
- Check whether your most recent annual CPNI certification was filed by March 1 with the FCC's Enforcement Bureau.
Legal and compliance own the certification. IT owns authentication and access controls. Operations owns campaign recordkeeping and vendor contracts. All three must coordinate.
Key Takeaways
CPNI compliance requires documented controls across authentication, recordkeeping, breach response, and annual officer-attested certification filed with the FCC by March 1 each year.
| Point | Details |
|---|---|
| Authentication is the top gap | Replace biographical checks with passwords or tokens in every customer-facing system. |
| Outbound marketing needs sign-off | Supervisory approval and one-year record retention are required before any CPNI-based campaign. |
| March 1 is a hard deadline | Annual certification must be filed in EB Docket No. 06-36 with officer attestation for the prior year. |
| Breach notification has a sequence | Notify law enforcement first, then customers; document all actions for the annual complaint summary. |
| Californiatelecom covers key controls | Managed LAN/WAN and UCaaS services provide the logging, monitoring, and access controls CPNI requires. |
Table of Contents
- What counts as customer proprietary network information?
- Who must comply, and what is the legal basis?
- When can you use or disclose CPNI?
- What safeguards does the FCC require?
- What goes into the annual CPNI certification?
- How to respond when CPNI is exposed
- How to manage vendors and third parties with CPNI access
- Your CPNI compliance checklist
- What to ask managed network and UCaaS providers about CPNI
- CPNI compliance is a trust asset, not just a legal checkbox
- Californiatelecom handles the network controls so you can focus on the certification
- Sources
What counts as customer proprietary network information?
CPNI is defined under 47 U.S.C. ยง 222 as information available to a carrier by virtue of the carrier-customer relationship that relates to the quantity, technical configuration, type, destination, location, and amount of use of a telecommunications service. In plain terms: call detail records, the location of an active device during a call, the specific service features a customer subscribes to, and billing and usage data tied to those services.
What is not CPNI matters just as much. Subscriber list information, meaning a customer's name, address, and telephone number published in a directory, falls outside CPNI's scope. Purely public directory data carries different rules. That distinction shapes which data fields your privacy policies, access controls, and marketing workflows must treat as regulated versus general customer data.
Concrete examples help teams scope systems correctly:
- Is CPNI: Call duration and destination numbers, data usage volumes by service tier, device location during an active session, voicemail feature subscriptions, and itemized billing records.
- Is not CPNI: A customer's name and listed phone number in a public directory, general account contact information not tied to usage, and aggregate statistical data that cannot be linked to an individual customer.
Who must comply, and what is the legal basis?
The rules apply to telecommunications carriers and interconnected VoIP providers. That covers traditional wireline and wireless carriers, cable operators offering voice services, and any VoIP provider whose service connects to the public switched telephone network. Resellers and agents who obtain CPNI from an underlying carrier are also covered when they use that data for their own marketing or operations.
The legal foundation is Section 222 of the Communications Act, implemented through 47 CFR ยง 64.2001 et seq. The FCC's Telecommunications Consumers Division enforces these rules under Sections 201(b) and 222, and the Enforcement Bureau has authority to impose forfeitures and consent decrees.
Key enforcement risks:
- Failure to file the annual certification by March 1 triggers enforcement exposure and potential forfeitures.
- Unauthorized disclosure of CPNI to third parties, including data brokers, is an enforcement priority.
- Inadequate authentication procedures that allow customer impersonation have drawn formal FCC action.
- Missing or incomplete breach notifications to customers and law enforcement compound initial violations.
When can you use or disclose CPNI?
Permitted uses are narrower than most teams assume. Carriers may use CPNI without separate customer approval to provide the service the customer already subscribes to, handle service-related billing, respond to 911 and other emergency calls, and comply with court orders or other legal process. Aggregate data that cannot be tied to an individual customer is also permissible for general business analytics.
For marketing purposes, the rules split into two tracks. Marketing services within the same category a customer already subscribes to (for example, promoting additional features on an existing voice plan) may use an opt-out approach, but the carrier must provide written notice and wait 30 days before acting on the customer's silence as approval. Marketing services in a different category requires affirmative opt-in approval. One-time oral approvals are permitted in limited circumstances but must be documented.
The notice requirements under 47 CFR ยง 64.2008 are specific: the written notice must describe what CPNI is, identify who will receive it, explain the purpose of the proposed use, and state the customer's right to deny or restrict access. Sending a vague privacy notice does not satisfy this standard.
Outbound marketing campaigns that rely on CPNI require supervisory approval before launch. That approval must be documented, and the records must be retained for at least one year.

What safeguards does the FCC require?
Authentication is where most carriers have gaps. 47 CFR ยง 64.2010 prohibits relying on biographical information or account data that is readily available, such as a billing address or the last four digits of a Social Security number, to authenticate a customer who contacts the carrier by phone or online. Required alternatives include customer-created passwords, passphrases, or token-based verification. Fallback authentication methods must also be non-biographical.
The Enforcement Bureau's 2024 advisory reinforced the full set of safeguards required under 47 CFR ยง 64.2009:
- Training: All personnel with access to CPNI must complete documented training on permissible uses, disclosure restrictions, and breach reporting duties.
- Disciplinary procedures: Written policies must specify consequences for unauthorized CPNI access or disclosure.
- Supervisory review: Outbound marketing proposals that use CPNI must receive documented supervisor sign-off before execution.
- Access controls: Apply least-privilege principles; restrict CPNI access to roles that genuinely need it.
- Logging: Maintain access logs that capture who accessed CPNI, when, and for what purpose.
- Encryption: Protect CPNI at rest and in transit. Periodic access reviews should revoke credentials for personnel who no longer need them.
Pro Tip: Build authentication procedures into your CRM and ticketing systems so agents cannot bypass them. A policy document alone will not satisfy the FCC if your systems allow agents to pull CPNI after a simple name-and-address check.
For teams evaluating authentication and privacy terminology, a structured glossary of KYC and verification concepts can help align internal training language with regulatory expectations.
What goes into the annual CPNI certification?
Every telecommunications carrier and interconnected VoIP provider must file an annual certification with the FCC's Enforcement Bureau by March 1, covering the prior calendar year. The 2022 Enforcement Bureau advisory and the 2024 follow-up notice both confirm that failure to file, or filing an inaccurate certification, can result in forfeitures.
| Certification element | What to document |
|---|---|
| Officer attestation | Signed by an officer with personal knowledge of the carrier's CPNI practices |
| Operating procedures | Statement that the carrier has established procedures compliant with 47 CFR ยง 64.2001 et seq. |
| Complaint summary | Summary of customer complaints received regarding unauthorized CPNI release |
| Data broker actions | Description of any actions taken against data brokers or unauthorized third-party access |
| Opt-out/opt-in explanation | Description of the opt-out and opt-in mechanisms offered to customers |
The officer attestation is not a formality. The FCC expects the signing officer to have actual knowledge of the carrier's CPNI program, not to simply countersign a document prepared entirely by technical staff. File in EB Docket No. 06-36 through the FCC's Electronic Comment Filing System (ECFS). Teams that need machine-readable access to the underlying regulatory text can pull the current version from 47 CFR Part 64 Subpart U via eCFR.
How to respond when CPNI is exposed
Speed and documentation both matter. When a breach is detected or suspected, follow this sequence:
- Contain immediately: Revoke compromised credentials, isolate affected systems, and preserve logs and evidence before any remediation that could overwrite data.
- Notify law enforcement: The FCC requires carriers to notify the FBI and United States Secret Service within seven business days of a reasonable determination that a breach occurred, before notifying customers.
- Notify affected customers: After the law enforcement notification window, notify affected customers promptly. The FCC's data protection guidance specifies that carriers must also submit annual summaries of consumer complaints related to CPNI breaches.
- Document opt-out failures separately: If the breach involves a failure of the opt-out notification mechanism, a five-business-day written notice obligation applies.
- Update the annual certification: The complaint summary and remedial actions taken must be accurately reflected in the next annual certification filing.
Post-incident, conduct a root-cause review and update your authentication procedures, access controls, and training materials based on findings. Regulators look at whether carriers learned from incidents, not just whether they reported them.
How to manage vendors and third parties with CPNI access
Any vendor, reseller, or partner that touches CPNI inherits your compliance obligations in practice, even if the legal duty stays with you. Contracts must include purpose-limitation clauses that restrict the vendor to using CPNI only for the specific service they are providing, prohibit re-use or onward disclosure, require breach notification to you within a defined window (48 hours is a reasonable standard), grant you audit rights, and mandate data return or deletion upon contract termination.
Pro Tip: Require vendors to provide an annual written attestation confirming their CPNI handling practices. Treat a vendor's failure to return that attestation as a material contract breach, not an administrative oversight.
Operational controls should include segregated access environments so vendors cannot reach CPNI outside their contracted scope, tokenized or masked data where full records are not needed, and continuous monitoring for anomalous access patterns. Reviewing common telecom operational mistakes can help teams identify vendor-related pitfalls before they become enforcement issues.
Your CPNI compliance checklist
Use this as a starting framework for an initial audit or annual review cycle.
| Task | Owner | Timing |
|---|---|---|
| Review and update CPNI policy | Legal/Compliance | Annually by March 1 |
| Audit authentication procedures | IT | Quarterly |
| Supervisory review of marketing campaigns | Operations/Compliance | Before each campaign launch |
| Retain outbound marketing records | Operations | Minimum one year |
| Complete staff CPNI training | HR/Compliance | Annually and at onboarding |
| File annual certification (EB Docket No. 06-36) | Legal/Officer | By March 1 |
| Vendor attestation collection | Procurement/Legal | Annually |
| Breach response plan test | IT/Legal | Annually |
Priority sequence for a first-phase implementation:
- Lock down authentication: update CRM and ticketing systems to enforce password or token-based verification.
- Document supervisory approval workflows for any outbound marketing that uses usage or service data.
- Establish a breach response runbook with named owners for each notification step.
- Schedule the annual certification on the legal calendar with a January 15 internal deadline to allow officer review before the March 1 FCC deadline.
For California-based operations, network compliance requirements at the state level intersect with federal CPNI obligations and should be reviewed alongside this checklist.
What to ask managed network and UCaaS providers about CPNI
Managed services providers that handle your network infrastructure, hosted voice, or unified communications will generate and process CPNI on your behalf. That does not transfer your legal obligation, but it does mean the provider's controls directly affect your compliance posture.
Questions to include in any RFP or due diligence review:
- Do you maintain access logs for all personnel and systems that touch call detail records or usage data, and how long are those logs retained?
- What authentication methods do your support agents use when customers contact you, and do those methods comply with 47 CFR ยง 64.2010?
- How do you notify us of a suspected CPNI breach, and what is your contractual notification SLA?
- Can you provide SOC 2 Type II reports or equivalent evidence of your access control and logging practices?
- Do you support annual certification documentation, including complaint summaries and opt-out mechanism descriptions?
Californiatelecom's managed LAN/WAN services include engineer-led deployment, continuous monitoring through a 24/7 U.S.-based NOC, and centralized logging across multi-location environments, all of which map directly to the access control and audit trail requirements under 47 CFR ยง 64.2009. For voice environments where call detail records are generated, UCaaS deployments should be evaluated against CPNI controls at the platform level, including how CDRs are stored, who can access them, and how breaches are detected and reported.
CPNI compliance is a trust asset, not just a legal checkbox
Most carriers treat the annual certification as a filing exercise. That framing misses what the FCC actually built into Section 222: a structural requirement that leadership, not just technical staff, owns customer data protection. The officer attestation exists precisely because regulators know that compliance programs delegated entirely to IT tend to drift. When an officer signs that certification with personal knowledge, they are accountable for whether the authentication procedures actually work, whether the training happened, and whether the complaint summary is accurate.
The carriers that get this right tend to treat CPNI controls the same way they treat network uptime: as something that directly affects customer trust and business continuity. A breach that exposes call records or location data is not just an FCC enforcement problem. It is a customer retention problem. Framing CPNI governance as a trust investment rather than a compliance cost tends to get it the organizational attention it deserves.
Californiatelecom handles the network controls so you can focus on the certification
Running a CPNI-compliant network across multiple locations means managing access logs, authentication enforcement, breach detection, and vendor accountability simultaneously. Californiatelecom's nationwide managed network services give IT and compliance teams a single accountable provider with engineer-led deployments, a 24/7 U.S.-based NOC, and centralized observability across every site.The practical result: your access logs are maintained, anomalous activity is flagged in real time, and your team has documented evidence ready when the annual certification requires it. One provider, one bill, one engineer's direct number. Start with a free consultation to map your current network environment to your CPNI obligations and identify the gaps before your next March 1 deadline.
Sources
Teams acting on this guide should verify current rule text and file directly through official FCC channels:
- 47 U.S. Code ยง 222 - Privacy of customer information | U.S. Code | US Law | LII / Legal Information Institute
- PUBLIC NOTICE (DA-24-125A1) TELECOMMUNICATIONS CARRIERS AND INTERCONNECTED VOIP PROVIDERS MUST FILE ANNUAL REPORTS CERTIFYING COMPLIANCE WITH COMMISSION RULES PROTECTING CUSTOMER PROPRIETARY NETWORK INFORMATION
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

