Skip to content
Back to all frameworks
Telecom

CPNI Rules

Customer Proprietary Network Information Protection Rules

FCC rules protecting sensitive customer data held by telecommunications carriers.

What is CPNI Rules?

Customer Proprietary Network Information (CPNI) rules protect sensitive customer data that telecommunications carriers obtain through provision of services. CPNI includes information about the quantity, technical configuration, type, destination, location, and amount of use of a customer's telecommunications services.

The FCC CPNI rules (47 CFR § 64.2001-64.2011) restrict how carriers can use and disclose this information, require customer authentication before disclosing CPNI, mandate breach notification, and require annual compliance certifications. Violations can result in substantial fines and enforcement actions.

Who Needs CPNI Rules?

  • Telecommunications carriers
  • Wireless providers
  • VoIP service providers
  • Resellers and MVNOs
  • Interconnected service providers

Key Requirements

Core compliance areas for CPNI Rules

1

Customer Authentication

Verify customer identity before disclosing CPNI via specified methods.

2

Use Restrictions

Limit use of CPNI to providing and marketing service categories.

3

Opt-In/Opt-Out

Obtain appropriate consent for marketing uses of CPNI.

4

Breach Notification

Notify FBI/Secret Service, FCC, and customers of CPNI breaches.

5

Annual Certification

File annual certification with FCC regarding CPNI compliance.

Benefits of CPNI Rules Compliance

  • FCC compliance
  • Customer privacy protection
  • Avoid substantial fines
  • Maintain carrier authority
  • Customer trust
  • Reduced breach liability

How PartnerAlly Helps with CPNI Rules

Streamline your path to CPNI Rules compliance with our AI-powered platform.

CPNI compliance assessment
Authentication procedure templates
Breach notification workflows
Training program materials
Annual certification preparation
Compliance monitoring