Skip to content

Evidence request lists

FCC Customer Proprietary Network Information (CPNI) and Data Breach Rules (47 CFR 64.2001-2011)

Evidence request list. 13 controls, 13 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

FCC CPNI: Annual Compliance Certification and Recordkeeping

CPNI-AnnualCert
Annual compliance certification - 1 March deadline (47 CFR 64.2009(e))

Section 64.2009(e) requires telecommunications carriers + interconnected VoIP providers to file an ANNUAL COMPLIANCE CERTIFICATION with the FCC by 1 MARCH OF EACH YEAR covering the previous calendar year. The certification must be SIGNED BY A CORPORATE OFFICER WITH PERSONAL KNOWLEDGE + must state that the officer has personal knowledge that the carrier has established operating procedures adequate to ensure compliance with the rules in this subpart. The certification must INCLUDE: (a) a statement explaining how the carrier's operating procedures ensure compliance; (b) an EXPLANATION OF ANY ACTIONS taken AGAINST DATA BROKERS + a summary of all consumer complaints received in the past year concerning the unauthorised release of CPNI. The certification must be FILED IN THE EB-CPNI DOCKET + made publicly available. Failure to file the annual certification is a per se violation + has resulted

Artefacts an auditor will ask for
  • Annual filing copy + EB-CPNI docket reference
  • Officer attestation file with supporting evidence
  • Operating procedures documentation
  • Data broker actions log + consumer complaint summary
Where this commonly fails
  • Annual filing missed or filed late
  • Officer certification signed without personal-knowledge basis
  • Data broker actions or consumer complaints summary missing
  • Filing format outdated relative to current FCC Public Notice
CPNI-Recordkeeping
Recordkeeping requirements (multi-rule)

FCC CPNI recordkeeping requirements aggregate from multiple sections: (a) Section 64.2009(b)/(c) - 1-YEAR retention of marketing campaign records (description of each campaign + CPNI used + products/services offered) + supervisory review records; (b) Section 64.2010 - records of customer authentication + account access events (industry practice typically 1-2 year retention); (c) Section 64.2011(d) - 2-YEAR retention of CPNI security breach records (all reports + dates + remediation steps); (d) Section 64.2009(e) - annual certification + supporting evidence retained for FCC examination periods (typically aligned with FCC statute-of-limitations + enforcement-action recordkeeping ~5-10 years); (e) consent records under Section 64.2004/64.2007/64.2008 - retained for the duration of customer relationship + reasonable period after relationship ends to support enforcement defence. Industry best

Artefacts an auditor will ask for
  • Records-retention policy specifying each CPNI category
  • Records access + retrieval procedure for FCC inquiries
  • Records disposal + destruction trail
Where this commonly fails
  • Records retention shorter than minimum required
  • Records not segregated by category making FCC-inquiry response slow
  • Disposal without proper documentation

FCC CPNI: Basis, Purpose and Definitions (64.2001-64.2003)

CPNI-64.2001_2003
Basis, purpose and definitions (47 CFR 64.2001 + 64.2003)

Section 64.2001 (Basis and purpose): the rules in this subpart implement Section 222 of the Communications Act of 1934 + provide standards governing telecommunications carriers' use + disclosure of customer proprietary network information (CPNI). Section 64.2003 (Definitions): (a) ACCOUNT INFORMATION = information that is specifically connected to the customer's service relationship with the carrier (account number + telephone number + service-related information that is publicly available); (b) AFFILIATE = a person that owns or controls + is owned or controlled by + is under common ownership or control with another person; (c) CALL DETAIL INFORMATION = any information that pertains to the transmission of specific telephone calls including originating + terminating telephone number + time of call + length of call; (d) COMMUNICATIONS-RELATED SERVICES = telecommunications + information + c

Artefacts an auditor will ask for
  • Scope determination memo identifying which entity types qualify (telecommunications carrier + interconnected VoIP)
  • Definitional walk-through for Call Detail Information + Service Plan + Location Information + Account Information
  • Affiliate identification + control + common ownership analysis
Where this commonly fails
  • Scope analysis missing interconnected VoIP provider status
  • Definitional drift between CPNI + general 'customer information' / 'PII' terminology
  • Affiliate identification not refreshed at corporate change of control
CPNI-Status
FCC CPNI - corpus status, enforcement landscape, broadband privacy

FCC CPNI rules + Section 222 of the Communications Act are the principal US federal telecommunications-privacy framework. Status: REGULATIONS IN FORCE since 1996 (Section 222) + 1998 (initial FCC CPNI Order) + 2007 + 2009 + 2011 + 2017 amendments. Key amendments: 2007 CPNI Order (FCC 07-22) tightening authentication + addressing pretexting; 2009 CPNI Order (FCC 09-9) further authentication + password protection + EB-CPNI annual filing; 2011 Data Breach Order (FCC 11-49) Section 64.2011 breach notification framework; 2016 FCC Broadband Privacy rules (FCC 16-148) extending CPNI-style protections to broadband internet access service - REPEALED by Congressional Review Act (Public Law 115-22) in April 2017; 2024 FCC enforcement actions against major carriers for sale of customer location data without consent (combined ~$200M+ in fines). FUTURE: the FCC continues to monitor location data + AI

Artefacts an auditor will ask for
  • Tracking of FCC enforcement actions + carrier-specific consent decrees
  • Monitoring of state privacy law interplay with Section 222
  • Location-data sale risk assessment
Where this commonly fails
  • Compliance program treating CPNI as static without tracking FCC enforcement
  • No state-privacy-law interplay analysis
  • Location-data sale risk not assessed (especially for indirect vendor chains)

FCC CPNI: Data Breach Notification (64.2011)

CPNI-64.2011
Notification of CPNI security breaches (47 CFR 64.2011)

Section 64.2011 establishes the data breach notification regime: (a) DEFINITION OF BREACH - 'a person, without authorisation or exceeding authorisation, has intentionally gained access to + use + disclose CPNI' (the FCC 2024 amendment expanded this to include 'inadvertent + accidental' breaches in certain circumstances). (b) LAW ENFORCEMENT NOTIFICATION - within 7 BUSINESS DAYS of REASONABLE DETERMINATION OF A BREACH the carrier must electronically notify the United States Secret Service (USSS) + the Federal Bureau of Investigation (FBI) through the CENTRAL REPORTING FACILITY at https://www.cpnireporting.gov + the FCC. (c) CUSTOMER NOTIFICATION TIMING - the carrier MUST NOT notify customers OR disclose the breach publicly until 7 business days have passed AFTER the law enforcement notification UNLESS law enforcement requests an extension. (d) NOTIFICATION CONTENT - notifications must inc

Artefacts an auditor will ask for
  • Breach-incident-response playbook covering 7-business-day LE notification
  • Central Reporting Facility account + filing capability
  • Customer-notification templates + delivery channels
  • 2-year breach records retention
Where this commonly fails
  • LE notification delayed past 7 business days
  • Customer notification before law enforcement waiting period
  • Breach records retention shorter than 2 years
  • Central Reporting Facility account not provisioned

FCC CPNI: Personnel Training and Marketing Campaign Records

CPNI-Marketing-OBM
Outbound marketing (OBM) records and supervisory review (47 CFR 64.2009(b)-(c))

Outbound marketing (OBM) is the most-scrutinised area under CPNI enforcement. Section 64.2009(b) + (c) requirements: (a) MARKETING CAMPAIGN RECORDS - the carrier must maintain a record of its OUTBOUND sales + marketing campaigns that use the customer's CPNI for a minimum of 1 year. The record must include: (i) a DESCRIPTION OF EACH CAMPAIGN; (ii) the SPECIFIC CPNI that was used; (iii) WHAT PRODUCTS + SERVICES WERE OFFERED as part of the campaign. (b) SUPERVISORY REVIEW - sales personnel must OBTAIN SUPERVISORY APPROVAL OF ANY PROPOSED OUTBOUND MARKETING REQUEST FOR CUSTOMER APPROVAL. (c) ANNUAL OFFICER CERTIFICATION must specifically address OBM compliance + summarise OBM compliance. The 2007 + 2009 CPNI Orders identified OBM as a major risk-area following enforcement findings against several carriers for misleading OBM scripts + insufficient supervisory oversight.

Artefacts an auditor will ask for
  • OBM campaign register
  • Supervisory approval records per OBM campaign
  • OBM script review records
  • Annual officer certification OBM-specific section
Where this commonly fails
  • OBM campaign records missing required elements (CPNI used + products / services offered)
  • Supervisory approval limited to campaign launch without ongoing review
  • OBM scripts not reviewed for CPNI compliance
CPNI-Personnel
Personnel training and disciplinary process (47 CFR 64.2009(a))

Section 64.2009(a) requires telecommunications carriers to TRAIN THEIR PERSONNEL as to when they are + are not authorised to use CPNI + to HAVE AN EXPRESS DISCIPLINARY PROCESS in place. Specific requirements: (a) initial training for new employees + contractors with CPNI access prior to commencement of CPNI duties; (b) ongoing / refresher training (typically annual); (c) role-specific training (call center + sales + technical operations + retail + third-party vendor training where contractors have CPNI access); (d) DISCIPLINARY PROCESS - the carrier must include consequences for failure to follow CPNI procedures including IMMEDIATE DISMISSAL where appropriate; the disciplinary procedures must be communicated to personnel; (e) records of training + disciplinary actions; (f) annual certification must include statement on training programme. The 2007 + 2009 CPNI Orders + subsequent FCC enfo

Artefacts an auditor will ask for
  • Training programme curriculum + records
  • Annual refresher records
  • Disciplinary policy + cases
  • Annual cert OBM section reference to training
Where this commonly fails
  • Training limited to onboarding without annual refresher
  • Disciplinary process documented but not enforced
  • Third-party vendor CPNI training absent
  • Training records not retained or partial

FCC CPNI: Safeguards on Use and Disclosure (64.2009-64.2010)

CPNI-64.2009
Safeguards required for use of CPNI (47 CFR 64.2009)

Section 64.2009 establishes safeguards on CARRIER'S USE of CPNI: (a) TRAINING - carriers must train their personnel as to when they are + are not authorised to use CPNI; carriers shall have an EXPRESS DISCIPLINARY PROCESS in place + carriers must include in the disciplinary process consequences for failure to follow CPNI procedures including immediate dismissal where appropriate. (b) MAINTENANCE OF RECORDS - carriers must maintain a record of its sales + marketing campaigns that use the customer's CPNI for a minimum of 1 YEAR; the record must include a description of each campaign + the specific CPNI that was used + what products + services were offered as part of the campaign. (c) SUPERVISORY REVIEW PROCESS - carriers must establish a supervisory review process regarding carrier compliance with the rules for outbound marketing situations + maintain records of carrier compliance for a mi

Artefacts an auditor will ask for
  • Training programme + records + disciplinary policy
  • Outbound marketing campaign records register
  • Supervisory review records for OBM
  • Annual CPNI compliance certification by corporate officer (filed by 1 March)
Where this commonly fails
  • Training not documented or limited to onboarding
  • Marketing-campaign records incomplete (missing CPNI used + products/services offered)
  • Supervisory review limited to first-quarter sales without continuing oversight
  • Officer certification signed without personal knowledge or based on incomplete attestation
CPNI-64.2010
Safeguards on disclosure - authentication for account access (47 CFR 64.2010)

Section 64.2010 establishes safeguards on DISCLOSURE of CPNI through customer-account-access channels. The 2007 + 2009 CPNI Orders strengthened these rules following the HP pretexting scandal + further data-broker abuse. (a) GENERAL DISCLOSURE PROHIBITION - telecommunications carriers MUST TAKE REASONABLE MEASURES TO DISCOVER + PROTECT AGAINST ATTEMPTS TO GAIN UNAUTHORISED ACCESS TO CPNI + may only disclose CPNI based on a customer's verified identification. (b) TELEPHONE ACCESS - carriers must AUTHENTICATE the customer prior to disclosing call detail information based on customer-initiated telephone contact without the use of readily available biographical information / account information; back-up authentication methods may be available (e.g. carriers may provide call detail to customers based on customer authentication or carriers may at the customer's request send the information to

Artefacts an auditor will ask for
  • Authentication procedure documentation by channel
  • Password / Q&A backup authentication design
  • In-store ID verification protocol
  • Account change notification automated process
Where this commonly fails
  • Telephone authentication relying on readily available biographical info (e.g. last four of SSN + DOB)
  • Password reset via readily available biographical info
  • No in-store ID verification
  • Account changes not notified to customer of record
CPNI-Vendor
Third party and joint venture CPNI restrictions (47 CFR 64.2007 + 64.2009)

CPNI rules apply to third parties + joint ventures + independent contractors that the carrier permits to access CPNI. Specific requirements: (a) Section 64.2007 OPT-IN required for joint venture + independent contractor use of CPNI for marketing not specifically related to the customer's existing service; (b) Section 64.2007 OPT-OUT may be sufficient for affiliated communications-related services entities; (c) Section 64.2009 SAFEGUARDS - carrier must extend CPNI safeguards to third parties through CONTRACTUAL FLOW-DOWN + monitoring + audit rights; (d) third-party vendor agreements must include CPNI confidentiality + use restrictions + breach notification flow-down to the carrier + audit rights; (e) third-party operational independence does NOT diminish carrier responsibility - the carrier remains fully accountable for CPNI under Section 222 even where access is via contractor / vendor /

Artefacts an auditor will ask for
  • Vendor agreement CPNI clauses + audit rights
  • Vendor breach notification flow-down
  • Annual vendor CPNI audit
  • Sale-of-location-data risk assessment
Where this commonly fails
  • Vendor agreement lacks CPNI-specific flow-down
  • Audit rights not exercised
  • Vendor breach notification not received or acted on
  • Location data sold via third-party data brokers without traceability or carrier oversight

FCC CPNI: Use, Approval and Notice (64.2004-64.2008)

CPNI-64.2004
Customer approval mechanisms - opt-in and opt-out (47 CFR 64.2004)

Section 64.2004 establishes the customer approval mechanisms for CPNI use. (a) CARRIERS MUST OBTAIN CUSTOMER APPROVAL BEFORE USING CPNI for marketing purposes outside of the relevant Section 222(c)(1) categories (i.e. outside the provision + offering of services adjacent to those the customer subscribes to + the carrier's category of service). (b) OPT-IN APPROVAL is required for: (i) disclosure to non-affiliated third parties for any purpose; (ii) joint venture or independent contractor use of CPNI for marketing not specifically related to the customer's existing service; (iii) certain affiliated marketing where the affiliate does not provide communications-related services. (c) OPT-OUT APPROVAL is sufficient for: (i) carrier's own use for marketing additional services; (ii) carrier's affiliates that provide communications-related services. (d) Notice + Election Process: customers must b

Artefacts an auditor will ask for
  • Customer-approval mechanism + record
  • Notice content + delivery evidence
  • 30-day election period observed
  • Opt-out election persistence tracking
Where this commonly fails
  • Opt-out used where opt-in required (e.g. non-affiliated third party)
  • Election period less than 30 days
  • No tracking of opt-in / opt-out revocations
  • Notice method limited to fine print at point-of-sale
CPNI-64.2005_2007
Use of CPNI without customer approval + approval required for use (47 CFR 64.2005-64.2007)

Section 64.2005 (Use of CPNI without customer approval): a telecommunications carrier may USE + DISCLOSE + PERMIT ACCESS TO CPNI for the purpose of providing or marketing service offerings AMONG THE CATEGORIES OF SERVICE (telecommunications + information + commercial mobile + interconnected VoIP) TO WHICH THE CUSTOMER ALREADY SUBSCRIBES from that carrier WITHOUT obtaining additional customer approval. Carriers may also: (a) provide call location information concerning a user of CPS to a public safety answering point + emergency medical service provider + law enforcement + fire fighting + responding to user's call for emergency services + a user's legal guardian; (b) use CPNI to initiate + render + bill + collect for telecommunications services; (c) protect rights / property of the carrier + customers / users from fraudulent + abusive + unlawful use of services. Section 64.2007 (Approval

Artefacts an auditor will ask for
  • Use-of-CPNI catalog mapping each use to the approval requirement
  • Carve-out documentation for emergency / fraud / billing purposes
  • Approval-required-use audit trail
Where this commonly fails
  • CPNI used for marketing additional services without verifying approval category
  • Carve-outs invoked broadly without per-use justification
  • Third-party disclosure occurring without opt-in approval
CPNI-64.2008
Notice requirements for use of CPNI (47 CFR 64.2008)

Section 64.2008 establishes notice requirements: (a) CONTENT - the notice must include: (i) sufficient information to enable customers to make an informed decision about whether to permit a carrier to use + disclose + permit access to CPNI; (ii) state that the customer has a right + the carrier has a duty under federal law to protect the confidentiality of CPNI; (iii) specify the types of information that constitute CPNI + the specific entities that will receive the CPNI + describe the purposes for which CPNI will be used; (iv) inform the customer of his or her right to disapprove uses + disclosures; (v) inform the customer that disapproval will not affect the provision of any services to which the customer subscribes; (vi) be comprehensible + not be misleading; (vii) be clearly legible + use sufficiently large type + placed in an area readily apparent to a customer + give individual not

Artefacts an auditor will ask for
  • Notice text reviewed against Section 64.2008(c)/(d) requirements
  • Customer-facing display evidence (web + mobile + bill insert + in-store)
  • Bilingual notice in markets requiring
  • Consent record retention
Where this commonly fails
  • Notice content missing required elements (often misses the 'right + duty' federal-law statement + 'disapproval will not affect services' assurance)
  • Notice not clearly legible + buried in legalese
  • Bilingual notice absent in Spanish-language markets
  • Consent records not retained or partially retained
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.