Recently, the FCC reminded telecom providers that the cost of failing to protect their customers’ privacy is steep. In a July 28, 2023 Notice of Apparent Liability for Forfeiture, the Federal Communications Commission fined Q Link Wireless LLC and Hello Mobile Telecom LLC, an affiliate of Q Link, $20 million for impermissibly relying upon readily available biographical information and account information to authenticate online customers.[1]

In an effort to mitigate against the threat of unauthorized third parties masquerading as customers, the Commission passed rules prohibiting carriers from authenticating a customer with “readily available biographical information [or] account information.”[2] Additionally, processes to recover lost passwords cannot authenticate customers by using biographic or account information as prompts.

Specific FCC Rule Violations: The Commission concluded that Q Link and Hello Mobile violated its rules requiring providers to:

  1. Take “reasonable measures to discover and protect against attempts to gain unauthorized access to CPNI.”[3] The Companies failed to meet this standard because customers’ CPNI was available to “effectively any party who knew—or could obtain—a customer’s readily available biographical information or account information.”[4]
  2. Authenticate a customer “without the use of readily available biographical information, or account information,” prior to allowing the customer online access to CPNI related to a telecommunications service account.[5] Once authenticated, the customer may only obtain online access to CPNI through a password that is not prompted by the carrier asking for readily available biographical information, or account information.[6]
  3. Not include “readily available biographical information” or “account information” when creating a backup customer authentication method prompt in the event that a customer loses or forgets the account password.[7]

Based on its forfeiture guidelines, the Commission determined a penalty of $40,000 per violation to be reasonable. Notably, the Commission concluded that each time the companies used readily available biographical information or account information to authenticate a customer or effectuate a password reset (conservatively estimated at 500 occurrences) constituted a separate violation—thus resulting in a $20 million forfeiture.

Analysis and Key Takeaways. This case signals the Commission’s renewed interest in rigorously safeguarding the privacy of subscriber information. Telecommunications providers, and MVNOs in particular, should be aware of the FCC’s CPNI rules and the potentially large fines that can accrue.

FOOTNOTES

[2] 47 CFR § 64.2010(c) & (e) .

[3] Id. § 64.2010(a).

[4] Notice of Apparent Liability for Forfeiture, at ¶ 19.

[5] 47 CFR § 64.2010(c).

[6] Id.

[7] Id. at § 64.2010(e).