FCC’s data breach reporting rules for telecoms are upheld in appeals court
美国联邦通信委员会(FCC)要求电信公司报告客户个人信息泄露的法规在法庭挑战中胜出。该法规于2024年实施,要求涉及500人以上信息泄露事件须在7个工作日内上报,并首次将社会安全号码和电子邮件地址等信息纳入保护范围。尽管行业团体质疑FCC权限,法院多数法官支持其合法性。 2025-8-14 15:15:45 Author: therecord.media(查看原文) 阅读量:10 收藏

The Federal Communications Commission’s regulations requiring telecom companies to report breaches of customers’ personally identifiable information (PII) have survived a court challenge. 

A federal appeals court panel voted 2-1 on Wednesday against a petition from industry groups, who argued that the 2024 rules exceeded the FCC’s statutory authority. Under the regulations, telecom companies must report breaches involving 500 or more customers’ PII within seven business days.

The rules, approved in December 2023 and imposed in March 2024, represented the first update to the agency’s data breach reporting requirements in 16 years.

Previous regulations covered breaches of data such as call records or billing information — also known as customer proprietary network information” (CPNI) — but the update added PII such as Social Security numbers and email addresses.

Multiple trade associations had asked federal judges to block the new rules, and many of those cases were consolidated into the petition in the Ohio-based U.S. Court of Appeals for the Sixth Circuit. 

“We have determined that the FCC has the statutory authority to impose the 2024 data breach reporting rule on telecommunications carriers,” the majority judges said in their opinion. They also determined that the regulations did not violate the Congressional Review Act, which lawmakers had used to reject similar rules in 2017.

Several high-profile telecom company data breaches have led to settlements with the FCC in recent years.

T-Mobile agreed to pay $31.5 million and overhaul its cybersecurity practices after a series of incidents dating back to 2021. AT&T paid $13.3 million after a breach at one of its cloud vendors. And Verizon-owned TracFone settled for $16 million after the agency alleged the company had failed to safeguard customer data.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/fcc-data-breach-reporting-rule-held-up-appeals-court
如有侵权请联系:admin#unsafe.sh