Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Data Breaches: Not Just for States and the FTC Anymore

By Sheila Millar & Tracy Marshall on April 8, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

The Federal Communications Commission (FCC) announced today that AT&T Services, Inc., will pay $25 million to resolve an investigation into whether the company violated Sections 201(b) and 222 of the Communications Act relating to consumer privacy at AT&T call centers in Mexico, Colombia, and the Philippines. According to the FCC’s order and consent decree, call center employees gained unauthorized access to customer names, full or partial Social Security numbers, and account-related information (known as “customer proprietary network information” or “CPNI”), and shared it with third parties who trafficked in stolen mobile phones or secondary market phones so that they could unlock the phones.

FCC Chairman Tom Wheeler said that the FCC, “[a]s the nation’s expert agency on communications networks, … cannot – and will not – stand idly by when a carrier’s lax data security practices expose the personal information of hundreds of thousands” of Americans. Nearly 280,000 customer accounts were reportedly affected.

This is the FCC’s second (and largest) enforcement action relating to data security, and the agency’s fifth major enforcement action in the last year relating to privacy and data security. As part of the settlement, in addition to paying a $25 million civil penalty, AT&T agreed to enhance its privacy and security practices, by (among other things) performing a risk assessment, adopting a written information security program, developing a compliance manual for employees and vendors, implementing a training program, and filing periodic compliance reports with the FCC.

This settlement is a reminder of the broad set of actors who are using their authority to police data breaches. Although the most prominent enforcers are the Federal Trade Commission (FTC) and a few select attorneys general (Kamala Harris in California and Eric Schneiderman in New York, for example), others are getting in the game. In fact, the Chief of the FCC’s Enforcement Bureau was previously Special Assistant Attorney General of California and a senior advisor to California A.G. Harris, suggesting that the FCC will continue to aggressively enforce privacy and data security violations. This settlement is also a reminder that U.S. data breach laws can extend outside U.S. borders to wherever a company handles information. Robust written procedures, including good hiring practices and training, and a sound data security program and breach response plan are necessary to assure that your customer and employee data is appropriately protected, wherever you process and store it.

Photo of Sheila Millar Sheila Millar

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has…

Sheila A. Millar is a partner at Keller and Heckman LLP, where she represents businesses and trade associations on a variety of public policy and regulatory issues, including privacy, data security, cybersecurity and advertising matters, as well as product safety issues. She has been involved in a variety of audit and compliance projects, including, among other issues, privacy and data security audits, and is experienced in providing crisis management legal support to a variety of national and international companies and associations.

Ms. Millar is a frequent speaker on regulatory and public policy matters, and has authored many articles. Ms. Millar is one of the vice chairs of the International Chamber of Commerce (ICC) Marketing and Advertising Commission, and chair of its Working Group on Sustainability, where she spearheaded the development of the ICC Framework Guides on Environmental Marketing Claims.

Ms. Millar is AV® PreeminentTM Rated by Martindale-Hubbell and for the eigth consecutive year was selected by her peers for inclusion in The Best Lawyers in America® 2018 for her work in practicing Advertising Law. She has also received the distinguished honor of Advertising Law “Lawyer of the Year” 2014 in Washington, DC by Best Lawyers®, and was awarded Advertising and Marketing Lawyer of the Year USA by Finance Monthly for their Finance Monthly Global Awards 2017.

Read more about Sheila MillarEmailSheila's Linkedin Profile
Show more Show less
Photo of Tracy Marshall Tracy Marshall

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She …

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She is a Certified Information Privacy Professional (CIPP/US) through the International Association of Privacy Professionals (IAPP) and helps clients implement privacy, data security, and security breach response programs, develop internal and public-facing privacy policies to comply with applicable laws, respond to cyber and data security incidents, and manage relationships with service providers and third parties. Tracy advises on structuring and conducting email and text messaging campaigns, sweepstakes, contests, and other promotions, and she helps clients protect and enforce their intellectual property rights.

In addition, Tracy counsels clients on corporate matters and assists with structuring and negotiating a variety of transactions, including licensing, marketing, and outsourcing arrangements.

Tracy is frequently invited to speak at privacy, data security, telecommunications, and advertising conferences and is a contributor to Keller and Heckman’s Consumer Protection Connection blog and Beyond Telecom Law Blog.


To learn more about Tracy’s practice areas, click here.
Read more about Tracy MarshallEmailTracy's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Consumer Protection Connection
  • Organization:
    Keller Heckman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo