Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

ALERT: The FCC Fines Companies $20 Million for Failing to Safeguard Customer Proprietary Network Information

By Drew Svor, Elfin Noce & Ethan Lamb on August 31, 2023
Email this postTweet this postLike this postShare this post on LinkedIn
FCC-Blog-Wireless-Broadband-Image-660x283

Recently, the FCC reminded telecom providers that the cost of failing to protect their customers’ privacy is steep. In a July 28, 2023 Notice of Apparent Liability for Forfeiture, the Federal Communications Commission fined Q Link Wireless LLC and Hello Mobile Telecom LLC, an affiliate of Q Link, $20 million for impermissibly relying upon readily available biographical information and account information to authenticate online customers.[1]

Background. Q Link and Hello Mobile are both mobile virtual network operators, or MVNOs. As such, they are both subject to Section 222 of the Communications Act, which requires service providers to take reasonable measures to discover and protect against unauthorized use, access, and disclosure of customer proprietary network information, or CPNI, which generally includes customer calling records and location information.

In an effort to mitigate against the threat of unauthorized third parties masquerading as customers, the Commission passed rules prohibiting carriers from authenticating a customer with “readily available biographical information [or] account information.”[2] Additionally, processes to recover lost passwords cannot authenticate customers by using biographic or account information as prompts.

Q Link and Hello Mobile set default passwords to “readily available” biographical information. If the customer neglected to change the password, that customer was forced to use biographical information to log in. While the specific category of information used by the Companies was redacted in the Commission’s Notice, the Commission determined that such information is “easily associated with [a customer’s] life story” and thus constitutes “readily available biographical information.” The mechanism to recover lost passwords also impermissibly contained readily available biographical information.

Specific FCC Rule Violations: The Commission concluded that Q Link and Hello Mobile violated its rules requiring providers to:

  1. Take “reasonable measures to discover and protect against attempts to gain unauthorized access to CPNI.”[3] The Companies failed to meet this standard because customers’ CPNI was available to “effectively any party who knew—or could obtain—a customer’s readily available biographical information or account information.”[4]
  2. Authenticate a customer “without the use of readily available biographical information, or account information,” prior to allowing the customer online access to CPNI related to a telecommunications service account.[5] Once authenticated, the customer may only obtain online access to CPNI through a password that is not prompted by the carrier asking for readily available biographical information, or account information.[6]
  3. Not include “readily available biographical information” or “account information” when creating a backup customer authentication method prompt in the event that a customer loses or forgets the account password.[7]

Based on its forfeiture guidelines, the Commission determined a penalty of $40,000 per violation to be reasonable. Notably, the Commission concluded that each time the companies used readily available biographical information or account information to authenticate a customer or effectuate a password reset (conservatively estimated at 500 occurrences) constituted a separate violation—thus resulting in a $20 million forfeiture.

Analysis and Key Takeaways. This case signals the Commission’s renewed interest in rigorously safeguarding the privacy of subscriber information. Telecommunications providers, and MVNOs in particular, should be aware of the FCC’s CPNI rules and the potentially large fines that can accrue.

FOOTNOTES

[1] Q Link Wireless LLC and Hello Mobile Telecom LLC, Notice of Apparent Liability for Forfeiture, FCC 23-59 (2023) (“Notice of Apparent Liability for Forfeiture”).

[2] 47 CFR § 64.2010(c) & (e) .

[3] Id. § 64.2010(a).

[4] Notice of Apparent Liability for Forfeiture, at ¶ 19.

[5] 47 CFR § 64.2010(c).

[6] Id.

[7] Id. at § 64.2010(e).

Photo of Drew Svor Drew Svor

Drew Svor is a partner in the firm’s Washington, D.C. office and serves as a member of the firm’s Telecom, Space & Satellite, CFIUS and AI Teams, as well as the D.C. office’s recruiting co-chair.

Read more about Drew SvorEmail
Photo of Elfin Noce Elfin Noce

Elfin Noce is an associate in the Intellectual Property Practice Group in the firm’s Washington, D.C. office. He also is a member of the Privacy and Cybersecurity Team.

Read more about Elfin NoceEmail
Photo of Ethan Lamb Ethan Lamb

Ethan Lamb is an associate in the Corporate Practice Group in the firm’s Washington, D.C. office. He is also a member of the firm’s CFIUS Team.

Read more about Ethan LambEmail
  • Posted in:
    Communications, Media & Entertainment
  • Blog:
    FCC Law Blog
  • Organization:
    Sheppard, Mullin, Richter & Hampton LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo