Customer Proprietary Network Information: Rights and SIM Swap Rules

Customer Proprietary Network Information, usually called CPNI, is the data your phone or VoIP carrier collects about how you use their service: the numbers you call, when and where you called from, how long you talked, the features on your plan, and the charges tied to that usage. Federal law under 47 U.S.C. ยง 222 restricts how carriers handle this information and gives you a say in whether it can be used for marketing or shared.1Office of the Law Revision Counsel. 47 U.S. Code 222 – Privacy of Customer Information Because CPNI paints a detailed picture of your relationships and habits, it’s a frequent target for identity thieves and the fuel behind scams like SIM swapping.

What CPNI Is

CPNI covers two broad categories: information about how you use your telecommunications service, and information that appears on your phone bill.1Office of the Law Revision Counsel. 47 U.S. Code 222 – Privacy of Customer Information

In practical terms, that includes:

  • Call detail records: the numbers you dial, the time and length of each call, and where you were when you placed it.
  • Service features you subscribe to, such as voicemail, call waiting, or an international calling plan.
  • Billing data tied to specific services and usage.
  • Technical configuration details about the type and amount of service you use.

Some things people assume are CPNI actually are not. Your name, address, and phone number are excluded when they appear in a published directory listing. Financial account details like credit card numbers or Social Security numbers fall outside the definition. Aggregated data that can’t be traced back to a single customer doesn’t count either.1Office of the Law Revision Counsel. 47 U.S. Code 222 – Privacy of Customer Information

The abstract list of numbers you called is anonymous on its own. Attached to your account, it becomes deeply personal, and the CPNI rules exist because of that connection.

Who Has to Follow CPNI Rules

CPNI rules apply to telecommunications carriers and to interconnected VoIP providers. That covers traditional landline companies, wireless carriers, and internet-based phone services that connect to the regular telephone network.2Federal Communications Commission. CPNI Template Submission

One boundary worth knowing: broadband internet service providers are not currently subject to the detailed CPNI implementing rules. The FCC’s 2024 Open Internet Order classified broadband as a telecommunications service but stopped short of extending the specific CPNI regulations to internet providers. Your browsing history and app usage do not get the same CPNI protections as your phone records.

What Carriers Can Do Without Asking You

Your carrier can freely use your CPNI to provide the service you already subscribe to. That means managing your plan, handling billing, and running the network. No special permission is required.1Office of the Law Revision Counsel. 47 U.S. Code 222 – Privacy of Customer Information

Marketing is where your consent enters. If your carrier wants to use your CPNI to pitch you other communications-related services, or to share it with its affiliates for marketing, it can do so under an opt-out framework: you are notified and given a chance to say no. For any other use of your individually identifiable CPNI, the carrier needs opt-in approval, meaning your affirmative, express consent before the data is used or shared.3eCFR. 47 CFR 64.2007 – Approval Required for Use of Customer Proprietary Network Information

You can also direct your carrier to send your CPNI to a third party. On your affirmative written request, the carrier must disclose the information to whoever you designate.1Office of the Law Revision Counsel. 47 U.S. Code 222 – Privacy of Customer Information

How Carriers Confirm You Are You

Before a carrier releases your CPNI, it has to verify your identity. The FCC’s authentication rules are designed to block pretexting, where a caller impersonates you to pull your call records. The rules differ by channel.

Over the phone, a carrier can release call detail information only if you first provide a password or PIN. The carrier cannot accept “readily available biographical information” like your date of birth, mother’s maiden name, or Social Security number as a substitute. If you haven’t set up a password, the carrier’s only options are mailing the information to the address on file or calling you back at the number on the account.4eCFR. 47 CFR 64.2010 – Safeguards on the Disclosure of Customer Proprietary Network Information

For online access, the carrier must authenticate you without relying on biographical or account data, and then require a password before showing you CPNI. In a retail store, a valid photo ID matching the account information is enough.4eCFR. 47 CFR 64.2010 – Safeguards on the Disclosure of Customer Proprietary Network Information

Forgot your password? The carrier can offer a backup authentication method, but the backup also cannot rely on readily available biographical data. The goal is to make social engineering hard at every step.

SIM Swap and Port-Out Protections

SIM swapping is the most common way CPNI protections get bypassed. A scammer convinces your wireless carrier to move your phone number to a new SIM card, then intercepts your calls, texts, and two-factor authentication codes. Port-out fraud works the same way, except the number is moved to a different carrier.

The FCC now requires wireless providers to authenticate customers using secure methods before processing any SIM change or port-out request, and to notify you when a SIM change is requested so you can flag fraud before it goes through.5Federal Communications Commission. FCC 23-95 – Protecting Consumers from SIM-Swap and Port-Out Fraud

Carriers must also give you the ability to lock your account against SIM changes and port-outs entirely. These rules apply to all wireless providers, including resellers, and cover prepaid and postpaid accounts alike.5Federal Communications Commission. FCC 23-95 – Protecting Consumers from SIM-Swap and Port-Out Fraud

If Your CPNI Is Breached

When a carrier discovers unauthorized access to customer data, a specific notification sequence kicks in. The carrier first reports the breach electronically to the U.S. Secret Service and the FBI through a central reporting facility, no later than seven business days after discovering it.6eCFR. 47 CFR 64.2011 – Notification of Customer Proprietary Network Information Security Breaches

After notifying law enforcement, the carrier must wait seven full business days before telling affected customers, unless there is an urgent need to prevent immediate harm. Law enforcement can extend that delay up to 30 days if customer notification would compromise an ongoing investigation.6eCFR. 47 CFR 64.2011 – Notification of Customer Proprietary Network Information Security Breaches

The FCC updated these rules in 2023, expanding them beyond CPNI to cover all personally identifiable information held by carriers. Under the updated framework, carriers must also notify the FCC alongside the FBI and Secret Service. Customer notification cannot be delayed more than 30 days after the carrier determines a breach occurred, and carriers must report what data was exposed, how the breach happened, and how many customers were affected.7Federal Communications Commission. FCC Data Breach Reporting Requirements

Steps You Can Take Now

Set a PIN or password on every telecommunications account you have. This is the single most effective step, because it is what the authentication rules actually rely on. Without a password, a carrier cannot release call detail information over the phone at all, but the password is also what protects online and in-store requests.4eCFR. 47 CFR 64.2010 – Safeguards on the Disclosure of Customer Proprietary Network Information

Turn on the account lock feature if your wireless carrier offers one to block SIM changes and number porting. It’s now a required option under FCC rules and the strongest defense against SIM swap fraud.5Federal Communications Commission. FCC 23-95 – Protecting Consumers from SIM-Swap and Port-Out Fraud

Review your phone bill regularly for services or charges you didn’t authorize. Treat any unsolicited call or message asking you to verify account information as suspect, even if the caller claims to be your carrier. Legitimate carriers do not ask for your password on an outbound call.

If you believe your CPNI has been accessed without authorization, contact your carrier right away. You can also file a privacy complaint directly with the FCC through its online complaint portal.8Federal Communications Commission. Privacy Complaints