Data Breach Reporting Requirements
In this document, the Federal Communications Commission (Commission) modifies the Commission's data breach notification rules to better ensure that providers of telecommunications, interconnected Voice over Internet Protocol (VoIP), and telecommunications relay services (TRS) are held accountable in their obligations to safeguard sensitive customer information, and to provide customers with the tools needed to protect themselves in the event that their data is compromised.
What this rule actually says
The FCC requires telecommunications companies, VoIP providers, and relay services to notify customers quickly when their data gets breached. The rule tightens what "quickly" means and ensures customers actually get useful information to protect themselves—not just a vague notice months later. For example, if a customer's phone number, account PIN, or call records leak, the provider must tell them soon and explain what happened.
Who it applies to
- If you provide phone service, VoIP, or telecommunications relay services (interpreters for deaf/hard-of-hearing users) to U.S. customers, this applies to you.
- If you build an AI medical scribe, hiring assistant, or support chatbot that doesn't touch telecommunications infrastructure, this probably doesn't apply to you—unless you're also selling VoIP or phone services.
- U.S. jurisdiction only. If you're serving only international customers or non-telecom use cases, you're out.
- Covered data: Customer names, phone numbers, PINs, account credentials, call records, and similar telecom-specific sensitive info. Your AI training data, general analytics, or anonymized logs typically don't trigger this.
- Exception: If you're a small indie team building an internal chatbot or a standalone AI tool (not integrated with telecom networks), you're not a "provider" under this rule.
What founders need to do
- Audit your product (1 day): Does it include phone service, VoIP, or relay services? If no, stop here. If yes, continue.
- Map what customer data you hold (2-3 days): Document where sensitive telecom data lives—databases, logs, backups, third-party vendors. Know what you actually store.
- Create a breach notification plan (3-5 days): Write down who you'll notify, how fast, and what you'll tell them. The rule requires "without unreasonable delay"—generally interpreted as 30 days max.
- Set up breach detection (1-2 weeks): Implement logging, monitoring, or audit trails so you'll actually catch breaches. This is the hard part; consider working with a security vendor if you're solo.
- Notify your legal/compliance contact or counsel (1 day): If you're taking investor money or have legal counsel, loop them in on your plan.
Bottom line
If you're building a standalone AI tool (scribe, chatbot, hiring assistant) without telecom infrastructure, ignore this. If you're operating a VoIP or phone service, act now to document what data you hold and how you'll notify customers if it leaks.