Privacy Act of 1974; System of Records
In this document, the Federal Communications Commission (FCC or Commission or Agency) is modifying a system of records, FCC/OSP-1, Broadband Dead Zone Report and Consumer Broadband Test, subject to the Privacy Act of 1974, as amended. This action is necessary to implement the Broadband Data Collection (BDC) program. The modified system, now known as FCC/OEA-6, Broadband Data Collection system of records (BDC system), will collect granular, detailed information on the availability and quality of service of fixed and mobile broadband internet access service from service providers, as well as verified broadband availability data from other Federal agencies, from State, local, and Tribal governmental entities that are primarily responsible for mapping or tracking broadband service coverage, and from other third parties. The BDC will additionally give the FCC, industry, Federal, State, local and Tribal government entities, and consumers the tools they need to continuously refine and improve the accuracy of these new mapping data. A number of broadband deployment funding mechanisms will rely upon BDC data, including the Broadband Equity, Access, and Deployment (BEAD) program, administered by the Department of Commerce's National Telecommunications and Information Administration (NTIA), the FCC's 5G Fund for Rural America, and potentially other broadband infrastructure deployment funding programs.
What this rule actually says
The FCC is creating a database to collect detailed information about broadband internet availability and speed across the U.S.—who has it, who doesn't, and how fast it is. The data comes from internet service providers, government agencies, and other sources. This rule establishes how the FCC will store, protect, and manage that collected information under federal privacy law.
Who it applies to
This rule likely does NOT apply to indie AI founders unless:
- Building a product that collects or processes broadband service availability data on behalf of the FCC or NTIA
- Operating as an internet service provider (ISP) and reporting broadband speeds/coverage to the FCC
- Contracted by state or local government to aggregate broadband mapping data for the FCC's Broadband Data Collection (BDC) program
It does NOT apply to:
- AI medical scribes, hiring assistants, or support chatbots (these don't touch broadband infrastructure data)
- Apps that analyze user internet speed (unless you're feeding that data into the official FCC BDC system)
- General consumer data collection from your users (this rule is narrowly about broadband availability mapping, not personal health, employment, or support chat data)
Jurisdictions: U.S. only (FCC authority).
What founders need to do
- Check if you're involved in broadband mapping (2 hours): Ask: Am I collecting or processing broadband availability/speed data for a government agency or ISP? If no, stop here.
- If yes, review Privacy Act requirements (1-2 days): Read the actual system of records notice (SORN) when published in final form. Understand what data you can collect, how long you keep it, and who can access it.
- Document your data handling practices (2-3 days): Create or update privacy policies explaining what broadband data you collect, store, and share—especially if you're sharing with the FCC or NTIA.
- Plan for data security and retention (ongoing): Implement safeguards for the broadband data you hold and establish a schedule for deleting it once its purpose is fulfilled.
- Stay updated on final rules (ongoing, low effort): This is currently a "proposed" rule. Monitor FCC announcements for the final version if your product touches broadband infrastructure data.
Bottom line
Ignore this unless you're explicitly involved in broadband availability mapping for the FCC or a government partner—and if you are, monitor for the final rule and then document your data practices.