

The proposal apparently includes “robust and flexible data security requirements for broadband providers, including an overarching data security standard” but few details are offered. The proposal would also:
- Require broadband providers to take reasonable steps to safeguard customer information from unauthorized use or disclosure;
- Adopt risk management practices; Institute personnel training practices;
- Adopt strong customer authentication requirements;
- Identify a senior manager responsible for data security; and
- Take responsibility for use and protection of customer information when shared with third parties.
Providers would be required to notify affected customers of breaches of their data no later than 10 days after discovery. In addition, they would have to notify the FCC of any breach of customer data no later than 7 days after discovery and the FBI and US Secret Service of breaches affecting more than 5,000 customers no later than 7 days after discovery of the breach.
Wheeler emphasized that the proposal does not affect:
- The privacy practices of web sites, like Twitter or Facebook, over which the Federal Trade Commission has authority.
- Other types of services offered by a broadband provider, such as operation of a social media website.
- Issues such as government surveillance, encryption or law enforcement.
The Notice will also seek comment on additional or alternative paths to achieve pro-consumer, pro-privacy goals.

Choice: Consumers have the right to exercise meaningful and informed control over what personal data their broadband provider uses and under what circumstances it shares their personal information with third parties or affiliated companies.
Transparency: Consumers deserve to know what information is being collected about them, how it’s being used, and under what circumstances it will be shared with other entities. Broadband providers must provide accurate disclosures of their privacy practices in an easily understandable and accessible manner.
Security: Broadband providers have a responsibility to protect consumer data, both as they carry it across their networks and wherever it is stored.
In response to Wheeler’s Proposal, Commissioner O’Rielly issued a statement saying, in part: “The “fact” sheet demonstrates that the FCC is doubling down on its misguided and broken Net Neutrality decision by imposing troubling and conflicting “privacy” rules on Internet companies, as well as freelancing on topics like data security and data breach that are not even mentioned in the statute.”

