The FCC wants to make some big changes to data breach reporting

Data Breach
(Image credit: Shutterstock)

The Federal Communications Commission (FCC) has revealed its plan to change the rules regarding how businesses report both data breaches and data leaks to their customers and the federal government.

FCC Chairwoman Jessica Rosenworcel has put forth a Notice of Proposed Rulemaking (NPRM) that would begin the process of changing the government agency's rules for notification customers and federal law enforcement about data breaches.

Rosenworcel explained in a press release that the increased frequency  of breaches and leaks is why she shared her new NPRM with colleagues at the FCC, saying:

“Current law already requires telecommunications carriers to protect the privacy and security of sensitive customer information. But these rules need updating to fully reflect the evolving nature of data breaches and the real-time threat they pose to affected consumers. Customers deserve to be protected against the increase in frequency, sophistication, and scale of these data leaks, and the consequences that can last years after an exposure of personal information. I look forward to having my colleagues join me in taking a fresh look at our data breach reporting rules to better protect consumers, increase security, and reduce the impact of future breaches.”

Updated breach notification requirements

Rosenworcel's proposal outlines several updates to the FCC's current rules in regard to how businesses notify customers and government agencies about breaches.

The first of which and likely the most important is that the current seven business day mandatory waiting period for notifying customers of a breach would be eliminated. If the proposal is accepted, this would mean that consumers would have more time to change their passwords and even invest in identity theft protection services before those responsible for a breach could use their data against them.

At the same time, the proposal would expand customer protections by requiring businesses to notify consumers of inadvertent breaches or data leaks. This could put additional pressure on companies to properly secure their data as their business could be affected by the news that they left a database unsecured online. Finally, Rosenworcel's proposal would require mobile carriers to notify the FCC of all reportable breaches in addition to both the FBI and US Secret Service.

The FCC's next open meeting is scheduled for later this month and we'll have to wait until then to see if the government agency approves the new data breach and data leak rules proposed by Rosenworcel.

We've also featured the best firewall, best endpoint protection software and best malware removal software

Via Engadget

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
marriott
FTC orders Marriott and Starwood to boost cybersecurity following major incidents
healthcare
US government wants to toughen up cybersecurity rules for healthcare organizations
China
US Government officials urged to lock down devices amid telecoms breach
Data Breach
US state sues T-Mobile over 2021 data breach which leaked data of millions
Digital US flag
Biden orders review, new rules governing US national cybersecurity
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
A Lego Pikachu tail next to a Pebble OS watch and a screenshot of Assassin's Creed Shadow
ICYMI: the week's 7 biggest tech stories from LG's excellent new OLED TV to our Assassin's Creed Shadow review
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models