The FCC wants to make some big changes to data breach reporting

Data Breach
(Image credit: Shutterstock)

The Federal Communications Commission (FCC) has revealed its plan to change the rules regarding how businesses report both data breaches and data leaks to their customers and the federal government.

FCC Chairwoman Jessica Rosenworcel has put forth a Notice of Proposed Rulemaking (NPRM) that would begin the process of changing the government agency's rules for notification customers and federal law enforcement about data breaches.

Rosenworcel explained in a press release that the increased frequency  of breaches and leaks is why she shared her new NPRM with colleagues at the FCC, saying:

“Current law already requires telecommunications carriers to protect the privacy and security of sensitive customer information. But these rules need updating to fully reflect the evolving nature of data breaches and the real-time threat they pose to affected consumers. Customers deserve to be protected against the increase in frequency, sophistication, and scale of these data leaks, and the consequences that can last years after an exposure of personal information. I look forward to having my colleagues join me in taking a fresh look at our data breach reporting rules to better protect consumers, increase security, and reduce the impact of future breaches.”

Updated breach notification requirements

Rosenworcel's proposal outlines several updates to the FCC's current rules in regard to how businesses notify customers and government agencies about breaches.

The first of which and likely the most important is that the current seven business day mandatory waiting period for notifying customers of a breach would be eliminated. If the proposal is accepted, this would mean that consumers would have more time to change their passwords and even invest in identity theft protection services before those responsible for a breach could use their data against them.

At the same time, the proposal would expand customer protections by requiring businesses to notify consumers of inadvertent breaches or data leaks. This could put additional pressure on companies to properly secure their data as their business could be affected by the news that they left a database unsecured online. Finally, Rosenworcel's proposal would require mobile carriers to notify the FCC of all reportable breaches in addition to both the FBI and US Secret Service.

The FCC's next open meeting is scheduled for later this month and we'll have to wait until then to see if the government agency approves the new data breach and data leak rules proposed by Rosenworcel.

We've also featured the best firewall, best endpoint protection software and best malware removal software

Via Engadget

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
marriott
FTC orders Marriott and Starwood to boost cybersecurity following major incidents
healthcare
US government wants to toughen up cybersecurity rules for healthcare organizations
China
US Government officials urged to lock down devices amid telecoms breach
Data Breach
US state sues T-Mobile over 2021 data breach which leaked data of millions
A smartphone on a sofa showing the WhatsApp, Telegram and Signal apps
RCS encryption is still months away following major US telecomms breach
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough