Home/Compliance Insights/CPNI & Privacy
CPNI & Privacy

What Is CPNI?

Most carriers have a CPNI policy. Far fewer have a CPNI program — and the annual certification is a statement about the program, not the policy.

EquiTel Compliance Solutions· ·6 min read ·Reviewed and kept current

Customer Proprietary Network Information is the data a carrier obtains about a customer by virtue of providing service. Numbers called, services purchased, account configuration, usage patterns — information the customer never volunteered but the network generated. Federal rules restrict how it may be used, disclosed, and protected.

The distance between a policy and a program

This is where most companies discover a gap. A compliant CPNI program is not a document; it is a set of operating facts, each of which has to be demonstrable: written policies that match actual practice, customer authentication applied consistently, access controls, trained employees, an incident response process, an annual review, and records proving each of those occurred.

A policy can be produced in an afternoon. The record showing it operated for two years cannot be produced at all, retroactively.

The test that matters

If someone asked today for your CPNI training records for the last two years, could you produce them? A policy without training records describes an intention. It does not describe a program.

The annual certification sits on top of all of it

Covered carriers file an annual certification stating that adequate operating procedures exist, with a statement explaining how those procedures work. Note the order that implies: the certification is a statement of fact about a program that already existed throughout the year. Building the program in the week the certification is due inverts that relationship, and produces filings that are difficult to defend afterward. See what the certification actually asserts.

Where programs fail their first real test

  • Template policies describing systems, roles, or controls the company does not have
  • Training that never reached the support and sales staff who actually handle accounts — including outsourced staff
  • Authentication practice that drifted, where one accommodation for a frustrated caller quietly became the norm
  • No records, so compliance activity that genuinely occurred cannot be demonstrated
  • Certification filed without anyone confirming the described program still matches operations

Why remediation is not a documentation exercise

Rebuilding a CPNI program means reconciling what the policy says, what the systems permit, what employees actually do, and what the company has already certified in prior years. Those four things are usually in tension, and the sequence in which they are reconciled affects the company's position on filings already made. That is a judgement problem before it is a drafting problem.

EquiTel builds and repairs these as CPNI practice work, with training delivered through Compliance Academy™. If a CPNI question has already arrived from a regulator, treat it as an enforcement matter.

Frequently Asked Questions

What is CPNI?

Customer Proprietary Network Information is data a telecommunications carrier obtains about a customer by virtue of providing service — numbers called, services purchased, and account configuration. Federal rules restrict its use, disclosure, and protection.

Is a written CPNI policy sufficient for compliance?

No. A compliant program also requires authentication procedures, access controls, employee training, incident response, annual review, and records demonstrating each occurred.

What does the annual CPNI certification assert?

That adequate operating procedures existed and operated during the year, accompanied by a statement explaining how those procedures ensure compliance.

Sister company — STIRSHAKEN.AI

Who files the CPNI certification.

EquiTel writes and defends the CPNI position. The annual certification is filed by STIRSHAKEN.AI; STIR SHIELD tracks the deadline so the next one is not missed.

EquiTel does the recovery. STIRSHAKEN.AI certifies, files and monitors. Engaging either does not commit you to the other.

CPNI & Privacy Practice

This guide is part of the CPNI & Privacy cluster. The practice page covers how EquiTel handles these matters directly.

View the Practice

Filed by STIRSHAKEN.AI

Who files the CPNI certification. Filing execution and STIR/SHAKEN certification are handled by our sister company STIRSHAKEN.AI — AI-powered, backed by humans. Continuous monitoring is STIR SHIELD.

STIRSHAKEN.AI

Facing This Now?

EquiTel provides confidential telecom compliance recovery, remediation, and regulatory advisory for established providers.

Request a Consultation

Facing a Telecom Compliance Issue?Talk to EquiTel.

EquiTel Compliance Solutions provides telecom compliance recovery, remediation, and regulatory advisory for established telecommunications providers. Every inquiry is confidential.