Professional Documents
Culture Documents
___________________________________
information, or account information. If the customer does not provide a password,the Company will only disclose
Call detail information by sending it to the customers address of record,or, by calling the customer at the telephone
number of record. If the customer is able to provide Calldetail information to the Company during a customerinitiated call without the Companys assistance,then the Company may discuss the Call detail information provided
by the customer.
(b) Online Access to CPNI. It is the Companys policy to authenticate a customer without the use ofreadily available
biographical information, or account information, prior to allowing the customer onlineaccess to CPNI related to a
telecommunications service account. Once authenticated, the customer mayonly obtain online access to CPNI
related to a telecommunications service account through a password,as described in Section (2) that is not prompted
by the Company asking for readily available biographical information, or account information.
(c)In Store Access to CPNI. It is the Companys policy that it may disclose CPNI to a customer who, at
any retail location operated by the Company, first presents to the Company or its agent a valid photo ID
matching the customers account information.
(2) Password Procedures. To establish a password, the Company will authenticate the customer withoutthe use of
readily available biographical information, or account information. The Company may createa back-up customer
authentication method in the event of lost or forgotten passwords, but such back-upcustomer authentication method
will not prompt the customer for readily available biographicalinformation or account information. If the customer
cannot provide the correct password or correctresponse for the back-up customer authentication method, the
customer must establish a new passwordas described in this paragraph.
(3) Notification of Account Changes. It is the Companys policy to notify customers immediately
whenever a password, customer response to a back-up means of authentication for lost or forgotten passwords,
online account, or address of record is created or changed. This notification may be throughCompany-originated
voicemail or text message to the telephone number of records, or by mail to theaddress of record, and will not reveal
the changed information or be sent to the new accountinformation.
(4) Business Customer Exemption. It is the Companys policy that it may contractually be bound to
other authentication regimes other than those described herein for services provided to businesscustomers that have
both a dedicated account representative and a contract that specifically addresses theCompanys protection of CPNI.
K. Notification of CPNI Security Breaches.
(1) It is the Companys policy to notify law enforcement of a breach in its customers CPNI as providedin this
section. The Company will not notify its customers or disclose the breach publicly until it hascompleted the process
of notifying law enforcement pursuant to paragraph (2).
(2)As soon as practicable, and in no event later than seven (7) business days after reasonabledetermination of the
breach, the Company will electronically notify the United States Secret Services(USSS) and the Federal Bureau of
Investigation (FBI) through a central reporting facility.
(a) Notwithstanding state law to the contrary, the Company shall not notify customers or disclose the breach to the
public until 7 full business days have passed after notification to the USSS and the FBI,except as provided in
paragraphs (b) and (c).
(b) If the Company believes that there is an extraordinarily urgent need to notify any class of affectedcustomers
sooner than otherwise allowed under paragraph (a), in order to avoid immediate andirreparable harm, it will so
indicate in its notification and may proceed to immediately notify its affectedcustomers only after consultation with
the relevant investigation agency. The Company will cooperatewith the relevant investigating agencys request to
minimize any adverse effects of such customernotification.
(c) If the relevant investigating agency determines that public disclosure or notice to customer wouldimpede or
compromise an ongoing or potential criminal investigation or national security, such agencymay direct the carrier
not to so disclose or notify for an initial period of up to 30 days. Such period may be extended by the agency as
reasonably necessary in the judgment of the agency. If such direction isgiven, the agency shall notify the carrier
when it appears that the public disclosure or notice to affectedcustomers will no longer impede or compromise
a criminal investigation or national security. Theagency shall provide in writing its initial direction to the carrier, any
subsequent extension, and anynotification that notice will no longer impede or compromise a criminal investigation
or nationalsecurity and such writings shall be contemporaneously logged on the same reporting facility thatcontains
records of notifications filed by the Company.
(3) Customer Notification. After the Company has notified law enforcement pursuant to paragraph (2), itwill notify
its customers of breach of those customers CPNI.
(4) Recordkeeping. The Company will maintain a record, electronically or in some other manner, of any breaches
discovered, notifications made to the USSS and the FBI pursuant to paragraph (2), andnotifications made to
customers. The record will include, if available, dates of discovery andnotification, a detailed description of the
CPNI that was the subject of the breach, and the circumstancesof the breach. The Company will maintain the record
for a minimum of 2 years.