CPNI rules under Section 222 apply to MVNOs, not just facilities-based carriers. Here's what that means in practice.

CPNI stands for Customer Proprietary Network Information: the data a carrier holds about a customer's use of the network, including call detail records, numbers dialed, service plans, features, and billing details. Under Section 222 of the Communications Act and the FCC's implementing rules, telecommunications carriers must protect this information, and MVNOs are covered. Reselling another carrier's network does not exempt you. If you bill subscribers for telecommunications service, CPNI obligations are yours.
This article is an operational overview, not legal advice. Use it to understand the landscape, then work with counsel on your specific program.
CPNI is information about a subscriber's use of the service that you obtain by virtue of the carrier-customer relationship: who they called and when, what plan and features they have, usage patterns, and amounts billed for service. Name, address, and phone number by themselves are treated separately (as subscriber list information), but in practice the safest posture is to treat the whole customer service record with CPNI-level care, because that's how your host carriers and the FCC will expect you to behave.
Use restrictions. You can use CPNI to provide the service, bill for it, and protect against fraud without asking permission. Using it to market categories of service the customer doesn't already have generally requires customer approval, either opt-in or opt-out depending on the marketing scenario, with opt-in required for sharing with third parties outside the carrier relationship.
Authentication before disclosure. The FCC's rules require carriers to authenticate customers before discussing call detail over the phone, and forbid using readily available biographical information (like an address or SSN fragment) as the sole authenticator for call detail records. In practice this means passwords or PINs on accounts, notification to the customer when account changes happen (password changes, address changes), and care team training so agents don't get socially engineered. SIM swap and port-out fraud protections live here too, and the FCC has tightened these rules specifically because fraudsters target wireless accounts.
Breach notification. If CPNI is breached, carriers must notify law enforcement through the FCC's central reporting portal and then notify affected customers, on defined timelines. Your incident response plan needs to account for this before an incident, not during one.
Annual certification. Carriers must have an officer sign an annual certification, filed with the FCC by March 1 each year, stating the company has operating procedures adequate to ensure CPNI compliance, with a statement explaining how. Missing this filing is one of the most common and most easily avoided CPNI enforcement triggers for small operators.
If you operate on Verizon, T-Mobile, or AT&T wholesale agreements, CPNI and PII obligations are written into your carrier contract, often with audit rights and breach notification timelines stricter than the regulatory baseline. A CPNI failure is therefore a double exposure: FCC enforcement on one side and a wholesale contract default on the other. Treat your carrier's code of conduct requirements as part of your compliance program, not separate paperwork.
A written CPNI policy an officer can honestly certify. Account PINs and customer authentication built into your care workflows and subscriber portal. Automatic customer notifications on sensitive account changes. Role-based access so employees and vendors see only the data their job requires. Training and discipline records for personnel handling CPNI. An incident response plan with the FCC reporting steps documented. Records of marketing campaigns that used CPNI and the approval status behind them.
One thing to be clear-eyed about: no software platform makes you CPNI compliant. Compliance lives in your policies, your training, and how your team actually handles customer data day to day. What a platform can do is give you the tooling and security foundation so that following your own rules is the path of least resistance. BeQuick provides that foundation: PIN-based customer authentication, automated account-change notifications, role-based access controls, and secure, redundant infrastructure, with your team deciding how those controls map to your compliance program. If CPNI is on your diligence list for a platform decision, book a demo and ask us the hard questions.
Fuel growth and scale your operations with BeQuick, the most advanced all-in-one platform for MVNO's.