Media / Business Law 101

AT&T and Verizon Fail to Block FCC Fines

Dr. David D. Schein examines AT&T and Verizon’s failed challenge to FCC fines and what the case means for regulatory authority and business risk.

Read the full analysis

Federal regulators fined major wireless carriers for failing to protect customers’ location information. The dispute matters because location data can reveal where a person lives, works, travels, worships, or seeks medical care, and telecommunications companies must control who can access that information.

What the FCC enforcement action addressed

The Federal Communications Commission announced nearly $200 million in forfeitures against AT&T, Sprint, T-Mobile, and Verizon after finding that the carriers unlawfully disclosed customers’ location data without adequate safeguards. The FCC’s enforcement release explains the agency’s view that the companies failed to protect customer proprietary network information.

Why location information receives special protection

Section 222 of the Communications Act places duties on telecommunications carriers that possess customer proprietary network information. A company cannot treat a third-party aggregator as the end of its responsibility. Controls must address downstream access, authorization, consent, monitoring, and the ability to stop misuse.

What the carriers challenged

The carriers disputed the FCC’s legal authority and aspects of the agency’s interpretation, process, and penalty calculations. Those arguments illustrate a recurring administrative-law question: how far an agency may go when enforcing a statute against modern data-sharing arrangements that Congress did not describe in technological detail.

Compliance lessons for data businesses

  • Map where sensitive information travels after collection.
  • Require verifiable authorization rather than relying on contractual promises alone.
  • Audit vendors and downstream recipients.
  • Use access controls, anomaly detection, and prompt termination procedures.
  • Preserve evidence showing how consent and access decisions were made.

Related DDSA coverage examines operational compliance costs, protection of confidential business information, and corporate governance choices.

Takeaway: outsourcing access does not necessarily outsource accountability. Companies handling sensitive data need controls that work across the entire disclosure chain.