Print Article
SHARE

The CommLaw Group has filed Comments with the Federal Communications Commission on behalf of the Consumer Access & Choice Coalition (“CACC”) in the FCC’s latest robocall proceeding addressing proposed “Know Your Customer” (“KYC”) requirements for originating voice service providers.

The filing builds on CACC’s prior advocacy in the FCC’s robocall, caller authentication, and caller identification proceedings. CACC supports the Commission’s core objective: stopping illegal robocalls before they enter the network and protecting consumers from fraud, scams, and abusive calling practices. But CACC cautions that the FCC’s proposals, if adopted without careful tailoring, could impose broad identity-verification, data-retention, and enforcement obligations on legitimate consumer-focused providers whose services do not resemble the high-volume enterprise calling operations most commonly associated with illegal robocall abuse.

The FCC’s KYC Proposal

The FCC’s Further Notice of Proposed Rulemaking seeks comment on whether originating providers should be required to collect and verify specified customer information before allowing customers to originate calls. The proposals under consideration include requiring providers to obtain a customer’s name, physical address, government-issued identification number, and alternate telephone number; collect additional information from high-volume customers; verify and periodically re-verify customer information; retain KYC records for four years after the customer relationship ends; and face potential per-call forfeiture exposure for violations of the FCC’s KYC rules.

The FCC also asks whether enhanced KYC requirements should vary based on customer type, service model, calling volume, prepaid versus postpaid service, and other risk indicators. That question is central to CACC’s filing.

Looking for a deeper dive? Shortly after filing these Comments, The CommLaw Group presented a webinar, Know Your Customer, Know Your Upstream Provider & Robocall Mitigation Compliance, examining the FCC’s proposed KYC requirements, recent enforcement actions, practical compliance strategies, and the implications for originating voice service providers. Providers seeking additional context on the issues addressed in this proceeding can view the webinar recording here: https://youtu.be/tKi_tNe5mbg.

CACC’s Core Message: Target Abuse, Not Legitimate Consumer Access

CACC’s Comments urge the FCC to adopt a flexible, risk-based framework that focuses enhanced scrutiny where the actual risk lies: high-volume, enterprise-scale, suspicious, or otherwise higher-risk calling activity.

CACC explains that a uniform KYC regime imposed on all customers and all providers would be overbroad. Many CACC members and similarly situated providers serve individual consumers, small accounts, nomadic VoIP users, app-based communications users, prepaid customers, and other low-volume or privacy-conscious subscribers. These customers use communications services for ordinary, lawful, and often essential personal purposes. Treating them like enterprise robocall originators would add friction, raise costs, discourage legitimate use, and potentially reduce access to affordable communications services without meaningfully improving robocall enforcement.

Privacy and Data Security Concerns

A major theme of CACC’s filing is that expanded KYC requirements must be evaluated not only as anti-robocall tools, but also as privacy and data-security mandates.

Collecting government-issued identification numbers, physical addresses, alternate phone numbers, and related personal information from every customer would create new repositories of sensitive consumer data. Those repositories would require additional compliance infrastructure, cybersecurity protections, vendor management, retention controls, and breach-risk planning. CACC cautions that requiring providers to collect more personal information than necessary may increase consumer risk rather than reduce it.

CACC therefore urges the FCC to respect data-minimization principles and avoid rules that force providers to collect highly sensitive information from low-risk users when less intrusive measures would suffice.

Small Provider and Competition Impacts

CACC also warns that overly prescriptive KYC rules could disproportionately burden small and mid-sized providers. Large carriers and enterprise communications platforms may be able to absorb new onboarding, verification, monitoring, and retention obligations. Smaller consumer-focused providers may not.

If the FCC adopts rigid rules without meaningful accommodations, the result could be reduced competition, higher consumer prices, diminished service availability, and further consolidation in the voice marketplace. That would be an unfortunate outcome in a proceeding intended to protect consumers.

CACC urges the FCC to preserve room for provider-specific compliance programs that reflect the nature of the provider’s service, customer base, risk profile, and operational capabilities.

Per-Call Penalties Require Careful Limits

The FCC’s proposal to assess KYC violations on a per-call basis is another area of concern. CACC recognizes that serious violations involving illegal traffic should have consequences. But a per-call penalty framework could create extraordinary exposure if applied mechanically to alleged paperwork, verification, or process deficiencies, particularly where the provider acted reasonably and did not knowingly facilitate unlawful calls.

CACC urges the FCC to avoid a strict-liability-style enforcement regime. Instead, any penalty framework should consider provider intent, actual knowledge, red flags, traffic volume, customer risk, remedial action, and whether the provider maintained a reasonable compliance program.

Safe Harbors and Flexible Compliance Options

CACC supports the FCC’s consideration of safe harbors and other flexible compliance mechanisms. Properly designed safe harbors could encourage providers to invest in effective fraud-prevention tools, automated monitoring, third-party verification solutions, and documented risk-based procedures without punishing legitimate providers for choosing different but reasonable compliance methods.

CACC encourages the FCC to focus on outcomes rather than mandating a single prescriptive compliance model. Providers should be permitted to use reasonable, technology-neutral methods to identify and mitigate risk, including automated tools, vendor-supported verification, customer attestations, traffic monitoring, contractual safeguards, and escalation procedures.

Why Coalition Advocacy Matters

This proceeding is exactly why CACC was formed.

The FCC’s robocall agenda is moving quickly, and the issues are no longer limited to traditional robocall mitigation plans or STIR/SHAKEN implementation. The Commission is increasingly examining how providers identify customers, validate caller information, monitor traffic, retain records, support law enforcement, and prevent abuse before traffic enters the network.

Those objectives are important. But the rules developed in these proceedings will shape the future operating environment for consumer-focused communications providers, including nomadic VoIP providers, OTT communications platforms, resellers, prepaid service providers, app-based voice providers, and other innovative service models.

CACC gives these providers a coordinated, cost-effective way to participate in proceedings that may otherwise be dominated by larger incumbents, enterprise stakeholders, and national trade associations. Through CACC, similarly situated providers can help build a record that supports strong consumer protection while preserving privacy, competition, innovation, affordability, and consumer choice.

What Providers Should Do Now

Providers that may be affected by the FCC’s proposed KYC rules should begin evaluating their current onboarding, verification, monitoring, record-retention, and escalation procedures. Providers should consider what customer information they collect today, how they verify that information, whether their procedures vary by customer risk, how they identify suspicious traffic or account activity, how long they retain customer records, and what changes would be required if the FCC adopts more prescriptive KYC obligations.

Providers should also consider whether their business model would be disproportionately affected by rigid rules designed primarily around high-volume enterprise calling activity. If so, participation in the FCC record may be important.

CACC will continue advocating for a balanced framework that targets bad actors without burdening lawful, consumer-focused providers or compromising legitimate privacy interests.

Providers interested in learning more about CACC, participating in future advocacy, or evaluating the potential impact of the FCC’s KYC proposals should contact Jonathan Marashlian at jsm@commlawgroup.com