CDT and EPIC File Comments Opposing FCC’s Proposed Identity Collection Requirements for Phone Service
On July 27, the Center for Democracy and Technology (CDT) and Electronic Privacy Information Center (EPIC) filed comments in response to the Federal Communications Commission’s proposed expansion of Know-Your-Customer requirements, which would require phone companies to collect a government-issued identification number, physical address, and alternate telephone number from every new and renewing subscriber.
While CDT and EPIC support efforts to combat illegal robocalls, the proposal would impose severe and unjustified privacy costs on hundreds of millions of Americans. Specifically, the comments argue that:
Mandatory identity collection from every subscriber would represent a significant and unreasonable expansion of existing rules, creating new opportunities for that data to be breached, sold, or accessed by law enforcement. Phone companies have a lackluster history protecting customer data—the FCC itself fined all four major carriers nearly $200 million for selling customer location data without consent.
The proposal would endanger anonymous communications, especially for people in situations where their safety is at risk. A domestic violence survivor fleeing an abuser should not be forced to create a record that leads back to her door in order to get a phone, and a whistleblower should not have to tie their identity to the behavior or company they are reporting.
Requiring government ID and a physical address as conditions of phone service would cut off unhoused individuals, low-income Americans, older adults, foster youth, and survivors of intimate partner violence from an essential service.
The Commission has not established that universal identity collection is necessary or would be effective. The proposal conflates attribution, deterrence, and prevention without distinguishing which measures serve which goal, and the most harmful scam operations already use stolen identities and shell companies that would pass the proposed checks.
The Commission should focus its KYC requirements on high-volume callers, bulk access providers, and foreign-based customers, and should not impose a sweeping identity collection mandate on every phone user in the country.
CDT and Partners Urge Passage of the California Location Privacy Act of 2025 (AB 322)
Location data is particularly sensitive, and when collected across time it can reveal a broad range of intrusive insights such as medical conditions, sexual orientation, political activities, and religious beliefs.
CDT and Allies Urge FCC Not to Violate Privacy of Cell Phone Buyers
CDT and EPIC led a coalition of 15 organizations in urging the FCC not to require phone companies to collect government IDs, physical addresses, and alternate phone numbers from every phone subscriber in the country.
As Brussels starts emptying for the summer, the risks of frontier AI models continue to capture the attention of policymakers as a key chapter of the AI Act becomes enforceable, and disclosure rules around the use of AI systems and AI-generated content are further clarified.
CDT Europe’s Feedback on the Draft Guidelines for the Classification of High-Risk AI Systems under the AI Act
CDT Europe responded to the European Commission’s consultation on the draft guidelines for the classification of high-risk artificial intelligence systems.