FCC Announces Intended $10 Million Fine in First Data Security Case
Time 2 Minute Read

On October 24, 2014, the Federal Communications Commission announced that it intends to impose a $10 million fine on TerraCom, Inc. (“TerraCom”) and YourTel America, Inc. (“YourTel”) for violating privacy laws relating to their customers’ personal information. This announcement marks the FCC’s first enforcement action in the data security arena as well as its largest privacy action to date.

Based on an investigation by the FCC’s Enforcement Bureau, TerraCom and YourTel allegedly maintained their customers’ sensitive information, including names, Social Security numbers, addresses and driver’s license numbers, on unprotected Internet servers that were accessible to the public. According to the FCC’s press release, this incident exposed the personal information of up to 305,000 consumers.

The FCC asserts that the carriers’ failure to reasonably secure their customers’ data violates their statutory obligation under the Communications Act of 1934 to protect personal information, and “constitutes an unjust and unreasonable practice in violation of the Act.” According to the FCC’s press release, the data security practices of these two companies lacked “even the most basic and readily available technologies and security features,” which created an “unreasonable risk of unauthorized access.” In addition, the FCC asserts that, even after becoming aware of the data security issue, the companies failed to notify affected customers, which also constitutes an unjust and unreasonable practice.

According to Travis LeBlanc, Chief of the FCC’s Bureau of Enforcement, “[c]onsumers trust that when phone companies ask for their Social Security number, driver’s license, and other personal information, these companies will not put that information on the Internet or otherwise expose it to the world.” He added that “[w]hen carriers break that trust, the Commission will take action to ensure that they are held accountable for unjust and unreasonable data security practices.”

FCC Commissioner Agit Pai issued a dissenting opinion accusing the FCC of running afoul of the fair warning rule by asserting that “these companies violated novel legal interpretations and never-adopted rules,” and seeking to impose a “substantial financial penalty.” Commissioner Pai noted that he “cannot support such ‘sentence first, verdict afterward’ decision-making.”

This announcement comes on the heels of notable FCC settlements with Verizon and Sprint.

Update: On July 9, 2015, the FCC announced the final settlement order with TerraCom and YourTel.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page