On July 27, the Center for Democracy and Technology (CDT) and Electronic Privacy Information Center (EPIC) filed comments in response to the Federal Communications Commission’s proposed expansion of Know-Your-Customer requirements, which would require phone companies to collect a government-issued identification number, physical address, and alternate telephone number from every new and renewing subscriber.
While CDT and EPIC support efforts to combat illegal robocalls, the proposal would impose severe and unjustified privacy costs on hundreds of millions of Americans. Specifically, the comments argue that:
- Mandatory identity collection from every subscriber would represent a significant and unreasonable expansion of existing rules, creating new opportunities for that data to be breached, sold, or accessed by law enforcement. Phone companies have a lackluster history protecting customer data—the FCC itself fined all four major carriers nearly $200 million for selling customer location data without consent.
- The proposal would endanger anonymous communications, especially for people in situations where their safety is at risk. A domestic violence survivor fleeing an abuser should not be forced to create a record that leads back to her door in order to get a phone, and a whistleblower should not have to tie their identity to the behavior or company they are reporting.
- Requiring government ID and a physical address as conditions of phone service would cut off unhoused individuals, low-income Americans, older adults, foster youth, and survivors of intimate partner violence from an essential service.
- The Commission has not established that universal identity collection is necessary or would be effective. The proposal conflates attribution, deterrence, and prevention without distinguishing which measures serve which goal, and the most harmful scam operations already use stolen identities and shell companies that would pass the proposed checks.
The Commission should focus its KYC requirements on high-volume callers, bulk access providers, and foreign-based customers, and should not impose a sweeping identity collection mandate on every phone user in the country.
Read the full comments here.
Facts Only
* CDT and EPIC filed comments in response to the FCC’s proposed expansion of Know-Your-Customer requirements for phone service.
* The proposal requires phone companies to collect government-issued identification, physical address, and alternate telephone number from new and renewing subscribers.
* Commenters argued mandatory identity collection expands existing rules, creating new risks for data breaches, sales, or law enforcement access.
* Phone companies have a history of insufficient customer data protection, including fines by the FCC on major carriers for selling location data without consent.
* The proposal endangers anonymous communications, particularly for individuals in situations where safety is at risk.
* Requiring government ID and a physical address as service conditions would exclude unhoused individuals, low-income Americans, older adults, foster youth, and survivors of intimate partner violence from essential services.
* Commenters argued the Commission failed to establish that universal identity collection is necessary or effective.
* The commenters suggested KYC requirements should focus on high-volume callers, bulk access providers, and foreign-based customers instead of imposing a sweeping mandate.
Executive Summary
The Center for Democracy and Technology (CDT) and the Electronic Privacy Information Center (EPIC) commented on the Federal Communications Commission’s proposal to expand Know-Your-Customer requirements for phone service. The proposal seeks to mandate that phone companies collect a government-issued identification number, physical address, and alternate telephone number from every new and renewing subscriber. Commenters argue this expansion imposes significant and unjustified privacy costs on Americans.
The primary arguments raised against the proposal focus on data security, safety, and access to essential services. Critics contend that mandatory identity collection creates new risks for data breaches, as phone companies have a history of insufficient data protection, citing fines levied by the FCC on major carriers for sharing location data without consent. Furthermore, the requirement endangers anonymous communications, arguing that forcing individuals fleeing danger or whistleblowers to link their identity to communication records compromises safety.
A significant concern raised is the potential exclusion of vulnerable populations from essential services; requiring government ID and a physical address as prerequisites for phone service could cut off access for unhoused individuals, low-income Americans, older adults, foster youth, and survivors of intimate partner violence. Commenters also dispute the Commission's justification, noting that it fails to establish necessity or effectiveness, and that existing scam operations already utilize stolen identities and shell companies capable of passing proposed checks. The commenters suggest that KYC requirements should target high-volume callers and bulk access providers rather than imposing a universal mandate on all phone users.
Full Take
The tension in this discussion centers on balancing perceived security goals against the concrete impact on individual autonomy and safety. The core conflict appears to be between a state-centric view of identity verification for public safety and an individual-centric view emphasizing privacy, vulnerability mitigation, and access to basic services. The argument that universal collection is necessary for deterrence conflates different operational goals: attribution, deterrence, and prevention, without demonstrating that mandatory identification checks are the most effective mechanism against illicit activity, especially given the existing infrastructure for anonymized communication flows.
A deeper pattern emerges regarding who bears the cost of security measures. The structure implies that the burden of establishing digital safety is shifted onto the end-user population—specifically those already marginalized or in vulnerable positions—rather than focusing regulation on the actors responsible for creating the data and exploiting systems. This reflects a historical dynamic where regulatory shifts, even those framed as beneficial, often disproportionately affect those with fewer resources to navigate new compliance requirements.
The move to focus KYC efforts narrowly on high-volume sources suggests a pattern of targeting efficiency over universality. If the goal is truly to combat scams and track illicit activity, then monitoring the points of highest systemic risk—those facilitating bulk access or large-scale fraudulent communications—may be more effective than attempting to establish an impossible standard for every consumer. The implications suggest that regulatory frameworks must explicitly prioritize dignity and safety alongside surveillance capabilities, asking whether a system based on universal data collection inherently respects human agency when applied to populations already facing acute vulnerability.
Bridge Questions: If regulation is shifted toward bulk access providers, what specific metrics could the FCC use to define "high-volume" or "bulk access" that minimize impact on legitimate users while targeting exploiters? How can regulatory bodies establish a threshold where identity collection demonstrably enhances safety without creating new vectors for systemic vulnerability among vulnerable populations? What alternatives exist to achieve deterrence and prevention goals that do not rely on mandatory, universal subscriber identification?
Sentinel — Human
The analysis presents a coherent argument from an advocacy perspective against proposed government data collection requirements, employing rhetorical techniques common in public comment submissions.
