BEFORE THE

Federal Communications Commission

Washington, D.C.

 

In the Matter of )  
Advanced Methods to Target and Eliminate Unlawful Robocalls )

)

CG Docket No. 17-59
Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 )

 

CG Docket No. 02-278

 

Reply Comments of

Thomas A. Schatz

President

Citizens Against Government Waste

On

Further Notice of Proposed Rulemaking

July 24, 2026

Citizens Against Government Waste (CAGW) is a private, nonprofit, nonpartisan organization dedicated to educating the American public about waste, mismanagement, and inefficiency in government.  On behalf of the more than one million members and supporters of CAGW, I offer the following reply comments regarding the Federal Communications Commission’s (FCC) further notice of proposed rulemaking (FNPRM) on the “Enhancing Know-Your-Customer (KYC) Requirements” proceeding (CG Docket No. 17-59, and CG Document No. 02-278).[1]

On December 30, 2019, the Pallone-Thune Telephone Robocall Abuse Criminal Enforcement and Deterrence Act (Pallone-Thune TRACED Act) was signed into law as Public Law No. 116-105.  This law increased the role of the FCC in combatting illegal robocalls and allowed law enforcement to “impose additional penalties for intentional violations of the Telephone Consumer Protection Act.”  The law also gave the FCC the authority to engage in its Secure Telephone Identity Revisited (STIR) and Signature-based Handling of Asserted Information using toKENS (SHAKEN) initiative that increased efforts to reduce illegal robocalls and texts and convene an interagency working group to combat these illegal activities.[2]  The law also required the FCC to issue rules for a “single consortium that conducts private-led efforts to trace back the origin of suspected unlawful robocalls,” leading to the creation of the Industry Traceback Group led by USTelecom.[3]

In 2020, the FCC adopted rules that required all communications service providers to implement the STIR/SHAKEN standards to combat robocalls, including making it easier for consumers to identify calls from the number displayed on the caller ID.[4]  This was a much-needed step forward to protect consumers from fraudulent caller ID spoofing and robocalls.

As CAGW noted in an October 28, 2021, blog post, “the FCC must continue to combat the massive number of robocalls consumers receive daily.”[5]  The STIR/SHAKEN initiatives have helped to reduce those robocalls by requiring “all providers – regardless of whether they have a STIR/SHAKEN implementation obligation – to institute robocall mitigation programs to ensure that they are not originating or transmitting illegal robocalls.”  However, bad actors continue to innovate and leverage new technologies to get around the initiative and continue to find new ways to spoof calls, and harm consumers.  As noted in comments filed by the banking and credit industry, illegal spoofed calls remain one of the primary tools criminals use to impersonate banks and steal consumer funds.[6]

Several commenters, including the banking industry, Twilio, and the Better Identity Coalition promote increasing the verification process and requirements that originating service providers (OSPs) must perform, as well as the amount of data retention the FNPRM would require.[7]  As noted in comments filed by Twilio, the “current standards are ambiguous and insufficient to address existing market vulnerabilities and result in disparate case-by-case enforcement, which creates uncertain precedence and compliance challenges for the industry.”[8] However, the FNPRM proposes to increase the requirements on telecommunications service providers to a level that could pose cybersecurity and identity theft risks to consumers, including highly sensitive personal customer information like social security numbers, dates of birth, and possibly alternative phone numbers, and retain this information for the duration of the customer relationship and for a period of time after that relationship has been severed.  This conflicts with data minimization principles aimed at preventing consumer identity theft.  The FNPRM would require this data collection for new customers and also require providers to re-verify their existing customers.

While we applaud the actions already taken by the FCC to combat incidences of robocalls, CAGW is concerned that the FNPRM could harm consumers through increased data collection and retention requirements affecting consumer data privacy as well as risk the ability for individual consumers who do not want to disclose additional personal data collection and retention to obtain or retain communications services.  The banking industry already must maintain a certain level of financial consumer data privacy under the Financial Modernization Act of 1999 (Gramm-Leach-Bliley Act), which regulates privacy for banking, credit reporting, and financial wire transactions, which other industries including the OSPs are not subject to for compliance.[9]

CAGW agrees with comments filed jointly by the Electronic Frontier Foundation (EFF) and the American Civil Liberties Union (ACLU) about the need to protect consumers from unintended harm to their personal information.  They noted, “The Commission’s approach will lead to a loss of privacy that directly harms and silences consumers, while also creating an exclusionary impact that disproportionately harms those the Commission should be serving.  Anonymity in calls provides people the safety they may require to organize with others, speak freely, and seek services.  Additionally, requiring data collection to have a phone number could prevent citizens from communicating with loved ones, getting a job, and feeding their families.”[10]  CAGW also recognizes the significant costs for such data collection to providers.  NCTA – The Internet & Television Association noted, “providers would be obligated to expend substantial resources to collect, maintain, and reverify significant amounts of sensitive and/or unnecessary information for its entire customer base – an overwhelming percentage of which is comprised of good actors.”[11]

Current rules for collection already offer flexibility in combatting unlawful robocalls, as noted by INCOMPAS in its comments which asks the FCC to “preserve that flexibility as it evaluates the effectiveness of its current rules and considers further action in this area.”  They also note that, “No single tool, including KYC, is sufficient on its own.”  In their recommendations, they suggest that the FCC consider a “safe harbor framework that would permit the agency to enumerate baseline KYC expectations while allowing providers the flexibility to evolve their requirements and respond to specific risk scenarios as fraudsters’ tactics change.”  They also recommend that those baseline requirements include the following information: Name, Address, and a “verified email address or alternate phone number that can be used as a form of verification to support identity confirmation.”[12]

While CAGW agrees that a baseline verification system is needed, requiring an alternative phone number or email address would disenfranchise those who do not have a secondary phone number or email account which could be used to verify their identity.  CAGW also believes that the data retention requirements in the FNPRM unnecessarily force providers to retain personal information, including sensitive personal information that increases the risk that consumer data could be exposed, stolen, or misused.

Instead, we suggest the FCC take the advice offered in the June 25, 2026, comments filed by CTIA – The Wireless Association (CTIA), which suggested, “When onboarding customers, wireless providers work with solutions providers that offer innovative technologies to verify the customers’ identities and take risk-based approaches catering to the unique types of customers.”  These actions should more than satisfy the existing KYC requirements.  CTIA also noted that the FNPRM may impose rigid new requirements for consumer onboarding that would hinder “competition, complicating the onboarding process, and frustrating consumers, contrary to the Commission’s customer service goals.”[13]

USTelecom’s comments also spotlight the problems that would be created with the more stringent requirements found in the FNPRM by “imposing static information collection and verification requirements on OSPs that would remove the flexibility needed to innovate KYC practices and tackle the increasingly sophisticated and dynamic tactics of illegal robocallers.”[14]

Smaller OSP representatives like America’s Communications Association (ACA) and WISPA – the Association for Broadband without Boundaries, and NCTA – The Rural Broadband Association noted their customers tend to be individuals or small businesses, and the requirements and fines imposed by non-compliance with the new standards proposed by the FNPRM would impose a hardship on their businesses.

While ACA “does not object to” imposing greater specificity on providers’ KYC obligations, it suggests that, “Specificity, however, should not become a universal checklist that applies same information-collection and verification requirements to every customer, every service, and every traffic profile.  This approach would introduce unnecessary data-security risks and divert compliance resources from the relationships and calling patterns mostly likely to be involved in robocall abuse.”  ACA further noted that, “Requiring providers to collect and retain unnecessary customer information may increase cybersecurity and privacy risks without materially improving robocall prevention.”[15]

WISPA proposes that the FCC create a tiered information collection standard based on number of customers a provider services and suggests that, “Annual re-verification of all existing customers would require a provider serving 5,000 customers to conduct 5,000 verification procedures each year – an overwhelming administrative burden for a provider with fewer than 10 employees.”[16]  NCTA maintains that the overly broad requirements in the FNPRM, “would impose needless burdens on small providers” and suggested instead that the “Commission should avoid burdensome provisions that are likely to be ineffective and/or unnecessary,” as these requirements would “divert resources from more effective efforts to address illegal robocalls and again, for small rural OSPs, force these costs to be recovered from a small customer base.”[17]

While not part of the FCC’s original comments received regarding the FNPRM, the House Energy and Commerce Subcommittee on Communications and Technology held a hearing on July 22, 2026, “Protecting Communications Networks and Improving Connectivity.”  During this hearing, several members noted the continuing need to combat robocalls.  According to Wiley Rein LLP partner Kevin Rupy’s opening statement, nearly $68 billion was lost to scams in 2025 alone, which spotlights the need to focus on efforts to combat illegal robocalls, most of which are generated by foreign criminal activities on an industrial scale.  He views these calls as a national security issue and urged Congress to prioritize targeted criminal enforcement against these international bad actors using the Industry Traceback Group and STIR/SHAKEN, while providing the industry flexibility to innovate fraud detection and prevention as threats evolve.[18]

CAGW agrees that OSPs must have the flexibility to mitigate ever-changing risks through a framework that advances robocall mitigation, while also safeguarding privacy, security, and access to legitimate communications.  CAGW and the Council for Citizens Against Government Waste have long championed the protection of consumer data and promoted a national framework through federal legislation to provide such protection in a consistent manner.[19]

The FCC has made significant progress in combating robocalls and should always consider how to do so while protecting consumer data privacy.  When new restrictions are considered, the FCC should also determine whether they may present barriers to entry for individuals who may be concerned about the increased data collection, or the cost of these new requirements on their service.

Again, I thank you for providing the opportunity to offer our reply comments for the record.

 

 

[1] Federal Communications Commission (FCC), “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” Further Notice of Proposed Rulemaking (FNPRM), Adopted April 30, 2026, Released May 1, 2026, https://docs.fcc.gov/public/attachments/FCC-26-27A1.pdf.

[2] Senate Committee on Commerce, Science, and Transportation, Bill Report, 116 Congress, S. 151, Telephone Robocall Abuse Criminal Enforcement and Deterrence Act, May 21, 2019, https://www.congress.gov/committee-report/116th-congress/senate-report/41/1.

[3] FCC, “Implementing Section 13(d) of the Pallone-Thuen Telephone Robocall Abuse Criminal Enforcement and Deterrence Act (TRACED Act), EB Docket No. 20-22,” Adopted August 22, 2022, Released August 22, 2022, https://docs.fcc.gov/public/attachments/DA-22-870A1.pdf.

[4] FCC, “Combating Spoofed Robocalls with Caller ID Authentication,” https://www.fcc.gov/call-authentication.

[5] Deborah Collier, “The FCC Could Have a Dark Future,” Citizens Against Government Waste, October 28, 2021, https://www.cagw.org/the-fcc-could-have-a-dark-future/.

[6] American Bankers Association, ACA International, American Financial Services Association, America’s Credit Unions, Bank Policy Institute, Consumer Bankers Association, Defense Credit Union Council, Electronic Transactions Association, Financial Technology Association, Mortgage Bankers Association , and Student Loan Servicing Alliance, “Comments to the Further Notice of Proposed Rulemaking,” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109920374/1.

[7] Twilio Inc., and Twilio US Technology Inc., “Comments in the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59) and Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991,” FCC, https://www.fcc.gov/ecfs/document/26109929223/1; Better Identity Coalition, Proposed Rule – Enhancing Know Your Customer Requirements, FCC, June 2026, https://www.fcc.gov/ecfs/document/26109926642/1.

[8] Ibid. Twilio Inc., and Twilio US Technology Inc., “Comments in the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59) and Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991.”

[9] Financial Services Modernization Act of 1999 (Gramm-Leach-Bliley Act), Pub. L. No. 106-434, S. 900, https://www.congress.gov/bill/106th-congress/senate-bill/900.

[10] The Electronic Frontier Foundation and the American Civil Liberties Union, “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109924593/1.

[11] Comments of NCTA – The Internet & Television Association, “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109926613/1.

[12] INCOMPAS, “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109927965/1.

[13] CTIA, “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109929171/1.

[14] USTelecom – the Broadband Association, “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109928939/1.

[15] America’s Communications Association (ACA), “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109926556/1.

[16] WISPA – The Association for Broadband Without Boundaries, “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109927308/1.

[17] NTCA – The Rural Broadband Association, “In the Matter of Advanced Methods to Target and Eliminate Unlawful Robocalls (CG Docket No. 17-59), Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (CG Docket No. 02-278),” FCC, June 25, 2026, https://www.fcc.gov/ecfs/document/26109923001/1.

[18] House Committee on Energy and Commerce Subcommittee on Communications and Technology, “Legislative Hearing on Protecting Communications Networks and Improving Connectivity,” July 22, 2026, https://www.youtube.com/watch?v=fm_vcypLeEY; https://d1dth6e84htgma.cloudfront.net/07_22_2026_CT_Leg_Hearing_Memo_7fc1a867bb.pdf.

[19] Deborah Collier, “CCAGW Applauds Introduction of National Data Privacy Bill,” Citizens Against Government Waste, April 29, 2026, https://www.cagw.org/ccagw-applauds-introduction-of-national-data-privacy-bill/.