Ohio Telecom Association v. FCCOhio Telecom Association v. FCC
COUNSEL
ARGUED: Roman Martinez, LATHAM & WATKINS, LLP, Washington, D.C., for Petitioners. Adam Sorensen, FEDERAL COMMUNICATIONS COMMISSION, Washington, D.C., for Respondents. ON BRIEF: Roman Martinez, Matthew A. Brill, Matthew T. Murchison, Charles S. Dameron, Christina R. Gay, LATHAM & WATKINS, LLP, Washington, D.C., for Petitioners. Adam Sorensen, Sarah E. Citrin, Jacob M. Lewis, FEDERAL COMMUNICATIONS COMMISSION, Washington, D.C., for Respondents. Jennifer Tatel, WILKINSON BARKER KNAUER, LLP, Washington, D.C., for Intervenor. John Anderson Jung, TECHFREEDOM, Washington, D.C., Trent McCotter, GEORGE MASON UNIVERSITY, Arlington, Virginia, Craig E. Gilmore, WILKINSON BARKER KNAUER, LLP, Washington, D.C., Alan Butler, ELECTRONIC PRIVACY INFORMATION CENTER, Washington, D.C., for Amici Curiae.
STRANCH, J., delivered the opinion of the court in which MATHIS, J., concurred, and GRIFFIN, J., concurred in part. GRIFFIN, J. (pp. 36-51), delivered a separate dissenting opinion.
OPINION
JANE B. STRANCH, Circuit Judge. These consolidated petitions for review challenge a rule of the Federal Communications Commission imposing reporting requirements on telecommunications carriers in the event of data breaches involving customers’ personally identifiable information. Petitioners contend that the reporting requirements exceed the Commission‘s statutory authority and violate the Congressional Review Act. For the reasons set forth below, we DENY the petitions for review.
I. BACKGROUND
A. Statutory Background
In 1934, Congress passed the Communications Act, which granted the Federal
Among the provisions of the 1934 Act was
Decades later, the Americans with Disabilities Act of 1990 added a new provision to the Communications Act—Section 225—which charged the FCC with ensuring the availability of “telecommunications relay services” (TRS) for hearing-impaired and speech-impaired individuals. Pub. L. No. 101-336, 104 Stat. 327, 366 (codified at
telephone transmission services that provide the ability for an individual who is deaf, hard of hearing, deaf-blind, or who has a speech disability to engage in communication by wire or radio with one or more individuals, in a manner that is functionally equivalent to the ability of a hearing individual who does not have a speech disability to communicate using voice communication services by wire or radio.
In 1996, Congress enacted extensive updates to the 1934 Act with the Telecommunications Act, Pub. L. No. 104-104, 110 Stat. 56, which sought to “foster industry competition in local markets, encourage the development of telecommunications technology, and provide consumers with affordable access to telecommunications services.” Robbins v. New Cingular Wireless PCS, LLC, 854 F.3d 315, 319 (6th Cir. 2017). The Telecommunications Act created a new statutory provision,
(A) information that relates to the quantity, technical configuration, type, destination, location, and amount of use of a telecommunications service subscribed to by any customer of a telecommunications carrier, and that is made available to the carrier by the customer solely by virtue of the carrier-customer relationship; and
(B) information contained in the bills pertaining to telephone exchange service or telephone toll service received by a customer of a carrier.
B. Regulatory Background
In 1998, the FCC issued its first rules implementing
In 2007, in response to the rising incidents of data brokers obtaining unauthorized access to CPNI, the FCC promulgated a new rule “adopting additional safeguards to protect customers’ CPNI against unauthorized access and disclosure.” Implementation of the Telecomms. Act of 1996: Telecomms. Carriers’ Use of Customer Proprietary Network Info. & Other Customer Info., 22 FCC Rcd. 6927, 6928 (2007) (2007 Order). Among other things, the 2007 Order required carriers to notify law enforcement and customers in the event of a CPNI breach and established specific protocols governing the notification process. Id. at 6929-30, 6943-45. The FCC explained that its “general rulemaking authority under the [Communications] Act” conferred by
The FCC built on its preexisting CPNI regulations in 2013. In response to rampant “waste, fraud, and abuse” in the provision of video relay services, the Commission applied CPNI protections—which mostly mirrored its CPNI protections in the carrier context—to relay service providers. Structure & Pracs. of Video Relay Serv. Program, 28 FCC Rcd. 8618, 8620, 8684-85 (2013).
In 2014, the FCC made clear its view that it has the statutory authority to regulate a carrier‘s handling of personally identifiable information (“PII“). In an order
The following year, the FCC reclassified broadband Internet access services as “telecommunications service[s].” Protecting & Promoting the Open Internet, 30 FCC Rcd. 5601, 5734 (2015). In 2016, in the wake of that reclassification and in response to an “increasingly Internet-based economy” creating new and evolving data privacy concerns, the FCC issued an omnibus Broadband Privacy Order seeking to “apply the privacy requirements of the Communications Act of 1934” to “broadband Internet access service[s].” Protecting Priv. of Customers of Broadband & Other Telecomms. Servs., 31 FCC Rcd. 13911, 13911-13 (2016) (2016 Order). As part of this regulatory overhaul, the Commission substantially revised its 2007 data breach reporting requirements, applying the requirements not only to breaches of CPNI, but also to breaches of customers’ PII. Id. at 14080-81, 14085-86. The 2016 Order defined PII as “any information that is linked or reasonably linkable to an individual or device,” such as an individual‘s name, email address, date of birth, or Social Security number. Id. at 13944-46, 14081.
The 2016 Order extensively addressed the FCC‘s statutory authority to impose requirements on carriers regarding PII. The FCC primarily relied on
Pursuant to the Congressional Review Act (CRA), the FCC submitted the 2016 Order to Congress for its review. The CRA, described in more detail below, prescribes an expedited procedure for Congress to strike down federal regulations of which it disapproves. It also prohibits agencies from reissuing a new rule that is “substantially the same” as the rule that Congress rejected.
Congress disapproves the rule submitted by the Federal Communications Commission relating to ‘Protecting the Privacy of Customers of Broadband and Other Telecommunications Services’ (81 Fed. Reg. 87274 (December 2, 2016)), and such rule shall have no force or effect.
Pub. L. No. 115-22, 131 Stat. 88, 88 (2017). The President signed the disapproval resolution on April 3, 2017. Id. The FCC accordingly rescinded the 2016 Order, including the amended data breach reporting rules, and reinstated the 2007 version of the rules. Protecting the Priv. of Customers of Broadband & Other Telecomms. Servs., 82 Fed. Reg. 44118, 44118-23 (Sept. 21, 2017).
C. 2024 Data Breach Reporting Rule and Procedural History
In January 2023, the FCC issued a Notice of Proposed Rulemaking seeking public comment on new amendments to the 2007 data breach rules. Data Breach Reporting Requirements, 38 FCC Rcd. 566 (2023). Concerned with the “increasing number of security breaches of customer information in recent years,” the Notice proposed a new rule “expand[ing] the Commission‘s definition of ‘breach’ to include inadvertent disclosures of customer information.” Id. at 566-67, 572. To that end, the Notice sought comment on “the Commission‘s authority to establish breach-reporting obligations” for “proprietary information other than CPNI that customers have an interest in protecting from public exposure, such as Social Security Numbers and financial records.” Id. at 577. The Commission also requested comment on “the impact of the Congressional disapproval of the 2016 Privacy Order on the Commission‘s legal authority to issue” its proposed rules. Id. at 573 (italics omitted).
On December 21, 2023, after the requisite notice-and-comment period, the FCC issued a new rule revising its data breach requirements, which was then published in the Federal Register as a final rule on February 12, 2024. Data Breach Reporting Requirements, 89 Fed. Reg. 9968 (Feb. 12, 2024) (2024 Order). The 2024 Order provided that the FCC‘s breach notification rules cover both CPNI and PII, id. at 9969, defining the latter category as:
(i) An individual‘s first name or first initial, and last name, in combination with any government-issued identification numbers or information issued on a government document used to verify the identity of a specific individual, or other unique identification number used for authentication purposes;
(ii) An individual‘s username or email address, in combination with a password or security question and answer, or any other authentication method or information necessary to permit access to an account; or
(iii) Unique biometric, genetic, or medical data.
Id. at 10003. Other changes contained within the new Order included adding a good faith exception to the definition of the term “breach,” id. at 9981; adding the stipulation that carriers need not notify customers of a breach if the carriers can reasonably determine that no harm is likely to occur, id. at 9977; and eliminating mandatory waiting periods for carriers to notify customers of data breaches, id. at 9979. In addition, the Commission adopted equivalent changes to the data breach obligations of TRS providers. Id. at 9981-89.
The 2024 Order extensively discussed, and responded to comments on, the FCC‘s statutory authority to promulgate the revised data breach reporting rules. The FCC pointed to the “breadth” of
Petitioners then sought judicial review of the 2024 Order under
On March 4, 2024, the United States Judicial Panel on Multidistrict Litigation issued a consolidation order for the then-pending petitions for review in the Fifth and Sixth Circuits. The panel randomly selected the Sixth Circuit in which to consolidate the petitions for review. The D.C. Circuit later transferred CTIA‘s petition for review to this circuit, and this court consolidated the three cases for submission. On March 20, 2024, Hamilton Relay, Inc. filed a motion to intervene, which this court granted.
II. ANALYSIS
A. Jurisdiction
Although no party contests our jurisdiction to review these petitions, we retain an independent obligation to police our own jurisdiction.1 United States v. Certain Land Situated in City of Detroit, 361 F.3d 305, 307 (6th Cir. 2004). Courts of appeals have exclusive jurisdiction over certain final orders issued by the FCC.
The FCC released the 2024 Order on December 21, 2023. The Order was then published in the Federal Register as a final rule on February 12, 2024. Data Breach Reporting Requirements, 89 Fed. Reg. at 9968. Ohio Telecom and the Texas Association of Business both petitioned for review of the Order on February 20, 2024. Because their petitions were filed within sixty days of both the Order‘s release and its publication in the Federal Register, we have
jurisdiction regardless of which date constitutes the Order‘s “entry.” But CTIA, NCTA, and USTelecom petitioned for review on March 15, 2024, which is within sixty days of the Order‘s publication, not
Congress has not statutorily defined the term “entry” as it is used in
Because all three petitions were filed within sixty days of the Order‘s publication in the Federal Register, we have jurisdiction to hear these consolidated petitions for review.
B. Standard of Review
Under the Administrative Procedure Act (APA), courts must “hold unlawful and set aside agency action, findings, and conclusions found to be . . . arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law . . . [or] in excess of statutory jurisdiction, authority, or limitations, or short of statutory right.”
provisions, and determine the meaning or applicability of the terms of an agency action.”
Applying the APA, we “must exercise [our own] independent judgment in deciding whether an agency has acted within its statutory authority.” Loper Bright Enters. v. Raimondo, 603 U.S. 369, 412 (2024). Although “[c]areful attention to the judgment of the Executive Branch may help inform that inquiry,” we “may not defer to an agency interpretation of the law simply because a statute is ambiguous.” Id. at 412-13. Instead, we rely on our “traditional tools of statutory construction” to determine a statute‘s “single, best meaning.” Id. at 400-01. Applying those tools, our inquiry begins with the “statutory text,” relying on “the language itself” and “the specific context in which that language is used.” United States ex rel. Felten v. William Beaumont Hosp., 993 F.3d 428, 431 (6th Cir. 2021) (quoting Robinson v. Shell Oil Co., 519 U.S. 337, 340-41 (1997)). And we interpret that text in accordance with our binding judicial precedent. Freeman v. Wainwright, 959 F.3d 226, 232 (6th Cir. 2020).
Petitioners contend that the 2024 Order exceeds the FCC‘s statutory authority and
C. Statutory Authority Under the Communications Act and its Amendments
The FCC points to two independent sources of statutory authority permitting it to impose data breach reporting requirements regarding PII—
1. 47 U.S.C. § 222(a)
The FCC argues that
i. Text
We first look to the operative text. See Felten, 993 F.3d at 431. The parties contest the plain meaning of the term “proprietary,” as used in the phrase “proprietary information of, and relating to . . . customers.” The term is defined as “of, relating to, or characteristic of an owner or title holder,” or “used, made, or marketed by one having the exclusive legal right.” Proprietary, Merriam Webster, https://perma.cc/2F5J-GXHP. Black‘s Law Dictionary defines the broader phrase “proprietary information” similarly—“[i]nformation in which the owner has a protectable interest,” such as a “trade secret.” Proprietary Information, Black‘s Law Dictionary (11th ed. 2019).
As Petitioners see it, this plain meaning confirms that the term “proprietary information” encompasses only the sort of information in which an owner has a protectable interest, which would exclude PII like individual names or addresses. As they note, in ordinary parlance, it “would be odd to refer to someone‘s name and address as one‘s ‘proprietary’ information, insofar as customers routinely disclose such information to third parties.” Petitioners’ Br. 26. The FCC contends that Petitioners’ construction is overly narrow, and that the term “proprietary” should be construed to include any information that belongs or pertains to an owner or proprietor, which necessarily encompasses information “obtained by [carriers] through [their] service relationship with [their] customers.” Respondent‘s Br. 34. As the FCC correctly notes, adopting Petitioners’ narrower construction would exclude the types of customer information that even Petitioners recognize falls within the ambit of
ii. Statutory Context and Structure
Because the operative language is unclear, we look to the statutory context and structure for clarification. See Felten, 993 F.3d at 431. Whereas
The FCC‘s reading of
Sections
In addition, as Petitioners note, Congress knows how to expressly reference PII when it so desires—other portions of the Communications Act directly mention PII. See Cable Communications Policy Act of 1984, Pub. L. No. 98-549, 98 Stat. 2779, 2794-95 (codified at
In response, the FCC points to the canon that, “[i]n a given statute . . . different terms usually have different meanings.” Pulsifer v. United States, 601 U.S. 124, 149 (2024). Because
In sum, although the FCC advances a plausible reading of
2. 47 U.S.C. § 201(b)
But that is not the end of the matter. The FCC points to
subject to APA constraints.
As a threshold matter, we must identify the regulated conduct at issue before we can determine whether it constitutes a “practice[] . . . in connection with [a] communication service.”
i. Text
We begin our statutory analysis with the text—namely, the term “practice,” which the statute does not define. See Felten, 993 F.3d at 431. We interpret the term “consistent with [its] ‘ordinary meaning . . . at the time Congress enacted the statute.‘” Wis. Cent. Ltd. v. United States, 585 U.S. 274, 277 (2018) (quoting Perrin v. United States, 444 U.S. 37, 42 (1979)). In 1934, the year the Communications Act was enacted, the word “practice” was broadly defined as “[a]ction; performance; operation; . . . deed; proceeding;” or “actual performance or application of knowledge; such actual performance or application habitually engaged in; often, repeated or customary action; usage; habit; custom; . . . the usual mode or method of doing something.” Practice, Webster‘s International Dictionary (2d ed. 1934). The term has a similarly broad definition today: “a repeated or customary action” or “the usual way of doing something.” Practice, Merriam Webster, https://perma.cc/FM4L-TL4L.
The plain meaning of the term “practice,” as understood then and now, refers to a carrier‘s usual mode of operating, which can encompass both positive acts and the refusal to act. This understanding is supported not only by the term‘s plain meaning, but also by Supreme Court precedent. In
ii. Statutory Context and Structure
regulations . . . in connection with” the furnishing of such services.
Again, Global Crossing provides helpful guidance. There, the Court explained why a carrier‘s refusal to compensate a payphone operator can constitute a practice “in connection with” a carrier‘s communication service. Payphone operators, the Court noted, play an integral role in facilitating a carrier‘s communication service—specifically, their services are part of the “total long-distance service the payphone operator and the long-distance carrier together provide to the caller, with respect to the carriage of his or her particular call.” Glob. Crossing, 550 U.S. at 55. Consequently, a carrier‘s “refusal to divide the revenues” incurred from that long-distance service is a practice that directly relates to and implicates its provision of communication services. Id. The Court also rejected the dissenting opinion‘s narrower interpretation of the statute,
The Global Crossing Court also cited multiple examples of other “practice[s] . . . in connection with [furnishing a] communication service” that the FCC has historically regulated pursuant to
Global Crossing reaffirms what is evident from
Resisting this conclusion, Petitioners (and the dissent) argue that the statute‘s context and structure require a narrower construction that forecloses
Each of these four terms, however, is sufficiently “distinct from the other,” and represent different categories of carrier conduct related to a carrier‘s provision of communication services.
Graham Cnty. Soil & Water Conservation Dist. v. U.S. ex rel. Wilson, 559 U.S. 280, 288 (2010).
Indeed, the position advanced by the Petitioners and dissent resembles a similar argument made by the dissent in Global Crossing—that “the terms ‘charges,’ ‘classifications,’ and ‘regulations‘” exclusively “involve either setting rules for the provision of service or setting rates for that provision” and thus limit the term “practice” to encompass only activities undertaken by a carrier in its role as a provider of communication services. 550 U.S. at 74-76 (Thomas, J., dissenting). The Court rejected this invocation of noscitur a sociis and instead looked to whether the practice at issue bore a close relationship to the provision of communication services. Id. at 55 (majority opinion). Adhering to this same approach leads us to conclude that a carrier‘s refusal to report breaches of customer data, which has a direct connection to the provision of communication services, indeed constitutes a “practice[] . . . in connection with [a] communication service.”9
Petitioners also point to caselaw from the D.C. Circuit, approvingly cited by the Supreme Court, interpreting the term “practice,” as it is used in Section 206 of the Federal Power Act (FPA), based on the surrounding statutory language. Cal. Indep. Sys. Operator Corp. v. FERC,
372 F.3d 395, 398-403 (D.C. Cir. 2004); see FERC v. Elec. Power Supply Ass‘n, 577 U.S. 260, 278 (2016). But that case involved a statute with markedly different language and structure, as well as an agency action that was substantively distinct from the one at issue here. The statute in that case, Section 206 of the Federal Power Act, confers the Federal Energy Regulatory Commission (FERC) with the authority to hold hearings and, based on such hearings, deem “unjust, unreasonable, unduly discriminatory or preferential” any “rate, charge, or classification” or any “rule, regulation, practice, or contract affecting such rate, charge, or classification.”
The D.C. Circuit rejected FERC‘s interpretation. As the court noted, Section 206 “only comes into play when the Commission has had a hearing and finds that a ‘rate, charge, or classification’ employed by a regulated utility in its jurisdictional transactions is ‘unjust, unreasonable, unduly discriminatory or preferential.‘” Id. at 400. The statutory language thus made clear at the outset Section 206‘s narrow focus on rates, charges, and classifications. And it expressly limited FERC‘s authority to regulate “practice[s]” to “practice[s] . . . affecting [a] rate, charge, or classification“—further evincing Congress‘s intent to cabin Section 206‘s reach to rates, charges, classifications, and closely related matters. The statute‘s narrow title, the court reasoned, only bolstered this interpretation: “Power of Commission to fix rates and charges; determination of cost of production or transmission.”
In the present matter, by contrast, § 201 deals with a carrier‘s “furnish[ing]” of “communication service[s].”
Petitioners further contend that, under the general/specific canon of statutory interpretation, we should read § 222 as superseding § 201(b). In Petitioners’ view, § 201(b)‘s general prohibition on unjust or unreasonable practices must give
As discussed above, the specific requirements and exceptions in § 222 apply to only certain categories of customer information—CPNI, aggregate customer information, and subscriber list information. Under the specific/general canon, those specific requirements and exceptions “presumptively govern[]” over the general prohibition on unjust or unreasonable practices in § 201(b). Id. Section 222 does not, however, reach or address privacy protections regarding customer PII. Because disclosure of breaches of customer PII is not the type of conduct within § 222‘s ambit, “the conduct at issue” does not “fall[] within the scope of both” § 222 and § 201(b). Id. Interpreting § 201(b) to confer the FCC with the authority to impose data breach reporting requirements regarding customer PII, therefore, does not result in “the superfluity of a specific provision that is swallowed by the general one.” Id. at 645.
Petitioners contend that, because § 222 specifically deals with certain aspects of data privacy, § 201(b)‘s “more general command to prohibit ‘unjust or unreasonable’ practices” can never apply to the data privacy context, including aspects of data privacy that § 222 does not address. Petitioners’ Br. 35. The dissent likewise embraces this view, arguing that, because § 222 provides a “specific framework” for regulating certain types of customer information and “does not mention PII, it follows that Congress did not intend for the FCC to regulate the privacy of customer PII” in § 201(b). Dissenting Op. at 46. But that is not how the general/specific canon works. As the Supreme Court has long explained:
It is an old and familiar rule that, where there is, in the same statute, a particular enactment, and also a general one, which, in its most comprehensive sense, would include what is embraced in the former, the particular enactment must be operative, and the general enactment must be taken to affect only such cases within its general language as are not within the provisions of the particular enactment.
RadLAX, 566 U.S. at 646 (quoting United States v. Chase, 135 U.S. 255, 260 (1890)). Our construction fully comports with this rule, interpreting § 201(b) to “affect only such cases within its general language as are not within the provisions of” § 222. Id.
The Petitioners’ and dissent‘s interpretation, by contrast, fails to accord with the statute and stretches the general/specific canon well beyond its limits. While § 222 regulates carriers’ handling of specific sets of customer information, at no point does it prohibit the Commission from regulating other aspects of customer data privacy that fall outside § 222‘s scope. It is true that § 201(b) and § 222 overlap in subject matter, but such overlap between statutes does not automatically render them impermissibly superfluous. See Skilling v. United States, 561 U.S. 358, 413 n.45 (2010) (concluding that overlap in federal bribery statutes, where different statutes applied to different categories of officials, did not render those statutes superfluous). This principle “is particularly true when agency authority is at stake.” Adirondack Med. Ctr., 740 F.3d at 699. As the D.C. Circuit has noted, “overlap among . . . various enforcement provisions is not [a] surprising” phenomenon because “Congress c[an] reasonably hand . . . agencies a palette sufficiently sophisticated to capture the full spectrum of enforcement possibility.” DeNaples v. Off. of Comptroller of Currency, 706 F.3d 481, 487 (D.C. Cir. 2013).
Here, the plain text of § 201(b) allows for regulation of unjust or unreasonable practices regarding customer PII. While § 222 imposes specific requirements and exceptions regarding enumerated categories of customer information, it does not bar the FCC from regulating certain carrier practices regarding other categories of customer data, including PII. Mere overlap in subject matter cannot displace unambiguous statutory text. Skilling, 561 U.S. at 413 n.45. Our directive to avoid surplusage requires that we give full operative effect to the specific requirements and exceptions in § 222. See RadLAX, 566 U.S. at 645. It does not mandate that we interpret § 222 as wholly displacing § 201(b)‘s authority over all aspects of data privacy, in contravention of § 201(b)‘s text.
Finally, the Petitioners and dissent point to § 222‘s lack of a savings clause and contrast that omission with § 251, enacted alongside § 222, which provides that “[n]othing in this section shall be construed to limit or otherwise affect the Commission‘s authority under section 201 of this title.”
As the FCC notes, moreover, there are other reasons why Congress may have opted to add a specific savings clause to § 251 but not § 222. Section 251 assigns various responsibilities in implementing the Act to the states; thus, it is logical that Congress
We therefore conclude, based on the statutory text, context, and structure, that § 201(b) gives the FCC the authority to impose reporting requirements in the event of a data breach of customer PII.
iii. Broader Legal Context
Although the statutory text, context, and structure are dispositive of our inquiry, the broader legal context in which § 201(b) exists provides additional support for our conclusion.
In Section 45 of the Federal Trade Commission Act (FTCA), Congress directed the Federal Trade Commission (FTC) to prevent businesses from engaging in “unfair or deceptive acts or practices in or affecting commerce.”
This statutory regime speaks to the issue here. In enacting the FTCA, Congress gave the FTC broad authority to prohibit harmful practices, including inadequate data privacy protections, while opting to exempt carriers from the FTC‘s authority and instead leave them within the FCC‘s regulatory authority. Congress chose to also enact, in § 201(b), a similarly broad prohibition on “unjust or unreasonable” carrier “practices . . . in connection with [a] communication service.”
iv. Regulatory Interpretations
Finally, while not dispositive, we address Petitioners’ contention that the FCC‘s reliance on § 201(b) is undermined by its regulatory history. Petitioners argue that, because the FCC has only recently concluded that § 201(b) can regulate data privacy, “the statute cannot plausibly be read to stretch that far.” Petitioners’ Br. 36-37.
First, our determination that the text, context, and structure of § 201(b) gives the
As part of its prerogative to regulate unjust or unreasonable practices, the FCC has long applied § 201(b) to a diverse set of problems, from deceptive marketing to exclusive contracts with commercial building owners. See Glob. Crossing, 550 U.S. at 53-55. Although the FCC did not invoke § 201(b) as a source of authority to regulate aspects of customer data privacy until 2014, see Terracom, Inc. & YourTel Am., Inc., 29 FCC Rcd. at 13329, it has never disclaimed this authority. Indeed, well before 2014, the FCC relied in part on § 201(b) to regulate certain carrier practices involving customer data, evincing a flexible, evolving approach to data regulation. In 1970, for example, the Commission promulgated rules regarding the provision of data processing services by carriers pursuant to its authority under § 201(b). Regul. & Pol‘y Probs. Presented by Interdependence of Comput. & Commc‘n Servs. & Facilities, 28 F.C.C.2d 291, 296, 300 (1970). One decade later, in 1980, the Commission, noting the existence of “broad consumer rights under Section 201(b),” required companies to disclose certain types of information while prohibiting certain carriers from disclosing to other companies “any customer proprietary information unless such information is available to any member of the public.” Amend. of Section 64.702 of the Comm‘n‘s Rules and Reguls., 77 F.C.C.2d 384, 440, 499 (1980).12 Contrary to Petitioners’ assertions, this is not a situation in which an agency has “claim[ed] to discover in a long-extant statute an unheralded power to regulate ‘a significant portion of the American economy.‘” Util. Air Regul. Grp. v. EPA, 573 U.S. 302, 324 (2014) (quoting FDA v. Brown & Williamson Tobacco Corp., 529 U.S. 120, 159 (2000)). Rather, it is part of the FCC‘s longstanding, flexible, and incremental application of § 201(b) to data regulation in the evolving environment of data collection and retention.
Petitioners also attempt to rehash their general/specific argument, asserting that “the FCC itself previously recognized the exclusive and comprehensive nature of Section 222” regarding customer data privacy. Petitioners’ Br. 36-37. That is incorrect. In support, Petitioners point to only a single line from a 1999 Order stating that the FCC “conclude[s] that the specific consumer privacy and consumer choice protections established in section 222 supersede the general protections identified in sections 201(b) and 202(a).” Telecomms. Carriers’ Use of Customer Proprietary Network Info. & Other Customer Info., 14 FCC Rcd. 14409, 14491 (1999). But Petitioners ignore the context and purpose of that statement. There, the FCC concluded that the “broad non-discrimination requirements” in § 201(b) and § 202(a) should not be construed and applied in a manner that would override § 222‘s protection of CPNI.
The respect we afford to an agency‘s interpretation of a statute is, of course, heightened when the interpretation was “issued roughly contemporaneously with enactment of the statute and [has] remained consistent over time.” Loper Bright, 603 U.S. at 386. But that concept does not bind an interpreting agency to its earliest exercises of regulatory authority, particularly in the context of a broad, decades-old statute like § 201(b) that has long been applied to a wide and evolving range of issues. As the Supreme Court has recognized, § 201(b) “permits,” and “Congress likely expected, the FCC to pour new substantive wine into its old regulatory bottles.” Glob. Crossing, 550 U.S. at 57.
It has now been over a decade since the FCC invoked § 201(b) as part of its statutory authority to protect customer data. That invocation is properly supported by the statute‘s plain text, context, and structure. We therefore uphold the Commission‘s reliance on § 201(b) to impose breach notification requirements concerning customer PII.
3. 47 U.S.C. § 225
Intervenor Hamilton Relay asserts that the FCC lacks the authority under § 225 to impose the 2024 data breach reporting requirements on TRS providers. Under § 225, TRS providers must provide telephone transmission services to hearing or speech-impaired individuals “in a manner that is functionally equivalent to the ability of a hearing individual who does not have a speech disability[.]”
We have determined that the FCC has the statutory authority to impose the 2024 data breach reporting rule on telecommunications carriers.13 See Section II.C.2, supra.
D. Congressional Review Act
Petitioners further argue that the FCC‘s promulgation of the 2024 Order impermissibly sidesteps Congress‘s 2017 disapproval resolution and violates the CRA. We describe the CRA and address our jurisdiction to determine Petitioners’ CRA arguments before turning to the merits.
1. Background
In 1996, Congress passed, and the President signed, the CRA. Pub. L. No. 104-121, 110 Stat. 847, 868-74 (codified at
Under the CRA, before a rule takes effect, the promulgating agency must provide both the House and Senate with various items, including a copy of the rule, a short statement regarding the rule, and a cost-benefit analysis of the rule (if any).
After receiving the rule, Congress may, within sixty days, pass a resolution of disapproval.
“That Congress disapproves the rule submitted by the __________ relating to __________, and such rule shall have no force or effect.” (The blank spaces being appropriately filled in).
The CRA also limits future agency action following the enactment of a disapproval resolution. The Act provides that:
A rule that does not take effect (or does not continue) . . . may not be reissued in substantially the same form, and a new rule that is substantially the same as such a rule may not be issued, unless the reissued or new rule is specifically authorized by a law enacted after the date of the joint resolution disapproving the original rule.
2. Jurisdiction
As noted, we have exclusive jurisdiction over certain final orders issued by the FCC.
On this question, the CRA‘s plain text is dispositive. Section 805 precludes judicial review of any “determination, finding, action, or omission under this chapter.”
Because the 2024 Order does not constitute an “action . . . under” the CRA, we have jurisdiction over Petitioners’ CRA claim.
3. Merits
The CRA provides that a “rule that does not take effect (or does not continue)” following the enactment of a disapproval resolution “may not be reissued in substantially the same form, and a new rule that is substantially the same as such a rule may not be issued, unless the reissued or new rule is specifically authorized by a law enacted after” the resolution.
Specifically, they argue that the disapproval of the 2016 Order precludes the FCC from promulgating a new rule that is “substantially the same” as any of the component provisions contained within the 2016 Order. The FCC disagrees, asserting that the disapproval resolution bars only the issuance of a new rule that is “substantially the same” as the entire 2016 Order that was rejected by Congress. To resolve this dispute, we evaluate the precise meaning and scope of the term “rule” as it is used in the CRA.
To date, neither the Supreme Court nor the Sixth Circuit has meaningfully examined the CRA, which has been
The starting point is the text. See Felten, 993 F.3d at 431. The CRA, incorporating the APA, defines the term “rule” as “the whole or a part of an agency statement of general or particular applicability and future effect designed to implement, interpret, or prescribe law or policy.”
Using the CRA‘s mandatory fill-in-the-blank format,
Petitioners argue that the phrase “rule that does not take effect (or does not continue)” refers not “to the rule specified in the joint resolution of disapproval,” but rather, to any constituent part of the broader rule that has been nullified by the applicable disapproval resolution. Petitioners’ Br. 48-51 (quotation omitted); see Dissenting Op. at 41 (agreeing with Petitioners’ construction). That reading contravenes the text of the CRA. Section 801(b)(2)‘s reference to “a rule that does not take effect (or does not continue)” refers back to § 801(b)(1), which provides that “[a] rule shall not take effect (or continue), if the Congress enacts a joint resolution of disapproval, described under section 802, of the rule.”
It is true that when Congress disapproved the 2016 Order, it nullified every constituent rule contained therein. That conclusion is plainly required by the CRA‘s mandate that “[a] rule shall not take effect (or continue), if the Congress enacts a joint resolution of disapproval . . . of the rule.”
Petitioners prognosticate that this construction would make a disapproval resolution “easy to circumvent” by reissuance of “any of the individual parts of [a] disapproved rule.” Petitioners’ Br. 54; see Dissenting Op. at 41-42 (similarly arguing that our construction would allow agencies to “easily circumvent” congressional disapprovals). Such a prediction does not overcome the Act‘s plain text. Even if it were material to our disposition, it is unfounded. Congress can resolve this concern by passing resolutions with specific language. The CRA gives Congress ample opportunity to identify specific rules in its disapproval resolutions. See
Accordingly, under the CRA‘s plain text, we must compare the 2024 Order to the entire 2016 Order and determine whether they are substantially the same.
Finally, even if we were to adopt Petitioners’ construction and directly compare the 2016 reporting requirements with the 2024 reporting requirements, we still would conclude that the two rules are not substantially the same. There are notable differences between the two sets of reporting requirements. For example, unlike the 2016 Order, the 2024 Order extends its reporting requirements to TRS providers. Data Breach Reporting Requirements, 89 Fed. Reg. at 9981-89. There are also small but meaningful differences between the substantive obligations imposed by the two sets of requirements. As the FCC notes, the 2024 requirements are materially less prescriptive regarding the content and manner of customer notice. Granting leeway to effectively provide notice, the 2024 Order requires only “sufficient information so as to make a reasonable customer aware that a breach occurred on a certain date, or within a certain estimated timeframe, and that such a breach affected or may have affected that customer‘s data.” Id. at 9980.
The 2016 Order requirements, in contrast, included written or electronic notification of a breach, a description of the data exposed and the date range of the breach, information the customer could use to contact the telecommunications carrier to inquire about the breach, and instructions for notifying federal authorities and law enforcement. Protecting Priv. of Customers of Broadband, 31 FCC Rcd. at 14085. The two Orders also define the term
We therefore conclude that the FCC‘s issuance of the 2024 Order did not violate the CRA.
III. CONCLUSION
For the foregoing reasons, we DENY the petitions for review.
DISSENT
GRIFFIN, Circuit Judge, dissenting.
For two independent reasons, the FCC‘s new data-breach-reporting rule is unlawful and should be set aside. First, Congress and the President expressly disapproved a similar rule in 2017, foreclosing this new version under the Congressional Review Act. And second, neither statute the FCC relies on authorizes the rule. Because the majority opinion upholds this doubly unlawful rule, I respectfully dissent.
I concur in the majority‘s rulings that we have jurisdiction to hear the consolidated petitions for review and to review the claim under the Congressional Review Act. Further, I join our court‘s holding that
I.
Under the Administrative Procedure Act (APA), we must “hold unlawful and set aside agency action” that is “in excess of statutory jurisdiction, authority, or limitations, or short of statutory right.”
II.
Begin with Congress‘s disapproval of a nearly identical rule related to data-breach reporting. That disapproval bars the FCC‘s new version of that rule.
A.
The Congressional Review Act (CRA) empowers Congress to oversee—and, with the President‘s assent, overturn—rules promulgated by federal agencies. See Pub. L. No. 104-121, § 251, 110 Stat. 868, 868–74 (1996) (codified at
After receiving an agency‘s report, Congress may enact a “joint resolution” of disapproval within a defined timeframe. See
Such a disapproval occurred here. Since 2007, the FCC has required telecommunications carriers to report breaches of a statutorily defined type of data called “customer proprietary network information” (CPNI)—technical information related to the customer‘s “use of a telecommunications service.”
As required under the CRA, the FCC submitted its 2016 order to Congress. Both houses of Congress then passed a joint disapproval resolution. See S.J. Res. 34, 115th Cong. (2017); H.R.J. Res. 230, 115th Cong. (2017). The joint resolution provided that “Congress disapproves the rule submitted by the Federal Communications Commission relating to ‘Protecting the Privacy of Customers of Broadband and Other Telecommunications Services’ (81 Fed. Reg. 87274) (December 2, 2016), and such rule shall have no force or effect.” Pub. L. No. 115-22, 131 Stat. 88, 88 (2017). The President signed Congress‘s disapproval resolution on April 3, 2017. See id. Consequently, the FCC rescinded the 2016 order, including the order‘s version of the data-breach-reporting rule. See Protecting the Privacy of Customers of Broadband and Other Telecommunications Services, 82 Fed. Reg. 44118, 44122–23 (Sept. 21, 2017).
B.
At issue is whether the 2017 disapproval forecloses the 2024 data-breach-reporting rule. All agree that, after the 2017 disapproval, Congress did not “specifically authorize[]” the 2024 rule by later-enacted legislation.
Start with the many similarities between the 2016 and 2024 data-breach-reporting rules. A table from petitioners’ brief (at 44) helps to visualize just how similar these rules are, particularly when compared to the predecessor 2007 rule concerning breach reporting for CPNI.
| | 2016 Rule | 2024 Rule | |
|---|---|---|---|
| Scope | Imposes reporting duties with respect to CPNI | Imposes reporting duties with respect to CPNI and PII | Imposes reporting duties with respect to CPNI and PII |
| Definition of “breach” | “[W]hen a person, without authorization or exceeding authorization, has intentionally gained access to, used, or disclosed CPNI.” 47 C.F.R. § 64.2011(e) (2008) (emphasis added). | “[A]ny instance in which a person, without authorization or exceeding authorization, has gained access to, used, or disclosed customer proprietary information.” 47 C.F.R. § 64.2002(c) (proposed 2016) (omits “intentionally“). | “[W]hen a person, without authorization or exceeding authorization, gains access to, uses, or discloses covered data.” 47 C.F.R. § 64.2011(e)(1) (2024) (omits “intentionally“). |
| Definition of protected data | Limited to “CPNI” only. 47 C.F.R. § 64.2011(e) (2008). | “Customer proprietary information” includes “CPNI” and “PII.” 47 C.F.R. § 64.2002(f) (proposed 2016) (emphasis added). | “Covered data” includes “CPNI” and “personally identifiable information.” 47 C.F.R. § 64.2011(e)(2) (2024) (emphasis added). |
| State of mind of the party responsible for the breach | Applies only where a person “intentionally” accesses or discloses covered data without authorization. 47 C.F.R. § 64.2011(e) (2008). | Omits the requirement of “intentional[]” access or disclosure. See 47 C.F.R. § 64.2002(c) (proposed 2016). | Omits the requirement of “intentional[ ]” access or disclosure. See 47 C.F.R. § 64.2011(e)(1) (2024). |
| Agencies to be notified | FBI and Secret Service. 47 C.F.R. § 64.2011(b) (2008). | FBI, Secret Service, and FCC. 47 C.F.R. § 64.2006(b)–(c) (proposed 2016). | FBI, Secret Service, and FCC. 47 C.F.R. § 64.2011(a) (2024). |
| Timeline for customer notification | No timeline. 47 C.F.R. § 64.2011(c) (2008). | “30 calendar days after the carrier reasonably determines that a breach has occurred.” 47 C.F.R. § 64.2006(a) (proposed 2016). | “30 days after reasonable determination of a breach.” 47 C.F.R. § 64.2011(b) (2024). |
In response, the majority points to minor, technical differences between the 2016 and 2024 data-breach-reporting rules, such as differences in what information must be included in breach notifications and how many customers must be affected to trigger reporting requirements. But such differences are inconsequential: The rules, adopting nearly identical regimes for reporting breaches of customer PII, are “substantially the same.”
Because the 2024 data-breach-reporting rule is “substantially the same” as the one Congress disapproved in 2017, the CRA blocks the new rule.
C.
But the majority directs our attention elsewhere. It asserts that, instead of focusing on the similarities between the specific breach-reporting rules, we should instead compare the entirety of the FCC‘s 2016 and 2024 orders, which included the breach-reporting rules and many other discrete rules.
That argument brings us to the heart of the CRA issue: When evaluating whether the new rule is “substantially the same as” the earlier, disapproved one,
As the majority notes, there is little precedent to guide our interpretation of the CRA. CRA disapprovals, by their nature, are enacted in historically rare circumstances—“when there has been a recent change in partisan control of the White House, the new President‘s party has majorities in both chambers of Congress, and there are rules from the previous administration for which the sixty-legislative-day clock has not yet run out.” Jody Freeman & Matthew C. Stephenson, The Untapped Potential of the Congressional Review Act, 59 Harv. J. on Legis. 279, 286 (2022). For this reason, there have been only a handful of CRA disapprovals since its 1996 enactment, id. at 286–87 & nn.32–34, and no on-point cases to guide our decision.
Thus, this interpretative challenge begins with the text of the 2017 disapproval: “Congress disapproves the rule submitted by the Federal Communications Commission relating to ‘Protecting the Privacy of Customers of Broadband and Other Telecommunications Services’ (81 Fed. Reg. 87274) (December 2, 2016), and such rule shall have no force or effect.” 131 Stat. at 88. By the resolution‘s plain terms, it cited to the entire 2016 order (i.e., the whole). So, at first blush, this text favors the majority‘s view.
But by disapproving the whole 2016 order, Congress disapproved of each of its constituent parts. After all, the CRA defines a “rule” as “[t]he whole or a part of an agency statement of general . . . applicability and future effect designed to implement, interpret, or prescribe law or policy.”
Quite to the contrary, our interpretation of the CRA ought to elevate the will of Congress over that of an administrative agency. It is our elected representatives, not unelected commissioners, whom the Constitution vests with legislative power. See Consumers’ Rsch., 145 S. Ct. at 2496. True, Congress can “seek assistance” from agencies by making limited delegations of rulemaking authority, id. at 2496-97 (citation modified), but as the CRA makes clear, Congress can and does rein in that authority when it disagrees with what an
The majority‘s exclusive focus on the entire order would allow administrative agencies to easily circumvent Congress‘s disapproval. For instance, if the FCC issued an order adopting four discrete rules (Rules A, B, C, and D) and Congress disapproved it, then, under the majority‘s logic, the FCC could skirt the disapproval by readopting Rules A and B in one order and Rules C and D in another. Neither of those new orders, under the majority‘s interpretation of the CRA, would be “substantially the same” as the one that Congress disapproved. That interpretation, rather than giving effect to congressional intent, merely encourages creative ways to flaunt it.
The majority responds that it would be an “anomalous construction of the CRA” if a disapproval prevented an agency from re-promulgating any “rule” in a disapproved order, which could include “the narrowest, most anodyne” of agency statements like “definitions.” But that argument has several flaws. First, depending on the circumstances, it is far from a clear that something like a definition qualifies as a “rule“—a “statement of general . . . applicability and future effect designed to implement, interpret, or prescribe law or policy.”
D.
To hold that Congress‘s 2017 disapproval does not bar this rule is to render that disapproval meaningless and to shift legislative power from Congress to an administrative agency. Cf. Loper Bright, 603 U.S. at 411-13 (correcting Chevron‘s improper shift of judicial power to administrative agencies). I interpret the CRA and the 2017 disapproval in a way that preserves Congress‘s ability to give agencies only those powers it wishes to confer. Thus, in my view, Congress‘s disapproval of the FCC‘s 2016 rule bars the FCC‘s 2024 data-breach-reporting rule because the two rules are “substantially the same.”
III.
There is another reason to set the rule aside. The FCC claims that two statutes authorize the rule—
Section 201(b) provides in relevant part:
All charges, practices, classifications, and regulations for and
in connection with [a] communication service [by wire or radio], shall be just and reasonable, and any such charge, practice, classification, or regulation that is unjust or unreasonable is declared to be unlawful . . . .
When, as here, a statute does not “expressly confer[] discretion on the agency,” Moctezuma-Reyes v. Garland, 124 F.4th 416, 420, 422 (6th Cir. 2024), we use our “traditional tools of statutory construction” to determine the scope of an agency‘s power,” Loper Bright, 603 U.S. at 401. “[S]tatutes, no matter how impenetrable, do—in fact, must—have a single, best meaning.” Loper Bright, 603 U.S. at 400. Indeed, “[t]hat is the whole point of having written statutes; ‘every statute‘s meaning is fixed at the time of enactment.‘” Id. (citation omitted); see also In re MCP No. 185, 124 F.4th 993, 1001 (6th Cir. 2025). “So instead of declaring a particular party‘s reading ‘permissible’ in such a case, courts use every tool at their disposal to determine the best reading of the statute and resolve the ambiguity.” Loper Bright, 603 U.S. at 400.
A.
Statutory interpretation begins with the text. I agree with the majority that the text, “practice[] . . . in connection with,” is facially broad. In some sense, everything a telecommunications carrier does—from laying fiber-optic cable to providing employees with healthcare benefits—is an activity in furtherance of, and thus a “practice in connection with,” the communication service the carrier provides. But our reading of that ambiguous phrase cannot be so literal as to be all-encompassing. Cf. Cal. Div. of Lab. Standards Enf‘t v. Dillingham Constr., N.A., Inc., 519 U.S. 316, 335 (1997) (Scalia, J., concurring) (opining that broad statutory language can provide “an illusory test” because, in some sense, “everything is related to everything else“). All agree that the FCC may not invoke
Instead of pretending that the plain text “in connection with” provides any meaningful limitation on its own, we must employ tools of statutory construction to understand the statute‘s limits and determine whether it permits the FCC to dictate to carriers when, how, and to whom they must report breaches of customer PII.
Consider first how the canon of noscitur a sociis—that a word is “known by the company it keeps“—narrows the term “practices.” See Gustafson v. Alloyd Co., 513 U.S. 561, 575 (1995). In the statute, the term “practices” appears in a group with “charges,” “classifications,” and “regulations.” These terms all address conduct that is inherent in or necessary for a carrier‘s provision of communication services, e.g., setting rates or classifying services.
By comparison, reporting breaches of customer PII is an activity much farther afield from providing communication services. True, carriers collect and store such data as part of their provision of services, so perhaps those activities (PII collection and storage) are inherent in or necessary for the provision of communication services. But the data-breach-reporting rule does not purport to govern how carriers collect or store PII; rather, it regulates whether and how carriers report to customers
Terms like “charges,” “classifications,” and “regulations” come nowhere close to encompassing data-breach reporting—an activity unnecessary for providing communication services. To hold that one term in the statutory foursome reaches such a tangentially related activity gives that term far more expansive meaning than the others and thus violates the canon of noscitur a sociis. See id.
The majority opinion brushes this canon aside, asserting that noscitur a sociis “cannot be used to ‘rob’ the plain statutory text of its independent and ordinary significance.” (Citing Graham Cnty. Soil & Water Conservation Dist. v. U.S. ex rel. Wilson, 559 U.S. 280, 288 (2010)). But what “independent and ordinary significance” does
Nor does the FCC offer a limiting principle on a broad construction of “practices.” Faced with the argument that a broad construction would allow it to regulate virtually anything a carrier does in its business, the FCC responds only that its “application of Section 201(b) has no such far-reaching ambition.” But if a broad construction would grant the FCC authority to make such “far-reaching” regulations when it has the “ambition” to do so, that construction is incorrect. It is, after all, up to us to “fix the boundaries” of the rulemaking authority delegated by statute. In re MCP No. 185, 124 F.4th at 1012 (quoting Loper Bright, 603 U.S. at 395); see also FCC v. Consumers’ Rsch., 145 S. Ct. 2482, 2496-97 (2025) (explaining that a statute delegating rulemaking authority must have an “intelligible principle” making clear the “boundaries” of the agency‘s authority (citation omitted)).
A second canon of construction, the general/specific canon, also supports a more limited view of
Construing
When such a detailed statute lays out such a specific framework related to “Privacy of customer information,” it is difficult to imagine that Congress intended
The majority opinion claims that this canon does not apply because
Congress made this general/specific point even clearer by omitting a key clause from
Thus, although
B.
Looking beyond the text and canons of construction, we look to precedent. On that score, I agree with the majority that Global Crossing Telecommunications, Inc. v. Metrophones Telecommunications, Inc., 550 U.S. 45 (2007), is instructive, but I read it as pointing in the opposite direction from the majority‘s holding.
Global Crossing addressed whether
The Court held that such a refusal fits within
The data-breach-reporting rule here differs from the regulation upheld in Global Crossing in two important ways. First, unlike in Global Crossing, the FCC did not enact the data-breach reporting rule in response to specific legislation calling for such a rule. Quite the opposite: The rule‘s authority is based solely on the vacuous language of a nearly 100-year-old statute; no recent action from Congress called for it. See Communications Act, 48 Stat. 1064 (1934) (codified as amended at
For support of its expansive reading of
First, the Court mentioned those other practices only to show “that the FCC has long implemented
Second, even assuming the validity of those other regulations under
As for other precedent, the majority discounts an instructive case from the D.C. Circuit, California Independent System Operator Corp. v. FERC, 372 F.3d 395 (D.C. Cir. 2004), which interpreted similar statutory language. There, the D.C. Circuit held that the term “practice” in
That reasoning applies forcefully here. The FCC‘s and majority‘s expansive view of the term “practice” is indeed “quite a leap,” id., effectively giving the FCC the green light to regulate all manner of carrier business activities and going well beyond anything “resembl[ing]” “the traditional, historical subject matter of
C.
Finally, the majority opinion‘s policy-based reasoning is both inappropriate and unpersuasive. The majority opines that a “regulatory void” will result if the FCC cannot enact the 2024 data-breach-reporting rule because carriers are exempt from similar requirements under the Federal Trade Commission Act. That argument has several flaws.
First, policy arguments alone cannot save a poor reading of a statute. If the “single, best meaning” of a statute leads to regulatory gaps, then it is for Congress, not us, to correct it. See Loper Bright, 603 U.S. at 400.
Second, the majority opinion‘s policy argument ignores other federal agencies’ regulations, based on other statutory authority, requiring data-breach reporting from telecommunications carriers. For instance, the Securities and Exchange Commission requires publicly traded companies to disclose “material cybersecurity incidents” on publicly filed forms. See Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, 88 Fed. Reg. 51896 (Aug. 4, 2023) (codified at
Finally, federal regulations aside, many states require data-breach reporting to consumers. See Security Breach Notification Laws, Nat‘l Conf. of State Legislatures (last updated Jan. 17, 2022), available at: https://www.ncsl.org/technology-and-communication/security-breach-notification-laws (collecting “laws requiring private businesses . . . in most states . . . to notify individuals of security breaches of information involving personally identifiable information.“). Thus, even considering the majority‘s policy arguments, the alleged “regulatory gap” that would result if petitioners prevailed here is much narrower than the majority suggests.
D.
For these reasons, I would hold that
IV.
Because this unlawful rule violates the disapproval resolution passed under the CRA and lacks statutory authorization, I would grant the petitions for review and set aside the rule.
I respectfully dissent.