Establishing secure connection…Loading editor…Preparing document…

Legal CPNI Document

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

LEGAL CPNI DOCUMENT

This Customer Proprietary Network Information Agreement (the Agreement) is entered into as of by and between Provider Name: , a telecommunications service provider, and Customer Name: . Provider and Customer are each a Party and together the Parties.

RECITALS

WHEREAS, Provider furnishes telecommunications services to Customer and, in the course of providing those services, obtains access to Customer Proprietary Network Information ("CPNI"), which includes information regarding the type, destination, and amount of Customer's communications services and related billing and usage information; and

WHEREAS, the Parties desire to establish the terms and conditions under which Provider may access, use, retain, disclose, or otherwise process CPNI in connection with the provision of services, lawful communications, billing, fraud prevention, and legitimate business purposes as set forth in this Agreement; and

WHEREAS, Customer acknowledges that certain uses of CPNI require express authorization and that Provider will implement reasonable safeguards to protect CPNI from unauthorized access and disclosure.

NOW, THEREFORE, in consideration of the mutual promises and covenants contained herein, the Parties agree as follows:

1. DEFINITIONS

1.1 "CPNI" means proprietary information that relates to the quantity, technical configuration, type, destination, location, and amount of use of telecommunications services subscribed to by Customer, and information contained in Customer's bills concerning the type and amount of telecommunications services purchased by Customer.

1.2 "Authorized Purpose" means the use of CPNI by Provider to provide, manage, bill, and collect for telecommunications services; to protect against fraud or unlawful use; to perform network and service operations; and to comply with lawful requests by governmental authorities.

2. SCOPE OF AUTHORIZATION

2.1 Customer hereby authorizes Provider to access and use Customer's CPNI solely for Authorized Purposes. Provider will not use or disclose CPNI for any purpose not expressly authorized by this Agreement without Customer's prior written consent, except as required by law.

2.2 Customer may revoke or limit this authorization at any time by delivering written notice to Provider in accordance with Section 11 (Notices). Any such revocation will become effective upon Provider's receipt of the notice, except to the extent Provider has relied in good faith on the prior authorization.

3. USE AND DISCLOSURE OF CPNI

3.1 Provider will use reasonable administrative, technical, and physical safeguards to protect CPNI from unauthorized access, disclosure, alteration, or destruction. Such safeguards will be appropriate to the sensitivity of the CPNI and shall include access controls, encryption where appropriate, and employee training as required by Section 6.

3.2 Provider may disclose CPNI to its affiliates, contractors, agents, or service providers only to the extent necessary to carry out Authorized Purposes and only if such recipients are bound by confidentiality obligations no less protective than those contained in this Agreement.

4. CUSTOMER CONSENT FOR MARKETING

Customer elects the following with respect to Provider's use of CPNI for marketing of communications-related products or services not currently provided to Customer:

Customer provides express written consent to Provider for use of CPNI for marketing.

Customer declines use of CPNI for marketing; Provider shall not use CPNI for marketing in reliance on this Agreement.

5. RECORDKEEPING AND AUDIT

5.1 Provider will maintain records of CPNI disclosures and uses, including the date, recipient, and purpose of each disclosure, for a period of at least two (2) years from the date of disclosure or use.

5.2 Upon reasonable notice, Customer may request an accounting of CPNI disclosures made by Provider relating to Customer during the preceding two (2) years. Provider will provide such accounting within a reasonable timeframe and subject to reasonable verification of Customer's identity.

6. EMPLOYEE TRAINING AND ACCESS

Provider will limit access to CPNI to employees and contractors with a legitimate business need and will train such personnel regarding the confidentiality requirements for handling CPNI. Provider will take disciplinary measures, up to and including termination, for employees who violate CPNI protection policies.

7. SECURITY BREACH; NOTICE

7.1 In the event of an unauthorized access, breach, or disclosure of Customer's CPNI, Provider will promptly investigate and take appropriate corrective measures to mitigate the effects of the breach.

7.2 Provider will notify Customer of any breach of CPNI reasonably believed to affect Customer's information within a commercially reasonable time following discovery, and will cooperate with Customer regarding remediation and any required communications.

8. TERM AND TERMINATION

8.1 This Agreement commences on the Effective Date set forth above and shall remain in effect until terminated by either Party upon thirty (30) days' written notice to the other Party. Termination shall not relieve Provider of obligations with respect to CPNI recorded or disclosed prior to termination.

9. REMEDIES AND INDEMNIFICATION

9.1 Each Party acknowledges that a breach of the terms governing CPNI may cause irreparable harm to the other Party for which monetary damages may be inadequate. In addition to any other remedies available at law or in equity, the non-breaching Party is entitled to seek injunctive or other equitable relief.

9.2 Provider shall indemnify and hold harmless Customer from and against any claims, liabilities, losses, or damages arising from Provider's unauthorized use or disclosure of CPNI, except to the extent such claim is caused by Customer's willful misconduct or negligence.

10. NOTICES

Provider Notices Address

Customer Notices Address

Notices under this Agreement shall be in writing and shall be deemed given when delivered in person, sent by nationally recognized overnight courier, or upon receipt when sent by certified mail to the addresses provided above or to such other address as a Party designates by written notice.

11. COMPLIANCE WITH LAW

Each Party agrees to comply with applicable laws and regulations governing the protection and use of CPNI. Nothing in this Agreement shall be construed to require a Party to violate applicable law.

12. MISCELLANEOUS

12.1 Governing Law. This Agreement shall be governed by and construed in accordance with the laws of the jurisdiction where Provider maintains its principal place of business, without regard to conflict of laws principles.

12.2 Entire Agreement. This Agreement constitutes the entire understanding between the Parties with respect to CPNI and supersedes all prior oral or written agreements relating to such subject matter.

12.3 Severability. If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions will remain in full force and effect and will be construed so as to give effect to the Parties' intent as nearly as may be possible.

12.4 Amendments and Waiver. No amendment or waiver of any provision of this Agreement will be effective unless in writing and signed by both Parties. No failure or delay in exercising any right shall operate as a waiver.

12.5 Counterparts. This Agreement may be executed in one or more counterparts, each of which will be deemed an original and all of which together will constitute one instrument.

13. ADDITIONAL AUTHORIZATIONS

13.1 Authorized Representatives. The undersigned individual signing for Customer certifies that they are authorized to grant the consents and authorizations contained herein on behalf of Customer. If signing on behalf of Provider, the signer represents and warrants authority to bind Provider.

13.2 Specific Limitations. Customer may specify any specific limitations to the use or disclosure of CPNI in the space below. If no limitation is specified, Provider will rely on the general authorizations in this Agreement.

CERTIFICATION

The undersigned representatives of Provider and Customer each certify under penalty of perjury that the information provided in this Agreement is true and correct to the best of their knowledge, that they are authorized to execute this Agreement on behalf of the Party for which they sign, and that they understand the obligations and limitations imposed herein concerning the handling of CPNI.

Provider

Printed Name:

By:

Date:

Customer

Printed Name:

By:

Date:

Enter text✕

What the Legal CPNI Document Is and when it matters

A Legal CPNI Document records customer consent, authorization limits, and provider disclosures related to Customer Proprietary Network Information (CPNI) as required under federal telecommunications law and FCC rules. It documents who may access account-level calling, billing, and service usage information, the permitted uses of that data, and any customer-facing disclosures. Providers use this record to demonstrate compliance with consumer-privacy obligations, to log account-level authentication and consent events, and to support audits or regulatory inquiries involving 47 U.S.C. §222 and 47 C.F.R. §64.2001 et seq.

Why a formal Legal CPNI Document protects providers and customers

A clear, auditable CPNI record reduces regulatory risk, documents customer choices, and creates a defensible timeline of permissions and disclosures under federal law.

Why a formal Legal CPNI Document protects providers and customers

Which teams and customers typically rely on this document

Telecommunications carriers, customer support, compliance officers, and business customers use the Legal CPNI Document to record and validate consent and access permissions.

  • Carrier compliance teams: log consent events, audit access, and prepare regulatory filings.
  • Customer service agents: confirm authorized contacts before disclosing account data.
  • Enterprise account managers: capture written consent for marketing or third-party access.

Properly completed CPNI records make operational workflows auditable, reduce costly disputes, and simplify responses to regulatory inquiries or consumer requests.

Core sections every professional Legal CPNI Document should include

A complete document groups consent, scope, authentication methods, retention policy, revocation process, and audit trail details so each authorization is traceable and legally defensible.

Customer authorization

Explicit statement of what CPNI the customer permits the provider to use or disclose, including any time limits or targeted purposes such as billing, technical support, or marketing; include name, account number, and customer signature or electronic consent evidence.

Scope of access

Defines permitted recipients (individuals or third parties), data categories (call detail, location, billing), and any exclusions; precise scope reduces ambiguity and limits exposure during audits.

Authentication method

Specifies acceptable identity checks for voice/in-person/email requests (e.g., account password, security questions, one-time code) and documents the level of authentication applied to each disclosure.

Revocation and changes

Explains how the customer revokes or modifies consent, required notice periods, and how changes are recorded and propagated across systems to prevent stale authorizations.

Retention and audit trail

Records timestamps, IP addresses, signed consent copies, and operator IDs retained to meet regulatory documentation needs and to support investigations or compliance reviews.

Legal and regulatory references

Identifies controlling statutes and rules (for example, 47 U.S.C. §222 and FCC CPNI rules) and cites internal policy identifiers so reviewers can cross-check obligations quickly.

Required data elements to capture on every CPNI form

Customer name: Full legal name
Account identifier: Account number or subscriber ID
Contact details: Phone, email, billing address
Consent scope: Allowed data categories
Authentication method: Password, OTP, or KBA type
Timestamp: Date and time of consent

Step-by-step: completing the Legal CPNI Document

Follow these steps to collect valid customer consent, authenticate identity, and store the record in a searchable compliance archive.

  • 01
    1. Identify the customer: Confirm account number and legal name before proceeding.
  • 02
    2. Explain the scope: Read permitted uses and get explicit affirmative consent.
  • 03
    3. Authenticate: Use company-approved method such as OTP or security questions.
  • 04
    4. Record consent: Capture signature, timestamp, and auditor ID in the system.

Configuring an online CPNI form workflow

Set up template settings to enforce authentication, retention, and auditing for every CPNI consent event.

Field Configuration
Authentication Require OTP or account password
Signer order Customer first, then agent attestation
Retention Auto-archive to compliance vault
Notifications Email receipt to customer and compliance

Digital signing and system requirements

Choose a platform that supports secure e-signatures, tamper-evident audit trails, and configurable signer authentication.

  • Integrations: Salesforce, NetSuite, MS 365, Google Workspace
  • File formats: PDF, DOCX, HTML supported
  • Security: TLS and AES-256 encryption

Where to send or file a completed CPNI record

After customer consent is captured, route copies to the compliance archive, account system, and the customer; maintain audit logs for regulatory review.

  • Compliance archive: Store signed record in a tamper-evident archive.
  • Customer copy: Email signed receipt to the subscriber immediately.
  • Account record: Link consent to the subscriber profile in CRM.
  • Investigation files: Produce logs promptly for audits or complaints.

Timing and operational checkpoints for CPNI handling

Follow these timing rules to keep CPNI handling consistent and defensible; adapt intervals to internal policy and regulatory guidance.

Consent capture timing:

Obtain consent at account setup or before any new disclosure.

Consent renewal:

Review or re-obtain consent annually or per company policy.

Revocation processing:

Apply revocation immediately upon receipt and log event.

Audit readiness:

Keep records accessible for at least two years for review.

Incident response:

Begin investigation within 72 hours of suspected unauthorized disclosure.

Principal penalties and operational risks of incorrect CPNI records

FCC fines: Civil monetary penalties and enforcement actions
State penalties: State consumer protection fines or sanctions
Civil liability: Customer lawsuits and statutory damages
Service disruption: Forced suspension of marketing or disclosures
Reputational harm: Loss of customer trust and churn
Regulatory audits: Extended compliance reviews and remediation costs

Real-world examples of compliant e-sign and consent workflows

These brief examples show how organizations used secure e-signature platforms to capture consent and keep auditable CPNI records.

Dan Rotelli, CEO — BIS

BIS needed traceable consent records for enterprise customers.

  • They required SOC 2–grade audit trails and ESIGN/UETA compliance.
  • "We felt most comfortable with airSlate SignNow given their SOC 2 certification and strict focus on ESIGN and UETA act compliance."

Tim Martin, Founder — Martin Properties

A property services firm captured tenant telecom consents remotely.

  • Mobile signing and offline capability were essential.
  • "I can process and execute all of these documents online with 100% compliance and built-in security. Whether on mobile or working offline, I can get forms back to their necessary parties efficiently."

eSignature pricing and capability comparison for CPNI workflows

A neutral comparison of common vendor pricing and core capabilities relevant to CPNI-conscious deployments; signNow is listed first per platform guidance.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes Yes
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently asked questions about the Legal CPNI Document

Answers to common questions about validity, revocation, e-signing, and recordkeeping to help operational teams avoid the most frequent errors.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users