Lumos — Letter of Agreement (Team Telecom)
The Letter of Agreement (LOA) establishes national-security and law-enforcement commitments by MTN and Gridiron Fiber Corporation (identified in the agreement as Lumos) in connection with applications to transfer indirect control of Section 214 authorization holders, including the authorizations associated with North State and Lumos Network, and supersedes the parties’ earlier mitigation agreements.
What it does The LOA requires Lumos to maintain a U.S. law-enforcement point of contact approved by DOJ and the FBI, preserve access to U.S. Records for lawful U.S. process, and keep responsive information within the United States when process is received. It restricts disclosure of U.S. Records, Domestic Communications, and call information to unapproved foreign governments or persons. It also requires approved security and cybersecurity plans, foreign-person and offshore-storage notices, controls on outsourced or offshored providers and principal equipment, incident reporting, annual compliance reports, and routine access for CMA site visits and interviews.
Who it affects The primary obligations fall on Lumos and its approved third-party providers, with oversight by DOJ, DHS, and DoD as the Compliance Monitoring Agencies. The agreement concerns MTN, North State, Lumos Network, Gridiron Fiber, Panther Parent, and their Section 214 authorization holders and successors.
Why it matters The agreement links telecommunications ownership transfers to continuing protections for U.S. customer and network data, lawful surveillance, foreign access, cybersecurity, and supply-chain changes. A material breach or unresolved national-security concern may support a CMA request that the FCC modify, condition, revoke, cancel, terminate, or nullify a relevant authorization.
Key dates and numbers
- Executed and dated October 6, 2023.
- Replaces the November 7, 2017 Lumos LOA and April 7, 2020 North State/MTN LOA.
- LEPOC information is due within 15 days; personnel-screening procedures within 60 days.
- Certain foreign-access, offshore-storage, provider, ownership, service, and equipment notices generally require 30 days’ advance notice.
- Third-party providers must report U.S.-Records breaches or losses within 72 hours of discovery; specified CPNI incidents must be reported within seven business days, and LOA incidents generally within 15 days.