Windstream — Letter of Agreement
The Letter of Agreement conditions Team Telecom’s non-objection to the FCC’s approval of Windstream Holdings II, LLC’s proposed increase in indirect foreign equity and voting interests on extensive national-security and law-enforcement safeguards.
What it does The agreement requires Windstream to maintain U.S.-based points of contact and a qualified security officer, support lawful U.S. process and electronic surveillance, keep responsive records within the United States, restrict foreign access and disclosure, and certify CALEA compliance. It also requires personnel screening, cybersecurity and system-security plans, incident reporting, equipment and network inventories, advance notice of ownership, service, storage, equipment, outsourcing, and network-operations changes, annual compliance reports, audits, and government site visits. The agreement covers U.S. Records, domestic communications and infrastructure, principal equipment, outsourced and offshored providers, and foreign personnel.
Who it affects The primary obligor is Windstream Holdings II, LLC, with obligations extending to its personnel, affiliates, vendors, contractors, managed network service providers, and outsourced or offshored service providers. DOJ, including the FBI, DHS, and DoD act as Compliance Monitoring Agencies; the FCC is the licensing authority whose approval and authorizations may be conditioned or subject to enforcement action.
Why it matters The LOA operationalizes Team Telecom mitigation for a telecommunications carrier handling sensitive customer and lawful-intercept data. Breach or failure to resolve agency concerns may support FCC modification, conditioning, revocation, cancellation, or termination of relevant authorizations. It also requires reporting concerning foreign-adversary suppliers, FCC Covered List providers, and Commerce Entity List providers.
Key dates and numbers
- Document date: January 17, 2023; the text is dated January 18, 2023.
- Dockets: ISP-PDR-20201021-00010, IB Docket No. 22-129, and TT 22-011.
- Many initial submissions are due within 15, 30, or 60 days after the Date of FCC Approval; security incidents generally must be reported within 72 hours.
- The annual report is due one year after FCC approval and annually thereafter.