They don't need to do that.
They just need to say "retain all data for XX years". Retention requirements are by no means a novel legislative requirement, you see them everywhere.
Now that PhoneCo. is holding all the data instead of the NSA, the NSA can then just ask the phone company to provide data on an as-needed basis using standard warrants/subpoenas using some variant of the Prism automated FISA/NSL-compliance system.