What Is Regulation S-P?
Regulation S-P is the privacy and safeguarding rule of the Securities and Exchange Commission, known as the SEC, found in Subpart A of Part 248 of Title 17 of the Code of Federal Regulations, known as the CFR, and headed Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Personal Information. Under Section 248.1(a), the privacy subpart governs the treatment of nonpublic personal information about consumers by the financial institutions listed in paragraph (b) of the section, and Section 248.30 requires every covered institution to develop, implement, and maintain written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information.
The SEC adopted Regulation S-P as privacy rules promulgated under section 504 of the Gramm-Leach-Bliley Act. The final rules implement the requirements of the Gramm-Leach-Bliley Act with respect to investment advisers registered with the SEC, brokers, dealers, and investment companies. Under the Gramm-Leach-Bliley Act, a financial institution must provide its customers with a notice of its privacy policies and practices, and the Gramm-Leach-Bliley Act also requires the SEC to establish for financial institutions appropriate standards to protect customer information.
Consumers, Customers and Nonpublic Personal Information
Under Section 248.1(b), the part applies to brokers, dealers, and investment companies, as well as to investment advisers that are registered with the SEC. It also applies to foreign (non-resident) brokers, dealers, investment companies and investment advisers that are registered with the SEC. Except with respect to Section 248.30(b), the privacy subpart applies only to nonpublic personal information about individuals who obtain financial products or services primarily for personal, family, or household purposes from the institutions listed in the section.
A consumer is an individual who obtains or has obtained a financial product or service from the firm that is to be used primarily for personal, family, or household purposes, or that individual's legal representative. A customer is a consumer who has a customer relationship with the firm. A customer relationship is a continuing relationship between a consumer and the firm under which the firm provides one or more financial products or services to the consumer that are to be used primarily for personal, family, or household purposes.
Nonpublic personal information means personally identifiable financial information, and any list, description, or other grouping of consumers (and publicly available information pertaining to them) that is derived using any personally identifiable financial information that is not publicly available information. Personally identifiable financial information means any information a consumer provides to the firm to obtain a financial product or service from the firm, information about a consumer resulting from any transaction involving a financial product or service between the firm and a consumer, or information the firm otherwise obtains about a consumer in connection with providing a financial product or service to that consumer.
An affiliate of a broker, dealer, or investment company, or an investment adviser registered with the SEC, is any company that controls, is controlled by, or is under common control with the broker, dealer, or investment company, or investment adviser registered with the SEC. A nonaffiliated third party is any person except the firm's affiliate, or a person employed jointly by the firm and any company that is not the firm's affiliate, but a nonaffiliated third party includes the other company that jointly employs the person.
Initial Privacy Notice
Under Section 248.4(a), a firm must provide a clear and conspicuous notice that accurately reflects its privacy policies and practices to two groups. An individual who becomes a customer must receive the notice not later than when the firm establishes a customer relationship, except as provided in paragraph (e) of the section. A consumer must receive the notice before the firm discloses any nonpublic personal information about the consumer to any nonaffiliated third party, if the firm makes such a disclosure other than as authorized by Sections 248.14 and 248.15.
Clear and conspicuous means that a notice is reasonably understandable and designed to call attention to the nature and significance of the information in the notice.
Under Section 248.4(b), a firm is not required to provide an initial notice to a consumer if the firm does not disclose any nonpublic personal information about the consumer to any nonaffiliated third party, other than as authorized by Sections 248.14 and 248.15, and the firm does not have a customer relationship with the consumer. A firm establishes a customer relationship when it and the consumer enter into a continuing relationship. A firm does not have a customer relationship with a consumer if it buys a loan made to the consumer but does not have the servicing rights for that loan.
Annual Privacy Notice
Except as provided by paragraph (e) of Section 248.5, a firm must provide a clear and conspicuous notice to customers that accurately reflects its privacy policies and practices not less than annually during the continuation of the customer relationship. Annually means at least once in any period of twelve consecutive months during which that relationship exists. The firm may define the twelve-consecutive-month period, but it must apply it to the customer on a consistent basis. A firm provides a notice annually if it defines the twelve-consecutive-month period as a calendar year and provides the annual notice to the customer once in each calendar year following the calendar year in which it provided the initial notice.
Under Section 248.5(e)(1), a firm is not required to deliver an annual privacy notice if it provides nonpublic personal information to nonaffiliated third parties only in accordance with Section 248.13, Section 248.14, or Section 248.15, and it has not changed its policies and practices with regard to disclosing nonpublic personal information from the policies and practices that were disclosed to the customer under Section 248.6(a)(2) through (5) and (9) in the most recent privacy notice provided pursuant to the part.
If a firm changes its policies or practices in such a way that it no longer meets the requirements for that exception, and Section 248.8 does not require it to provide a revised privacy notice, it must provide an annual privacy notice within one hundred days of the change in its policies or practices that causes it to no longer meet the requirement.
Content of Privacy Notices
Under Section 248.6(a), the initial, annual, and revised privacy notices must include each of the following items of information that applies to the firm or to the consumers to whom it sends its privacy notice, in addition to any other information the firm wishes to provide: the categories of nonpublic personal information that the firm collects, the categories of nonpublic personal information that the firm discloses, and the categories of affiliates and nonaffiliated third parties to whom the firm discloses nonpublic personal information, other than those parties to whom it discloses information under Sections 248.14 and 248.15.
The notices must also include the categories of nonpublic personal information about former customers that the firm discloses and the categories of affiliates and nonaffiliated third parties to whom it discloses nonpublic personal information about former customers, other than those parties to whom it discloses information under Sections 248.14 and 248.15. If the firm discloses nonpublic personal information to a nonaffiliated third party under Section 248.13, and no other exception applies to that disclosure, the notices must include a separate statement of the categories of information the firm discloses and the categories of third parties with whom it has contracted.
The notices must further include an explanation of the consumer's right under Section 248.10(a) to opt out of the disclosure of nonpublic personal information to nonaffiliated third parties, including the method or methods by which the consumer may exercise that right at that time, and any disclosures the firm makes under section 603(d)(2)(A)(iii) of the Fair Credit Reporting Act, that is, notices regarding the ability to opt out of disclosures of information among affiliates. The notices must include the firm's policies and practices with respect to protecting the confidentiality and security of nonpublic personal information, and any disclosure made under paragraph (b) of Section 248.6.
Opt Out Right
Under Section 248.10(a)(1), except as otherwise authorized in the subpart, a firm may not, directly or through any affiliate, disclose any nonpublic personal information about a consumer to a nonaffiliated third party unless it has provided to the consumer an initial notice as required under Section 248.4, it has provided to the consumer an opt out notice as required in Section 248.7, it has given the consumer a reasonable opportunity, before it discloses the information to the nonaffiliated third party, to opt out of the disclosure, and the consumer does not opt out.
Under Section 248.7(a)(1), a firm required to provide an opt out notice under Section 248.10(a) must provide a clear and conspicuous notice to each of its consumers that accurately explains the right to opt out. The notice must set out that the firm discloses or reserves the right to disclose nonpublic personal information about its consumer to a nonaffiliated third party, that the consumer has the right to opt out of that disclosure, and a reasonable means by which the consumer may exercise the opt out right.
A firm provides a reasonable means to exercise an opt out right if it designates check-off boxes in a prominent position on the relevant forms with the opt out notice, includes a reply form together with the opt out notice, provides an electronic means to opt out, such as a form that can be sent via electronic mail or a process at its web site, if the consumer agrees to the electronic delivery of information, or provides a toll-free telephone number that consumers may call to opt out.
A firm provides a consumer with a reasonable opportunity to opt out if it mails the notices required in paragraph (a)(1) of the section to the consumer and allows the consumer to opt out by mailing a form, calling a toll-free telephone number, or any other reasonable means within thirty days after the date the firm mailed the notices. When a customer opens an on-line account with the firm and agrees to receive the notices required in paragraph (a)(1) of the section electronically, the firm provides a reasonable opportunity if it allows the customer to opt out by any reasonable means within thirty days after the date that the customer acknowledges receipt of the notices in conjunction with opening the account.
For an isolated transaction, such as the provision of brokerage services to a consumer as an accommodation, the firm provides the consumer with a reasonable opportunity to opt out if it provides the notices required in paragraph (a)(1) of the section at the time of the transaction and requests that the consumer decide, as a necessary part of the transaction, whether to opt out before completing the transaction.
A firm may allow a consumer to select certain nonpublic personal information or certain nonaffiliated third parties with respect to which the consumer wishes to opt out. A consumer may exercise the right to opt out at any time, and a consumer's direction to opt out under Section 248.7 is effective until the consumer revokes it in writing or, if the consumer agrees, electronically.
Revised Privacy Notices
Under Section 248.8(a), except as otherwise authorized in the subpart, a firm must not, directly or through any affiliate, disclose any nonpublic personal information about a consumer to a nonaffiliated third party other than as described in the initial notice that it provided to that consumer under Section 248.4, unless it has provided to the consumer a clear and conspicuous revised notice that accurately describes its policies and practices, it has provided to the consumer a new opt out notice, it has given the consumer a reasonable opportunity, before it discloses the information to the nonaffiliated third party, to opt out of the disclosure, and the consumer does not opt out.
Delivering Notices
Under Section 248.9(a), a firm must provide any privacy notices and opt out notices, including short-form initial notices that the subpart requires, so that each consumer can reasonably be expected to receive actual notice in writing or, if the consumer agrees, electronically.
Exceptions to the Opt Out Requirements
Section 248.13 is headed Exception to opt out requirements for service providers and joint marketing. Under Section 248.13(a)(1), the opt out requirements in Sections 248.7 and 248.10 do not apply when a firm provides nonpublic personal information to a nonaffiliated third party to perform services for it or functions on its behalf, if the firm provides the initial notice in accordance with Section 248.4 and enters into a contractual agreement with the third party that prohibits the third party from disclosing or using the information other than to carry out the purposes for which the firm disclosed the information, including use under an exception in Section 248.14 or Section 248.15 in the ordinary course of business to carry out those purposes.
Section 248.14 is headed Exceptions to notice and opt out requirements for processing and servicing transactions. Under Section 248.14(a), the requirements for initial notice in Section 248.4(a)(2), for the opt out in Sections 248.7 and 248.10, and for initial notice in Section 248.13 in connection with service providers and joint marketing, do not apply if the firm discloses nonpublic personal information as necessary to effect, administer, or enforce a transaction that a consumer requests or authorizes, or in connection with processing or servicing a financial product or service that a consumer requests or authorizes, maintaining or servicing the consumer's account with the firm, or with another entity as part of a private label credit card program or other extension of credit on behalf of such entity, or a proposed or actual securitization, secondary market sale (including sales of servicing rights), or similar transaction related to a transaction of the consumer. Section 248.15 is headed Other exceptions to notice and opt out requirements.
Account Numbers and Marketing
Section 248.12 is headed Limits on sharing account number information for marketing purposes. Under its paragraph (a), headed General prohibition on disclosure of account numbers, a firm must not, directly or through an affiliate, disclose, other than to a consumer reporting agency, an account number or similar form of access number or access code for a consumer's credit card account, deposit account, or transaction account to any nonaffiliated third party for use in telemarketing, direct mail marketing, or other marketing through electronic mail to the consumer.
Safeguarding Customer Information
Under Section 248.30(a)(1), every covered institution must develop, implement, and maintain written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information. Under Section 248.30(a)(2), these written policies and procedures must be reasonably designed to ensure the security and confidentiality of customer information, protect against any anticipated threats or hazards to the security or integrity of customer information, and protect against unauthorized access to or use of customer information that could result in substantial harm or inconvenience to any customer.
Customer information, for any covered institution other than a transfer agent registered with the SEC or another appropriate regulatory agency, means any record containing nonpublic personal information as defined in Section 248.3(t) about a customer of a financial institution, whether in paper, electronic or other form, that is in the possession of a covered institution or that is handled or maintained by the covered institution or on its behalf regardless of whether the information pertains to individuals with whom the covered institution has a customer relationship, or to the customers of other financial institutions where the information has been provided to the covered institution.
A covered institution means any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the SEC or another appropriate regulatory agency as defined in section 3(a)(34)(B) of the Securities Exchange Act of 1934.
Incident Response Program
The written policies and procedures must include a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including customer notification procedures. The response program must include procedures for the covered institution to assess the nature and scope of any incident involving unauthorized access to or use of customer information and identify the customer information systems and types of customer information that may have been accessed or used without authorization, to take appropriate steps to contain and control the incident to prevent further unauthorized access to or use of customer information, and to notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, unless the covered institution determines, after a reasonable investigation of the facts and circumstances of the incident, that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience.
Customer information systems means the information resources owned or used by a covered institution, including physical or virtual infrastructure controlled by such information resources, or components thereof, organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of customer information to maintain or support the covered institution's operations.
Sensitive Customer Information
Sensitive customer information means any component of customer information alone or in conjunction with any other information, the compromise of which could create a reasonably likely risk of substantial harm or inconvenience to an individual identified with the information.
Sensitive customer information can include customer information uniquely identified with an individual that has a reasonably likely use as a means of authenticating the individual's identity, including a Social Security number, official State- or government-issued driver's license or identification number, alien registration number, government passport number, employer or taxpayer identification number, a biometric record, a unique electronic identification number, address, or routing code, or telecommunication identifying information or access device as defined in 18 U.S.C. 1029(e). It can also include customer information identifying an individual or the individual's account, including the individual's account number, name or online user name, in combination with authenticating information such as information described in paragraph (d)(9)(ii)(A) of the section, or in combination with similar information that could be used to gain access to the customer's account such as an access code, a credit card expiration date, a partial Social Security number, a security code, a security question and answer identified with the individual or the individual's account, or the individual's date of birth, place of birth, or mother's maiden name.
Notifying Affected Individuals
Under Section 248.30(a)(4)(i), unless a covered institution has determined, after a reasonable investigation of the facts and circumstances of the incident of unauthorized access to or use of sensitive customer information that occurred at the covered institution or one of its service providers that is not itself a covered institution, that sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience, the covered institution must provide a clear and conspicuous notice, or ensure that such notice is provided, to each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization. The notice must be transmitted by a means designed to ensure that each affected individual can reasonably be expected to receive actual notice in writing.
If an incident of unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred, but the covered institution is unable to identify which specific individuals' sensitive customer information has been accessed or used without authorization, it must provide notice to all individuals whose sensitive customer information resides in the customer information system that was, or was reasonably likely to have been, accessed or used without authorization. Notwithstanding the foregoing, if the covered institution reasonably determines that a specific individual's sensitive customer information that resides in the customer information system was not accessed or used without authorization, it is not required to provide notice to that individual under the paragraph.
Under Section 248.30(a)(4)(iii), a covered institution must provide the notice as soon as practicable, but not later than thirty days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred, unless the United States Attorney General determines that the notice required under the rule poses a substantial risk to national security or public safety, and notifies the SEC of the determination in writing, in which case the covered institution may delay providing the notice for a time period specified by the Attorney General, up to thirty days following the date when the notice was otherwise required to be provided. The notice may be delayed for an additional period of up to thirty days if the Attorney General determines that the notice continues to pose a substantial risk to national security or public safety and notifies the SEC of the determination in writing.
Under Section 248.30(a)(4)(iv), the notice must describe in general terms the incident and the type of sensitive customer information that was or is reasonably believed to have been accessed or used without authorization. It must include, if the information is reasonably possible to determine at the time the notice is provided, any of the following: the date of the incident, the estimated date of the incident, or the date range within which the incident occurred.
The notice must also include contact information sufficient to permit an affected individual to contact the covered institution to inquire about the incident, including a telephone number (which should be a toll-free number if available), an email address or equivalent method or means, a postal address, and the name of a specific office to contact for further information and assistance. If the individual has an account with the covered institution, the notice must recommend that the customer review account statements and immediately report any suspicious activity to the covered institution.
The notice must explain what a fraud alert is and how an individual may place a fraud alert in the individual's credit reports to put the individual's creditors on notice that the individual may be a victim of fraud, including identity theft. It must recommend that the individual periodically obtain credit reports from each nationwide credit reporting company and that the individual have information relating to fraudulent transactions deleted, and it must explain how the individual may obtain a credit report free of charge. The notice must also include information about the availability of online guidance from the Federal Trade Commission and usa.gov regarding steps an individual can take to protect against identity theft, a statement encouraging the individual to report any incidents of identity theft to the Federal Trade Commission, and the Federal Trade Commission's website address where individuals may obtain government information about identity theft and report suspected incidents of identity theft.
Service Provider Oversight
A service provider is any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution. Under Section 248.30(a)(5)(i), a covered institution's response program must include the establishment, maintenance, and enforcement of written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring, of service providers, including to ensure that the covered institution notifies affected individuals as set forth in paragraph (a)(4).
The policies and procedures must be reasonably designed to ensure service providers take appropriate measures to protect against unauthorized access to or use of customer information, and to provide notification to the covered institution as soon as possible, but no later than seventy-two hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider. Upon receipt of such notification, the covered institution must initiate its incident response program.
As part of its incident response program, a covered institution may enter into a written agreement with its service provider to notify affected individuals on the covered institution's behalf. Notwithstanding a covered institution's use of a service provider, the obligation to ensure that affected individuals are notified rests with the covered institution.
Disposal of Information
Under Section 248.30(b)(1), every covered institution, other than notice-registered broker-dealers, must properly dispose of consumer information and customer information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal. Under Section 248.30(b)(2), every covered institution, other than notice-registered broker-dealers, must adopt and implement written policies and procedures that address the proper disposal of consumer information and customer information according to that standard.
A notice-registered broker-dealer is a broker or dealer registered by notice with the SEC under section 15(b)(11) of the Securities Exchange Act of 1934. Consumer information, for purposes of Section 248.30, is any record about an individual, whether in paper, electronic or other form, that is a consumer report or is derived from a consumer report, or a compilation of such records, that a covered institution maintains or otherwise possesses for a business purpose, regardless of whether the information pertains to individuals with whom the covered institution has a customer relationship, or to the customers of other financial institutions where the information has been provided to the covered institution. It does not include information that does not identify individuals, such as aggregate information or blind data.
Amendments, Records and Compliance Dates
The effective date of the amendments to Regulation S-P is August 2, 2024. The amendments require covered institutions, other than funding portals, to make and maintain written records documenting compliance with the requirements of the safeguards rule and disposal rule. The amendments extend both the safeguards rule and the disposal rule to transfer agents registered with the SEC or another appropriate regulatory agency.
Larger entities must comply with the amendments by December 3, 2025, which is eighteen months after publication in the Federal Register, while smaller entities must comply by June 3, 2026, which is twenty-four months after publication in the Federal Register. Larger entities include all broker-dealers that are not small entities under the Securities Exchange Act for purposes of the Regulatory Flexibility Act. The definitions of larger and smaller entities do not correspond with the definitions of large and small firms used by the Financial Industry Regulatory Authority, known as FINRA, which are characterized by the number of registered representatives at the firm.
Exam Relevance
The Securities Industry Essentials examination content outline lists, in Topic 3.2.4, Books and Records and Privacy Requirements, the bullets Privacy requirements with Regulation S-P named in parentheses, Nonpublic personal information, Confidentiality of information, Privacy notifications, and Safeguard requirements. The list of SEC rules and regulations in Section 3, Understanding Trading, Customer Accounts and Prohibited Activities, includes Regulation S-P – Privacy of Consumer Financial Information and Safeguarding Personal Information. Candidates should check the current outline before the examination.
Common Misunderstandings
Every person whose information a firm holds is a customer. A customer is a consumer who has a customer relationship with the firm, and a consumer is an individual who obtains or has obtained a financial product or service from the firm that is to be used primarily for personal, family, or household purposes, or that individual's legal representative.
A privacy notice is given only when the account is opened. An individual who becomes a customer must receive the initial notice not later than when the firm establishes a customer relationship, and a customer must receive a notice not less than annually during the continuation of the customer relationship, which means at least once in any period of twelve consecutive months during which that relationship exists.
An annual notice is always required. A firm is not required to deliver an annual privacy notice if it provides nonpublic personal information to nonaffiliated third parties only in accordance with Section 248.13, Section 248.14, or Section 248.15 and has not changed its policies and practices with regard to disclosing nonpublic personal information from those disclosed in the most recent privacy notice.
A consumer can opt out only at account opening. A consumer may exercise the right to opt out at any time.
An opt out lasts for thirty days. A reasonable opportunity to opt out is measured within thirty days after the date the notices were mailed, and a consumer's direction to opt out is effective until the consumer revokes it in writing or, if the consumer agrees, electronically.
The opt out right applies to every disclosure. The opt out requirements in Sections 248.7 and 248.10 do not apply when a firm provides nonpublic personal information to a nonaffiliated third party to perform services for it or functions on its behalf, if the conditions of Section 248.13 are met, and the requirements for the opt out do not apply to disclosures described in Section 248.14(a).
Regulation S-P covers only privacy notices. The rule also requires written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information, an incident response program, service provider oversight, and proper disposal of consumer information and customer information.
Every security incident requires notice to all customers. A covered institution must notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, unless it has determined, after a reasonable investigation of the facts and circumstances of the incident, that sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience.
The notice deadline is seventy-two hours. A covered institution must provide the notice as soon as practicable, but not later than thirty days, after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred, and the seventy-two hours applies to a service provider's notification to the covered institution after becoming aware of a breach in security.
Using a service provider transfers the notification duty. The obligation to ensure that affected individuals are notified rests with the covered institution.
The safeguards rule covers only a firm's own customers. Customer information includes records containing nonpublic personal information about the customers of other financial institutions where the information has been provided to the covered institution.
Key Points to Retain
Regulation S-P governs the treatment of nonpublic personal information about consumers by brokers, dealers, investment companies, and investment advisers registered with the SEC, and requires written safeguards for customer information.
A consumer is an individual who obtains a financial product or service primarily for personal, family, or household purposes, and a customer is a consumer who has a customer relationship with the firm.
An individual who becomes a customer receives a clear and conspicuous initial privacy notice not later than when the customer relationship is established, and customers receive a notice not less than annually, subject to the exception in Section 248.5(e).
A firm may not disclose nonpublic personal information about a consumer to a nonaffiliated third party unless it has provided the initial notice and the opt out notice, has given the consumer a reasonable opportunity to opt out, and the consumer does not opt out, except as otherwise authorized.
A consumer may exercise the right to opt out at any time, and the direction is effective until the consumer revokes it in writing or, if the consumer agrees, electronically.
Every covered institution must have written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information.
The incident response program is reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including customer notification procedures.
Notice to affected individuals is due as soon as practicable, but not later than thirty days, after the covered institution becomes aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred.
Oversight of service providers is the covered institution's responsibility, and a service provider must notify the covered institution as soon as possible, but no later than seventy-two hours after becoming aware of a breach in security.

