Regulation S-P
Also known as: reg s-p, privacy of consumer financial information rule
Regulation S-P is the SEC rule that governs how broker-dealers, investment advisers, and investment companies protect customers' nonpublic personal information. It requires privacy notices, an opt-out before sharing data with unaffiliated third parties, and written safeguards.
Regulation S-P implements the privacy provisions of the Gramm-Leach-Bliley Act for SEC-regulated firms. It applies to nonpublic personal information — account numbers, balances, Social Security numbers, transaction histories, and anything else a customer provides that is not publicly available. Publicly available information, such as a phone number listed in a directory, falls outside the rule.
The core requirements are notice, choice, and safeguards. A firm must deliver an initial privacy notice when a customer relationship begins and an annual notice thereafter describing what information it collects and with whom it shares that information. Under a FAST Act exception, a firm that shares only within the statutory exceptions and has not changed its policies is relieved of the annual notice. Before disclosing nonpublic personal information to a nonaffiliated third party, the firm must give the customer a reasonable opportunity to opt out. Exceptions exist for disclosures necessary to service the account, process transactions, or comply with legal and regulatory requests. Separately, the safeguards rule requires written policies and procedures reasonably designed to protect customer records from unauthorized access and to dispose of consumer report information securely.
Regulation S-P also draws a line between a customer and a consumer. A consumer obtains a financial product for personal use in a one-off way and receives a notice only if the firm intends to share the data; a customer has an ongoing relationship and receives the initial and annual notices as a matter of course. Firms that share only with affiliates or only under the servicing exceptions still owe notice, but no opt-out applies.
The SEC amended Regulation S-P in 2024 and both compliance dates have now passed. Covered firms must maintain a written incident response program designed to detect, respond to, and recover from unauthorized access to customer information, extend that program to service providers, and notify affected individuals within 30 days of becoming aware that their sensitive customer information was, or likely was, accessed without authorization.
Regulation S-P shows up on the SIE, Series 6, and Series 7 exams. Expect questions on the timing of the initial and annual notices, when a customer's opt-out right is triggered, and what counts as nonpublic personal information. On the Series 7 it is often paired with Regulation S, the rule governing offshore offerings, so keep the two straight.
Key takeaways
- Regulation S-P requires firms to protect customers' nonpublic personal information and disclose their privacy practices.
- Customers receive an initial privacy notice when the relationship begins and an annual notice thereafter.
- Customers must be given an opt-out before their information is shared with nonaffiliated third parties.
- Since the SEC's 2024 amendments, firms must run a written incident response program and notify affected customers of a breach within 30 days.
- Firms must maintain written safeguards for protecting and disposing of customer records securely.
