SEC Adopts Rule Amendments to Regulation S-P to Enhance Protection of Customer Information
The SEC has adopted amendments to Regulation S-P to modernize data privacy protections and mandate breach notifications for covered financial institutions.
The SEC's amendments to Regulation S-P require broker-dealers, investment companies, and advisers to implement formal incident response programs. Covered institutions must now provide notice to affected individuals within 30 days of discovering unauthorized access to sensitive information. While no specific fraud charges or dollar amounts are cited, the rule establishes strict timelines for compliance based on entity size.
The Securities and Exchange Commission has announced amendments to Regulation S-P to modernize the protection of nonpublic personal information held by financial institutions. These updates target broker-dealers, investment companies, registered investment advisers, and transfer agents to address modern cybersecurity risks. Under the new rules, covered institutions must maintain written policies for incident response programs designed to detect and recover from unauthorized data access. A key requirement is the mandatory notification of affected individuals within 30 days of a breach discovery. The notification must include specific details regarding the incident and steps for consumer protection. Compliance timelines are staggered, with larger entities having 18 months and smaller entities having 24 months to comply following publication in the Federal Register.
Exhibits & Attached Documents (1)
Extracted insights
- person larger entities
- agency sec chair gary gensler
- agency Securities and Exchange Commission
- person smaller entities
- Securities And Exchange Commission announced adoption amendments to Regulation S-P
- Amendments update requirements broker-dealers, investment companies, registered investment advisers, and transfer agents
- Sec Chair Gary Gensler said Over the last 24 years, the nature, scale, and impact of data breaches has transformed substantially
- Amendments require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program
- Amendments require response program to include procedures for covered institutions to provide notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed or used without authorization
- Amendments require covered institution to provide notice as soon as practicable, but not later than 30 days after becoming aware of an incident involving unauthorized access to customer information
- Amendments will become effective 60 days after publication in the Federal Register
- Larger Entities will have 18 months after the date of publication in the Federal Register to comply with the amendments
- Smaller Entities will have 24 months after the date of publication in the Federal Register to comply with the amendments
The Securities and Exchange Commission today announced the adoption of amendments to Regulation S-P to modernize and enhance the rules that govern the treatment of consumers’ nonpublic personal information by certain financial institutions. The amendments update the rules’ requirements for broker-dealers (including funding portals), investment companies, registered investment advisers, and transfer agents (collectively, “covered institutions”) to address the expanded use of technology and corresponding risks that have emerged since the Commission originally adopted Regulation S-P in 2000. “Over the last 24 years, the nature, scale, and impact of data breaches has transformed substantially,” said SEC Chair Gary Gensler. “These amendments to Regulation S-P will make critical updates to a rule first adopted in 2000 and help protect the privacy of customers’ financial data. The basic idea for covered firms is if you’ve got a breach, then you’ve got to notify. That’s good for investors.” The amendments require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program that is reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The amendments also require that the response program include procedures for, with certain limited exceptions, covered institutions to provide notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed or used without authorization. The amendments require a covered institution to provide notice as soon as practicable, but not later than 30 days, after becoming aware that an incident involving unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The notice must include details about the incident, the breached data, and how affected individuals can respond to the breach to protect themselves. The amendments will become effective 60 days after publication in the Federal Register. Larger entities will have 18 months after the date of publication in the Federal Register to comply with the amendments, and smaller entities will have 24 months after the date of publication in the Federal Register to comply.
The Securities and Exchange Commission today announced the adoption of amendments to Regulation S-P to modernize and enhance the rules that govern the treatment of consumers’ nonpublic personal information by certain financial institutions. The amendments update the rules’ requirements for broker-dealers (including funding portals), investment companies, registered investment advisers, and transfer agents (collectively, “covered institutions”) to address the expanded use of technology and corresponding risks that have emerged since the Commission originally adopted Regulation S-P in 2000. “Over the last 24 years, the nature, scale, and impact of data breaches has transformed substantially,” said SEC Chair Gary Gensler. “These amendments to Regulation S-P will make critical updates to a rule first adopted in 2000 and help protect the privacy of customers’ financial data. The basic idea for covered firms is if you’ve got a breach, then you’ve got to notify. That’s good for investors.” The amendments require covered institutions to develop, implement, and maintain written policies and procedures for an incident response program that is reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The amendments also require that the response program include procedures for, with certain limited exceptions, covered institutions to provide notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed or used without authorization. The amendments require a covered institution to provide notice as soon as practicable, but not later than 30 days, after becoming aware that an incident involving unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The notice must include details about the incident, the breached data, and how affected individuals can respond to the breach to protect themselves. The amendments will become effective 60 days after publication in the Federal Register. Larger entities will have 18 months after the date of publication in the Federal Register to comply with the amendments, and smaller entities will have 24 months after the date of publication in the Federal Register to comply.