Quick Answer
Firms must give clients an initial privacy notice at account opening and an annual notice thereafter, describing how nonpublic personal information (NPI) is collected and shared, plus a clear opt-out right before sharing with nonaffiliated third parties. State-registered advisers also owe NASAA's separate cybersecurity-policy and annual privacy-policy duties, which have no exception.
Advisers and broker-dealers handle sensitive client data. Two overlapping regimes govern that data: the SEC's Regulation S-P for federally regulated firms, and NASAA's model rule for state-registered investment advisers.
Who Has to Comply?
| Regime | Covered Firms |
|---|---|
| SEC Regulation S-P | SEC-registered broker-dealers, SEC-registered investment advisers, registered investment companies (mutual funds) |
| NASAA IA Information Security and Privacy Rule | Investment advisers registered, or required to be registered, with the state |
What Must the Privacy Notices Say, and When?
| Notice Type | When Required | Content |
|---|---|---|
| Initial privacy notice | At the beginning of the customer relationship (account opening) | How nonpublic personal information (NPI) is collected, used, and shared |
| Annual privacy notice | Annually thereafter | Same content as the initial notice; reminder of opt-out rights |
| Opt-out notice | Before sharing NPI with nonaffiliated third parties | Clear description of the right to opt out and how to exercise it |
Exam Tip: Gotchas
Regulation S-P has a narrow annual-notice exception; the NASAA rule does not. A federally covered firm can skip the annual notice if it (1) shares NPI with nonaffiliated third parties only when an exception applies, and (2) has not changed its privacy policies since the last notice. A state-registered adviser has no comparable out: it delivers a privacy policy at engagement and every year after, full stop.
What Counts as Nonpublic Personal Information?
NPI is personally identifiable financial information the firm obtains from the consumer, from a transaction, or through providing financial services. Examples include Social Security numbers, account balances, transaction history, income, and tax returns.
NPI does not include publicly available information, such as information in public court records or a publicly listed phone number.
When Can a Firm Share NPI Without an Opt-Out?
Consumers get a reasonable opportunity to opt out, through a clear and conspicuous method (mail-in form, phone number, website), before a firm shares their NPI with nonaffiliated third parties. Certain sharing needs no opt-out at all:
- sharing with service providers that need the data to process transactions (for example, a clearing firm);
- sharing required by law (subpoenas, regulatory inquiries);
- sharing for fraud prevention;
- sharing with affiliates (related companies under common control).
What Safeguards Must a Firm Maintain?
Broker-dealers and advisers must adopt written policies and procedures reasonably designed to:
- ensure the security and confidentiality of customer records and information;
- protect against anticipated threats to the security or integrity of those records;
- protect against unauthorized access that could cause substantial harm or inconvenience to a customer.
Firms must designate a person responsible for information security. The safeguards must also include an incident response program: a plan to detect, respond to, and recover from unauthorized access to customer information, including timely notification to affected individuals.
What Does NASAA's State-Level Rule Add for Investment Advisers?
State-registered advisers, and advisers required to be state-registered, have a distinct set of duties under NASAA's Investment Adviser Information Security and Privacy Rule (2019):
- Establish, implement, update, and enforce written physical-security and cybersecurity policies, tailored to the adviser's business model, size, services, and number of locations.
- The policies must protect against anticipated threats, safeguard confidential client information, and protect information whose release could harm or inconvenience a client.
- The policies must cover five required functions: Identify, Protect, Detect, Respond, and Recover.
- Review the policies at least annually and modify them as needed.
- Deliver a privacy policy to each client upon initial engagement and annually thereafter.
- If the privacy policy becomes inaccurate, promptly update and deliver an amended version.
A separate NASAA IA recordkeeping duty requires current copies of these policies, evidence of the annual review, records of any violation and its remediation, and a backup copy kept separate from the adviser's primary systems.
Exam Tip: Gotchas
Memorize the five functions in order: Identify, Protect, Detect, Respond, Recover. The exam may test the list itself or ask which function covers a given scenario (for example, restoring service after a breach is Recover, not Respond).
What Should You Check on Exam Day?
- Match the regime to the registrant: Regulation S-P for SEC-registered firms and registered funds; the NASAA rule for state-registered advisers.
- Remember Regulation S-P's annual-notice exception requires both conditions (exception-only sharing and no policy changes); the NASAA rule has no equivalent exception.
- Confirm NPI's scope: financial information tied to the consumer or the relationship, not information that is already public.
- List the four no-opt-out sharing categories: service providers, legal compulsion, fraud prevention, affiliates.
- Keep the NASAA adviser duties straight: written cybersecurity policies covering five functions, reviewed annually, plus a privacy policy delivered at engagement and annually, with prompt updates when it becomes inaccurate.