Cybersecurity, Privacy, and Data Protection

Quick Answer

Regulation S-P requires advisers to give clients a privacy notice and an opt-out (not opt-in) right before sharing nonpublic personal information with nonaffiliated third parties, backed by written safeguards policies. Separately, advisers must maintain written cybersecurity policies covering unauthorized access, breach response, and timely notice to affected individuals.


What Does SEC Regulation S-P Require for Privacy?

Regulation S-P is the SEC's primary privacy rule for financial institutions, based on the Gramm-Leach-Bliley Act (GLBA). It applies to broker-dealers, investment advisers, and investment companies.

Privacy Notice Requirements

  • Requires advisers to provide a privacy notice to clients describing what nonpublic personal information is collected and how it is shared
  • Clients must be given the opportunity to opt out of sharing information with nonaffiliated third parties
  • Advisers must adopt written policies and procedures (safeguards rule) to protect customer records and information from unauthorized access or use

Exam Tip: Gotchas

  • Regulation S-P requires an opt-out mechanism, not opt-in. Clients must be told how their information may be shared and given a reasonable opportunity to prevent sharing with nonaffiliated third parties. Sharing with affiliates generally does not require opt-out.

What Are the Cybersecurity Obligations?

  • Advisers must adopt and implement written information security policies
  • Must address risks of unauthorized access, data breaches, and cyber threats
  • Must have incident response procedures for data breaches
  • Must provide notice to affected individuals as soon as practicable, and not later than 30 days after becoming aware that unauthorized access to or use of their sensitive customer information has occurred or is reasonably likely to have occurred (as amended in 2024)

What Should You Check on Exam Day?

  • Regulation S-P is based on the Gramm-Leach-Bliley Act (GLBA) and applies to broker-dealers, investment advisers, and investment companies
  • Clients must receive a privacy notice describing what nonpublic personal information is collected and how it is shared
  • The mechanism is opt-out, not opt-in: clients must be given a reasonable opportunity to prevent sharing with nonaffiliated third parties
  • Sharing with affiliates generally does not require an opt-out
  • Advisers must adopt written safeguards policies to protect customer records from unauthorized access or use
  • Written cybersecurity policies must address unauthorized access, data breaches, and cyber threats, with incident response procedures
  • Affected individuals must receive notice as soon as practicable and not later than 30 days after the adviser becomes aware of a breach