Quick Answer
Regulation S-P covers SEC-registered advisers: a privacy notice, an opt-out (not opt-in) before sharing information with nonaffiliated third parties, written safeguards, and breach notice within 30 days. Customers also get an annual notice unless the FAST Act exception applies. State-registered advisers instead follow the NASAA rule, which requires written five-function security policies and an annual privacy policy with no exception.
What Does SEC Regulation S-P Require for Privacy?
Regulation S-P is the SEC's primary privacy rule for financial institutions, based on the Gramm-Leach-Bliley Act (GLBA). By its own terms, it reaches brokers, dealers, and investment companies, plus investment advisers that are registered with the SEC.
A state-registered adviser is outside Regulation S-P, but that does not leave it without privacy and cybersecurity duties. State-registered advisers answer to the NASAA Investment Adviser Information Security and Privacy Rule instead, covered below. Two regimes, not one regime and a gap.
Which Privacy Notices Must a Firm Provide?
- Requires advisers to provide a privacy notice to clients describing what nonpublic personal information is collected and how it is shared
- The initial notice is due at or before the firm establishes the relationship
- Clients must be given the opportunity to opt out of sharing information with nonaffiliated third parties
- Advisers must adopt written policies and procedures (safeguards rule) to protect customer records and information from unauthorized access or use
Consumer or Customer: Who Gets Which Notice?
Regulation S-P sorts individuals into two categories, and the category determines which notices they are owed.
| Consumer | Customer | |
|---|---|---|
| Relationship | A one-time transaction with no ongoing relationship, such as a walk-in who buys securities as an accommodation | A continuing relationship, such as a brokerage account, an advisory contract, or a custodied IRA |
| Notice owed | An initial notice, and only if the firm discloses information to a nonaffiliated third party outside an exception | An initial notice and an annual notice for as long as the relationship continues |
A prospective client who meets with an adviser once for a single financial plan and never opens an account is a consumer. A client with an ongoing advisory contract is a customer.
When Is the Annual Notice Not Required?
The FAST Act created an exception that lets a firm skip the annual notice entirely. A firm qualifies if it meets both conditions:
- It does not share nonpublic personal information with nonaffiliated third parties outside the exceptions described below, and
- It has not changed its privacy policies or practices since the last notice it sent
If either condition stops being true, the annual notice obligation comes back.
Exam Tip: Gotchas
- Regulation S-P requires an opt-out mechanism, not opt-in. Clients must be told how their information may be shared and given a reasonable opportunity to prevent sharing with nonaffiliated third parties. Sharing with affiliates generally does not require opt-out.
- The FAST Act exception excuses the annual notice only. Every customer still gets an initial notice, and every consumer whose information is disclosed outside an exception still gets a notice before that disclosure.
What Other Disclosures Do Not Require an Opt-Out?
Beyond the affiliate exemption, three more situations let a firm disclose nonpublic personal information without honoring, or even offering, an opt-out:
- Service providers and joint marketing. A firm may share information with a nonaffiliated third party that performs services on the firm's behalf, such as a clearing firm processing transactions, as long as the firm gives the initial notice and has a written contract limiting the third party's use of the information.
- Processing and servicing the transaction the client asked for. Sharing that is necessary to effect, administer, or enforce a transaction the client requested or authorized does not require opt-out.
- Legal process. Complying with a properly authorized subpoena, court order, or other legal process, or cooperating with a regulatory or law enforcement investigation, does not require opt-out. A client's existing opt-out election does not stop a firm from responding to a valid subpoena.
What Makes an Opt-Out Method Reasonable?
- Reasonable methods: a reply form included with the notice, a toll-free telephone number, or an electronic opt-out process if the client has agreed to electronic delivery
- Not reasonable: requiring the client to write and mail their own letter
- When a firm mails the privacy and opt-out notices, giving the client 30 days from the mailing date to respond counts as a reasonable opportunity to opt out
What Counts as Nonpublic Personal Information?
Nonpublic personal information (NPI) is personally identifiable financial information a firm collects about a client, unless that information is otherwise publicly available. Examples include:
- Account balances, payment history, and transaction information
- The fact that a person is or has been a client of the firm
- Information collected through an internet cookie on the firm's website
Sensitive customer information is a narrower subset of NPI: information whose compromise could create a reasonably likely risk of substantial harm, such as a Social Security number, a government-issued identification number, biometric data, or account-access credentials. Only a breach involving sensitive customer information triggers the breach-notification duty below; a broader NPI exposure does not by itself.
What Are the Cybersecurity Obligations?
- Advisers must adopt and implement written information security policies addressing administrative, technical, and physical safeguards
- Must address risks of unauthorized access, data breaches, and cyber threats
- Must have incident response procedures for data breaches
- Must provide notice to affected individuals as soon as practicable, and not later than 30 days after becoming aware that unauthorized access to or use of their sensitive customer information has occurred or is reasonably likely to have occurred (as amended in 2024)
When Can a Firm Skip Individual Breach Notice?
A firm does not have to notify affected individuals if, after a reasonable investigation, it determines the sensitive customer information was not, and is not reasonably likely to be, used in a way that would cause substantial harm or inconvenience. This is an exception, not a delay: if the investigation clears the incident, no individual notice is required at all.
How Must the Notice Be Delivered, and What Must It Say?
- The notice must go out by a method designed so the affected individual can reasonably be expected to receive actual written notice, such as a mailed letter. A general website posting or a customary marketing channel is not enough.
- The notice must describe the incident in general terms, give the date or date range of the incident if reasonably known, and provide contact information the individual can use to ask questions.
- The notice does not need to identify the intruder or their motive.
What Does the Disposal Rule Require?
- Firms must take reasonable measures to protect consumer and customer information against unauthorized access or use when they dispose of it, whether the records are on paper or on electronic media
- Disposal includes discarding paper records, and also selling, donating, or transferring any equipment, such as retired servers, on which the information is stored
- Handing old hardware to a recycler or reseller without protecting the data on it is still a disposal event, even if the recycler pays for the equipment
What Does a State-Registered Adviser Have to Do?
Series 65 is largely a state-adviser exam, so this is the regime most questions are really asking about. The NASAA Investment Adviser Information Security and Privacy Rule applies to every adviser registered or required to be registered at the state level.
Security side. The adviser must establish, implement, update, and enforce written physical security and cybersecurity policies and procedures, tailored to the firm's size, services, and number of locations. They must cover at least five functions:
| Function | What it means |
|---|---|
| Identify | Understand the information security risk to systems, assets, data, and capabilities |
| Protect | Implement safeguards that keep critical services running |
| Detect | Implement activities that spot an information security event when it happens |
| Respond | Implement activities that take action on a detected event |
| Recover | Maintain resilience plans and restore capabilities impaired by an event |
The adviser must review these policies at least annually and modify them as needed.
Privacy side. The adviser must deliver a privacy policy to each client upon engagement and annually thereafter, and must promptly update and redeliver it if anything in it becomes inaccurate.
Exam Tip: Gotchas
- The FAST Act annual-notice exception is a Regulation S-P feature and does not carry over. A state-registered adviser owes the annual privacy policy every year, with no equivalent way to switch it off. If a stem gives you a state-registered adviser that shares nothing with nonaffiliated third parties and has not changed its practices, it still owes the annual delivery.
- "Not covered by Regulation S-P" is not "has no privacy duty." A state-registered adviser out of scope for Regulation S-P is squarely inside the NASAA rule. An answer choice saying a state-registered adviser has no written cybersecurity or privacy obligation is wrong.
- The five functions are Identify, Protect, Detect, Respond, Recover, in that order.
What Should You Check on Exam Day?
- Regulation S-P is based on the Gramm-Leach-Bliley Act (GLBA) and applies to broker-dealers, investment companies, and SEC-registered investment advisers
- A consumer (one-time transaction) gets an initial notice only; a customer (ongoing relationship) gets an initial notice and an annual notice, unless the FAST Act exception applies
- Clients must receive a privacy notice describing what nonpublic personal information is collected and how it is shared, delivered at or before the relationship is established
- The mechanism is opt-out, not opt-in: clients must be given a reasonable opportunity to prevent sharing with nonaffiliated third parties
- Sharing with affiliates, with service providers under a written contract, to complete a client-requested transaction, or in response to a valid subpoena does not require opt-out
- A reply form, a toll-free number, or agreed-upon electronic delivery are reasonable opt-out methods; requiring the client to write and mail a letter is not
- Advisers must adopt written safeguards policies addressing administrative, technical, and physical protections for customer records
- The Disposal Rule requires reasonable measures to protect information, on paper or electronic media, when it is discarded or the storage equipment is sold or transferred
- Written cybersecurity policies must address unauthorized access, data breaches, and cyber threats, with incident response procedures
- Affected individuals must receive notice as soon as practicable and not later than 30 days after the adviser becomes aware of a breach involving sensitive customer information, unless a reasonable investigation clears the incident
- A state-registered adviser is outside Regulation S-P but inside the NASAA Investment Adviser Information Security and Privacy Rule: written security policies covering Identify, Protect, Detect, Respond, Recover, reviewed at least annually
- That adviser must deliver a privacy policy upon engagement and annually thereafter, updated and redelivered promptly if it becomes inaccurate; there is no FAST Act-style exception at the state level