Cybersecurity, Privacy, and Data Protection

Quick Answer

The federal privacy rule requires written policies, an initial AND annual privacy notice, and an opt-out from sharing nonpublic personal information with non-affiliated third parties, subject to specific exceptions. The safeguards rule demands written (not verbal) protections. Cybersecurity programs should cover risk assessment, access controls, encryption, incident response, training, and vendor management. Amended Regulation S-P now sets a federal incident-response and customer-notification standard (generally within 30 days), on top of whatever a state's own breach-notification law separately requires.

With fiduciary duties and conflict rules in place, protecting client information is the next critical obligation. An adviser can follow every trading rule perfectly and still face enforcement action if client data is mishandled.


Regulation S-P (Privacy of Consumer Financial Information)

Regulation S-P implements the privacy provisions of the Gramm-Leach-Bliley Act (GLBA) for SEC-registered financial institutions.

Think of it this way: Regulation S-P is the "privacy notice" rule. Whenever a firm collects personal financial data from a client, S-P dictates what the firm must tell the client and what choices the client gets about how that data is shared.

Core requirements:

  • Written privacy policies: Must adopt and maintain written privacy policies and procedures
  • Initial privacy notice: Provide to customers at the start of the relationship
  • Annual privacy notice: Provide to customers annually
  • Opt-out right: Allow customers to opt out of sharing nonpublic personal information (NPI) with non-affiliated third parties

Exceptions to opt-out requirement: Firms may share information without providing an opt-out when:

  • Sharing with service providers under a joint marketing arrangement
  • Maintaining and servicing customer accounts
  • Protecting against fraud
  • Complying with legal and regulatory requirements

Annual-notice exception: A firm can skip the annual privacy notice for a given year if it shares nonpublic personal information only under one of the permitted exceptions above and has not changed the privacy policies and practices it previously disclosed to the customer.

Exam Tip: Gotchas

  • Regulation S-P requires BOTH initial AND annual privacy notices, unless the annual-notice exception applies: sharing only under a permitted exception, with no change to the disclosed policies. Missing the initial notice is always a violation.
  • Customers can opt out of sharing with non-affiliated third parties, but there are exceptions (fraud prevention, account servicing, joint marketing). The opt-out right is not absolute.

Safeguards Rule

The Safeguards Rule (part of Regulation S-P) requires brokers, dealers, investment companies, and registered investment advisers to:

  • Adopt written policies and procedures to protect customer records and information
  • Address administrative, technical, and physical safeguards
  • Protect against unauthorized access to or use of customer information

Exam Tip: Gotchas

  • The Safeguards Rule requires WRITTEN policies. Verbal policies are not sufficient. If an exam question describes an adviser with "informal" or "verbal" safeguards, that is a violation.

Cybersecurity Program Elements

Investment advisers and broker-dealers should maintain cybersecurity programs that address:

  • Risk assessment: Identify and evaluate cyber threats
  • Access controls: Limit who can access sensitive data
  • Data encryption: Protect data in transit and at rest
  • Incident response plans: Procedures for responding to breaches
  • Employee training: Regular cybersecurity awareness education
  • Vendor management: Ensure third-party service providers also protect client data

Data Breach Notification

  • Amended Regulation S-P now imposes a federal incident-response program requirement on broker-dealers, investment companies, and SEC-registered advisers, including a customer-notification duty
  • Notification to each affected individual is triggered when their sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization; notice is not required if a reasonable investigation determines the information hasn't been and isn't reasonably likely to be misused in a way that causes substantial harm or inconvenience
  • When notice is required, it must generally go out as soon as practicable, and no later than 30 days, after the firm becomes aware of the incident
  • This federal deadline can be delayed only on written notice from the U.S. Attorney General that notice would pose a substantial risk to national security or public safety
  • State-level requirements still exist alongside the federal rule and can impose additional or overlapping notification duties
  • NASAA guidance emphasizes that investment advisers should have clear procedures for breach detection and response

Exam Tip: Gotchas

  • There IS now a federal breach-notification standard. Don't teach this as state-law-only: amended Regulation S-P requires notice generally within 30 days of a covered incident, on top of whatever state law separately requires.

What Should You Check on Exam Day?

  • Can you name the four core Regulation S-P requirements (written policies, initial notice, annual notice, opt-out)?
  • Do you know when a firm can skip the annual privacy notice (permitted-exception sharing only, with no policy changes)?
  • Can you list the opt-out exceptions (service providers, account servicing, fraud protection, legal compliance)?
  • Do you know the safeguards rule requires written, not verbal, policies?
  • Can you name the six cybersecurity program elements (risk assessment, access controls, encryption, incident response, training, vendor management)?
  • Do you know amended Regulation S-P sets a federal ~30-day breach-notification deadline, in addition to any state-law notification duties?