Quick Answer
Absent an exception, a firm may not disclose nonpublic personal information to a nonaffiliated third party unless it gave the initial notice, gave an opt-out notice, gave a reasonable opt-out opportunity, and the consumer has not opted out. Firms must also run a written incident-response program and, unless harm is unlikely, notify affected customers within 30 days.
When May a Firm Disclose Nonpublic Information to a Nonaffiliated Third Party?
- Absent an exception, a firm may not disclose NPI about a consumer to a nonaffiliated third party unless it has:
- Given the initial privacy notice
- Given an opt-out notice
- Given the consumer a reasonable opportunity to opt out
- Received no opt-out from the consumer
- All four conditions must be met before the disclosure; missing any one blocks it, absent an exception.
What Exceptions Let a Firm Skip Notice and Opt-Out?
| Exception | What it covers |
|---|---|
| Service providers and joint marketing | Sharing NPI with a nonaffiliated third party to perform services for the firm or on its behalf, including joint marketing, provided the firm gives the initial notice and contracts with the third party to bar it from disclosing or using the information for anything other than the purpose the firm disclosed it for. That is a purpose limit, not just a confidentiality promise |
| Processing and servicing transactions | Disclosures necessary to process or service a product or transaction the consumer requested or authorized, to maintain or service the consumer's account, or in connection with a securitization or secondary-market sale related to the consumer's transaction |
| Other exceptions | A closed list of seven, in the rule's own order: (1) disclosure with the consumer's consent or direction, where that consent has not been revoked; (2) to protect the confidentiality or security of records, or against fraud, unauthorized transactions, claims, or other liability, for institutional risk control or to resolve a consumer dispute or inquiry, to a person with a legal or beneficial interest in the account, or to a person acting in a fiduciary or representative capacity for the consumer; (3) to insurance rate advisory organizations, guaranty funds or agencies, agencies that rate the firm, compliance-assessment persons, or the firm's attorneys, accountants, and auditors; (4) to law enforcement agencies, self-regulatory organizations, or for a public-safety investigation, where other law permits or requires it; (5) to or from a consumer reporting agency; (6) in connection with a proposed or actual sale, merger, transfer, or exchange of a business or operating unit, where the disclosure concerns only that unit's consumers; and (7) to comply with law, a subpoena, a properly authorized civil, criminal, or regulatory investigation, or to respond to judicial process, or to a government regulatory authority with jurisdiction over the firm, for examination, compliance, or another purpose the law allows |
Exam Tip: Gotchas
- "Other exceptions" is not one exception; it is a closed list of seven, numbered in the rule itself. Consent, fraud protection, legal compliance, consumer reporting, and a business sale or merger are separate items on that list, not examples of one broad carve-out.
What Must a Firm's Incident-Response Program Include?
- Every firm must maintain written policies and procedures reasonably designed to safeguard customer information, including a written incident-response program.
- Those policies and procedures must be reasonably designed to meet three objectives:
- Ensure the security and confidentiality of customer information
- Protect against any anticipated threats or hazards to its security or integrity
- Protect against unauthorized access to or use of it that could result in substantial harm or inconvenience to any customer
- The response program must let the firm:
- Assess the nature and scope of an incident
- Contain and control the incident
- Notify affected customers, including customer-notification procedures
- Service providers are a fourth piece of the program. It must require oversight of them, through due diligence and monitoring.
- A service provider must notify the firm no later than 72 hours after becoming aware of a breach reaching a customer information system it maintains.
- A firm may agree in writing that a service provider will notify affected individuals for it. The duty to make sure they are notified still rests with the firm.
- If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify each affected customer as soon as practicable, and no later than 30 days after becoming aware that the unauthorized access occurred or was reasonably likely to have occurred.
- That duty is not absolute. It falls away if the firm determines, after a reasonable investigation, that the information has not been and is not reasonably likely to be used in a way that causes substantial harm or inconvenience.
- The deadline can also move. The U.S. Attorney General may determine that the notice poses a substantial risk to national security or public safety and, on written notice to the SEC, delay it for a specified period.
- When the firm cannot tell who was affected, it must notify every individual whose sensitive customer information sits in the system that was, or was reasonably likely to have been, accessed without authorization. It may leave out an individual only where it reasonably determines that person's information was not accessed or used without authorization.
- The notice must be clear and conspicuous, and sent by a means designed so that each affected individual can reasonably be expected to receive actual notice in writing.
- Disposal is a separate duty. Every covered institution other than a notice-registered broker-dealer must properly dispose of consumer and customer information, taking reasonable measures to protect against unauthorized access or use during disposal, and must adopt written policies and procedures for doing so.
Exam Tip: Gotchas
- The 30-day notification clock starts when the firm becomes aware that unauthorized access occurred or was reasonably likely to have occurred, not from the date the incident itself happened. This incident-response and notification duty was added to Regulation S-P after the original notice-and-opt-out framework, so expect current material to test the notification duty directly.
What Should You Check on Exam Day?
- Confirm all four disclosure conditions are met: initial notice, opt-out notice, reasonable opportunity to opt out, and no opt-out received.
- Treat "other exceptions" as seven distinct categories, not one blanket carve-out for anything reasonable.
- Check the incident-response program covers all three steps: assess, contain and control, and notify, plus oversight of service providers.
- Remember the 72-hour clock belongs to the service provider notifying the firm, and the 30-day clock belongs to the firm notifying affected individuals.
- Verify the notification deadline: 30 days from when the firm becomes aware, not from the incident date.