Nonpublic Personal Information

Quick Answer

Regulation S-P protects nonpublic personal information about consumers, meaning individuals obtaining a financial product or service for personal, family, or household purposes. A firm gives privacy notices and an opt-out opportunity before most disclosures to a nonaffiliated third party. Written safeguards carry three objectives.

Regulation S-P governs how covered financial institutions treat nonpublic personal information about consumers.


Who Does Regulation S-P Protect?

  • A consumer is an individual who obtains or has obtained a financial product or service primarily for personal, family, or household purposes.
  • A customer is a consumer who has a continuing relationship with the firm.
  • Information about companies or individuals obtaining services for business, commercial, or agricultural purposes falls outside this consumer privacy scope.
  • A vendor or associated-person relationship does not independently bring information within Regulation S-P.

Exam Tip: Gotchas

Regulation S-P protects consumer financial information, not every business relationship. Vendor or associated-person status alone does not create consumer privacy coverage.

What Counts as Nonpublic Personal Information?

Nonpublic personal information (NPI) includes personally identifiable financial information. It also includes consumer lists, descriptions, or groupings derived using personally identifiable financial information that is not publicly available.

Personally identifiable financial information includes information that:

  • A consumer provides to obtain a financial product or service.
  • Results from a transaction involving a financial product or service.
  • A firm otherwise obtains while providing a financial product or service to the consumer.

Publicly available information is generally excluded. It can still be NPI when its disclosure indicates that an individual is or was the firm's consumer. A consumer grouping can also be NPI when the firm derived it using nonpublic personally identifiable financial information. Aggregate or blind data without personal identifiers is not personally identifiable financial information.

What Duties Apply to Consumer Information?

  • Firms provide customers with notices about their privacy policies and practices.
  • Before most disclosures of NPI to a nonaffiliated third party, a firm provides the required notices and a reasonable opportunity to opt out. The consumer may opt out at any time, subject to applicable disclosure exceptions.
  • Covered institutions maintain written administrative, technical, and physical safeguards for customer information. The safeguards ensure its security and confidentiality, protect against anticipated threats or hazards to its security or integrity, and protect against unauthorized access or use that could cause substantial harm or inconvenience.

The Customer Privacy Rules and Disclosures lesson covers these duties in more detail.

Exam Tip: Gotchas

  • Safeguards have three objectives. They ensure customer information's security and confidentiality, protect against anticipated threats or hazards to its security or integrity, and protect against unauthorized access or use that could cause substantial harm or inconvenience.

What Should You Check on Exam Day?

  • Confirm that the information concerns a consumer who obtained a financial product or service for personal, family, or household purposes.
  • Identify personally identifiable financial information and consumer groupings derived from it.
  • Apply privacy notices, disclosure limits, opt-out rights, and written safeguards.
  • Confirm that the safeguards ensure customer information's security and confidentiality, protect against anticipated threats or hazards to its security or integrity, and protect against unauthorized access or use that could cause substantial harm or inconvenience.