What Is SEC Regulation S-P and Who Must Comply?

SEC Regulation S-P is the Securities and Exchange Commission’s rule, codified at 17 CFR Part 248, governing how SEC-registered financial firms collect, protect, share, and dispose of customer information. It requires covered firms to give customers privacy notices, offer opt-out rights before sharing certain data with outside parties, safeguard records against unauthorized access, and — under 2024 amendments taking effect in late 2025 and mid-2026 — maintain a written incident response program and notify affected individuals of data breaches within 30 days.1Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information

Who Has to Comply

The rule applies to brokers, dealers, investment companies (including mutual funds and unit investment trusts), and investment advisers registered with the SEC. It also reaches foreign brokers, dealers, and advisers that hold SEC registration.2eCFR. 17 CFR Part 248 – Regulations S-P, S-AM, and S-ID Firm size and location do not change the analysis. A two-person advisory practice faces the same core obligations as a global brokerage.

The 2024 amendments extended the Safeguards Rule and Disposal Rule to registered transfer agents, whether registered with the SEC or another appropriate regulatory agency. Larger entities had 18 months from the June 3, 2024 publication date to come into compliance, putting their deadline in roughly December 2025. Smaller entities received 24 months, pushing their deadline to roughly June 2026.3Federal Register. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information

What the Rule Protects

Regulation S-P protects “nonpublic personal information,” or NPI. That covers personally identifiable financial information a consumer gives a firm to obtain a financial product or service, and information generated through transactions afterward. Social Security numbers, account balances, payment histories, credit card purchases, and loan application details all qualify.4eCFR. 17 CFR Part 248 Subpart A – Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Personal Information

Purely public information, such as government real estate records or listed phone numbers, sits outside NPI on its own. But once a firm combines public data with protected NPI in a way that reveals private details about an individual, the combined information takes on NPI protection.4eCFR. 17 CFR Part 248 Subpart A – Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Personal Information Customer data does not lose its protected status just because pieces of it happen to be public elsewhere.

Privacy Notices and Opt-Out Rights

Every covered firm must give customers a clear, conspicuous privacy notice describing how it collects, uses, and shares their information. The initial notice goes out no later than when the customer relationship begins. For a brokerage, that usually means when the customer opens an account or executes a first trade. An annual notice follows for each year the relationship stays active.4eCFR. 17 CFR Part 248 Subpart A – Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Personal Information

The notice must describe the categories of information collected, identify the types of affiliates and non-affiliated third parties that receive it, and explain what the firm discloses about former customers.4eCFR. 17 CFR Part 248 Subpart A – Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Personal Information It has to be in writing, or, with customer consent, delivered electronically. Firms whose customers transact online can post the notice on the website, provided it stays continuously available in a clear and conspicuous location. A phone call alone does not satisfy the requirement.

Customers can also stop a firm from sharing their NPI with non-affiliated third parties. The firm must explain this opt-out right and offer a reasonable way to exercise it, such as a toll-free number, a check-off box, or an electronic mechanism. Requiring customers to mail in a written letter as the only option is not permitted.5eCFR. 17 CFR 248.7 – Form of Opt Out Notice to Consumers

The opt-out does not reach every situation. Firms can share NPI without offering an opt-out when doing so is necessary to process a transaction the consumer initiated, or when sharing with a service provider performing functions on the firm’s behalf. That service provider exception depends on a contractual agreement that limits the third party to using the information only for the service it was hired to perform.6eCFR. 17 CFR 248.13 – Exception to Opt Out Requirements for Service Providers and Joint Marketing

One boundary worth flagging: the opt-out applies only to sharing with non-affiliated third parties. Regulation S-P does not let consumers block information sharing among affiliates in the same corporate family. Affiliate marketing sits under a separate rule, Regulation S-AM, also in 17 CFR Part 248.

Safeguards and Disposal

Every covered institution must adopt written policies and procedures reasonably designed to protect customer information against foreseeable threats and unauthorized access.7eCFR. 17 CFR 248.30 – Procedures to Safeguard Customer Records and Information The rule does not dictate a fixed security program. Firms build their safeguards around the nature of their business, the sensitivity of the data they hold, and the risks they actually face. The 2024 amendments added a requirement to review and update those procedures periodically rather than treating the initial plan as final.1Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information

When consumer report information is no longer needed, disposal has to prevent recovery. Paper records get shredded, burned, or pulverized. Electronic media must be wiped with specialized software or physically destroyed so the data cannot be read.7eCFR. 17 CFR 248.30 – Procedures to Safeguard Customer Records and Information Deleting a file or dropping documents into a dumpster does not meet the standard.

Incident Response and Breach Notification

The 2024 amendments added a requirement the original regulation did not contain. Every covered institution must now develop, implement, and maintain a written incident response program designed to detect, respond to, and recover from unauthorized access to customer information.1Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information The written procedures have to cover three areas:

  • Assessment of the nature and scope of any incident, which systems were compromised, and what customer information may have been reached.
  • Containment steps that stop the breach from spreading and prevent further unauthorized access.
  • Notification to affected individuals whose sensitive customer information was, or is reasonably likely to have been, accessed without authorization.

Notification must go out as soon as practicable, and no later than 30 days after the firm becomes aware that unauthorized access has occurred or is reasonably likely to have occurred.1Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information The clock starts at awareness, not at confirmation. If the firm cannot pinpoint which individuals were affected, it must notify everyone whose information sat in the compromised system.

There is one carve-out. If, after a reasonable investigation, the firm concludes that the compromised information has not been and is not reasonably likely to be used in a way that would cause substantial harm or inconvenience, notification is not required.1Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information Reaching that conclusion takes evidence.

Oversight of Service Providers

The 2024 amendments also formalized third-party oversight. Every covered institution must establish and enforce written policies for conducting due diligence on service providers and monitoring them. A service provider is any person or entity that receives, maintains, processes, or otherwise accesses customer information through services it provides directly to the firm, and the definition includes the firm’s own affiliates.1Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information

The policies must be reasonably designed to ensure that service providers protect customer information against unauthorized access and notify the firm within 72 hours of becoming aware of a breach affecting a customer information system they maintain.1Securities and Exchange Commission. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information Once that 72-hour notice arrives, the firm has to activate its own incident response program immediately.

A firm can enter a written agreement delegating the customer notification task to the service provider, but the firm keeps ultimate responsibility for making sure affected individuals hear about the breach on time.3Federal Register. Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information Delegating the task does not delegate the liability.

Enforcement

The SEC enforces Regulation S-P against the entities it oversees using the authority available under the Securities Exchange Act of 1934. Its toolkit includes administrative proceedings, cease-and-desist orders, civil monetary penalties, and, in serious cases, industry bars for responsible individuals. Penalties scale with severity. A minor paperwork lapse draws a different response than a systemic failure to protect customer data.

The 2024 amendments raised the stakes by creating clear, verifiable compliance benchmarks. A firm that suffers a breach and misses the 30-day notification window now faces a specific, documented violation rather than a general safeguard deficiency. For smaller firms working toward the June 2026 deadline, that shift is the reason to build or overhaul the required programs well before the calendar runs out.