ATTORNEY ON CALL · 24/7
212 300 5196
FROM THE DEFENSE DESK / UNCATEGORIZED
2 AUG 2026 · 13 MIN READ · BY TODD A. SPODEK
THE BRIEF · FILED UNDER: UNCATEGORIZED
DOCKET NO. 909 · THE DEFENSE DESK

SEC Regulation S-P: Privacy and Data Security Enforcement.

★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
SUPER LAWYERS · 2020-25AVVO · “SUPERB”SECOND GENERATION · SINCE 1976
AS SEEN ON NETFLIX · CNN · FOX NEWS · NY POST

SEC Regulation S-P (17 C.F.R. Part 248) implements the privacy and safeguarding provisions of the Gramm-Leach-Bliley Act (GLBA) as they apply to SEC-regulated financial institutions. The GLBA, for its part, supplies a general confidentiality framework governing financial institutions’ treatment of financial records. By reason of this relationship, Regulation S-P’s specific privacy and safeguarding duties will often overlap with (and trigger simultaneous enforcement under) the GLBA’s broader statutory requirements. Importantly, however, this fact does not immunize securities firms from civil liability in the event of cybersecurity breaches. To the contrary, the two provisions are complementary. Cyber incidents are frequently considered “events” under both the GLBA and the Securities Exchange Act of 1934. Accordingly, a single incident has the potential to trigger regulatory enforcement proceedings under both Regulation S-P and the GLBA, among other statutes, and private civil litigation under both the Securities and Exchange Act and other statutes.

In practice, cybersecurity compliance scrutiny often involves examining a covered firm’s reporting structures, record-keeping practices, and internal communications policies. Regulators want to determine if covered firms’ leadership was kept informed of security-related issues, and what leadership did (or did not do) with that information. Some examples of regulators’ inquiries include:

  • Did the firm establish internal mechanisms ensuring security officers (i.e., the CISO, CRO, or other similarly-titled personnel) can regularly report on compliance efforts, issues, concerns, or proposed remedial measures to senior executives and the board of directors?
  • Did the firm establish reporting lines to help senior management and the board make informed decisions about cybersecurity policies, procedures, technology capital investments, staffing, and budgets?
  • Did the firm’s board of directors receive sufficient cybersecurity-related information to adequately oversee the firm’s cybersecurity compliance?
  • Did the firm’s board of directors receive this information on a regular basis?

Does SEC Regulation S-P apply to my securities firm?

Which Securities Firms Must Comply with Regulation S-P?

Regulation S-P’s overarching applicability depends on (i) the substance of the provision at issue, and (ii) whether the firm is registered as a broker, dealer, investment company, or investment adviser with the SEC. Specifically:

  • “Privacy Rule” Compliance: Regulation S-P’s general and amended privacy rules apply to all covered securities firms and their affiliates.
  • Safeguards and Disposal Rule Compliance: Regulation S-P’s amended safeguards and disposal rules apply to all covered securities firms. However, they also apply to transfer agents that have registered with the SEC or are registered with “another appropriate regulatory agency” and subject to Regulation S-P’s applicability with respect to “safeguarding,” “confidentiality,” and “disposal” rules.

As a general rule, Regulation S-P’s application begins with determining whether a firm is “covered.” Then, for particular provisions of the SEC Regulation S-P (i.e., the “Privacy Rule,” the “Safeguards Rule,” the “Disposal Rule,” or the “Safeguards and Disposal Rule” as amended by the SEC), firms will need to evaluate their duties under Regulation S-P in light of the relevant definitions.

What are “Consumers,” “Customers,” and “Sensitive Customer Information” under Regulation S-P?

When identifying (i) whether it must comply with (ii) a particular substantive requirement of Regulation S-P, firms will need to examine the following definitions:

  • “Consumer”: “Any individual with respect to whom the financial institution extends a financial product or service. An individual does not become a consumer when an application is filed unless the financial institution is required to disclose privacy practices to the applicant.” “A person is a consumer for purposes of the Privacy Rule only if the financial institution provides a financial product or service to that person for personal, family, or household purposes. The requirements of the Privacy Rule do not apply to financial products or services provided to entities; services provided to individual consumers exclusively for commercial purposes; or services provided solely incidental to financial transactions made by the consumers for commercial purposes.”
  • “Customer”: “A consumer who has a continuing relationship with a covered institution. (1) If an individual is a consumer . .. but is not a customer, that individual will nonetheless be deemed a customer if the individual is a consumer with respect to a financial product or service provided by the financial institution in connection with the individual’s employment, or if the individual obtained the financial product or service for personal, family, or household purposes and the individual’s consumer relationship continues with the institution . .. or in other circumstances the individual obtains a financial product or service and the financial institution maintains the relationship with the individual on an ongoing basis.)”
  • “Customer Information”: “Any nonpublic personal information about a consumer or customer that is handled by a covered institution in connection with the administration of a continuing relationship with the consumer or customer.”
  • “Sensitive Customer Information”: “Customer information that, when lost, stolen, inappropriately accessed, or inappropriately disclosed, creates a reasonably likely risk of substantial harm or inconvenience.”

When are the 2024 Amendments under Regulation S-P Applicable?

In accordance with the SEC Regulation S-P (Amendment) Order, the amended safeguards and disposal rules under Regulation S-P had the following compliance dates. For cybersecurity incidents, for instance, “larger” covered institutions had to comply by December 3, 2025; “smaller” covered institutions had to comply by June 3, 2026.

When must we investigate and notify customers after an incident?

The amended safeguards rule under Regulation S-P, codified at 17 C.F.R. Part 248, requires securities firms to implement a “security program” with particular (written) policies and procedures. The section discussing incident response (at Section 248.30(a)(3)) imposes substantive requirements as well. Specifically, covered firms must:

1. Establish Written Incident-Response Procedures

The amended safeguards rule imposes the following written incident-response obligations:

  • Develop Written Procedures: “ covered institutions will need to develop and implement written incident-response procedures that establish a program for detecting and responding to unauthorized access to customer information (i.e. cybersecurity incidents).”
  • Requirements for Detecting and Responding to Unauthorized Access: Covered institutions’ procedures for detecting and responding to cybersecurity incidents will need to:
  • (i) Establish an Incident-Response Plan: Develop “an incident-response plan that includes provisions for: (A) assessment of an incident’s nature, scope, and the specific customer information affected, (B) containment and control of any affected customer information or systems to prevent further unauthorized access, use, or disclosure, and (C) investigation, remedial, and corrective measures.”
  • (ii) Establish Incident-Response Procedures: “Develop procedures for implementing its incident-response plan that have been reasonably designed to allow it to promptly detect and respond to cybersecurity incidents.”
  • (iii) Establish Training and Review Measures: “Develop procedures for (A) training, (B) review and testing (including simulations), and (C) updating its incident-response plan and procedures.”
  • (iv) Establish a Reporting-Line Hierarchy: “Develop a reporting hierarchy that allows the covered institution to promptly communicate the nature and scope of cybersecurity incidents to senior management and the board of directors. The reporting line of covered institutions’ security officers must be sufficient to permit them to promptly convey concerns and information to the appropriate senior management and board personnel.”

2. Initiate a “Reasonable Investigation”

Regulation S-P’s amended safeguards rule imposes affirmative notice obligations upon the occurrence of a cybersecurity incident involving sensitive customer information. However, these notice obligations only apply “after a reasonable investigation find[s] that such sensitive customer information has been, or is reasonably likely to have been, accessed or used without authorization.” With this limitation in mind, notice obligations under Regulation S-P are essentially contingent upon the findings of a “reasonable investigation.” While Regulation S-P does not further elaborate on what constitute an institution’s “reasonable investigation” obligations, covered firms will need to ensure they are promptly initiating an investigation, and that they are ensuring that this investigation promptly generates reliable findings, following the occurrence of a cybersecurity incident.

3. Provide Adequate Notification

If the “reasonable investigation” triggers a covered firm’s notice obligations, the firm will then need to provide “adequate notification” under the relevant circumstances. Generally, this means that covered firms must:

  • (i) Notify Affected Individuals: If the reasonable investigation finds that, (A) “sensitive customer information,” (B) “was, or is reasonably likely to have been, accessed or used without authorization,” and (C) “is subject to the requirements of SEC Regulation S-P,” notice is due to (i) “the affected individual customer,” or, (ii) “the customer’s employer, agent, fiduciary, or other representative (if the individual’s relationship with the covered institution is based on its status as a customer of the employer, agent, fiduciary, or other representative).”
  • (ii) No Separate SEC Notification Requirement: The amended safeguards rule does not require covered firms to notify the SEC of a cybersecurity incident. Its notification obligation runs to affected individuals only, although separate reporting duties may arise under other SEC rules, SRO rules, or state breach-notification laws.
  • (iii) Provide Notice Promptly: The notice must be provided “as soon as practicable . .. but no later than 30 days after such institution becomes aware of the incident.”
  • (iv) Include All Required Information: A notice must identify: “(i) the affected customer, (ii) a general description of the customer information accessed or used without authorization, (iii) the general nature of the cybersecurity incident, (iv) the dates of the cyberattack or period of time during which the security failure occurred, (v) contact information sufficient to permit the affected customer to ask questions or obtain additional information, including a telephone number, an email address or equivalent, and a postal address, (vi) specific protective measures (if any) the affected customer can take, (vii) what the covered institution is doing to prevent a similar incident in the future, and (viii) the covered institution’s name and information regarding how the covered institution can be contacted by the affected customer.”

Todd Spodek and the attorneys at Spodek Law Group handle federal cases of this kind from New York, Brooklyn, Queens and Los Angeles.

How must we oversee vendors and dispose of customer information?

1. Oversight of Third-Party Service Providers

Under the amended safeguards rule, a covered securities firm’s data-security obligations extend to “all third parties that may have unauthorized access or access for use in violation of the applicable privacy laws and regulations,” which would include not only data processors and cloud providers, but also other vendors. The amended safeguards rule, Section 248.30(a)(5), specifically requires covered institutions to ensure that “their use of service providers does not impair the security of customer information,” by implementing controls for assessing, selecting, monitoring, and terminating service-provider relationships. For example, “service-provider controls must include due diligence to determine if the service provider can meet the covered institution’s safeguarding requirements, and due diligence to ensure the service provider continues to maintain the covered institution’s safeguarding requirements during the course of the service provider relationship.”

In addition to providing adequate monitoring and termination mechanisms, the SEC Regulation S-P’s amended safeguards rule also imposes affirmative contract requirements. Specifically, covered institutions’ contracts with service providers must require that the service provider “provide notification of any cybersecurity incident involving customer information promptly, and no later than, 72 hours after it becomes aware of the cybersecurity incident.”

Firms should also review their contracts with vendors for additional, separate cyber-incident notification obligations, which can be a key aspect of a firm’s vendor diligence and contract review process. In addition to requiring notification in the event of a cybersecurity incident, vendor diligence evaluations will also focus on assessing, and managing, any cybersecurity risks a covered firm may face as a result of its data-sharing relationship with the vendor in question.

2. Disposal of Customer Information and Consumer Report Information

Under Regulation S-P’s “disposal rule,” covered institutions must “develop and implement policies and procedures that are reasonably designed to prevent the unauthorized access to or use of customer information and consumer report information through the disposal of customer information and consumer report information.” This includes customer and consumer report information “in paper, electronic, or other form.”

Although covered institutions can contractually delegate some aspects of their disposal obligations to vendors that facilitate the disposal of customer information and consumer report information, firms that share this relationship still have residual oversight responsibility. Namely, these firms must retain sufficient oversight to ensure that the service provider is taking adequate steps to protect against unauthorized access and use of customer data and consumer report information in order to be in compliance with Regulation S-P.

What privacy notices and opt-out rights must we provide?

1. Privacy Rule Compliance

The SEC Regulation S-P (Amendment) Order imposes several privacy-related duties for complying with Regulation S-P. These duties are triggered when a covered institution collects, uses, retains, transfers, or destroys customer information. Because these duties apply throughout the lifecycle of customer information, covered institutions must:

  • (i) Disclose a Customer’s Information: In order to comply with Regulation S-P, any covered institution that collects, uses, retains, transfers, or destroys customer information must be prepared to disclose a customer’s information to a covered institution’s customer. Covered institutions must also be prepared to disclose a customer’s information to the customer’s employer or other representative where applicable.
  • (ii) Provide an Initial Privacy Notice: Generally speaking, an initial privacy notice must be provided to the customer at the time the customer relationship begins. After that, an initial privacy notice must be provided again whenever the covered institution materially changes its privacy practices.
  • (iii) Provide Annual Privacy Notices: While a customer relationship remains active, covered institutions will generally have an obligation to provide annual privacy notices. When providing an annual privacy notice, a covered institution must disclose to the customer any material changes to the firm’s privacy practices since the last annual privacy notice was provided. However, annual privacy notices are only required if (i) the covered institution is required to provide opt-out rights under Regulation S-P, and, (ii) it continues to provide those opt-out rights under Regulation S-P.
  • (iv) Provide Opt-Out Rights: Unless one of Regulation S-P’s specified exceptions applies, any covered institution that shares a consumer’s or customer’s nonpublic personal information with a nonaffiliated third party must provide the consumer or customer with (i) a notice regarding the disclosure, and (ii) an opportunity to opt out of the disclosure. This requirement applies regardless of whether the information is shared in the course of business or in response to the consumer’s or customer’s request.
  • (v) Be Prepared to Comply with the GLBA and State Privacy Laws: Even though the SEC Regulation S-P imposes several direct obligations on covered institutions, covered firms still have indirect obligations. As a general matter, the GLBA incorporates any “state or federal laws” that require a covered institution to afford consumers, customers, or consumers’ employers, agents, fiduciaries, or other representatives greater protections than those afforded by the GLBA and the SEC Regulation S-P. Accordingly, covered firms must be prepared to comply with any applicable state and federal privacy laws. This includes laws such as the California Consumer Privacy Act of 2018 (“CCPA”), which grants consumers expanded rights in certain circumstances.

1. Regulation S-P Enforcement

Although Regulation S-P contains no express private right of action, the SEC has the authority to seek enforcement under Regulation S-P, and it does so with regularity. As a general matter, the SEC investigates actual and potential violations under the SEC Regulations S-P (i.e., both the amended and pre-amended Safeguards Rule). For example, following data breaches at covered securities firms, the SEC will frequently initiate inquiries or investigations to determine whether the affected institutions had adequate safeguards in place to prevent the cybersecurity incident. While one such investigation closed without SEC enforcement action, the majority of these inquiries ultimately yield unfavorable enforcement outcomes.

In any event, the regulatory nature of the Safeguards Rule presents unique compliance risks. For example, while an entity’s potential disclosure obligations may be clear under federal securities laws, an entity subject to both regimes may owe additional customer notices under Regulation S-P, and the relevant timelines may not align. A public company, for example, may owe an investor disclosure under Form 8-K, while simultaneously owing an individual customer notice under Regulation S-P.

The SEC also scrutinizes potential violations of Regulation S-P through the examination process. SEC examiners can scrutinize covered firms’ compliance efforts under all aspects of Regulation S-P, including:

  • Written Policies and Procedures: Examiners can scrutinize covered firms’ written safeguards policies, incident-response plans, policies concerning the oversight of service providers, policies for determining when the affected customers need to be notified of a cybersecurity incident, and disposal policies and procedures.
  • Vendor Oversight Efforts: In addition to reviewing written policies and procedures, SEC examiners will also scrutinize covered firms’ efforts to monitor and oversee their service providers.
  • Disposal Practices: Along with reviewing written policies and procedures, SEC examiners will also scrutinize the adequacy of covered firms’ disposal practices.

During the examination process, SEC examiners can escalate any potential compliance issues into full-blown SEC enforcement investigations. For example, during the last three years, the SEC has issued a series of orders imposing penalties against a total of eight broker-dealers for failing to adequately implement safeguards to prevent unauthorized access to customer email accounts (with the three orders imposing a combined $750,000 in penalties in 2021).

In 2022, the SEC further underscored the potential for enforcement action under the Safeguards Rule by imposing a $35 million penalty on Morgan Stanley Smith Barney in connection with the improper disposal of data-containing devices. As the SEC observed in the order, more than 15 million of the company’s customers’ data had been compromised.

Contact a Federal Criminal Defense Attorney

Nothing here is legal advice, and the details of your case matter. Todd Spodek and Spodek Law Group take federal criminal and white collar cases nationwide, from offices in New York, Brooklyn, Queens and Los Angeles. You can reach the firm at 212-300-5196.

LEGAL INFORMATION, NOT LEGAL ADVICE · STATUTES CHANGE - VERIFY CURRENT LAW · ATTORNEY ADVERTISING
THE AUTHOR'S RECORD · PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME
Acquitted.
$26M MONEY LAUNDERING
Dismissed.
RICO · 10-YEAR MINIMUM FACED
Six months.
$12M PONZI · YEARS ASKED
ALL RESULTS →
★★★★★VERIFIED CLIENT · FEDERAL CASE · 2022 · VIA GOOGLE REVIEWS
"By the time our free consultation was over, we left at ease."
1,100+ FIVE-STAR GOOGLE REVIEWS →
RISK FREE · CONFIDENTIAL · 24/7

Reading is good. Calling is better.

Answered within 24 hours, guaranteed. Some stories are better told out loud -

212 300 5196
AFTER YOU REACH OUT
01A person answers - not a service. Day or night. 02Free, confidential consultation - ask us anything, regardless of how long it takes. 03Strategy starts the same day - and you hold the senior partner's cell number.
★★★★★1,100+ FIVE-STAR GOOGLE REVIEWS
READ THEM →
INTAKE · PRIVILEGED & CONFIDENTIAL
24/7
01
02
03
04
05
ANSWERED WITHIN 24 HOURS, GUARANTEED OR CALL 212 300 5196
EVERYTHING YOU SHARE IS PROTECTED BY ATTORNEY-CLIENT PRIVILEGE FROM THE FIRST WORD.