SEC Proposes Changes to Reg S-P to Enhance Protection of Customer Information
The Securities and Exchange Commission proposed amendments to Regulation S-P to enhance customer data protection by requiring broker-dealers, investment companies, registered investment advisers, and transfer agents to notify affected individuals of data breaches within 30 days.
The proposed amendments aim to strengthen customer data protection by introducing mandatory breach notification and expanding the safeguards and disposal rules to cover a broader definition of 'customer information.' The amendments would require notice to be provided within 30 days of the institution becoming aware of an incident. No fines or penalties are involved, as this is a regulatory proposal aimed at prevention, not enforcement.
The Securities and Exchange Commission proposed amendments to Regulation S-P to enhance customer data protection by requiring broker-dealers, investment companies, registered investment advisers, and transfer agents to notify affected individuals of data breaches within 30 days. The proposal closes a regulatory gap by introducing mandatory breach notification, which was previously absent. The amendments also expand and align the safeguards and disposal rules to cover a broader definition of 'customer information,' including data received from other financial institutions. Additionally, the requirements would be extended to transfer agents registered with any appropriate regulatory agency, not just the SEC. The proposed amendments update policies to address modern technological risks since the rule's 2000 adoption. No fines or penalties are involved, as this is a regulatory proposal aimed at prevention, not enforcement. The public has 60 days after Federal Register publication to comment before finalization. The proposing release will be published in the Federal Register, marking the beginning of the public comment period.
Exhibits & Attached Documents (2)
Extracted insights
- person proposing release
- agency sec chair gary gensler
- Securities and Exchange Commission Proposed Amendments Regulation S-P
- Securities and Exchange Commission Require Notice Individuals affected by certain types of data breaches
- SEC Chair Gary Gensler Say These firms have no requirement to notify customers about breaches
- SEC Chair Gary Gensler Believe These amendments, if adopted, would help customers maintain their privacy and protect themselves
- Regulation S-P Require Broker-dealers, investment companies, and registered investment advisers to adopt written policies and procedures for the protection of customer records and information
- Regulation S-P Require Proper disposal of consumer report information
- Commission Update Rule’s requirements to address the expanded use of technology and corresponding risks
- Commission’s proposal Require Broker-dealers, investment companies, registered investment advisers, and transfer agents to adopt written policies and procedures for an incident response program
- Proposed amendments Require Covered institutions to provide notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed or used without authorization
- Proposed amendments Require Covered institution to provide this notice as soon as practicable, but not later than 30 days after the covered institution becomes aware that an incident involving unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred
- Proposed amendments Make Changes Regulation S-P, including: Broadening and aligning the scope of the safeguards rule and disposal rule to cover 'customer information,' a new defined term
- Proposed amendments Extend Safeguards rule, including the proposed enhancements, to transfer agents registered with the Commission or another appropriate regulatory agency
- Proposed amendments Expand Existing scope of the disposal rule to include transfer agents registered with another appropriate regulatory agency
- Proposed amendments Conform Regulation S-P’s existing provisions relating to the delivery of an annual privacy notice for consistency with a statutory exception created by Congress in 2015
- Proposing release Be Published In the Federal Register
- Public comment period Remain Open Until 60 days after the date of publication of the proposing release in the Federal Register
The Securities and Exchange Commission today proposed amendments to Regulation S-P that would enhance the protection of customer information by, among other things, requiring broker-dealers, investment companies, registered investment advisers, and transfer agents to provide notice to individuals affected by certain types of data breaches that may put them at risk of identity theft or other harm. “Though Regulation S-P currently requires covered firms to notify customers about how they use their financial information, these firms have no requirement to notify customers about breaches,” said SEC Chair Gary Gensler. “I think we should close this gap. Thus, under our proposal, covered firms would be required to notify customers of breaches that might put their personal financial data at risk. I believe that these amendments, if adopted, would help customers maintain their privacy and protect themselves.” Regulation S-P currently requires broker-dealers, investment companies, and registered investment advisers to adopt written policies and procedures for the protection of customer records and information (“safeguards rule”). Regulation S-P also requires the proper disposal of consumer report information (“disposal rule”). Today’s proposal, if adopted, would update the rule’s requirements to address the expanded use of technology and corresponding risks since the Commission originally adopted Regulation S-P in 2000. The Commission’s proposal would require broker-dealers, investment companies, registered investment advisers, and transfer agents (collectively, “covered institutions”) to adopt written policies and procedures for an incident response program to address unauthorized access to or use of customer information. The proposed amendments would also require, with certain limited exceptions, covered institutions to provide notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed or used without authorization. The proposal would require a covered institution to provide this notice as soon as practicable, but not later than 30 days after the covered institution becomes aware that an incident involving unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The proposed amendments would also make a number of additional changes to Regulation S-P, including: Broadening and aligning the scope of the safeguards rule and disposal rule to cover “customer information,” a new defined term. This change would extend the protections of the safeguards and disposal rules to both nonpublic personal information that a covered institution collects about its own customers and to nonpublic personal information that a covered institution receives about customers of other financial institutions; Extending the safeguards rule, including the proposed enhancements, to transfer agents registered with the Commission or another appropriate regulatory agency, and expanding the existing scope of the disposal rule to include transfer agents registered with another appropriate regulatory agency rather than only those registered with the Commission; and Conforming Regulation S-P’s existing provisions relating to the delivery of an annual privacy notice for consistency with a statutory exception created by Congress in 2015. The proposing release will be published in the Federal Register. The public comment period will remain open until 60 days after the date of publication of the proposing release in the Federal Register.
The Securities and Exchange Commission today proposed amendments to Regulation S-P that would enhance the protection of customer information by, among other things, requiring broker-dealers, investment companies, registered investment advisers, and transfer agents to provide notice to individuals affected by certain types of data breaches that may put them at risk of identity theft or other harm. “Though Regulation S-P currently requires covered firms to notify customers about how they use their financial information, these firms have no requirement to notify customers about breaches,” said SEC Chair Gary Gensler. “I think we should close this gap. Thus, under our proposal, covered firms would be required to notify customers of breaches that might put their personal financial data at risk. I believe that these amendments, if adopted, would help customers maintain their privacy and protect themselves.” Regulation S-P currently requires broker-dealers, investment companies, and registered investment advisers to adopt written policies and procedures for the protection of customer records and information (“safeguards rule”). Regulation S-P also requires the proper disposal of consumer report information (“disposal rule”). Today’s proposal, if adopted, would update the rule’s requirements to address the expanded use of technology and corresponding risks since the Commission originally adopted Regulation S-P in 2000. The Commission’s proposal would require broker-dealers, investment companies, registered investment advisers, and transfer agents (collectively, “covered institutions”) to adopt written policies and procedures for an incident response program to address unauthorized access to or use of customer information. The proposed amendments would also require, with certain limited exceptions, covered institutions to provide notice to individuals whose sensitive customer information was or is reasonably likely to have been accessed or used without authorization. The proposal would require a covered institution to provide this notice as soon as practicable, but not later than 30 days after the covered institution becomes aware that an incident involving unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The proposed amendments would also make a number of additional changes to Regulation S-P, including: Broadening and aligning the scope of the safeguards rule and disposal rule to cover “customer information,” a new defined term. This change would extend the protections of the safeguards and disposal rules to both nonpublic personal information that a covered institution collects about its own customers and to nonpublic personal information that a covered institution receives about customers of other financial institutions; Extending the safeguards rule, including the proposed enhancements, to transfer agents registered with the Commission or another appropriate regulatory agency, and expanding the existing scope of the disposal rule to include transfer agents registered with another appropriate regulatory agency rather than only those registered with the Commission; and Conforming Regulation S-P’s existing provisions relating to the delivery of an annual privacy notice for consistency with a statutory exception created by Congress in 2015. The proposing release will be published in the Federal Register. The public comment period will remain open until 60 days after the date of publication of the proposing release in the Federal Register.