Achievable logoAchievable logo
Series 6
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Resources
Exam catalog
Mountain with a flag at the peak
Textbook
Introduction
1. Common stock
2. Preferred stock
3. Debt securities
4. Corporate debt
5. Municipal debt
6. US government debt
7. Investment companies
8. Insurance products
9. The primary market
10. The secondary market
11. Brokerage accounts
12. Retirement & education plans
13. Rules & ethics
13.1 The regulators
13.2 Public communications
13.3 Social media
13.4 Regulation BI
13.5 Registered representative rules
13.6 Regulation S-P
13.7 Protecting vulnerable investors
13.8 Restitution & penalties
13.9 Recordkeeping requirements
14. Suitability
Wrapping up
Achievable logoAchievable logo
13.6 Regulation S-P
Achievable Series 6
13. Rules & ethics

Regulation S-P

3 min read
Font
Discuss
Share
Feedback

Regulation S-P focuses on protecting the personal and private information of customers of financial firms. Because firms collect and store so much information electronically, they must take specific steps to safeguard customer privacy.

Regulation S-P also clarifies what counts as private (non-public) information. Some examples are straightforward, such as Social Security numbers, suitability information, and account balances. Other sources can be less obvious - for example, data collected through internet cookies. Even when the source is less obvious, the information still must be protected.

In addition to identifying and safeguarding non-public information, Regulation S-P requires firms to disclose to customers when the firm provides non-public information to third parties. For example, a firm must tell you if it sends your non-public information to a third-party company that prints checks. To print checks, that third party needs access to account numbers and other private account information.

Firms must provide these disclosures at account opening and then annually. There is one exception: a firm is not required to deliver the annual notice if it shares non-public information with non-affiliated third parties only under exceptions that carry no opt-out right and has not changed the policies described in its most recent notice. The account-opening notice is always required. The firm must also give the customer an “opt-out” feature, which prevents the firm from disclosing private information to third parties. Opt-out methods must be easy to use; check-off boxes on letters or emails are commonly used. More burdensome requirements - such as making a customer write a lengthy letter to request the opt-out - are prohibited.

Regulation S-P’s safeguarding rules also cover data breaches. Firms must maintain a written incident response program, reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The program must extend to service providers: the firm must oversee them and require a provider to notify the firm no later than 72 hours after it learns of a breach.

If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify each affected individual as soon as practicable and no later than 30 days after becoming aware of the incident - unless a reasonable investigation shows the information is not reasonably likely to be used in a way that causes substantial harm or inconvenience.

Regulation S-P overview

  • Protects personal/private customer information at financial firms
  • Requires safeguards for electronically stored data

Non-public information

  • Includes SSNs, suitability info, account balances
  • Also covers less obvious sources (e.g., internet cookies)
  • All such data must be protected regardless of source

Disclosure to third parties

  • Firms must disclose when non-public info is shared with third parties
    • Example: check-printing vendors needing account details
  • Disclosures required at account opening and annually
    • Exception: no annual notice needed if sharing only under no-opt-out exceptions and no policy changes since last notice

Opt-out rights

  • Customers must be given easy opt-out method (e.g., check-off box)
  • Cannot impose burdensome opt-out procedures (e.g., requiring letters)

Data breach & incident response

  • Firms must maintain written incident response program
    • Designed to detect, respond to, recover from unauthorized access/use
  • Oversight of service providers required
    • Providers must notify firm within 72 hours of discovering a breach

Customer notification requirements

  • Must notify affected individuals if sensitive info accessed/used without authorization
  • Notification due as soon as practicable, no later than 30 days after firm becomes aware
  • Exception: not required if investigation shows low likelihood of substantial harm/inconvenience

Sign up for free to take 5 quiz questions on this topic

Previous
Next  | 13.7 Protecting vulnerable investors
All rights reserved ©2016 - 2026 Achievable, Inc.

Regulation S-P

Regulation S-P focuses on protecting the personal and private information of customers of financial firms. Because firms collect and store so much information electronically, they must take specific steps to safeguard customer privacy.

Regulation S-P also clarifies what counts as private (non-public) information. Some examples are straightforward, such as Social Security numbers, suitability information, and account balances. Other sources can be less obvious - for example, data collected through internet cookies. Even when the source is less obvious, the information still must be protected.

In addition to identifying and safeguarding non-public information, Regulation S-P requires firms to disclose to customers when the firm provides non-public information to third parties. For example, a firm must tell you if it sends your non-public information to a third-party company that prints checks. To print checks, that third party needs access to account numbers and other private account information.

Firms must provide these disclosures at account opening and then annually. There is one exception: a firm is not required to deliver the annual notice if it shares non-public information with non-affiliated third parties only under exceptions that carry no opt-out right and has not changed the policies described in its most recent notice. The account-opening notice is always required. The firm must also give the customer an “opt-out” feature, which prevents the firm from disclosing private information to third parties. Opt-out methods must be easy to use; check-off boxes on letters or emails are commonly used. More burdensome requirements - such as making a customer write a lengthy letter to request the opt-out - are prohibited.

Regulation S-P’s safeguarding rules also cover data breaches. Firms must maintain a written incident response program, reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The program must extend to service providers: the firm must oversee them and require a provider to notify the firm no later than 72 hours after it learns of a breach.

If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify each affected individual as soon as practicable and no later than 30 days after becoming aware of the incident - unless a reasonable investigation shows the information is not reasonably likely to be used in a way that causes substantial harm or inconvenience.

Key points

Regulation S-P overview

  • Protects personal/private customer information at financial firms
  • Requires safeguards for electronically stored data

Non-public information

  • Includes SSNs, suitability info, account balances
  • Also covers less obvious sources (e.g., internet cookies)
  • All such data must be protected regardless of source

Disclosure to third parties

  • Firms must disclose when non-public info is shared with third parties
    • Example: check-printing vendors needing account details
  • Disclosures required at account opening and annually
    • Exception: no annual notice needed if sharing only under no-opt-out exceptions and no policy changes since last notice

Opt-out rights

  • Customers must be given easy opt-out method (e.g., check-off box)
  • Cannot impose burdensome opt-out procedures (e.g., requiring letters)

Data breach & incident response

  • Firms must maintain written incident response program
    • Designed to detect, respond to, recover from unauthorized access/use
  • Oversight of service providers required
    • Providers must notify firm within 72 hours of discovering a breach

Customer notification requirements

  • Must notify affected individuals if sensitive info accessed/used without authorization
  • Notification due as soon as practicable, no later than 30 days after firm becomes aware
  • Exception: not required if investigation shows low likelihood of substantial harm/inconvenience

More from Rules & ethics

  • The regulators
  • Social media
  • Regulation BI
  • Registered representative rules
  • Protecting vulnerable investors