Regulation S-P
Regulation S-P focuses on protecting the personal and private information of customers of financial firms. Because firms collect and store so much information electronically, they must take specific steps to safeguard customer privacy.
Regulation S-P also clarifies what counts as private (non-public) information. Some examples are straightforward, such as Social Security numbers, suitability information, and account balances. Other sources can be less obvious - for example, data collected through internet cookies. Even when the source is less obvious, the information still must be protected.
In addition to identifying and safeguarding non-public information, Regulation S-P requires firms to disclose to customers when the firm provides non-public information to third parties. For example, a firm must tell you if it sends your non-public information to a third-party company that prints checks. To print checks, that third party needs access to account numbers and other private account information.
Firms must provide these disclosures at account opening and then annually. There is one exception: a firm is not required to deliver the annual notice if it shares non-public information with non-affiliated third parties only under exceptions that carry no opt-out right and has not changed the policies described in its most recent notice. The account-opening notice is always required. The firm must also give the customer an “opt-out” feature, which prevents the firm from disclosing private information to third parties. Opt-out methods must be easy to use; check-off boxes on letters or emails are commonly used. More burdensome requirements - such as making a customer write a lengthy letter to request the opt-out - are prohibited.
Regulation S-P’s safeguarding rules also cover data breaches. Firms must maintain a written incident response program, reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The program must extend to service providers: the firm must oversee them and require a provider to notify the firm no later than 72 hours after it learns of a breach.
If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify each affected individual as soon as practicable and no later than 30 days after becoming aware of the incident - unless a reasonable investigation shows the information is not reasonably likely to be used in a way that causes substantial harm or inconvenience.