Achievable logoAchievable logo
Series 7
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Resources
Exam catalog
Mountain with a flag at the peak
Textbook
Introduction
1. Common stock
2. Preferred stock
3. Bond fundamentals
4. Corporate debt
5. Municipal debt
6. US government debt
7. Investment companies
8. Alternative pooled investments
9. Options
10. Taxes
11. The primary market
12. The secondary market
13. Brokerage accounts
14. Retirement & education plans
15. Rules & ethics
15.1 The regulators
15.2 Public communications
15.3 Social media
15.4 Regulation BI
15.5 Registered representative rules
15.6 Protecting vulnerable investors
15.7 Regulation S-P and Regulation S
15.8 Code of procedure
15.9 Recordkeeping
16. Suitability
Wrapping up
Achievable logoAchievable logo
15.7 Regulation S-P and Regulation S
Achievable Series 7
15. Rules & ethics

Regulation S-P and Regulation S

4 min read
Font
Discuss
Share
Feedback

Regulation S-P

Regulation S-P focuses on protecting the personal and private information of customers of financial firms. Because firms collect and store so much data electronically, they must take steps to safeguard customer privacy.

Regulation S-P also clarifies what counts as private (non-public) information. Some examples are straightforward, such as Social Security numbers, suitability information, and account balances. Other sources - like data collected through internet cookies - may be less obvious, but they can still be considered non-public information. The key point is that all non-public customer information must be protected appropriately.

In addition to identifying and protecting non-public information, Regulation S-P requires firms to disclose to customers when that information is shared with third parties. For example, a firm must tell a customer if it sends the customer’s non-public information to a third-party company that prints checks. To print checks, the third party needs access to account numbers and other private account information.

Firms must provide these disclosures at account opening and then annually. There is one exception: a firm is not required to deliver the annual notice if it shares non-public information with non-affiliated third parties only under exceptions that carry no opt-out right and has not changed the policies described in its most recent notice. The account-opening notice is always required. The firm must also give the customer an “opt-out” option, which prevents the firm from sharing non-public information with third parties. Opt-out methods must be easy to use. Common examples include check-off boxes on letters or emails. More burdensome requirements - such as forcing a customer to write a lengthy letter to request an opt-out - are prohibited.

Regulation S-P’s safeguarding rules also cover data breaches. Firms must maintain a written incident response program, reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The program must extend to service providers: the firm must oversee them and require a provider to notify the firm no later than 72 hours after it learns of a breach.

If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify each affected individual as soon as practicable and no later than 30 days after becoming aware of the incident - unless a reasonable investigation shows the information is not reasonably likely to be used in a way that causes substantial harm or inconvenience.

Regulation S

Regulation S provides an exemption from SEC registration for securities that are offered and sold outside the United States. Because the offering takes place offshore, the issuer does not have to register the securities under the Securities Act of 1933. The regulation is designed to keep foreign offerings separate from U.S. markets.

Regulation S also places restrictions on how quickly those securities can be resold into the United States. For debt securities, such as bonds, issued by most reporting issuers, the typical distribution compliance period is 40 days. During this period, the securities cannot be offered or sold to U.S. persons. After the compliance period has passed, resales into the U.S. may occur, subject to any applicable rules.

In general, Regulation S securities cannot be immediately sold back into U.S. markets. Depending on the issuer and the type of security, exam questions may reference resale restrictions lasting 6 to 12 months. The key idea is that Regulation S applies to offshore offerings, provides an exemption from SEC registration, and imposes resale restrictions to prevent securities from flowing directly back into US markets.

Regulation S-P

  • Protects customers’ personal/private (non-public) information at financial firms
  • Non-public info examples: SSNs, suitability data, account balances, internet cookie data
  • Must disclose to customers when info shared with third parties (e.g., check-printing vendors)
  • Disclosure timing:
    • Required at account opening (always)
    • Required annually, unless firm only shares under no-opt-out exceptions and policy unchanged
  • Must offer easy opt-out option (e.g., checkbox) — cannot be burdensome
  • Requires written incident response program for data breaches
    • Covers oversight of service providers
    • Providers must notify firm within 72 hours of breach discovery
  • Customer notification of breach: as soon as practicable, no later than 30 days after firm awareness (unless investigation shows no likely substantial harm)

Regulation S

  • Exempts securities offered/sold outside the U.S. from SEC registration under Securities Act of 1933
  • Keeps offshore offerings separate from U.S. markets
  • Resale restrictions prevent quick flow back into U.S.:
    • Debt securities from most reporting issuers: 40-day distribution compliance period
    • Other issuers/securities: restrictions may range 6–12 months
  • Core concept: offshore offering + registration exemption + resale restriction

Sign up for free to take 6 quiz questions on this topic

Previous
Next  | 15.8 Code of procedure
All rights reserved ©2016 - 2026 Achievable, Inc.

Regulation S-P and Regulation S

Regulation S-P

Regulation S-P focuses on protecting the personal and private information of customers of financial firms. Because firms collect and store so much data electronically, they must take steps to safeguard customer privacy.

Regulation S-P also clarifies what counts as private (non-public) information. Some examples are straightforward, such as Social Security numbers, suitability information, and account balances. Other sources - like data collected through internet cookies - may be less obvious, but they can still be considered non-public information. The key point is that all non-public customer information must be protected appropriately.

In addition to identifying and protecting non-public information, Regulation S-P requires firms to disclose to customers when that information is shared with third parties. For example, a firm must tell a customer if it sends the customer’s non-public information to a third-party company that prints checks. To print checks, the third party needs access to account numbers and other private account information.

Firms must provide these disclosures at account opening and then annually. There is one exception: a firm is not required to deliver the annual notice if it shares non-public information with non-affiliated third parties only under exceptions that carry no opt-out right and has not changed the policies described in its most recent notice. The account-opening notice is always required. The firm must also give the customer an “opt-out” option, which prevents the firm from sharing non-public information with third parties. Opt-out methods must be easy to use. Common examples include check-off boxes on letters or emails. More burdensome requirements - such as forcing a customer to write a lengthy letter to request an opt-out - are prohibited.

Regulation S-P’s safeguarding rules also cover data breaches. Firms must maintain a written incident response program, reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. The program must extend to service providers: the firm must oversee them and require a provider to notify the firm no later than 72 hours after it learns of a breach.

If sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify each affected individual as soon as practicable and no later than 30 days after becoming aware of the incident - unless a reasonable investigation shows the information is not reasonably likely to be used in a way that causes substantial harm or inconvenience.

Regulation S

Regulation S provides an exemption from SEC registration for securities that are offered and sold outside the United States. Because the offering takes place offshore, the issuer does not have to register the securities under the Securities Act of 1933. The regulation is designed to keep foreign offerings separate from U.S. markets.

Regulation S also places restrictions on how quickly those securities can be resold into the United States. For debt securities, such as bonds, issued by most reporting issuers, the typical distribution compliance period is 40 days. During this period, the securities cannot be offered or sold to U.S. persons. After the compliance period has passed, resales into the U.S. may occur, subject to any applicable rules.

In general, Regulation S securities cannot be immediately sold back into U.S. markets. Depending on the issuer and the type of security, exam questions may reference resale restrictions lasting 6 to 12 months. The key idea is that Regulation S applies to offshore offerings, provides an exemption from SEC registration, and imposes resale restrictions to prevent securities from flowing directly back into US markets.

Key points

Regulation S-P

  • Protects customers’ personal/private (non-public) information at financial firms
  • Non-public info examples: SSNs, suitability data, account balances, internet cookie data
  • Must disclose to customers when info shared with third parties (e.g., check-printing vendors)
  • Disclosure timing:
    • Required at account opening (always)
    • Required annually, unless firm only shares under no-opt-out exceptions and policy unchanged
  • Must offer easy opt-out option (e.g., checkbox) — cannot be burdensome
  • Requires written incident response program for data breaches
    • Covers oversight of service providers
    • Providers must notify firm within 72 hours of breach discovery
  • Customer notification of breach: as soon as practicable, no later than 30 days after firm awareness (unless investigation shows no likely substantial harm)

Regulation S

  • Exempts securities offered/sold outside the U.S. from SEC registration under Securities Act of 1933
  • Keeps offshore offerings separate from U.S. markets
  • Resale restrictions prevent quick flow back into U.S.:
    • Debt securities from most reporting issuers: 40-day distribution compliance period
    • Other issuers/securities: restrictions may range 6–12 months
  • Core concept: offshore offering + registration exemption + resale restriction

More from Rules & ethics

  • The regulators
  • Social media
  • Regulation BI
  • Registered representative rules
  • Protecting vulnerable investors