Financial privacy & safeguards

SEC Regulation S-P & FINRA Safeguards

Regulation S-P requires broker-dealers and investment advisers to adopt written policies to safeguard customer records and information, with FINRA reinforcing vendor-oversight and incident-response expectations.

Official source (opens in a new tab): 17 CFR Part 248 (Reg S-P); FINRA rules

Scope

Who it applies to.

Regulation S-P’s privacy-notice and opt-out provisions apply to brokers, dealers, investment companies, and investment advisers registered with the Commission (17 CFR § 248.1(b)). The safeguards and disposal provisions reach further: § 248.30(d)(3) defines a “covered institution” as any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission or another appropriate regulatory agency. Transfer agents are therefore in scope for § 248.30 even though the subpart’s privacy-notice provisions do not list them.

The safeguards rule
Every covered institution must develop, implement, and maintain written policies and procedures addressing administrative, technical, and physical safeguards for customer information. Under § 248.30(a)(2) those policies must be reasonably designed to ensure the security and confidentiality of the information, protect against anticipated threats or hazards, and protect against unauthorized access or use that could result in substantial harm or inconvenience to any customer.
The disposal rule
Covered institutions other than notice-registered broker-dealers must properly dispose of consumer information and customer information by taking reasonable measures to protect against unauthorized access or use in connection with disposal, and must adopt written policies and procedures addressing that standard (§ 248.30(b)(1)–(2)). “Disposal” covers discarding or abandoning records and also selling, donating, or transferring any medium — including computer equipment — on which the information is stored (§ 248.30(d)(7)).
Incident-response program (2024 amendments)
The amendments the SEC adopted in May 2024 require the written policies to include a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information (§ 248.30(a)(3)). It must provide procedures to assess the nature and scope of an incident, identify the customer information systems and types of information involved, contain and control the incident, and notify affected individuals.
Customer notification within 30 days
A covered institution must provide clear and conspicuous written notice to each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization — “as soon as practicable, but not later than 30 days” after becoming aware of the incident (§ 248.30(a)(4)(iii)). Notice is not required if a reasonable investigation shows the information is not reasonably likely to be used to cause substantial harm or inconvenience.
Service-provider oversight
The response program must include written policies and procedures reasonably designed to require oversight — through due diligence and monitoring — of service providers, including to ensure they take appropriate measures to protect against unauthorized access to customer information and to notify the institution no later than 72 hours after becoming aware of a breach. The duty to ensure affected individuals are notified stays with the covered institution (§ 248.30(a)(5)).
FINRA supervision & continuity
FINRA member broker-dealers carry supervisory obligations on top of Reg S-P. Rule 3110 requires a supervisory system and written supervisory procedures reasonably designed to achieve compliance with applicable securities laws and regulations, together with internal inspections of offices. Rule 4370 requires a written business continuity plan whose enumerated elements begin with data back-up and recovery, reviewed at least annually by senior management.

The vendor & sub-processor obligation

What it puts on you.

Firms are expected to perform due diligence on, and oversee, third parties that handle customer information — so each cloud or AI service becomes another vendor to assess and monitor.

Every covered institution must develop, implement, and maintain written policies and procedures that address administrative, technical, and physical safeguards for the protection of customer information.
17 CFR § 248.30(a) (official text)

How self-hosting addresses it

Remove the third party, remove the burden.

When customer records stay on infrastructure you control, there is no third party handling that data to diligence or supervise under Reg S-P.

How FileFerret applies

The 2024 amendments sharpened § 248.30(a)(5): you owe due diligence and monitoring of every service provider permitted access to customer information. Running document search on an appliance inside your own network means that workload adds no such provider to bind and oversee. It does not by itself satisfy the safeguards, disposal, or notification duties — those remain yours. See how it’s built →

Full, current text is maintained at the official source: 17 CFR Part 248 (Reg S-P); FINRA rules.

Enforcement

Who enforces it, and how.

The SEC enforces Reg S-P through administrative proceedings and civil penalties. In September 2022 the Commission charged Morgan Stanley Smith Barney with violating the Safeguards and Disposal Rules after decommissioned hard drives and servers holding the personal information of roughly 15 million customers were resold without the data being removed; the firm paid a $35 million penalty without admitting or denying the findings. FINRA separately disciplines member firms, with sanctions ranging from fines and censure to suspension or expulsion.

Common questions

Questions firms ask.

When did the 2024 amendments actually start to bite?

The SEC adopted them on May 16, 2024. They were published in the Federal Register on June 3, 2024 and took effect August 2, 2024, but compliance was staggered by firm size: larger entities had 18 months, to December 3, 2025, and smaller entities 24 months, to June 3, 2026. Both dates have now passed, so the incident-response and notification requirements apply across the board.

Which firms counted as “larger entities” for the staggered dates?

The adopting release set thresholds: investment companies, together with others in the same group of related investment companies, with net assets of $1 billion or more as of the most recent fiscal year end; registered investment advisers with $1.5 billion or more in assets under management; and broker-dealers and transfer agents that are not small entities under the Exchange Act for Regulatory Flexibility Act purposes.

If a vendor is breached, can the vendor handle the customer notices?

Section 248.30(a)(5)(ii) lets you enter a written agreement for a service provider to notify affected individuals on your behalf, but § 248.30(a)(5)(iii) states the obligation to ensure those individuals are notified still rests with the covered institution. Your policies must also require providers to alert you no later than 72 hours after becoming aware of a breach of a customer information system they maintain.

More in Financial privacy & safeguards

Related guides.

GLBA Safeguards Rule (16 CFR 314)

The Safeguards Rule requires financial institutions — defined broadly enough to cover many accountants, tax preparers, advisers, and lenders — to maintain a written information-security program with administrative, technical, and physical safeguards for customer information.

IRS Pub. 4557 (FTC Safeguards)

IRS Publication 4557 guides tax professionals on safeguarding taxpayer data and points to the FTC Safeguards Rule as the legal baseline, including the duty to have a written security plan.

PCI DSS (service providers)

The Payment Card Industry Data Security Standard sets requirements for protecting cardholder data across everyone who stores, processes, or transmits it.

← All compliance guides

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.