GLBA

Regulation S-P After the 2024 Amendments: Incident Response and Customer Notice at 17 CFR 248.30

Key Takeaways

  • Section 248.30(a)(3) requires a written program to detect, respond to and recover from unauthorized access to customer information, including customer notification procedures.
  • Notice runs to affected individuals rather than to a regulator, and is due as soon as practicable and no later than 30 days after the institution becomes aware that unauthorized access occurred or is reasonably likely to have occurred.
  • Notice is excused only where the institution determines, after a reasonable investigation, that sensitive customer information has not been and is not reasonably likely to be used in a way causing substantial harm or inconvenience.
  • Service provider policies must be designed to require notice to the covered institution within 72 hours, and the duty to see that individuals are notified stays with the covered institution.
  • Compliance was due 18 months after the June 3, 2024 publication for larger entities and 24 months for smaller ones — December 3, 2025 and June 3, 2026.

Regulation S-P Before the Amendments

Regulation S-P was first adopted in 2000 as the SEC's implementation of the privacy title of the Gramm-Leach-Bliley Act. Its safeguards provision required covered firms to adopt written policies and procedures for protecting customer records; a companion disposal provision governed how consumer report information was destroyed. What it did not do is say anything about what happens after a failure. As the Commission put it in the adopting release, "[b]efore adopting these amendments, the Commission did not require covered institutions to notify customers (or the Commission) in the event of a data breach."

The amendments were adopted on May 15, 2024 and published at 89 FR 47688 on June 3, 2024, with an effective date of August 2, 2024. They rewrote 17 CFR 248.30, which now carries the heading "Procedures to safeguard customer information, including response programs for unauthorized access to customer information and customer notice; disposal of customer information and consumer information."

Covered Institutions

Section 248.30(d)(3) defines a covered institution as "any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission or another appropriate regulatory agency." The transfer agents are the newly swept-in population: the Commission explained that the FTC has not adopted disposal and privacy rules governing transfer agents registered with a regulatory agency other than the SEC, and that it was exercising its authority under section 17A(d)(1) of the Exchange Act to close that gap.

The definitions section also carries the rule's two operative information categories. "Customer information" in § 248.30(d)(5) reaches any record containing nonpublic personal information about a customer of a financial institution held by the covered institution or on its behalf — including, expressly, information about the customers of other financial institutions that has been provided to it. "Sensitive customer information" in § 248.30(d)(9) is the narrower category that drives notification: any component of customer information "the compromise of which could create a reasonably likely risk of substantial harm or inconvenience to an individual identified with the information," followed by an illustrative list running from Social Security and passport numbers through biometric records to an account number combined with a security question and answer.

The Incident Response Program

Section 248.30(a)(3) folds the response program into the written policies the rule already required. The program must be reasonably designed to detect, respond to and recover from unauthorized access to or use of customer information, and it must include customer notification procedures. Three procedural elements are spelled out:

  • Assess the nature and scope of any incident and identify the customer information systems and types of customer information that may have been accessed or used without authorization;
  • Take appropriate steps to contain and control the incident to prevent further unauthorized access or use; and
  • Notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization.

The third element carries the rule's only off-ramp, and it is drafted as an exception rather than a threshold. Notice is required unless the institution determines, "after a reasonable investigation of the facts and circumstances of the incident," that the sensitive customer information "has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience." The default is notice; the investigation is what displaces it.

Customer Notification Obligations

Section 248.30(a)(4)(iii) sets the timing: notice as soon as practicable, but not later than 30 days after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. Delay is available only where the United States Attorney General determines that notice poses a substantial risk to national security or public safety and notifies the Commission in writing — up to 30 days, extendable by a further 30, and in extraordinary circumstances by a final 60, beyond which the Commission will consider requests for relief by exemptive order.

Where the institution cannot identify which individuals were affected, § 248.30(a)(4)(ii) requires notice to every individual whose sensitive customer information resides in the customer information system that was, or was reasonably likely to have been, accessed — subject to an exclusion for any individual the institution reasonably determines was not affected. Notice must be clear and conspicuous and "transmitted by a means designed to ensure that each affected individual can reasonably be expected to receive actual notice in writing."

Paragraph (a)(4)(iv) prescribes the contents in eight subparagraphs. Beyond a description of the incident and the type of information involved, the date or date range where reasonably determinable, and contact details including a telephone number, an email address, a postal address and the name of a specific office, the notice must explain what a fraud alert is and how to place one, recommend obtaining credit reports from each nationwide credit reporting company and having fraudulent-transaction information deleted, explain how to obtain a credit report free of charge, and point to identity-theft guidance from the Federal Trade Commission and usa.gov.

Recordkeeping runs alongside. Section 248.30(c)(1) requires covered institutions to make and maintain the written policies, documentation of any detected unauthorized access and the response to it, and documentation of any investigation and determination about whether notification was required — including the basis for the determination, any Attorney General correspondence about a delay, and a copy of any notice sent. Under § 248.30(c)(2) those records are preserved for at least six years, the first two in an easily accessible place.

Service Provider Oversight

The Commission proposed requiring a written contract with each service provider and did not adopt it. Section 248.30(a)(5)(i) instead requires the response program to include written policies and procedures reasonably designed to require oversight of service providers through due diligence and monitoring, designed to ensure that service providers protect against unauthorized access and "[p]rovide notification to the covered institution as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider." Receipt of that notification is itself the trigger to start the incident response program.

Paragraph (a)(5)(ii) permits a written agreement under which the service provider notifies affected individuals on the covered institution's behalf. Paragraph (a)(5)(iii) then closes the loop: notwithstanding any such arrangement, "the obligation to ensure that affected individuals are notified" rests with the covered institution. The Commission noted in the release that dropping the contract mandate in favor of a policies-and-procedures standard was one of the modifications that let it hold the compliance period to 18 and 24 months.

Compliance Dates by Firm Size

The Commission set a tiered compliance period measured from the June 3, 2024 publication date: 18 months for larger entities and 24 months for smaller ones, which places the two dates at December 3, 2025 and June 3, 2026. Both have passed. The release's Table 3 defines "larger entity" by category:

  • Investment companies, together with other funds in the same group of related investment companies: net assets of $1 billion or more as of the end of the most recent fiscal year;
  • Registered investment advisers: $1.5 billion or more in assets under management;
  • Broker-dealers: all that are not small entities under the Exchange Act for Regulatory Flexibility Act purposes; and
  • Transfer agents: all that are not small entities on the same test.

Smaller entities are those that do not meet the applicable standard. The Commission's own estimates in the release put roughly 77 percent of registered investment companies, 23 percent of registered investment advisers and 77 percent of broker-dealers in the larger-entity tier as of September 2023. A Federal Register search of Commission documents mentioning Regulation S-P published since January 2025 returns no extension of either date.

Overlap With the Safeguards Rule

Firms that fall under both the SEC's rule and the FTC's Part 314 face two regimes that point in different directions, and the Commission said so in the release. Discussing private fund advisers that may be subject to both, it observed that the FTC's rule had been updated to require notice to the FTC within 30 days of discovery of a breach involving the unencrypted information of at least 500 consumers, and then noted: "Although the FTC Safeguards Rule does not contain a customer notification requirement, the FTC indicated that it 'intends to enter notification event reports into a publicly available database' unless a law enforcement official requests delay."

That is the structural difference between the two instruments. The FTC's paragraph (j) is a report to the regulator, triggered by acquisition of unencrypted information above a numeric floor, with publicity as the downstream mechanism. Section 248.30(a)(4) is a notice to the individual, triggered by unauthorized access to sensitive customer information with no consumer-count floor at all, and rebuttable only by an investigation finding no reasonable likelihood of substantial harm or inconvenience. The clocks are both 30 days, and they are counted from different events.

Background

For the underlying law rather than this development: Financial Services privacy law.

Frequently Asked Questions

Does Regulation S-P require notifying the SEC of a data breach?
Section 248.30(a)(4) requires notice to affected individuals, not to the Commission. The Commission is involved only through the delay mechanism: the Attorney General must notify the Commission in writing of a determination that notice poses a substantial risk to national security or public safety before a covered institution may delay.
Which firms are covered institutions under the amended Regulation S-P?
Section 248.30(d)(3) names any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission or another appropriate regulatory agency. Transfer agents registered with an agency other than the SEC were brought in by these amendments.
What is sensitive customer information under 17 CFR 248.30?
Section 248.30(d)(9) defines it as any component of customer information whose compromise could create a reasonably likely risk of substantial harm or inconvenience to the individual, and gives examples including Social Security, driver's license, passport and taxpayer identification numbers, biometric records, and an account number or user name combined with authenticating information.
How long does a service provider have to report a breach to a covered institution?
Section 248.30(a)(5)(i)(B) requires the covered institution's policies to be designed to have service providers notify it as soon as possible and no later than 72 hours after becoming aware of a breach resulting in unauthorized access to a customer information system the provider maintains.
Have the Regulation S-P compliance dates passed?
Yes. The adopting release set 18 months from the June 3, 2024 publication for larger entities and 24 months for smaller ones, giving December 3, 2025 and June 3, 2026. A Federal Register search of SEC documents mentioning Regulation S-P published from January 2025 onward returns no document extending either date.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.