Large registered investment advisers must act before December 3, 2025

The recent amendments to Regulation S-P by the Securities and Exchange Commission (SEC) have significant implications for SEC-registered investment advisers, particularly in terms of safeguarding customer information. These changes require covered institutions to implement new measures to enhance data protection practices.

One of the key requirements introduced by the Reg S-P Amendments is the need for investment advisers to establish an incident response program. This program must include written policies and procedures aimed at detecting, responding to, and recovering from unauthorized access to or use of customer information. Advisers are also mandated to assess the nature and scope of any incident and take appropriate steps to contain and control it to prevent further unauthorized access.

Another crucial aspect of the amendments is the oversight of service providers who have access to client information. Investment advisers are required to engage in due diligence and ongoing monitoring of such service providers, ensuring that they have appropriate measures in place to protect against unauthorized access or use of client information. Additionally, advisers must ensure that service providers notify them of any data breaches within 72 hours of becoming aware of the incident.

Moreover, the Reg S-P Amendments now mandate that advisers notify affected individuals of any data breaches involving sensitive information within 30 days of becoming aware of the incident. This notification must include various details about the breach, recommended actions for affected customers, and information about available guidance from the Federal Trade Commission. While notification to the SEC is not necessary, it is crucial for advisers to develop notification templates to promptly inform customers in case of a breach.

Furthermore, the amendments broaden the definition of “customer information” under Regulation S-P’s safeguards and disposal rules to encompass any record containing nonpublic personal information about a customer. Investment advisers are required to maintain written records documenting compliance with these rules, including policies and procedures, as well as notifications sent to affected individuals. All records must be retained for five years, with the first two years in an easily accessible location.

In conclusion, the Reg S-P Amendments present a comprehensive framework for safeguarding customer information in the SEC-registered investment adviser industry. By requiring incident response programs, oversight of service providers, notification of data breaches, and recordkeeping of compliance efforts, these changes aim to enhance data protection practices and ensure the security of customer information within the financial sector. Investment advisers must act swiftly to comply with these amendments to meet the upcoming deadlines and uphold the integrity of their operations.