SEC Releases Long-awaited Proposal To Revise Regulation S-P

TC
Thompson Coburn LLP
Contributor
For almost 90 years, Thompson Coburn LLP has provided the quality legal services and counsel our clients demand to achieve their most critical business goals. With more than 380 lawyers and 40 practice areas, we serve clients throughout the United States and beyond.
For some of the above items, the SEC proposes concrete revisions or additions to Regulation S-P and requests comment on several issues.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

On March 15th, the Securities and Exchange Commission ("SEC") issued a proposed rule to revise Regulation S-P ("Proposed Regulation S-P") which implements the privacy and security requirements of the Gramm-Leach-Bliley Act ("GLBA") and certain other laws. The new proposed rule was issued almost exactly 15 years after the SEC issued proposed, but never finalized, revisions to Regulation S-P. On the same day, the SEC released a proposed cybersecurity risk proposed rule for several types of regulated securities entities ("Cyber Risk Proposal").

The 2023 Proposed Regulation S-P addresses several topics relating to SEC-regulated financial institutions, including:

  • Introducing a new requirement of security breach notification to customers
  • Requiring policies and procedures to address cybersecurity risks from employees working remotely
  • Harmonizing the scope and requirements of the GLBA Safeguards Rule and the Fair Credit Reporting Act Disposal Rule
  • Recordkeeping requirements for compliance with the Safeguards Rule and the Disposal Rule
  • Incorporating the statutory exemption to the GLBA annual privacy notice requirements
  • Requesting comment on permissible information sharing in the context of advisors changing firms
  • Overlap of cybersecurity requirements under Regulation S-P and other SEC cybersecurity regulations
  • Review of existing SEC statement and letters regarding Regulation S-P

For some of the above items, the SEC proposes concrete revisions or additions to Regulation S-P and requests comment on several issues. For other areas, the SEC does not propose language, but solicits comments on whether topics would be appropriate for inclusion in the ultimate regulation. The SEC also outlines some items that were considered, but not included in the proposed rule.& 160; Comments to the Proposed Regulation S-P are due by June 5, 2023, 60 days after publication of the proposed rule in the Federal Register.

The SEC proposal is noteworthy both for what is included and for what is not. The new proposal includes a consumer notification requirement for incident response with timing and content requirements consistent with the requirements of many state laws. Notice to the SEC for "Significant Cybersecurity Incidents" would be required under the Cyber Risk Proposal.

The Proposed Regulation S-P expands the existing Regulation S-P language on security controls, but does not follow the more prescriptive approach of the New York Department of Financial Services' Cybersecurity Regulation or the Federal Trade Commission's version of the Safeguards Rule. The Cyber Risk Proposal also considers cybersecurity program requirements separate from those in Regulation S-P.

Where the 2008 proposed Regulation S-P revision included specific provisions for information sharing relating to departing advisors, the new proposed rule only solicits comment about if such a provision is appropriate.

We will continue to monitor the Regulation S-P and Cyber Risk Proposal rulemaking process and report on events leading to the final rules.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

SEC Releases Long-awaited Proposal To Revise Regulation S-P

United States Technology
Contributor
For almost 90 years, Thompson Coburn LLP has provided the quality legal services and counsel our clients demand to achieve their most critical business goals. With more than 380 lawyers and 40 practice areas, we serve clients throughout the United States and beyond.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More