SEC Approves Amendment to Eliminate PII Collection in CAT
The SEC approved an amendment to the National Market System Plan Governing the Consolidated Audit Trail (the "CAT NMS Plan") to eliminate the requirement for the Central Repository to collect and store customer's personally identifiable information ("PII").
Under the approved amendment, the Customer & Account Information System ("CAIS") will be renamed the "Reference Database" and modified to capture Transformed Identifiers rather than sensitive personal data. By codifying the "CCID Alternative," the amendment allows the Plan Processor to generate unique CAT-Customer-IDs ("CCIDs") without maintaining a centralized database of social security numbers, dates of birth, or account numbers.
In addition to permanently codifying previous exemptive relief, the amendment mandates several changes to the CAT NMS Plan, including:
- Data Minimization: Eliminating requirements to report names, addresses, years of birth, and account numbers for all customers, extending relief to foreign nationals and legal entities;
- Historical Data: Directing the Plan Processor to develop a mechanism to delete previously reported PII currently stored in the CAIS system;
- Plan Definitions: Replacing "Customer Account Information" with "Account Reference Data" and "Customer Identifying Information" with "Customer Reference Data" to reflect the reduced scope of data retention; and
- Cost Savings: Reducing annual operating costs by approximately $7 million to $9 million, following an estimated one-time implementation cost of $4.5 million to $5.5 million.
The SEC acknowledged that removing PII from the Central Repository will reduce regulatory efficiency by requiring regulators to rely on ad hoc requests or Electronic Blue Sheets to identify individuals associated with specific CCIDs. However, the SEC concluded that the security benefits of eliminating the bulk storage of sensitive investor data outweighed the delays associated with indirect access to customer identities.
Commentary
The requirement imposed by the prior Administration at the SEC that CAT collect personal data, along with trading data, was reckless. (See SIFMA Urges SEC to Pause Finalization of Proposed Personal Data Requirements for CAT, Jan. 29, 2021.)
Anyone who runs a database that holds customer information knows that the information is both valuable to have and dangerous to hold. It makes the data repository a target for bad actors. Requiring that FINRA hold personal data, in combination with trading data, made FINRA into one of the most valuable targets in the world, for every kind of bad actor, U.S. and non-U.S., state actors, or common criminals.
Imposing the duty to protect such data on FINRA seemed unfair to FINRA. While FINRA obviously requires good data security, there is a large gap between state of the art data security and being responsible for a data Fort Knox. Potential damage in the event of a breach would have extended well beyond the incredible number of individuals impacted. It would have severely damaged the credibility of both FINRA and the SEC—the latter for imposing the requirement. As Hester Peirce made clear at the time: "Even the most vigilant employer, however, cannot identify every possible bad actor, and one security lapse involving only one of the CAT's thousands of users could compromise the entire database. Moreover, even an honest employee can become the inadvertent conduit for a cyber breach. If history is any guide, unauthorized access to, or disclosure of, the information contained in the CAT is almost certainly just a matter of time. Given these risks, we should eliminate the CAT." (See SEC Statement, Hester Peirce, May 15, 2020.)
Imposing impediments on the SEC's retrieval of this personal information is a useful check on governmental power. Now, in order to connect trading information to personal information, the regulators must go through private entities (meaning the broker-dealers), which will have some business incentive not to simply hand over information without at least some legal process. Again, as Commissioner Peirce anticipated: "This massive surveillance program provides too much information and power to government regulators, and by compiling all this data in one place, sets the stage for potential abuse either by regulators or cybercriminals." (See SEC Speech, Hester Peirce, Nov. 4, 2019.)