IAA Reports Early Lessons From Advisers Under Amended Regulation S-P

The Investment Adviser Association ("IAA") reported early lessons from advisers under the SEC's amended Regulation S-P, the data-privacy and data-security rule.

The report flagged three immediate tasks: (i) firms are advised to map where their customer data is stored, (ii) firms must develop a true incident-response plan that provides for real monitoring and containment, and (iii) firms must review all their vendors with a focus on those that have administrator access.

The rule, which took effect for larger firms in December 2025 and for smaller firms in June 2026, has four new requirements:

  • Each adviser must develop and maintain an incident-response program tailored to its own risks, covering how to detect, respond to, and recover from a breach.
  • An adviser must notify an affected individual when a breach poses a risk of "substantial harm."
  • Outside vendors must inform the adviser within 72 hours of finding a breach, and advisers must record this requirement in their contracts with vendors or discuss this requirement with vendors and document the conversation.
  • Advisers must maintain records for set periods and adopt policies to properly dispose of customer data, as well as ensure that service providers do the same.

The report stated that "customer information" is broadly defined. The report noted that the rule covers any nonpublic information a firm holds about any individual, not just current clients, and that even a firm that serves only institutions could hold personal data that falls under the rule.

Premium Content

Available only to Premium subscribers.

 

Tags