Now that the SEC's amended Regulation S-P is in effect for smaller RIAs (since June 3, 2026), the customer notification is the one deliverable most likely to be drafted under pressure — after a real incident, on a 30-day clock. The rule tells you the minimum the notice must contain. Drafting the skeleton before anything happens turns a stressful legal question into a fill-in-the-blank task.
When the notice is required. You must notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization — unless, after a reasonable investigation, you determine the information has not been and is not reasonably likely to be used in a way that would cause substantial harm or inconvenience. The clock: as soon as practicable, and no later than 30 days after you become aware.
Under the amended rule, the notice must be clear and conspicuous and delivered by a means designed to ensure the customer can reasonably be expected to receive actual notice in writing. On content, the rule requires the notice to include the following (to the extent the information is reasonably possible to determine at the time):
| Required element | What to write |
|---|---|
| The incident, in general terms | A general description of what happened — enough for the customer to understand the nature of the event, without over-disclosing technical detail that isn't yet confirmed. |
| The type of sensitive customer information | The category of information that was, or is reasonably believed to have been, accessed or used without authorization (e.g., name with SSN, account number, government ID). |
| The date, estimated date, or date range | The date of the incident — or an estimated date or a date range — if it is reasonably possible to determine when the notice is provided. |
Those three are the rule's stated minimum. The elements below are widely recommended in practice but are not, by themselves, the rule's mandatory content — treat them as best practice, confirmed with your counsel.
Many advisers also coordinate the Reg S-P notice with any state data-breach notification laws that apply to the same individuals, since those can carry their own content and timing rules. Reg S-P sets a federal floor; it does not displace stricter state requirements.
The 30-day clock is the wrong time to be writing from scratch. AdviserLedger keeps a pre-approved notice template, the harm-determination worksheet, and a timestamped log of when you became aware and when notice went out — the evidence an exam asks for.
See how it works →Subject: Important notice about your information
Dear [Customer name],
We are writing to let you know about an incident that may have involved some of your information. [General description of the incident.]
Based on our review, the information that may have been accessed includes [type(s) of sensitive customer information]. We [believe this occurred on / estimate this occurred on / believe this occurred between] [date, estimated date, or date range — if determinable].
[Best-practice additions:] Here is what we have done in response: [general steps]. Here are steps you can take to protect yourself: [monitoring, fraud alert / credit freeze, resources]. If you have questions, contact us at [phone / email / mailing address / website].
Sincerely, [Firm name]
This skeleton is a drafting aid, not approved language — the wording, the harm determination, and whether notice is required at all are firm- and fact-specific. Have counsel review your template before you need it.
Related on this site: Reg S-P for small RIAs — the five obligations · Writing the incident response program — a section-by-section IRP outline · Service-provider oversight — the vendor 72-hour clock that feeds this one · Reg S-P vs. state breach notification laws — the five places they diverge — including whether one notice can satisfy both regimes. · the privacy notice — a different customer-facing document with different content and delivery rules; do not let one stand in for the other