Reg S-P overview › The disposal rule
Almost all of the attention on the 2024 Reg S-P amendments went to the dramatic parts: the written incident-response program and the 30-day customer notice. Sitting quietly beside them is § 248.30(b), the disposal rule, which was also rewritten — and which, unlike the breach machinery, produces obligations during ordinary weeks when nothing has gone wrong at all.
The disposal rule is the one Reg S-P provision that gets triggered by a mundane operational decision: replacing a laptop, closing an old file cabinet, letting a vendor's contract lapse, donating a monitor and the workstation under it. Most small firms have never thought of those as regulated events.
The one-line version: § 248.30(d)(7) defines "disposal" to include "the sale, donation, or transfer of any medium, including computer equipment, on which consumer information or customer information is stored." Since the 2024 amendments, the rule reaches customer information as well as consumer information — and § 248.30(b)(2) requires written policies and procedures addressing proper disposal.
The SEC described the pre-amendment rule in its own final release: the disposal rule "applies to transfer agents registered with the Commission in addition to the institutions covered by the safeguards rule," and "requires proper disposal of consumer report information." Consumer report information — narrow, credit-report-derived.
Then, in the Commission's summary of the final amendments:
"The final amendments will more closely align the information protected under the safeguards rule and the disposal rule by applying the protections of both rules to 'customer information,' a newly defined term. The final amendments will also broaden the group of customers whose information is protected under both rules."
| Before | Now | |
|---|---|---|
| Information covered | Consumer report information | Consumer information and customer information |
| Whose information | Narrower | Includes customers of other financial institutions whose information was provided to you |
| Written policies required? | Standard only | Yes — § 248.30(b)(2) requires written policies and procedures addressing proper disposal |
| Who must comply | Every covered institution "other than notice-registered broker-dealers" — which for an RIA means: you | |
"Every covered institution, other than notice-registered broker-dealers, must properly dispose of consumer information and customer information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal."
Note what it does not say. It does not name a method, prescribe a shredder specification, or mandate a wiping standard. It says reasonable measures, judged against unauthorized access or use in connection with disposal. That is the same flexible-standard drafting used throughout the safeguards rule, and it means the examination question will not be "did you use the right tool" but "can you show what your measures were, and why they were reasonable for the information involved."
Which is exactly why paragraph (b)(2) matters: "must adopt and implement written policies and procedures that address the proper disposal of consumer information and customer information according to the standard identified in paragraph (b)(1)." A defensible answer to "why was that reasonable" is a document that existed before the disposal happened.
| Term | Definition (§ 248.30(d)) | What small RIAs miss |
|---|---|---|
| Consumer information | Any record about an individual "whether in paper, electronic or other form, that is a consumer report or is derived from a consumer report, or a compilation of such records," maintained or possessed for a business purpose — regardless of whether it pertains to individuals you have a customer relationship with, or to "the customers of other financial institutions where such information has been provided to the covered institution." It excludes information that does not identify individuals, "such as aggregate information or blind data." | It is not limited to your clients. A credit report pulled on a prospect who never signed is consumer information you still hold. So is a statement or report about someone else's client that came to you during a transition or a held-away review. |
| Customer information | Any record containing nonpublic personal information about a customer of a financial institution, "whether in paper, electronic or other form, that is in the possession of a covered institution or that is handled or maintained by the covered institution or on its behalf" — again regardless of whether it pertains to your own customers or to customers of other financial institutions whose information was provided to you. | "Or on its behalf." A copy sitting in your cloud backup, your document-storage vendor, or a departed contractor's drive is inside the definition. Your disposal obligation does not stop at the edge of hardware you own. |
§ 248.30(d)(7) says disposal means:
"(i) The discarding or abandonment of consumer information or customer information; or
(ii) The sale, donation, or transfer of any medium, including computer equipment, on which consumer information or customer information is stored."
Limb (ii) is the one that catches small firms, because it converts routine hardware decisions into regulated events. A partial list of things that are disposals under this definition:
| Everyday event | Why it is a disposal |
|---|---|
| Trading in a laptop or phone against a new one | Transfer of a medium on which the information is stored |
| Selling an old workstation, tablet, or server | Sale of a medium |
| Donating retired equipment to a school or charity | Donation of a medium — named explicitly |
| Giving a departing employee the laptop they used | Transfer of a medium |
| Returning a leased copier or MFP with a hard drive | Transfer of a medium; document scanners and copiers commonly store images |
| Recycling a failed external drive without wiping it | Discarding or abandonment |
| Putting boxes of old client files in the dumpster | Discarding — the original disposal case, and paper is expressly in scope |
None of these involves a breach, an attacker, or a bad actor. They are the ordinary hardware lifecycle of a small office, and the rule attaches to them.
The vendor-exit case. Because customer information includes records "handled or maintained by the covered institution or on its behalf," the end of a vendor relationship is a disposal question, not merely a contracting one: what happens to their copy, who does it, and how do you know it was done. That is the same vendor list your 2024 oversight obligations already point at — see service-provider oversight — approached from the other end of the relationship. Building the two into one vendor record is less work than maintaining two.
The most common misreading is that the disposal rule tells a firm when it may or must purge records. It says the opposite, in terms:
"Nothing in this paragraph (b) shall be construed: (i) To require any covered institution to maintain or destroy any record pertaining to an individual that is not imposed under other law; or (ii) To alter or affect any requirement imposed under any other provision of law to maintain or destroy records."
So the disposal rule is silent on retention. It governs the manner of disposal if and when you dispose. Retention periods for an adviser come from elsewhere — see Reg S-P recordkeeping and the five-year rule. In practice this means a disposal policy that reads "we destroy client records after N years" is answering a question the disposal rule did not ask, and must be checked against the retention rule that did.
One related nuance about the recordkeeping paragraph itself, since it is easy to mis-cite: § 248.30(c) as codified imposes its own make-and-maintain requirement — six years, first two in an easily accessible place — on covered institutions that are investment companies not registered under section 8 of the Investment Company Act. Its list at (c)(1)(vi) expressly includes "the written policies and procedures required to be adopted and implemented pursuant to paragraph (b)(2)" — the disposal policies. The parallel obligation for registered advisers sits in the Advisers Act books-and-records rule, on the different retention period covered on our recordkeeping page. Either way, your written disposal policy is itself a record.
The rule does not supply a template, and we will not pretend it does. But the definitions above map cleanly onto the sections a policy has to have if it is going to address the standard:
Nothing on that list requires software, a consultant, or a budget. It requires a page of writing that exists before the next laptop is replaced.
One more written policy you did not know you owed? AdviserLedger turns the amended Reg S-P into a short, dated checklist sized for a solo or small firm — safeguards, incident response, vendors, disposal, and the review reminders that keep them current.
See AdviserLedger →It is not a data-destruction standard. The rule sets a reasonableness standard rather than naming approved methods, and we have deliberately not invented specifications it does not contain — no wipe-pass counts, no shred sizes, no certification requirements, because § 248.30(b) states none. It is also not a survey of state data-disposal statutes, several of which impose their own destruction requirements on businesses holding personal information; those run alongside Reg S-P, in the same way state breach-notification laws run alongside the federal customer notice. Check your states.
Related on this site: the plain-English Reg S-P overview · does the rule apply to my firm? — the consumer/customer distinction this page turns on is set out there · the privacy-notice half of Reg S-P — your notice has to describe the security practices this policy is part of · writing the incident-response program · what the FY2026 exam priorities say about Reg S-P.