Get Reg S-P ready →

Reg S-P overview › The disposal rule

The disposal rule after 2024: trading in a laptop is a compliance event

Last reviewed August 29, 2026 · quoted from the eCFR text linked below

Almost all of the attention on the 2024 Reg S-P amendments went to the dramatic parts: the written incident-response program and the 30-day customer notice. Sitting quietly beside them is § 248.30(b), the disposal rule, which was also rewritten — and which, unlike the breach machinery, produces obligations during ordinary weeks when nothing has gone wrong at all.

The disposal rule is the one Reg S-P provision that gets triggered by a mundane operational decision: replacing a laptop, closing an old file cabinet, letting a vendor's contract lapse, donating a monitor and the workstation under it. Most small firms have never thought of those as regulated events.

The one-line version: § 248.30(d)(7) defines "disposal" to include "the sale, donation, or transfer of any medium, including computer equipment, on which consumer information or customer information is stored." Since the 2024 amendments, the rule reaches customer information as well as consumer information — and § 248.30(b)(2) requires written policies and procedures addressing proper disposal.

What actually changed in 2024

The SEC described the pre-amendment rule in its own final release: the disposal rule "applies to transfer agents registered with the Commission in addition to the institutions covered by the safeguards rule," and "requires proper disposal of consumer report information." Consumer report information — narrow, credit-report-derived.

Then, in the Commission's summary of the final amendments:

"The final amendments will more closely align the information protected under the safeguards rule and the disposal rule by applying the protections of both rules to 'customer information,' a newly defined term. The final amendments will also broaden the group of customers whose information is protected under both rules."
BeforeNow
Information coveredConsumer report informationConsumer information and customer information
Whose informationNarrowerIncludes customers of other financial institutions whose information was provided to you
Written policies required?Standard onlyYes — § 248.30(b)(2) requires written policies and procedures addressing proper disposal
Who must complyEvery covered institution "other than notice-registered broker-dealers" — which for an RIA means: you

The standard itself is short

"Every covered institution, other than notice-registered broker-dealers, must properly dispose of consumer information and customer information by taking reasonable measures to protect against unauthorized access to or use of the information in connection with its disposal."

Note what it does not say. It does not name a method, prescribe a shredder specification, or mandate a wiping standard. It says reasonable measures, judged against unauthorized access or use in connection with disposal. That is the same flexible-standard drafting used throughout the safeguards rule, and it means the examination question will not be "did you use the right tool" but "can you show what your measures were, and why they were reasonable for the information involved."

Which is exactly why paragraph (b)(2) matters: "must adopt and implement written policies and procedures that address the proper disposal of consumer information and customer information according to the standard identified in paragraph (b)(1)." A defensible answer to "why was that reasonable" is a document that existed before the disposal happened.

Two categories, and the words in each definition that do the work

TermDefinition (§ 248.30(d))What small RIAs miss
Consumer information Any record about an individual "whether in paper, electronic or other form, that is a consumer report or is derived from a consumer report, or a compilation of such records," maintained or possessed for a business purpose — regardless of whether it pertains to individuals you have a customer relationship with, or to "the customers of other financial institutions where such information has been provided to the covered institution." It excludes information that does not identify individuals, "such as aggregate information or blind data." It is not limited to your clients. A credit report pulled on a prospect who never signed is consumer information you still hold. So is a statement or report about someone else's client that came to you during a transition or a held-away review.
Customer information Any record containing nonpublic personal information about a customer of a financial institution, "whether in paper, electronic or other form, that is in the possession of a covered institution or that is handled or maintained by the covered institution or on its behalf" — again regardless of whether it pertains to your own customers or to customers of other financial institutions whose information was provided to you. "Or on its behalf." A copy sitting in your cloud backup, your document-storage vendor, or a departed contractor's drive is inside the definition. Your disposal obligation does not stop at the edge of hardware you own.

"Disposal" is defined — and it is broader than destruction

§ 248.30(d)(7) says disposal means:

"(i) The discarding or abandonment of consumer information or customer information; or
(ii) The sale, donation, or transfer of any medium, including computer equipment, on which consumer information or customer information is stored."

Limb (ii) is the one that catches small firms, because it converts routine hardware decisions into regulated events. A partial list of things that are disposals under this definition:

Everyday eventWhy it is a disposal
Trading in a laptop or phone against a new oneTransfer of a medium on which the information is stored
Selling an old workstation, tablet, or serverSale of a medium
Donating retired equipment to a school or charityDonation of a medium — named explicitly
Giving a departing employee the laptop they usedTransfer of a medium
Returning a leased copier or MFP with a hard driveTransfer of a medium; document scanners and copiers commonly store images
Recycling a failed external drive without wiping itDiscarding or abandonment
Putting boxes of old client files in the dumpsterDiscarding — the original disposal case, and paper is expressly in scope

None of these involves a breach, an attacker, or a bad actor. They are the ordinary hardware lifecycle of a small office, and the rule attaches to them.

The vendor-exit case. Because customer information includes records "handled or maintained by the covered institution or on its behalf," the end of a vendor relationship is a disposal question, not merely a contracting one: what happens to their copy, who does it, and how do you know it was done. That is the same vendor list your 2024 oversight obligations already point at — see service-provider oversight — approached from the other end of the relationship. Building the two into one vendor record is less work than maintaining two.

The trap: this rule tells you how, never whether

The most common misreading is that the disposal rule tells a firm when it may or must purge records. It says the opposite, in terms:

"Nothing in this paragraph (b) shall be construed: (i) To require any covered institution to maintain or destroy any record pertaining to an individual that is not imposed under other law; or (ii) To alter or affect any requirement imposed under any other provision of law to maintain or destroy records."

So the disposal rule is silent on retention. It governs the manner of disposal if and when you dispose. Retention periods for an adviser come from elsewhere — see Reg S-P recordkeeping and the five-year rule. In practice this means a disposal policy that reads "we destroy client records after N years" is answering a question the disposal rule did not ask, and must be checked against the retention rule that did.

One related nuance about the recordkeeping paragraph itself, since it is easy to mis-cite: § 248.30(c) as codified imposes its own make-and-maintain requirement — six years, first two in an easily accessible place — on covered institutions that are investment companies not registered under section 8 of the Investment Company Act. Its list at (c)(1)(vi) expressly includes "the written policies and procedures required to be adopted and implemented pursuant to paragraph (b)(2)" — the disposal policies. The parallel obligation for registered advisers sits in the Advisers Act books-and-records rule, on the different retention period covered on our recordkeeping page. Either way, your written disposal policy is itself a record.

What a small firm's disposal policy needs to cover

The rule does not supply a template, and we will not pretend it does. But the definitions above map cleanly onto the sections a policy has to have if it is going to address the standard:

  1. An inventory of where the two categories live — paper files, laptops, phones, external drives, backups, the copier, and every vendor holding a copy on your behalf.
  2. A method per medium, with the reasoning recorded: paper, spinning disks, solid-state drives, and mobile devices do not respond to the same measures, and "we deleted the files" is a weaker answer for an SSD than for a filing cabinet.
  3. A hardware-lifecycle trigger. The policy has to fire on purchase-and-trade-in, on employee departure, and on lease return — not only on a scheduled purge date.
  4. A vendor-exit step, because of the "or on its behalf" language.
  5. Evidence. Certificates of destruction, wipe logs, a dated line in a disposal register. The standard is "reasonable measures," and reasonableness is demonstrated, not asserted.
  6. An explicit pointer to your retention rule, so that the two questions — may we dispose of this yet? and how must we do it? — stay separate and both get answered.

Nothing on that list requires software, a consultant, or a budget. It requires a page of writing that exists before the next laptop is replaced.

One more written policy you did not know you owed? AdviserLedger turns the amended Reg S-P into a short, dated checklist sized for a solo or small firm — safeguards, incident response, vendors, disposal, and the review reminders that keep them current.

See AdviserLedger →

What this page is not

It is not a data-destruction standard. The rule sets a reasonableness standard rather than naming approved methods, and we have deliberately not invented specifications it does not contain — no wipe-pass counts, no shred sizes, no certification requirements, because § 248.30(b) states none. It is also not a survey of state data-disposal statutes, several of which impose their own destruction requirements on businesses holding personal information; those run alongside Reg S-P, in the same way state breach-notification laws run alongside the federal customer notice. Check your states.

Related on this site: the plain-English Reg S-P overview · does the rule apply to my firm? — the consumer/customer distinction this page turns on is set out there · the privacy-notice half of Reg S-P — your notice has to describe the security practices this policy is part of · writing the incident-response program · what the FY2026 exam priorities say about Reg S-P.

Official sources