Get Reg S-P ready →

Reg S-P overview › Does it apply to me?

"I'm a small shop — does Regulation S-P even apply to me?"

Last reviewed July 21, 2026 · official SEC sources linked below

This is the first question most solo and small advisers ask, and it usually comes wrapped in a hopeful assumption: surely a rule this heavy is aimed at the big firms. It isn't. The short answer is that if you are an SEC-registered investment adviser, Regulation S-P applies to you — there is no assets-under-management floor that exempts small firms from the rule itself. What the well-known "$1.5 billion" number actually controlled was when you had to be compliant, not whether. This page separates those two ideas, spells out exactly who is covered and which client information the rule protects, and clears up the two mix-ups that send small advisers down the wrong path.

The one-line version: every SEC-registered adviser is a "covered institution" under Reg S-P regardless of size. The $1.5B RAUM line only split the compliance deadline into two tiers (larger firms December 3, 2025; smaller firms June 3, 2026) — both of which have now passed.

Applicability vs. deadline — the distinction that trips people up

These are two separate questions, and conflating them is the most common Reg S-P error we see among small firms.

QuestionAnswerDoes AUM matter?
Does the rule apply to my firm?Yes, if you're an SEC-registered investment adviser (and to broker-dealers, investment companies, funding portals, and transfer agents).No — there's no AUM applicability threshold.
When did I have to be compliant?Larger entities: December 3, 2025. Smaller entities (RIAs under $1.5B RAUM): June 3, 2026.Yes — but only to set which of the two deadlines applied.

So "we're under $1.5 billion" never meant "we're exempt." It meant "we were in the later compliance tier" — a tier whose date, June 3, 2026, is already behind us. If that reasoning led your firm to defer the work, the deadline has passed and the catch-up is now the priority. (We walk the catch-up sequence on the compliance-deadline page.)

Who is a "covered institution"?

The amended rule defines "covered institution" to include brokers, dealers, investment companies, registered investment advisers, funding portals, and registered transfer agents, as specified in the regulation. For advisers, "registered" here means registered with the SEC. The safeguards obligations — written policies for administrative, technical, and physical protection of customer records and information — fall on all of them.

Consumer vs. customer — and why the difference matters

Reg S-P uses two terms that sound interchangeable but aren't, and they scope different obligations.

TermWho it isWhy it matters
ConsumerAn individual who provides nonpublic personal information to a covered institution in connection with obtaining or seeking to obtain advisory services — whether or not a continuing relationship is ever established.A prospect who sends you their financial details and then never signs can still be a consumer whose information you must protect and properly dispose of.
CustomerA consumer with a continuing relationship with your firm (your actual advisory clients).The safeguards and notification obligations center on "customer information," but the disposal and consumer-protection pieces reach beyond just active clients.

Which information is actually covered

Reg S-P protects nonpublic personal information about individuals who obtain financial products or services primarily for personal, family, or household purposes. Two consequences follow directly from that scope:

A practical read for a typical small RIA: if you advise individuals and households, you hold nonpublic personal information the rule protects, you are a covered institution, and the amended safeguards, incident-response, notification, service-provider-oversight, disposal, and recordkeeping obligations apply to you in full — small headcount and modest AUM change none of that.

Where do state-registered advisers stand?

Regulation S-P is an SEC rule, and its "covered institution" definition reaches investment advisers registered with the SEC. If your firm is state-registered rather than SEC-registered, this particular rule's amended requirements are not what binds you — but that is not the same as "no privacy obligations." State-registered advisers are generally subject to the Gramm-Leach-Bliley Act privacy framework through their state regulators and applicable state law, and many state rules track the same principles. If you're a mid-sized adviser near the SEC-registration line, confirm your registration status first, because it decides which regime you're in. This page addresses the SEC's Reg S-P; confirm your state's requirements with your state securities regulator.

Still not sure? Three questions that usually settle it

  1. Are you registered with the SEC as an investment adviser? If yes, you're a covered institution — full stop, regardless of AUM.
  2. Do you hold nonpublic personal information about individuals who came to you for personal, family, or household financial advice? If yes, that's exactly the information Reg S-P protects.
  3. Did "we're small" lead you to skip the work? If yes, note that the smaller-entity deadline (June 3, 2026) has passed and the amended obligations are now enforceable against you.

For the full picture of what the rule then requires, start with the plain-English Reg S-P overview, then the incident-response program outline and customer-notice requirements.

Small RIA and finally sure the rule applies to you? AdviserLedger turns the amended Reg S-P into a short, dated checklist — written IRP, customer-notice skeleton, vendor log, and review reminders — sized for a solo or small firm rather than a compliance department.

See AdviserLedger →

Related on this site: Reg S-P vs. state breach notification laws — the five places they diverge — a separate question from state registration: state breach-notification statutes can apply to your firm regardless of who you register with · what the SEC's FY2026 exam priorities say about Reg S-P. · initial and annual privacy notices — the notice half of the rule follows this same covered-institution scope · the disposal rule — the consumer-versus-customer distinction set out above is exactly what decides which records it reaches · does Regulation S-ID apply to my RIA? — a different scope test in the same CFR part: S-P reaches you as a covered institution, while S-ID reaches you only if you are a "financial institution" or "creditor" under FCRA and offer or maintain covered accounts. Answering yes here does not answer that

Official sources