Reg S-P overview › Privacy notices
Almost everything written about Regulation S-P since May 2024 is about one section: § 248.30, the safeguards and disposal rule, with its new incident-response program, 30-day customer notice, and vendor oversight. That is the half that changed.
The other half did not go anywhere. §§ 248.4 through 248.9 have governed privacy notices since 2000 — the document you hand a new client describing what you collect and who you share it with. It is older, quieter, and nobody is writing alerts about it, which is exactly why small advisers get it wrong in both directions: some mail an annual notice they do not owe, and some skip an initial notice they do owe, or deliver it in a way the rule specifically says does not count.
The one-line version: a typical small RIA that shares client information only with its custodian, portfolio software, and other ordinary service providers probably owes no annual privacy notice at all — the § 248.5(e) exception covers it. That same firm almost certainly does owe an initial notice, no later than when the advisory contract is signed, and posting it on your website does not satisfy that one.
| Notices (§§ 248.4–248.9) | Safeguards & disposal (§ 248.30) | |
|---|---|---|
| Question it answers | What must you tell clients about how you handle their information, and when? | What must you do to protect that information, and what happens after a breach? |
| In force since | 2000, largely unchanged | 2000, substantially amended 2024 |
| What the 2024 amendments did to it | One change: codified a statutory exception to the annual notice, at § 248.5(e) | Nearly all of it — incident response, customer notification, service-provider oversight, expanded disposal scope, recordkeeping |
| Covered on this site | This page | Overview, IRP, customer notice, vendors, disposal |
The Commission described that single notice change in its own summary of the final amendments: they "amend the existing requirement to provide annual privacy notices to codify a statutory exception." Everything else in the notice half is the same rule your firm was subject to before 2024.
The rule requires "a clear and conspicuous notice that accurately reflects your privacy policies and practices" to an individual who becomes your customer, not later than when you establish a customer relationship.
§ 248.4(c)(3) gives examples, and one of them is written specifically for advisers. A customer relationship is established when the consumer:
"Enters into an advisory contract with you (whether in writing or orally)"
The parenthetical is the trap. A firm that treats notice delivery as part of its onboarding-paperwork packet has tied the notice to the moment the papers are signed. The rule ties it to the moment the advisory relationship is formed — and it says that can happen orally. If you agree to advise someone on a call and the engagement letter follows a week later, the rule's clock started on the call.
There are narrow exceptions in § 248.4(e) that let the initial notice arrive "within a reasonable time after" the relationship begins: where establishing the relationship was not at the customer's election, where notice first would "substantially delay the customer's transaction and the customer agrees to receive the notice at a later time," or where a nonaffiliated broker, dealer, or adviser establishes the relationship without your prior knowledge. The rule then supplies a matching negative example — notice would not substantially delay the transaction "when the relationship is initiated in person at your office or through other means by which the customer may view the notice, such as on a web site." A routine in-person or online onboarding does not qualify for the delay.
Under § 248.4(d), when an existing customer obtains a new financial product or service for personal, family, or household purposes, you satisfy the initial-notice requirement if the notice you most recently provided "was accurate with respect to the new financial product or service." If it was, no new notice is needed. If the new service changed what you collect or who you share it with, it was not accurate, and you owe a revised notice under § 248.8.
The general rule reads:
"Except as provided by paragraph (e) of this section, you must provide a clear and conspicuous notice to customers that accurately reflects your privacy policies and practices not less than annually during the continuation of the customer relationship. Annually means at least once in any period of 12 consecutive months during which that relationship exists. You may define the 12-consecutive-month period, but you must apply it to the customer on a consistent basis."
The rule's own worked example: if you define the period as a calendar year and "a customer opens an account on any day of year 1, you must provide an annual notice to that customer by December 31 of year 2."
This is the paragraph the 2024 amendments added, codifying the exception Congress created in 2015. You are not required to deliver an annual privacy notice if you:
Those three cross-referenced sections are the sharing patterns that never triggered an opt-out in the first place:
| Section | Covers | Typical small-RIA example |
|---|---|---|
| § 248.13 | Nonaffiliated third parties performing "services for you or functions on your behalf" — conditioned on having given the initial notice and a contract barring the vendor from using or disclosing the information for anything else | Portfolio accounting, CRM, document storage, an outsourced CCO |
| § 248.14 | Disclosure "as necessary to effect, administer, or enforce a transaction that a consumer requests or authorizes" — including processing or servicing, and maintaining the account | Sending client data to the custodian to open and service the account |
| § 248.15 | Other exceptions — including "with the consent or at the direction of the consumer," fraud prevention, and resolving disputes | Sending a statement to the client's CPA at the client's direction |
Read plainly: a firm whose entire data-sharing footprint is custodian + software vendors + things clients ask for is sharing only under §§ 248.13–248.15, and if its disclosure policies have not changed since its last notice, it meets both conditions. [Inference] — that is our reading of the rule text applied to a common firm profile, not a determination about your firm; whether your sharing genuinely stays inside those three sections is a factual question about your vendors and your contracts, and § 248.13 in particular is conditional on the contract term being in place.
A detail worth noticing. Condition (2) is keyed to a specific, enumerated list — § 248.6(a)(2) through (5) and (9), which are the disclosure items: what you disclose, to whom, about former customers, and under the § 248.13 service-provider exception. § 248.6(a)(8) — "your policies and practices with respect to protecting the confidentiality and security of nonpublic personal information" — is not in that list. [Inference]: on the text, rewriting your security practices does not by itself break the annual-notice exception, because the exception tracks changes to disclosure policies. That is a reading of which paragraphs the rule enumerates; we have not found SEC guidance stating it, and a change that alters both at once would be judged on the disclosure half. Do not lean on it without checking your facts against the rule.
§ 248.5(e)(2) is the part that catches firms, because it creates a deadline that has nothing to do with your annual cycle. If you change your policies or practices so that you no longer qualify:
The rule supplies the arithmetic itself. A firm on a calendar-year cycle that falls out of the exception effective April 1 of year 1: if it had provided a revised notice on March 1, the annual notice is due December 31 of year 2; if no revised notice was required, it is due July 9 of year 1. Same firm, same change, two due dates nearly nineteen months apart, decided by whether § 248.8 was triggered.
Once you have provided that annual notice and again meet the conditions, § 248.5(e)(2)(iii)(B) says you do not need to provide further annual notices until you fall out again.
§ 248.5(b) is short and useful: "You are not required to provide an annual notice to a former customer." Its examples name the adviser case directly — an individual becomes a former customer when "the individual's investment advisory contract is terminated." An annual mailing list that never gets pruned is doing unpaid work.
The standard is not "made available." It is that you must provide the notice "so that each consumer can reasonably be expected to receive actual notice in writing or, if the consumer agrees, electronically." The rule then lists what does and does not meet that standard.
| Counts as reasonable expectation of actual notice | Does not |
|---|---|
|
|
"It's on our website" is an annual-notice answer, not an initial-notice answer. § 248.9(c) is titled "Annual notices only." The website route works when "the customer uses your web site to access financial products and services electronically and agrees to receive notices at the web site and you post your current privacy notice continuously in a clear and conspicuous manner on the web site" — three conditions, all of which must hold, and it applies to the annual notice. A firm relying on a website footer link to deliver its initial notice has not used a method the rule blesses. (Under § 248.4(f), posting a notice where the customer may view it is enough to defeat the "substantial delay" excuse for late delivery — which is not the same as delivering it.)
One more delivery requirement that is easy to miss: § 248.9(e) says initial, annual, and revised notices must be provided to customers "so that the customer can retain them or obtain them later" in writing or, with agreement, electronically. A notice shown once inside a signing flow and never retrievable afterward does not satisfy this.
The initial, annual, and revised notices must include each of the following that applies to you:
Item 4 is the one most small-firm notices omit outright — the rule asks about former customers separately, and a notice silent on them is incomplete on its face.
§ 248.6(b) is a drafting convenience worth knowing: for information shared under §§ 248.14 and 248.15, "you are not required to list those exceptions"; it is sufficient to say you make disclosures to other nonaffiliated companies "for your everyday business purposes such as [include all that apply] to process transactions, maintain account(s), respond to court orders and legal investigations, or report to credit bureaus" or "as permitted by law." That is where the familiar boilerplate in every bank privacy notice comes from — it is a safe harbour the rule wrote, not marketing language.
Item 8 above is the seam. § 248.6(a)(8) requires your privacy notice to describe how you protect confidentiality and security — and the 2024 amendments made you write, for the first time, an incident-response program, service-provider oversight procedures, and written disposal policies. [Inference]: if your notice's security paragraph still describes the firm as it operated before that work, it may no longer "accurately reflect your privacy policies and practices" in the sense §§ 248.4 and 248.5 require. We have not seen the SEC address this interaction, and as noted above a security-description change does not appear to be what the § 248.5(e) exception is keyed to. The practical point is narrower and safer: if you rewrote your safeguards policies for the 2026 deadline, re-read your privacy notice against them. It is a ten-minute check with a real chance of finding a stale sentence.
Not sure which notices your firm actually owes? AdviserLedger turns Reg S-P into a short, dated checklist for a solo or small firm — the safeguards work and the notice obligations in one place, with review reminders instead of a binder.
See AdviserLedger →Related on this site: does Reg S-P apply to my RIA at all? — the notice rules in Subpart A follow the same "covered institution" scope · service-provider oversight — the § 248.13 contract condition and the 2024 vendor rule are separate requirements that land on the same vendor list · the disposal rule after 2024 · the June 3, 2026 deadline and the catch-up order.