Get Reg S-P ready →

Reg S-P overview › Reg S-P and state breach laws

Reg S-P does not replace your state breach notification law — five places they diverge

Last reviewed August 25, 2026 · quoted from the SEC's adopting release

Most small advisory firms that thought about data breaches before 2026 thought about them in state-law terms: your state's statute, its definition of personal information, its notice deadline, its attorney-general filing. Now that the smaller-entity Reg S-P compliance date of June 3, 2026 has passed, there is a second, federal notice duty running alongside it — and the single most common wrong assumption we see is that the federal rule supersedes the state one.

The one-line version: the amended Regulation S-P notification requirement is a federal floor that sits on top of state data-breach law, not a replacement for it. The SEC described it in the adopting release as "a consistent minimum Federal notification standard." A firm with a reportable incident generally has to satisfy both, and the two bodies of law do not line up on who gets notified, what triggers the duty, how long you have, or whether encryption gets you out of it.

What the SEC actually said about state law

This is not an inference from silence. Commenters on the proposed amendments asked the Commission directly to defer to, or harmonize with, existing state breach statutes. The Commission addressed it head-on in the June 3, 2024 adopting release:

"[W]hile we recognize that existing State laws require covered institutions to notify State residents of data breaches in some cases, State laws are not consistent on this point and exclude some entities from certain requirements. The final amendments will require notification to all customers of a covered institution affected by a data breach (regardless of State residency), in order to provide timely and consistent disclosure of important information to help affected customers respond to a data breach."

— SEC, Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information, adopting release (Release Nos. 34-100155; IA-6604), 89 FR 47688 (June 3, 2024)

"Regarding commenters' concerns about harmonizing Regulation S-P with State law requirements, State law notification standards vary widely such that broad harmonization would be impracticable, and a benefit of the final amendments is that they provide a consistent minimum Federal notification standard to protect affected individuals in an environment of enhanced risk."

— same release

Read those together and the architecture is clear: the SEC did not try to occupy the field. It set a minimum that applies to every customer of a covered institution, and left the state regimes where they were.

The five divergences that actually change what you do

These are the points where "I already follow my state's statute" produces the wrong answer under the federal rule. Each is drawn from the adopting release; the state-law side is stated in general terms because state statutes genuinely differ from one another — treat the right-hand column as the question to ask about your state, not as a summary of it.

#IssueAmended Reg S-PTypical state breach statute
1 Who gets notified All affected customers of the covered institution, regardless of state of residency. Keyed to residents of that state. A client who moved, or who lives somewhere with a narrower statute, can fall outside it.
2 What triggers the duty A presumption in favor of notifying, which the firm may rebut only after a reasonable investigation determines the sensitive customer information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience. Many states require an affirmative determination that harm is likely before any duty attaches — the opposite default. The SEC declined commenters' request to adopt that approach.
3 The outside deadline As soon as practicable, and not later than 30 days after becoming aware that unauthorized access to or use of sensitive customer information has occurred or is reasonably likely to have occurred. Varies widely. Some states set 30, 45 or 60 days; some say only "without unreasonable delay" with no outside limit. The release notes the federal deadline "is shorter than the timing currently mandated by many States."
4 Encryption No safe harbor. Commenters asked for one; the SEC declined to write an exception into the definition of sensitive customer information. Encryption is instead a factor in deciding whether a compromise creates a reasonably likely risk of substantial harm. An encryption safe harbor is one of the most common features of state statutes — encrypted data is often carved out of the definition entirely.
5 Who can authorize a delay Only the U.S. Attorney General, on a determination that notice poses a substantial risk to national security or public safety, communicated in writing to the Commission — for a period the Attorney General specifies, up to 30 days beyond the original due date. Many states allow a delay simply at the request of a law enforcement agency — including state or local police.

Why #4 and #5 are the ones that bite

Divergences 1 through 3 are scope-and-calendar problems: you notify more people, sooner, on a lower trigger. Annoying, but you find them by reading the rule once.

The encryption gap is different, because it is the exact point where a state-law reflex produces a confident wrong answer. A firm that has internalized "the laptop was encrypted, so there's nothing to report" has internalized a state-law rule. On the federal side the SEC was explicit that the rule text "effectively addresses encrypted information without the need for a provision specifically tailored to that information," and that a covered institution "may consider encryption as a factor in determining whether the compromise of customer information could create a reasonably likely harm risk." That is a judgment you have to make, document, and be able to defend — not a box the incident falls out of automatically. The release also ties the analysis to current industry-standard practice and to whether the decryption key stayed secure, and says firms "generally should review and update, as appropriate, their encryption practices" as standards evolve.

The delay gap is different because it can go wrong in real time, during the one week you have the least attention to spare. If a state or local law-enforcement contact asks you to hold off on notifying while they work an investigation, that request — however legitimate, and however clearly it would pause a state-law clock — does not by itself stop the federal 30-day clock. The Commission addressed exactly this scenario:

"With respect to commenters who recommended that other Federal agencies, State and local law enforcement agencies, and foreign law enforcement authorities also be permitted to trigger a delay or suggested that the perceived limited nature of this delay would cause conflict with State authorities, the rule does not preclude any such entity from requesting that the Attorney General determine that the disclosure poses a substantial risk to national security or public safety and communicate that determination to the Commission. Designating a single law enforcement agency as the point of contact for both the covered institution and the Commission on such delays is critical to ensuring that the rule is administrable."

— same release

In other words: the route exists, but it runs through the Department of Justice and terminates at the SEC. A local request is the beginning of that route, not a substitute for it. If your incident response plan contains a line like "notify unless law enforcement directs otherwise," that line is describing state law only, and is worth rewriting.

Solo or small RIA? AdviserLedger keeps the Reg S-P paper trail as a short, dated set of records — IRP, incident log, notification-decision template, and a vendor register — so the determination you made, and when, is written down before anyone asks. The beta waitlist is open; planned pricing is $249/year.

Get Reg S-P ready →

Can one notice satisfy both?

Often, yes — and the SEC said so, with a condition attached:

"[T]o the extent a covered institution will have a notification obligation under both the final amendments and a similar State law, a covered institution may be able to provide one notice to satisfy notification obligations under both the final amendments and the State law, provided that the notice includes all information required under both the final amendments and the State law, which may reduce the number of notices an individual receives."

— same release

Note the conditional verbs. "May be able to," "provided that." The combined notice works only if it is a strict superset — every element the federal rule requires and every element the applicable state statute requires. Practically, that means the template you pre-draft should be built federal-first (see what the Reg S-P customer notice must contain) with a clearly marked block for state-specific additions — the toll-free numbers for the consumer reporting agencies, the state-specific rights language, and anything your state requires you to send to its attorney general as a separate filing.

One thing a combined notice does not collapse: regulator-side reporting. State statutes that require you to notify an attorney general or a state regulator at a threshold number of affected residents are a separate obligation with a separate recipient. Sending customers one good letter does not discharge it.

What to actually do with this

  1. Write down which state law applies to you — and remember the federal duty reaches every client regardless of where they live, so your client list, not your office address, defines the state-law analysis you may need to run.
  2. Set your internal deadline at 30 days, and treat it as the binding one. If your state allows longer, the federal clock is the one that will run out first. If your state is shorter, use the shorter one. Either way there is one date on the calendar, not two.
  3. Delete the encryption safe harbor from your mental model. Keep encryption as an input to the harm determination, and write the determination down — the recordkeeping requirement expects the investigation and the notify/don't-notify decision to exist as records.
  4. Fix the law-enforcement line in your IRP. Replace "unless law enforcement asks us to wait" with the actual federal mechanism, and note that a local request has to be escalated to DOJ to have federal effect.
  5. Build the notice template as a superset now. Drafting under a 30-day clock, mid-incident, with two bodies of law open on the desk, is the worst possible time to discover the two lists differ.

What this page is not. It is not a fifty-state survey, and it does not tell you what your state's statute says. State breach-notification laws differ from each other on nearly every element discussed above and are amended frequently. The federal side here is quoted from the SEC's adopting release and linked below; the state side is described in general terms precisely because generalizing further would be misleading. Confirm your own state's current statute — and any state where a client resides — before you rely on any of it.

Sources

Related on this site: the Reg S-P overview for small RIAs · the June 3, 2026 smaller-entity deadline and a catch-up sequence · what the customer notice must say · writing the incident response program · the four records you have to keep · what the SEC's FY2026 exam priorities say about Reg S-P. · the federal disposal rule — several states also impose their own data-destruction duties that run alongside it