Reg S-P overview › State-registered advisers
Almost every page written about the 2024 Regulation S-P amendments — including ours — is written for SEC-registered investment advisers. That is correct as far as it goes. Reg S-P is an SEC rule and its "covered institution" definition reaches advisers registered with the SEC.
But most advisory firms in the United States are not SEC-registered. Firms below the SEC-registration threshold register with their states instead, and NASAA's 2019 announcement of its information security model rule put that population at 17,500 state-registered investment advisers, the large majority of them very small shops. For all of them, the honest answer to "does Reg S-P apply to me?" is no — and that answer is where nearly every article stops.
It is the wrong place to stop, because "Reg S-P does not apply to you" is not the same sentence as "no federal data-security rule applies to you." Three federal rulebooks implement the Gramm-Leach-Bliley Act's privacy and safeguards provisions for different populations. A state-registered adviser is named inside one of them and expressly excluded from the other two. Each of those three facts is quoted below from the rule text itself.
This is the one that matters, and it does not require any inference. The scope section of the Safeguards Rule, 16 CFR § 314.1(b), lists the kinds of entities the FTC's enforcement authority reaches:
"The 'financial institutions' subject to the Commission's enforcement authority are those that are not otherwise subject to the enforcement authority of another regulator under section 505 of the Gramm-Leach-Bliley Act… More specifically, those entities include, but are not limited to, mortgage lenders, 'pay day' lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, travel agencies operated in connection with financial services, collection agencies, credit counselors and other financial advisors, tax preparation firms, non-federally insured credit unions, investment advisors that are not required to register with the Securities and Exchange Commission, and entities acting as finders."
That phrase — investment advisors that are not required to register with the Securities and Exchange Commission — is in the rule's own scope text, not in commentary about it. The FTC repeats it in FTC Safeguards Rule: What Your Business Needs to Know, which states on its face that it "serves as the small entity compliance guide under the Small Business Regulatory Enforcement Fairness Act." The logic of § 314.1(b) is the same logic that puts SEC registrants under Reg S-P: GLBA section 505 hands each population to a regulator, and the FTC takes the ones nobody else took.
Regulation P is the CFPB's GLBA privacy-notice rule, recodified in 2011 from the rules the banking agencies and the FTC had issued. It is a natural place to look for a state-registered adviser's privacy-notice duty. It is also the wrong place, and the rule says so directly. 12 CFR § 1016.1(b)(3) — "Nothing in this part shall apply to" — lists at subparagraph (iv):
"A registered investment adviser, properly registered by or on behalf of either the Securities Exchange Commission or any state, with respect to its investment advisory activities and its activities incidental to those investment advisory activities."
Read the clause carefully: it does not merely carve out SEC registrants, which would be routine. It carves out advisers registered by any state as well. Regulation P is not your privacy-notice rule either.
Older guidance — including NASAA's own long-standing GLBA primer for state advisers, State Advisers Subject to FTC Privacy Rules — tells state-registered advisers that "the FTC regulations governing state registered advisers are found at 16 C.F.R. § 313." That was accurate when it was written. It no longer describes the CFR.
Open 16 CFR § 313.1(b) today and the scope reads:
"The 'financial institutions' subject to the Commission's rulemaking authority are any persons described in 12 U.S.C. 5519 that are predominantly engaged in the sale and servicing of motor vehicles, the leasing and servicing of motor vehicles, or both."
Part 313's amendment history is on the section itself: 65 FR 33677, May 24, 2000, as amended at 86 FR 70025, Dec. 9, 2021. The NASAA primer linked above is a vintage document — its text refers to a July 1, 2001 mandatory-compliance date — and we link it because it is the clearest statement of the original jurisdictional split, not as a current citation.
Why this matters more than a citation correction. A firm that reads "16 CFR 313" in a 2001-era compliance memo and goes looking for its obligations will find a rule about car dealerships, conclude the topic does not concern it, and stop. The safeguards duty at Part 314 is a different part of the CFR, and it is the one with teeth.
Different rule, same problem. A written program that was filed once and never exercised fails the same way under the Safeguards Rule as it does under Reg S-P. AdviserLedger is a records-and-workflow log for keeping the dates, drills, vendor attestations and evidence in one place.
See how it works →Section 314.4 sets out the elements of the written information security program. Several are notably more prescriptive than anything in Reg S-P, which is the opposite of what "we're only state-registered" usually implies:
Section 314.6 is one sentence, and for a solo or two-person firm it is the most consequential sentence in the rule:
"Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers."
Translated, a firm under that threshold is relieved of four specific items: the written risk assessment with formal evaluation criteria, the annual penetration testing and six-monthly vulnerability assessments, the written incident response plan, and the annual written report to a board or senior officer.
What survives the carve-out is everything else in the list above — MFA, encryption, access controls, the two-year disposal clock, training, vendor oversight, the Qualified Individual, and the obligation to evaluate and adjust the program. And one more thing, which is where firms are most likely to be caught out.
This is the single most useful difference to carry away, and it runs opposite to the intuition that the state-registered regime is the lighter one.
| Reg S-P (SEC-registered adviser) | Safeguards Rule (state-registered adviser) | |
|---|---|---|
| Who gets told | The affected individuals | The Federal Trade Commission |
| Trigger | Unauthorized access to or use of customer information, per the amended rule's harm determination | A "notification event" — unauthorized acquisition of unencrypted customer information — involving at least 500 consumers (§ 314.4(j)(1)) |
| Clock | 30 days | As soon as possible, and no later than 30 days after discovery |
| In force since | June 3, 2026 for smaller entities | May 13, 2024 (§ 314.5: "Section 314.4(j) is effective as of May 13, 2024") |
| Form | Notice to the customer, contents specified by the rule | An electronic form on the FTC's website |
Two details in § 314.4 are worth reading closely rather than summarising. First, the definition at § 314.2(m) presumes against you: "Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless you have reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of such information." Second, § 314.4(j)(2) defines when the 30-day clock starts: the event is treated as discovered on "the first day on which such event is known to you," and you are "deemed to have knowledge" if it is known to any employee, officer or agent other than the person who committed the breach.
The FTC's own May 14, 2024 notice that the requirement had taken effect adds a practical point most firms would rather learn in advance than afterwards: "Your report may be made public. For example, your report might be included in a public listing of breach notifications or in response to a Freedom of Information Act request."
And none of this displaces state breach-notification law. The FTC's guidance says so plainly — "compliance with the Safeguard Rule isn't a substitute for obligations under other state and federal laws." The same stacking problem we mapped for SEC registrants applies here, with the federal layer swapped: see Reg S-P does not replace your state breach notification law, where the residency, trigger and encryption-safe-harbour divergences are set out.
Here is an honest loose end rather than a tidy answer.
The GLBA statute imposes the privacy-notice duty directly. 15 U.S.C. § 6803(a) requires that "at the time of establishing a customer relationship with a consumer and not less than annually during the continuation of such relationship, a financial institution shall provide a clear and conspicuous disclosure" of its policies on disclosing and protecting nonpublic personal information. But § 6803(b) then routes the mechanics elsewhere: those disclosures "shall be made in accordance with the regulations prescribed under section 6804."
And for a state-registered adviser, the two federal regulations that would have supplied those mechanics both point away: Regulation P excludes you by name, and FTC Part 313 now reaches only motor-vehicle dealers. We are not going to resolve that seam here, because doing it properly is a legal question about implementing authority and not something we can settle by quoting a scope clause. What we can say is where the practical answer comes from for most firms: state rules.
On May 21, 2019 NASAA announced that its membership had voted to adopt an investment adviser information security model rule package with three components: a model rule "requiring investment advisers to adopt policies and procedures regarding information security (both physical security and cybersecurity) and to deliver its privacy policy annually to clients"; an amendment to the model recordkeeping rule requiring those records be maintained; and amendments adding "failing to establish, maintain, and enforce a required policy or procedure" to the model unethical-business-practices and prohibited-conduct rules.
A model rule is not law anywhere until a jurisdiction adopts it. NASAA's announcement says exactly that — the package "now is available for individual jurisdictions throughout the United States to implement through regulation." So the operative question for your firm is not what NASAA adopted in 2019 but what your own state adopted, and when. That is a question for your state securities regulator's current investment adviser rules, and it is the one item on this page we cannot answer for you.