SEC: Financial orgs have 30 days to send data breach notifications
ID: c0835ac5-b1ac-5797-8791-8ec24dabf629
STIX ID: report--c0835ac5-b1ac-5797-8791-8ec24dabf629
Feed Name: Bleeping Computer
The SEC amended Regulation S-P to mandate that broker-dealers, investment companies, registered investment advisers, and transfer agents notify affected individuals within 30 days of discovering unauthorized access or use of sensitive customer information, implement documented incident response programs, and expand safeguards and disposal rules to all nonpublic personal information. The changes, which take effect 60 days after publication, include compliance timelines of 18 months for larger firms and two years for smaller entities, align annual privacy notice delivery with the FAST Act, and extend safeguards to transfer agents, reflecting modernization of privacy protections amid evolving data breach risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
