Reg S-P (Privacy) and Reg S-ID (Identity Theft)

Read the Free Lesson โ†’ free ยท no signup wall

What this video covers

  • Why Regulation S-P is an inside-out privacy defense and Regulation S-ID is an outside-in identity-theft shield, and how to pick the right rule when a scenario describes a vendor breach versus a fraudster login
  • The three core notices under Regulation S-P: initial privacy notice, annual privacy notice, and opt-out notice, plus who receives each and when
  • Why the Gramm-Leach-Bliley Act (GLBA) opt-out applies only to nonaffiliated third parties, not corporate affiliates, and how the exam baits you with sister-company sharing scenarios
  • The annual-notice exception: how a firm can legally skip the 12-month rhythm if its sharing policies are unchanged and it only uses enumerated exceptions
  • The Safeguards Rule trifecta: administrative, technical, and physical safeguards, plus the Disposal Rule requiring shredding or wiping before trashing customer data
  • The new Regulation S-P amendments incident response program (assess, contain, notify) and the hard 30-day customer notification window for unauthorized access to sensitive customer information
  • The four functional elements of a written identity theft prevention program under Regulation S-ID: identify, detect, respond, and update
  • The five red-flag categories versus the four functional elements, and why senior management or board approval is required for the program

Read the full lesson, free

This video's complete written lesson is free to read in the CertFuel app, no signup wall. The complete Series 24 course also includes adaptive practice questions and spaced-repetition flashcards, free through the end of 2026.

Read the Free Lesson โ†’ free ยท no signup wall