Information Security and Privacy: SEC Regulation S-P
Chapters in this video
- 0:00 NPI and the dumpster fire that started it all
- 1:37 Consumer versus customer: the identity trap
- 2:21 The three privacy notices and their order
- 4:51 Exceptions that kill the opt-out right
- 6:09 Safeguards Rule: physical, administrative, technical
- 6:59 Breach deadlines: 72 hours, then 30 days
- 8:15 Disposal Rule and why dumpsters are illegal
- 8:48 Rapid-fire exam recap
What this video covers
- The distinction between a consumer and a customer, and why someone who only requests a brochure is neither
- The timing and content of the initial privacy notice, and why it must arrive before the customer relationship is established
- The opt-out notice requirements, including the 30-day reasonable opportunity window and the validity of partial opt-outs
- The two-part exception that allows a firm to skip the annual privacy notice entirely
- The five specific situations where opt-out rights disappear entirely, including service providers, transaction processing, risk control, legal compliance, and consumer reporting agencies
- The three mandatory pillars of the Safeguards Rule: physical, administrative, and technical safeguards
- The breach notification deadlines: 72 hours for a service provider to notify the firm, and 30 days for the firm to notify affected customers
Read the full lesson, free
This video's complete written lesson is free to read in the CertFuel app, no signup wall. The complete Series 6 course also includes adaptive practice questions and spaced-repetition flashcards.