Privacy and Information Security
Chapters in this video
- 0:00 What NPI is and the public-information exclusion
- 1:30 The two privacy bosses: SEC versus NASAA
- 2:24 The privacy notice playbook: initial, annual, and opt-out
- 3:30 Zero exceptions for state-registered advisers
- 4:30 Four categories for sharing without opt-out
- 5:29 Safeguards, written policies, and incident response
- 6:38 The five cyber functions in exact order
- 8:19 Backup rules, annual review, and rapid-fire recap
What this video covers
- What counts as nonpublic personal information (NPI), including the public-information exclusion that removes NPI protection instantly
- The two regulatory regimes (SEC Regulation S-P versus NASAA's state-level rule) and which firms each regime covers
- The three required notices (initial, annual, and opt-out) and when each must be delivered during the customer relationship
- The critical exam distinction that state-registered investment advisers have zero exceptions for the annual privacy notice, unlike federally covered firms with the narrow SEC exception
- The four categories where sharing NPI with nonaffiliated third parties requires no opt-out: service providers, required by law, fraud prevention, and affiliates
- The written safeguards requirement, designated responsible person, and incident response program including timely customer notification
- The five mandatory NASAA cybersecurity functions in exact order: Identify, Protect, Detect, Respond, Recover, plus the backup-copy and annual-review duties
Read the full lesson, free
This video's complete written lesson is free to read in the CertFuel app, no signup wall. When you're ready to drill the topic, the full Series 63 course adds adaptive practice questions and spaced-repetition flashcards.
Start on this site: free Series 63 practice questions · Series 63 pass rate