Cybersecurity, Privacy, and Data Protection
Chapters in this video
- 0:00 The heist and shield narrative: Regulation S-P as your foundation
- 1:00 Four non-negotiable tools: written policies, notices, and opt-out
- 2:25 The annual-notice exception and opt-out limits
- 4:17 Safeguards Rule: why verbal policies violate federal law
- 4:48 Six elements of a compliant cybersecurity program
- 5:37 The 30-day federal breach notification deadline
- 6:25 Rapid-fire exam recap
What this video covers
- The four core requirements of Regulation S-P: written privacy policies, initial privacy notice, annual privacy notice, and the opt-out right for non-affiliated third-party sharing
- The strict two-part annual-notice exception and why missing the initial notice is always a violation
- The limits on opt-out rights, including the key exceptions for fraud protection, account servicing, joint marketing, and legal compliance
- Why the Safeguards Rule requires written administrative, technical, and physical safeguards, and why verbal or informal policies are automatic violations
- The six elements of a compliant cybersecurity program: risk assessment, access controls, data encryption, incident response plans, employee training, and vendor management
- The federal breach notification standard under amended Regulation S-P: trigger, 30-day deadline, and the sole exception through written U.S. Attorney General notice
- Why federal and state breach notification duties operate concurrently, not exclusively
Read the full lesson, free
This video's complete written lesson is free to read in the CertFuel app, no signup wall. The complete Series 66 course also includes adaptive practice questions and spaced-repetition flashcards.