Blog

Regulation S-P Notification Clocks: the 30-Day Customer Notice and the 72-Hour Vendor Notice

· 4 min read

The 2024 amendments to Regulation S-P put two clocks in the rule: 30 days to notify affected individuals, and 72 hours for a service provider to notify the firm. Most of the work they create happens before an incident — in the written incident response program and in vendor contracts. This post answers the questions advisers ask about both clocks. Full detail is on the Regulation S-P page.

Who do the notification clocks apply to?

Regulation S-P is the SEC’s privacy and safeguards rule for registered investment advisers, broker-dealers, investment companies, and transfer agents. The 2024 amendments require covered institutions to maintain a written incident response program for unauthorized access to customer information, to notify affected individuals, and to impose notification duties on their service providers.

When do the amendments have to be complied with?

There are two compliance dates in the adopted amendments:

  • December 3, 2025 — larger covered institutions
  • June 3, 2026 — smaller RIAs and other smaller covered institutions

June 3, 2026 is the date in the rule, not a marketing window. A smaller adviser that has not finished the written program, the vendor clauses, and the evidence trail should treat the work as overdue rather than optional.

When does the 30-day customer clock start?

A covered institution must notify affected individuals as soon as practicable, and no later than 30 days after becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred.

Two words in that sentence do the work. Becoming aware is what starts the clock, which is why the detection and escalation path has to be written down and dated. Reasonably likely means the obligation can attach before anyone has proved exfiltration — the firm cannot wait for certainty it may never get.

What has to be in the file when a customer notice goes out?

The 30 days is an outer bound, not a target. The incident file should hold:

  • A decision record — what was accessed, who is affected, who approved the notice
  • The notice content and the delivery method
  • Evidence of coordination with counsel and the CCO
  • A copy of what was actually sent, filed with the incident workpapers

That file is what an examiner reads afterwards. A notice sent on day 12 with no record of how the firm reached the affected-person list is weaker than one sent on day 25 with the analysis attached.

What is the 72-hour vendor clock?

Service providers that maintain, process, or are otherwise permitted access to customer information must notify the covered institution as soon as possible, and no later than 72 hours after becoming aware of a breach in their own environment or a sub-processor’s.

That duty runs to the firm, not from it. The firm’s own 30-day clock can only start on time if the vendor’s 72-hour notice actually arrives.

Why the 72-hour clock is a contract problem before it is a security problem

The clock only works if the paperwork says so. The work is:

  • Inventory every vendor that touches customer information
  • Confirm the 72-hour notice obligation is in the agreement or an addendum
  • Record how notice would reach the firm after hours — which mailbox, which person, and who covers it when that person is away
  • Tabletop the path from a vendor’s email to the firm’s incident response plan

A 72-hour clause pointing at an unmonitored shared mailbox is a clause the firm cannot rely on.

What does the written incident response program have to say?

The amendments require a written program, not an informal playbook. It should state how the firm:

  • Detects and assesses unauthorized access to customer information
  • Contains the incident and documents decisions
  • Determines whose information was, or is reasonably likely to have been, accessed
  • Notifies customers and regulators on the clocks above
  • Preserves logs and workpapers for the exam file

The program also has to match reality: the same escalation path the monitoring actually uses, and the same vendor list the diligence file actually tracks.

What should be on file before an incident?

  • The written incident response program and its last annual review
  • The WISP sections that implement the Safeguards Rule
  • Customer notification procedures, and any notices already issued
  • The vendor inventory, contracts, and 72-hour clauses
  • MFA and access evidence for systems that store customer information
  • Incident tickets showing the program runs outside of exam season

This post summarises how the rule applies to the technology a firm runs. It is not legal advice; notification decisions should be made with counsel and the CCO.

Questions about how this applies to your firm? Call (203) 930-3410 or schedule a consultation.