privacy-data-security

Installation
SKILL.md

Privacy and Data Security

Purpose

Guide the design, implementation, and operation of privacy and data security programs for SEC-registered investment advisers, broker-dealers, investment companies, and other financial services firms. This skill covers Regulation S-P (privacy of consumer financial information), Regulation S-ID (identity theft prevention), SEC cybersecurity rules and examination expectations, incident response requirements, state privacy law intersections, vendor and third-party risk management, data governance, and employee training obligations.

Layer

9 — Compliance & Regulatory Guidance

Direction

prospective

When to Use

  • Designing or reviewing a firm's written information security program under the Reg S-P Safeguards Rule
  • Drafting or updating initial and annual privacy notices under Reg S-P
  • Evaluating whether the firm qualifies for the FAST Act annual privacy notice exception
  • Building an Identity Theft Prevention Program under Reg S-ID (Red Flags Rule)
  • Preparing for an SEC cybersecurity-focused examination
  • Responding to a data breach or cybersecurity incident affecting customer NPI
  • Assessing vendor and third-party service provider data security arrangements
Related skills

More from joellewis/finance_skills

Installs
130
GitHub Stars
75
First Seen
Feb 19, 2026