Meeting SEC Regulation S-P requirements for secure disposal of customer information in broker-dealer and investment advisory firms.
The Securities and Exchange Commission's Regulation S-P (Privacy of Consumer Financial Information) requires financial institutions to implement safeguards to protect customer information—including during disposal.
Section 248.30(b) requires firms to "properly dispose of consumer information" by implementing policies and procedures to protect against unauthorized access to or use of customer information in connection with its disposal.
The SEC's Disposal Rule works in conjunction with Regulation S-P to mandate specific data destruction practices:
Documented disposal procedures that address the proper disposal of consumer information.
Use methods that render information unreadable or undecipherable (shredding, burning, pulverizing for paper; wiping, degaussing, or destruction for electronic media).
Exercise due diligence in selecting service providers and require contractual commitments to proper disposal.
Train staff on disposal procedures and the importance of protecting customer information.
Regularly review and update disposal policies to address evolving threats and technologies.
For electronic storage media containing customer information, the SEC expects firms to use industry-recognized data sanitization standards:
// Acceptable Disposal Methods
✓ DoD 5220.22-M (3 or 7-pass overwrite)
✓ NIST 800-88 compliant sanitization
✓ Cryptographic erasure (SEDs)
✓ Physical destruction (shredding, degaussing)
✗ Standard delete or format (INSUFFICIENT)
If using ITAD vendors or disposal services, SEC requires firms to:
During examinations, the SEC will look for evidence of compliance with disposal requirements. Be prepared to demonstrate:
D-Secure provides turnkey SEC Regulation S-P compliance with automated documentation, audit trails, and examination-ready reporting.
Device-level destruction verification for SEC exams
DoD 5220.22-M and NIST 800-88 as standard
Immutable records for regulatory review
Get expert guidance on meeting SEC Regulation S-P requirements and preparing for examinations.
Schedule Compliance ReviewYour email address will not be published. Providing an email is optional.
Send us an enquiry regarding: SEC Compliance & Data Disposal
No comments yet. Be the first to comment.