Information Security and Privacy Regulations
Chapters in this video
- 0:00 GLBA and the birth of Regulation S-P
- 1:42 Consumer versus customer: the notice divide
- 2:43 Initial notice timing and the annual notice waiver trap
- 3:33 Opt-out rights and the Reg S-P versus Reg S-AM boundary
- 4:24 Four exceptions that bypass the opt-out requirement
- 5:09 The safeguards rule and Sam the supervisor
- 5:37 The 30-day breach notification deadline
- 6:05 Rapid-fire exam recap
What this video covers
- The difference between a consumer and a customer under Regulation S-P, and which one receives the initial and annual privacy notices
- The two strict conditions that must both be met for a firm to waive the annual privacy notice requirement
- When the opt-out right applies: specifically to nonaffiliated third parties, not to affiliated entities under Regulation S-AM
- The four exceptions that permit sharing nonpublic personal information (NPI) without an opt-out, and why the service provider exception requires a written contractual agreement
- What "clear and conspicuous" means for the opt-out notice, and why fine print buried in a contract fails the standard
- The written policies and procedures requirement under the safeguards rule, and what the firm must protect against
- The 30-day outer deadline for customer breach notification, and why "as soon as practicable" does not mean deliberate delay
Read the full lesson, free
This video's complete written lesson is free to read in the CertFuel app, no signup wall. When you're ready to drill the topic, the full Series 7 course adds adaptive practice questions and spaced-repetition flashcards.
Start on this site: free Series 7 practice questions · Series 7 pass rate