Amended Regulation S-P Is Now Fully in Effect – And Yes, It Applies to Private Fund Managers
Insights
Geoffrey Perusse ·
Victor J. Gonzalez · July 10, 2026
The compliance date for the SEC’s amendments to Regulation S-P has now passed for all covered firms: December 3, 2025 for larger entities, and June 3, 2026 for smaller entities -including registered investment advisers with less than $1.5 billion in assets under management. Advisers that have not yet implemented the required policies and procedures are out of compliance today, and SEC examination staff has identified Regulation S-P as a current examination priority.
Why private fund managers should read this alert
Many private fund managers have historically taken the position that Regulation S-P had little or no application to their business. The reasoning was straightforward: Regulation S-P protects the nonpublic personal information of “customers,” defined as natural persons with a customer relationship with the firm. A private fund adviser’s client is the fund itself -a legal entity, not a natural person – so, the thinking went, the adviser had no “customers” and the rule’s obligations largely did not reach it.
The amendments eliminate the practical benefit of that position. The amended safeguards and disposal rules apply to “customer information,” which is now defined to include any record containing nonpublic personal information about a customer of a financial institution – not just the adviser’s own customers – whether in the adviser’s possession or handled or maintained on the adviser’s behalf.
Consider what a typical fund manager actually holds: subscription documents, investor questionnaires, AML/KYC files, tax forms, and wire instructions for its funds’ individual limited partners – many of whom are natural persons, and virtually all of whom are customers of some financial institution. Under the amended rules, that investor information is protected customer information in the adviser’s hands. A manager whose investors include individuals, family vehicles, or trusts cannot avoid the amended rules by pointing to the fund as its only client.
What the amended rules require
- A written incident response program. Your safeguards policies must now include a program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information, including procedures to assess the nature and scope of an incident and to contain and control it.
- Investor breach notification within 30 days. If sensitive customer information was -or is reasonably likely to have been – accessed or used without authorization, affected individuals must be notified as soon as practicable, and no later than 30 days after the firm becomes aware of the incident. The notice must describe the incident, the data involved, and steps individuals can take to protect themselves. A narrow exception applies only where the firm determines the information is not reasonably likely to be used in a manner resulting in substantial harm or inconvenience.
- Service provider oversight. Firms must establish written policies and procedures requiring due diligence and monitoring of service providers, and must be positioned to receive notification from a service provider as soon as possible, but no later than 72 hours after the provider becomes aware of a breach in security resulting in unauthorized access to a customer information system it maintains. For fund managers, this squarely covers fund administrators, transfer agents, cloud and IT providers, and other vendors that touch investor data – vendor contracts should be reviewed and, where necessary, amended.
- Expanded disposal and recordkeeping obligations. The disposal rule now covers the full scope of customer information described above, and firms must maintain written records documenting compliance with the safeguards and disposal rules, including incident response and investor notification determinations.
What fund managers should do now
- Confirm your written information security program has been updated – a legacy privacy policy that predates the amendments will not satisfy the incident response program requirement.
- Inventory where investor personal information lives – internally and at your administrator and other vendors -so a 30-day notification clock can actually be met.
- Review administrator and key vendor agreements for breach notification and oversight provisions consistent with the 72-hour framework.
- Document the program. In an examination, staff will ask for the written policies, the vendor oversight records, and evidence the program has been implemented – not merely adopted.
Exempt reporting advisers are not directly subject to Regulation S-P, but state privacy and breach notification laws impose overlapping obligations, and institutional investors increasingly expect equivalent safeguards as a matter of operational due diligence.
Please contact a member of our Investment Management team if you would like assistance assessing your compliance posture, updating your policies and incident response program, or reviewing vendor arrangements.
This summary is provided for informational purposes only and is not intended to constitute legal advice nor does it create an attorney-client relationship with Rimon, P.C. or its affiliates.
Rimon’s Investment Management Practice advises investment advisors, private fund managers, broker-dealers, family offices, and institutional investors on the full spectrum of regulatory, transactional, and operational issues. Our attorneys provide practical, business-minded counsel on fund formation, securities regulation, compliance, trading, and governance. Read more here.


