Sitonce
Country: HK
Show exams for United States Hong Kong
Sign in

How CFP confidentiality duties relate to Regulation S-P

Updated 6 min read
Key takeaway

CFP Board's confidentiality duty is a professional obligation to protect information about a current or prospective client, subject to specified exceptions.

More key points
  • SEC Regulation S-P is a separate legal privacy framework that applies to covered financial institutions and governs nonpublic personal information.
  • A planner must satisfy both when they apply; permission under one framework does not automatically resolve the other.
On this page11 sections
  1. CFP Board confidentiality duty
  2. Regulation S-P privacy framework
  3. Apply both, not one instead of the other
  4. Classify the information before sharing it
  5. Apply exceptions narrowly
  6. Safeguards include vendors and everyday workflows
  7. Worked example: adult child asks for a parent’s plan
  8. A practical disclosure decision tree
  9. Respond to an incident in the right order
  10. Use data minimization as a routine control
  11. Exam takeaway

A client may share financial, family, health and identity information so a planner can provide advice. The professional must protect it and use or disclose it only for an authorized purpose.

CFP Board confidentiality duty

The CFP Board Code and Standards require CFP professionals to keep confidential and protect information about a current, former or prospective client, subject to exceptions such as client consent, legal requirements and certain professional or disciplinary processes described in the standards. The obligation is part of the professional relationship and applies beyond a narrow category of financial account data.

Regulation S-P privacy framework

Regulation S-P implements federal privacy protections for nonpublic personal information held by covered financial institutions, including applicable broker-dealers and investment advisers. It addresses privacy notices, limits on disclosure to nonaffiliated third parties, safeguards and other duties. Scope and exceptions depend on the institution and information; the rule is not identical to CFP Board's ethical confidentiality standard.

Apply both, not one instead of the other

  • Identify whether the person is a CFP professional and whether the firm is a covered financial institution.
  • Determine what information is involved and the purpose of the proposed use or disclosure.
  • Check client consent, legal mandate, service-provider exception and other applicable conditions.
  • Use minimum necessary access and firm security controls where relevant.
  • If one rule permits disclosure but another professional duty restricts it, obtain legal or compliance guidance before sharing.

Classify the information before sharing it

A planner may hold identity details, account numbers, tax returns, health information, family disputes, investment records, and data received from custodians or employers. Different rules can apply to different records. Regulation S-P governs privacy and safeguarding obligations for covered financial institutions and consumer information; state privacy, breach-notification, contract, and other federal laws may add duties. The CFP confidentiality standard covers information related to the professional relationship, subject to its exceptions. Do not assume that information is free to disclose because it is in a client file.

Before sharing, identify the recipient, purpose, information needed, client authorization, and applicable exception. A client’s permission should be specific enough to understand what will be shared and with whom. A broad consent buried in onboarding documents may not answer whether a sensitive tax record can be sent to a new vendor or family member.

Apply exceptions narrowly

Confidentiality is not absolute. Applicable law may permit disclosures for services the client authorized, to comply with a legal obligation, to defend against a claim, or to prevent certain harms. The CFP standards identify exceptions that must be interpreted according to the Code and applicable law. If an exception may apply, disclose only information reasonably necessary and document the basis. When a subpoena, court order, or government request arrives, promptly consult counsel and the firm’s privacy officer rather than responding informally.

Safeguards include vendors and everyday workflows

Use approved systems, access controls, encryption where required, secure file transfer, retention limits, and vendor oversight. Confirm who can access shared folders and remove permissions when a staff member leaves. Avoid sending sensitive information to a personal email account or unapproved AI tool. Verify a recipient using a known contact channel before sending an account statement or tax return. A misaddressed email is a privacy incident even if it was accidental.

Regulation S-P includes requirements related to safeguarding customer information and responding to unauthorized access at covered institutions. The compliance program should define escalation, containment, investigation, notification, and recordkeeping. State breach laws may have different triggers and deadlines. Planners should report a suspected incident immediately through firm procedures rather than decide on their own that it is harmless.

Worked example: adult child asks for a parent’s plan

An adult child calls asking for a parent’s investment statement and says the parent asked them to help. The planner should not disclose the information based on the caller’s assertion. Verify the client’s identity and authorization through approved procedures, confirm the scope and duration of permission, and share only the documents needed. If the client lacks capacity or a power of attorney is presented, route the request through the firm’s legal and compliance process to confirm authority.

A practical disclosure decision tree

  1. Is the information confidential or personally identifiable?
  2. Who is requesting it and have they been authenticated?
  3. What purpose and specific data are necessary?
  4. Has the client authorized disclosure or does a valid legal exception apply?
  5. Do firm policy, Regulation S-P, state law, or a contract require additional steps?
  6. Can the data be minimized, secured, logged, and disclosed safely?
  • Do not promise absolute secrecy if legal exceptions apply.
  • Do not treat a family relationship as permission.
  • Escalate subpoenas, suspicious requests, and suspected breaches promptly.
  • Document authorization, purpose, data shared, and recipient.

Respond to an incident in the right order

  1. Contain the exposure using approved security procedures; do not delete evidence.
  2. Notify the firm’s privacy, security, and compliance leads immediately.
  3. Determine what information was affected, who accessed it, and whether access was unauthorized.
  4. Assess applicable SEC, CFP Board, state, contractual, and other legal duties.
  5. Preserve logs and document decisions, notices, and remediation.
  6. Communicate with the client as required and explain practical protective steps.

A privacy incident is not limited to hacking. A laptop left in a public place, a file shared with the wrong recipient, a former employee retaining access, or a vendor compromise may qualify. Regulation S-P amendments require covered institutions to maintain incident-response procedures and, subject to limited exceptions, notify affected individuals as soon as practicable and no later than 30 days after becoming aware of a qualifying incident. Applicability and compliance dates depend on the covered institution and facts; firms should follow current SEC rules rather than assume every incident has the same deadline.

Use data minimization as a routine control

Collect only information needed for the service, retain it according to a defensible schedule, and securely dispose of it when no longer needed. Before sending a client file to an outside accountant or attorney, confirm authorization and share only relevant records. Redact account numbers when a full identifier is unnecessary. These small steps reduce the harm if information is misdirected or accessed without permission.

Exam takeaway

CFP confidentiality is an ethical duty; Regulation S-P is a statutory privacy regime for covered institutions. Both can apply at once, so analyze scope, information, purpose and exceptions under each.

Common questions

Does Regulation S-P replace the CFP Board confidentiality duty?

No. A CFP professional may have to comply with both the professional standard and applicable privacy law.

Can a CFP professional share information because a service provider needs it?

Only if the applicable legal and ethical conditions are met, safeguards are in place and the disclosure is within the permitted purpose.

Does CFP confidentiality end when someone stops being a client?

The CFP Board duty extends to former clients, subject to the standards' stated exceptions.