Regulators have heightened rulemaking and enforcement to strengthen recordkeeping, data retention, and data deletion requirements
October 2022
乐鱼(Leyu)体育官网 Insights:聽Regulators are increasingly scrutinizing data retention and recordkeeping laws, including collection, storage, retention, and disposal practices.聽 This scrutiny falls under existing data retention, privacy and risk management regulations and guidance鈥攁nd regulatory expectations are quickly being established via supervision and enforcement. In anticipation of heightened regulatory attention, companies should review their electronic communications policies, practices, and communications as well as their data retention and deletion policies and practices across legacy and multi-platform systems and unstructured data repositories.聽
Regulators have heightened their attention and enforcement on data privacy and security, including issues related to recordkeeping, data retention, and data deletion. Recent actions include:
1.聽 聽聽SEC:聽An SEC final rule that 鈥渕odernizes鈥� electronic recordkeeping requirements for broker-dealers and security-based swap entities.
2.聽聽 聽Enforcement:聽Enforcement actions against various firms, including:
3.聽 聽 New Regulations:聽New laws and rulemakings (at the state and federal levels) intended to place limits on minimizing the data that are collected and retained, including the duration of the retention period, and mandating deletion.
The SEC issued a聽聽to 鈥渕odernize鈥� electronic recordkeeping requirements for broker-dealers and security-based swap entities to:
Multiple enforcement actions have been issued relative to the storage, retention, and disposal of both customer and company data. Public enforcements include:
In particular, the agencies found that the firms鈥� employees conducted business communications through unauthorized channels and on personal devices, and also that these communications were not maintained or preserved. The agencies further cited the firms for related supervisory failures. The federal securities laws and the Commodity Exchange Act require the creation and retention of records for reasons of investor protection and public interest.
In particular, the SEC found the firm violated both its Safeguards Rule and Disposal Rule under Regulation S-P, which require, respectively, 鈥渨ritten policies and procedures to address administrative, technical, and physical safeguards reasonably designed for the protection of customer records and information,鈥� and, at the time of their disposal, reasonable measures to protect against unauthorized access to, or use of, the data.
FTC.聽In December 2021, the FTC聽聽a final rule amending its Standards for Safeguarding Customer Information (Safeguards Rule), which are applicable to financial institutions under the FTC鈥檚 jurisdiction. The rule amendments became effective in January 2022 and include provisions related to data retention and disposal. In particular, the rule now states covered financial institutions must:
In August 2022, the FTC聽聽an advanced notice of proposed rulemaking (ANPR) seeking public comment on commercial surveillance and data security practices, including those that relate to the FTC鈥檚 Safeguards Rule. Among other things, the ANPR poses multiple questions on the collection, use, and retention of consumer data including whether:
CPRA. The California Privacy Rights Act (), which was enacted in 2020 and becomes fully effective in January 2023, establishes limitations on data collection and retention. More specifically:
乐鱼(Leyu)体育官网 Regulatory Insights is the thought leader hub for timely insight on risk and regulatory developments.