Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Category: Privacy

Regulation S-P – Privacy Notices and Safeguard Policies

Posted on May 1, 2019May 1, 2019 by Doug Cornelius

The Securities and Exchange Commission’s Office of Compliance Inspections and Examinations (OCIE) issued a risk alert on compliance issues related to privacy regulations. The alert comes from recent examinations of broker-dealers and registered investment advisers. Regulation S-P is the primary SEC rule regarding privacy notices and safeguards. The Risk Alert doesn’t cover all of the…

Read more

Phone Phishing

Posted on October 18, 2018 by Doug Cornelius

The old-fashioned telephone turns out to be a way to hack into other people’s accounts. Voya Financial was the victim of cybercriminals using their phones instead of their computers. Voya ran the portal for its investment advisers and registered representatives to to manage the accounts of their customers. Voya also had a support line to…

Read more

New SEC Rule to Protect Investors from Identity Theft

Posted on April 11, 2013December 4, 2013 by Doug Cornelius

The Securities and Exchange Commission adopted new rules requiring investment advisers, broker-dealers, mutual funds, and certain other entities regulated by the agency to adopt programs to detect red flags and prevent identity theft. In 2010, the Dodd-Frank Wall Street Reform and Consumer Protection Act amended the Fair Credit reporting Act to add the SEC to…

Read more

Data Breaches in Massachusetts

Posted on May 1, 2012September 29, 2013 by Doug Cornelius

Through September 30, 2011, the largest share of breaches was not in the financial sector, but in the retail and healthcare industries, along with government. On October 31, 2007, the Commonwealth’s Data Security Breach Law, Mass. Gen. Law c. 93H, went into effect. On March 1, 2010, the Office of Consumer Affairs and Business Regulation’s…

Read more

Proposed Identity Theft Red Flags Rules

Posted on February 29, 2012February 29, 2012 by Doug Cornelius

Identity theft is a serious problem. Title X of the Dodd-Frank Wall Street Reform and Consumer Protection Act increased the scope of firms that would be subject to federal regulatory requirements on identity theft rules. The Securities Exchange Commission and the Commodities Futures Trading Commission just published a proposed rule addressing that new scope. Section…

Read more

Enforcement of the Massachusetts Data Privacy Law

Posted on August 30, 2011August 24, 2011 by Doug Cornelius

It’s been almost 18 months since the Massachusetts Data Privacy Law went into effect. Belmont Savings Bank has become one of the first charged with violating the law. Belmont Savings Bank maintained personal information on an unencrypted backup data tape and then lost the tape. According to surveillance footage the tape was likely discarded inadvertently by…

Read more

Is Your Copier in Compliance?

Posted on February 28, 2011February 27, 2011 by Doug Cornelius

I remember the days of the mimeograph. In class people would inevitably sniff the newly printed pages. For a teacher, the danger was that the latent copy would fall into the wrong hands. Animal House highlighted that danger. Current day copiers are much more advanced than the mimeograph, but the dangers of the latent copy…

Read more

Data Privacy Day

Posted on January 28, 2011January 28, 2011 by Doug Cornelius

Data Privacy Day is January 28, 2011. There have events throughout the week to inform and educate us all about our personal data rights and protections. Here are some key reminders: Never Post or Share Personal Information such as a date of birth, personal address, or maiden name because identity thieves now friend as many…

Read more

Dilbert on Employee Email Privacy

Posted on May 6, 2010 by Doug Cornelius

It looks like even Dilbert is keeping an eye on the Quon case at the Supreme Court.

Read more

Feds Release Usable Model Consumer Privacy Notice

Posted on April 19, 2010April 19, 2010 by Doug Cornelius

There was much cheering when federal regulators finally released their Final Model Privacy Notice Form back in November. That was quickly followed by a gnashing of teeth when it turns out the regulators did not understand the concept of a form or how to use Adobe Acrobat. They merely created a static document that you…

Read more

Posts pagination

  • 1
  • 2
  • 3
  • 4
  • …
  • 8
  • Next

Search for Stuff

Recent Stories

  • SEC Enforcement Results for FY 2025
  • Proposed Fundamental Reforms to AML Programs
  • Is It a Truck or a Security?
  • The One with Low IQ from Pet IQ
  • The Downsizing of the SEC
  • When “Today” Is Not all of “Today”
  • Compliance Bricks and Mortar for March 27
  • The One Where Theory Meets Reality
  • When the COVID Pandemic Hits Your Valuation
  • SEC’s Private Markets Roundtable

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.