Virginia Administrative Code
Title 21 - SECURITIES AND RETAIL FRANCHISING
Agency 5 - STATE CORPORATION COMMISSION
Chapter 80 - INVESTMENT ADVISORS
Part V - Miscellaneous
Section 21VAC5-80-260 - Information security and privacy
Current through Register Vol. 41, No. 3, September 23, 2024
A. Every investment advisor registered or required to be registered shall establish, implement, update, and enforce written physical security and cybersecurity policies and procedures reasonably designed to ensure the confidentiality, integrity, and availability of physical and electronic records and information. The policies and procedures shall be tailored to the investment advisor's business model, taking into account the size of the firm, type of services provided, and the number of locations of the investment advisor.
B. The investment advisor shall deliver upon the investment advisor's engagement by a client, and on an annual basis thereafter, a privacy policy to each client that is reasonably designed to aid in the client's understanding of how the investment advisor collects and shares, to the extent permitted by state and federal law, nonpublic personal information. The investment advisor shall promptly update and deliver to each client an amended privacy policy if any of the information in the policy becomes inaccurate.
Statutory Authority: §§ 12.1-13 and 13.1-523 of the Code of Virginia.