Skip to content

🦖 Serve docs via Docusaurus - #31

Merged
JFWooten4 merged 6 commits into
mainfrom
Docusaurus
Jun 3, 2026
Merged

🦖 Serve docs via Docusaurus#31
JFWooten4 merged 6 commits into
mainfrom
Docusaurus

Conversation

@JFWooten4

Copy link
Copy Markdown
Member

closes #30

Regulatory basis

Subsection (k): transfer-agent Reg S-P record retention

Every registered transfer agent shall maintain in an easily accessible place:

  1. The written policies and procedures required to be adopted and implemented pursuant to § 248.30(a)(1) of this chapter for no less than three years after the termination of the use of the policies and procedures;

  2. The written documentation of any detected unauthorized access to or use of customer information, as well as any response to, and recovery from such unauthorized access to or use of customer information required by § 248.30(a)(3) of this chapter for no less than three years from the date when the records were made;

  3. The written documentation of any investigation and determination made regarding whether notification is required pursuant to § 248.30(a)(4) of this chapter, including the basis for any determination made, any written documentation from the United States Attorney General related to a delay in notice, as well as a copy of any notice transmitted following such determination, for no less than three years from the date when the records were made;

  4. The written policies and procedures required to be adopted and implemented pursuant to § 248.30(a)(5)(i) of this chapter until three years after the termination of the use of the policies and procedures;

  5. The written documentation of any contract or agreement entered into pursuant to § 248.30(a)(5) of this chapter until three years after the termination of such contract or agreement; and

  6. The written policies and procedures required to be adopted and implemented pursuant to § 248.30(b)(2) of this chapter for no less than three years after the termination of the use of the policies and procedures.

Changes to be made

  • Create a transfer-agent Reg S-P recordkeeping binder or index for records required under Subsection (k).
  • Add a section for written safeguards policies and procedures required by § 248.30(a)(1).
  • Add a section for detected unauthorized access to or use of customer information, including response and recovery documentation required by § 248.30(a)(3).
  • Add a section for customer-notification investigations and determinations required by § 248.30(a)(4), including the basis for each determination.
  • Add a section for any Attorney General delay documentation related to customer notice timing.
  • Add a section for copies of customer notices transmitted after notification determinations.
  • Add a section for service-provider oversight policies and procedures required by § 248.30(a)(5)(i).
  • Add a section for service-provider contracts or agreements entered into under § 248.30(a)(5).
  • Add a section for written disposal policies and procedures required by § 248.30(b)(2).
  • Define naming, dating, ownership, and storage conventions so records are maintained in an easily accessible place.
  • Define retention periods for each record category based on Subsection (k).
  • Cross-reference the safeguards, incident response, assessment, containment, customer notice, service-provider oversight, 72-hour vendor notice, and disposal workstreams.

Co-authored-by: Codex <noreply@openai.com>
JFWooten4 and others added 5 commits June 3, 2026 12:13
Co-authored-by: Codex <noreply@openai.com>
Co-authored-by: Codex <noreply@openai.com>
Co-authored-by: Codex <noreply@openai.com>
Co-authored-by: Codex <noreply@openai.com>
@JFWooten4
JFWooten4 marked this pull request as ready for review June 3, 2026 21:12
@JFWooten4
JFWooten4 merged commit 5194934 into main Jun 3, 2026
@JFWooten4
JFWooten4 deleted the Docusaurus branch June 3, 2026 21:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

🦕 How can we best serve the policy docs on a public URL?

1 participant