SEC gets new data-protection mandate—but scope of 'proprietary' stays vague
H.R. 6161 — SEC Data Protection Act · Filed by David Scott (D-GA) · 21 cosponsors · Introduced Nov 19, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the SEC to adopt data protection policies within one year to safeguard sensitive, nonpublic proprietary information it receives from investment advisers. The SEC must establish procedures addressing when it requests such information, how it safeguards it based on sensitivity level, who can access it, and how it prevents unlawful use or disclosure.
Why we flagged it
The bill is a narrow procedural mandate requiring the SEC to establish internal data protection standards for information it receives from regulated entities. It is not a substantive policy change but a governance requirement focused on information security and confidentiality protocols.
What the text implies
- The bill does not define 'proprietary information' or 'sensitive, nonpublic' data, leaving the SEC broad discretion to determine scope—potentially shielding adviser misconduct evidence from disclosure if classified as proprietary.
- No requirement that data protection policies balance confidentiality against transparency or public-interest disclosure; SEC could restrict FOIA access or whistleblower protections under a broad confidentiality umbrella.
The full analysis lists 4 implications of this text.
Who stands to gain
investment advisers (reduced risk of proprietary information disclosure); large asset managers (competitive advantage if trade secrets are protected from regulatory leaks)