SEC Reg E-Delivery: Are You Ready?

SEC Reg E-Delivery: Are You Ready?

financial services email
Regulatory Update · Broker-Dealer Compliance

SEC Proposes Regulation E-Delivery: Are You Ready?

A new SEC rule would flip electronic delivery from opt-in to opt-out; here's what it means for your compliance program.

By Maria Minguez, Senior Consultant, MCG Consulting  |  Updated August 2026
Compliance professional reviewing electronic delivery regulations and standards on a laptop

OOn July 16, 2026, the SEC proposed Reg E-Delivery: a sweeping new SEC rulemaking effort that would replace the Commission's decades-old, guidance-based approach to electronic delivery with one codified framework. This SEC proposal would apply across the federal securities laws, and it would reach every covered entity, including broker-dealer firms. If adopted, it would mark the biggest shift in fintech compliance and client communications, confirms, statements, and disclosures in a generation.

So, what's actually in the proposal? And what should your compliance program do about it right now? Let's break it down.

First, a quick disclaimer: this is a proposed rule, not a final one. It has no compliance date yet, and its terms could still change before adoption. So, treat this as a planning signal, not a checklist to implement today.

Why Is the SEC Doing This?

Here's the Commission's logic: paper-by-default, e-delivery-by-opt-in no longer matches how most investors actually want their information. Instead, it just adds cost, for issuers, for intermediaries, and ultimately, for investors themselves.

Chairman Paul Atkins called it part of a broader modernization push. Meanwhile, SEC Division of Investment Management Director Brian Daly pushed the point further: a simple swap from paper to emailed PDFs, he warned, would be a disappointing outcome. In other words, the SEC wants more than a digital copy of an old process; it wants interactive, personalized disclosure, eventually.

The proposal is ambitious in scope, too. Reg E-Delivery isn't limited to confirms and statements; it's built as a standalone framework covering delivery obligations under the Securities Act, the Exchange Act, the Trust Indenture Act, the Investment Company Act, and the Investment Advisers Act. Therefore, compliance teams shouldn't scope this narrowly: the rule's reach goes well beyond any single document type.

The Core Mechanics: How It Would Work

At its core, Reg E-Delivery lets "covered entities," a group that includes broker-dealers, investment advisers, and issuers, use e-delivery as the default method. No opt-in consent required. That's the headline change: consent-by-default flips to delivery-by-default, provided certain conditions are met.

Three Conditions for the Default to Apply:

  • The recipient has provided an electronic address;
  • The entity has clearly disclosed it will send information to that address; and
  • The recipient hasn't opted out.

Beyond that, the proposal sets rules for timing, opt-out mechanics, the recipient's right to a free paper copy, and requirements for any website used to host delivered content.

Two Delivery Methods: PFI Is the Dividing Line

Here's where it gets operationally tricky for broker-dealers, since so much client communication touches account data:

  • No personal financial information (PFI): direct delivery is fine, whether as an email attachment or embedded content.
  • Includes PFI: direct delivery isn't allowed. Instead, the firm must send a notice of availability, essentially, an email with a link to a secure webpage. Firms may also use this method for non-PFI content, if they'd rather run one consistent workflow.

Confirms and account statements likely touch PFI. So, classifying every communication type is a necessary first step, before any delivery-method decision can be made.

Don't overlook PACI. The proposal introduces a companion term: "Publicly Accessible Covered Information," or PACI, for content that carries no personal data and is therefore suitable for the notice-of-availability method. PFI, however, is defined broadly; it can sweep in account and transaction details for entities, not just individuals. So, a trust or corporate account isn't automatically exempt just because there's no individual investor involved.

Two controls follow directly from this PFI/non-PFI split:

  • If PFI is hosted online, firms need real safeguards: password protection or multi-factor authentication, not a bare, unauthenticated link.
  • If a firm chooses direct delivery, it needs a screening process first, to confirm no PFI is embedded before anything goes out.
Decision flow: does the communication contain personal financial information? Communication to Deliver Contains PFI? No Direct e-delivery allowed (email attachment or embedded content) Yes Notice of availability required (secure link to hosted content)
Figure 1: Reg E-Delivery's PFI-based routing decision for every outbound communication.

One more wrinkle: "electronic address" means more than email. It also includes a mobile phone number, or any electronic means capable of alerting a recipient that something was sent, including delivery through a mobile app. So, if your firm already uses SMS or in-app notifications, factor that channel into your planning now, not later.

Baseline Operating Conditions: What Firms Would Actually Have to Build

Beyond the three threshold conditions, covered entities relying on default e-delivery would generally need to:

  • Maintain a valid electronic address for each recipient, and update it as changes occur;
  • Adopt reasonable policies to keep those addresses accurate over time;
  • Investigate transmission failures, whenever notified that a delivery didn't go through;
  • Give recipients an easy way to request paper copies or update preferences; and
  • Keep records that demonstrate compliance.

Bounce-detection isn't a footnote; it's a build. The proposal requires written procedures specifically for catching and fixing failed e-delivery, including bounced or dead addresses. Remediation must be prompt, too: think, obtaining a new address, or reverting to paper until one's provided. In short, firms will need bounce-detection logic, an escalation path, and a documented fallback-to-paper trigger, likely wired into existing CRM and recordkeeping systems.

The Transition Process for Current Paper Recipients

What about clients who currently receive paper? Reg E-Delivery lays out a specific transition path, and it's fairly prescriptive:

  1. Initial notice (paper, mailed to the recipient's last known address): sent at least 180 days before the transition date. It must name the electronic address to be used, describe what's moving to e-delivery, explain the delivery methods, and spell out opt-out, paper, and address-update rights.
  2. Follow-up notice (also paper): sent 30 days before the transition date, covering the same content.
180-day and 30-day paper-to-electronic transition notice timeline Day −180 Initial paper notice mailed standalone Day −30 Follow-up paper notice same content required Day 0 Transition date e-delivery begins
Figure 2: The two-notice runway required before converting a paper recipient to default e-delivery.

The initial notice must stand alone; it can't be bundled into another mailing. However, if a recipient confirms or updates their electronic address in response, the firm can move faster than the full 180-day window. One catch: this transition mechanism can't be reused for a recipient who's already chosen to stay on paper once.

Bottom line: firms with a sizable paper-based client base should treat the 180-day/30-day sequence as a real mailing-logistics project, not just a policy update.

E-SIGN Act Relief

Here's some good news: where Reg E-Delivery would otherwise trigger consent requirements under the federal E-SIGN Act, the proposal exempts that information from E-SIGN entirely. As a result, firms would no longer need to reconcile two overlapping consent frameworks. The Commission is relying on its exemptive authority under E-SIGN Act Section 104(d)(1), a point worth citing directly in any comment letter.

Who Counts as a "Covered Recipient"?

Don't undersell the scope here. "Covered recipient" isn't limited to active clients; it extends to legal representatives, designees, and anyone owed post-relationship delivery, such as former clients still entitled to Regulation S-P privacy notices. So, if your e-delivery planning only covers active accounts, widen the lens: any obligation that survives account closure needs the same electronic-address and opt-out infrastructure as current clients get.

Related Rule Changes Bundled Into the Proposal

  • Rescission of Investment Company Act Rule 30e-3: currently gives funds an alternate method for shareholder report transmission. Relevant if your firm distributes fund shareholder reports.
  • Amendments to Regulations 14A and 14C, and Exchange Act Rule 14d-5: affecting how proxy and tender offer materials get disseminated.

Comment Period and Key Dates

MilestoneDate
ProposedJuly 16, 2026
Comment deadlineSeptember 21, 2026 (60 days post-publication)
Effective date, if adopted60 days after final rule publication
Compliance runwayTwo-year interim period, under existing or new guidance

File No. S7-2026-25; Release Nos. 33-11430; 34-105921; 39-2564; IA-6980; IC-36252. Still, double-check the comment deadline against the Federal Register notice before locking in internal timelines; comment periods do get extended, occasionally.

Compliance Planning Checklist

  • Inventory every delivery obligation: confirms, statements, prospectuses, privacy notices, Reg BI disclosures, and anything that survives the client relationship.
  • Flag PFI-bearing communications; remember, PFI can attach to entity accounts, not just individuals.
  • Design a PFI screening control, for any direct-delivery communications.
  • Confirm safeguards, like password protection or MFA, for PFI hosted via notice-of-availability.
  • Assess electronic address coverage; plan for mobile numbers and in-app delivery, not just email.
  • Build bounce-detection and remediation workflows, with a documented paper fallback.
  • Model the 180-day/30-day transition-notice workflow with your mail vendor.
  • Review opt-out tracking and free-paper-copy fulfillment, at the recipient level.
  • Watch the 30e-3 rescission, plus the proxy and tender offer amendments.
  • Prepare, or coordinate, a comment letter before September 21, 2026.

Bottom Line

Reg E-Delivery is a fundamental shift: opt-in becomes opt-out, across the federal securities laws. It's also a change broker-dealer compliance teams have seen coming for years, as investor preferences shifted toward digital. The proposal is thoughtfully built, too: PFI versus non-PFI, transition notices, E-SIGN harmonization all point to a workable rule, not just a permissive one.

Still, "proposed" is doing a lot of work in that sentence. Use the comment period wisely: pressure-test this against your actual client communication infrastructure, and raise any operational gaps with the Commission, before the rule gets finalized.

Need Help Scoping Your E-Delivery Readiness?

MCG Consulting helps broker-dealers turn proposed SEC rules into concrete, auditable compliance programs, before they become mandatory.

Talk to Our Compliance Team
SEC Regulation E-DeliveryBroker-Dealer ComplianceElectronic Delivery RuleFinancial Regulatory ComplianceReg BIRegulation S-P
Sources: SEC.gov, "Electronic Delivery of Information Under the Federal Securities Laws," Release Nos. 33-11430 et al., File No. S7-2026-25 (proposed July 16, 2026); SEC Fact Sheet, "Electronic Delivery of Information Under the Federal Securities Laws"; Dechert LLP, "Signed, Sealed, E-Delivered: The SEC's Proposed Regulation E-Delivery, Unpacked" (OnPoint, August 3, 2026). This post is for informational purposes only, and does not constitute legal advice.