Subpoenas are not suggestions
The most significant event this week isn't a fine for a missed filing, but a fight over the files themselves. The SEC has moved to enforce a subpoena against ISS, the proxy adviser. When a regulator sues you simply because you refused to hand over documents, they aren't just looking for data; they're asserting dominance.
The claim from firms in this position is usually that they're protecting client confidentiality or maintaining "independence". It sounds noble in a brochure. However, the evidence here suggests a simple refusal to comply with a legal demand. The implication is clear: if you believe your status as an industry gatekeeper exempts you from the discovery process, you've fundamentally misunderstood who holds the power.
One might argue that this is a heavy-handed approach that could chill the independence of proxy advice. That’s a convenient shield. In reality, the SEC's power to compel production is well-established; ignoring it isn't "independence", it's a gamble on the regulator's patience. The second-order effect here is where it gets interesting. Other proxy advisers who have spent years quietly resisting similar requests will now realise their shield has a hole in it. They'll be wondering if they're next on the list for an enforcement action.
Across the channel, the CNIL has reminded us that hospitals are perpetually terrible at data security. A French hospital has been fined €500,000 after a breach exposed just over 727,000 records. The press release will undoubtedly mention "the fundamental right to privacy", but the actual rule violated is usually far more boring: someone forgot to patch a server or left a database open.
It's a tidy sum for a hospital, though the real cost isn't the fine; it's the audit they'll now have to endure to prove they can actually lock a digital door.
Then we have the SEC moving to scrap the "Pay-to-Play" rule regarding political donations by investment advisers. It's a rare moment of regulatory retreat. For years, firms have had to track every penny sent to a political campaign to ensure it wasn't a thinly veiled bribe for government contracts. Now, the paperwork is becoming optional. I suspect this isn't because the SEC has suddenly grown trustful, but because they've realised the rule was an administrative nightmare that produced very little usable evidence of actual corruption.
Finally, those dealing with crypto assets in Thailand should mark their calendars. The SEC there has finalised the Travel Rule. It doesn't take effect until February 2027.
That gives firms nearly two years to figure out how to attach identity data to every transfer. Most will wait until January 2027 to start worrying about it. I imagine they'll find that rather optimistic.
One has to wonder if the SEC's sudden appetite for repealing donation rules is a strategic pivot to free up resources for more aggressive pursuits, like chasing proxy advisers who won't talk. I'll be watching whether other "nuisance" rules are quietly deleted over the next quarter.
Sources
The reporting this piece was written from. Check the originals before relying on anything here.
- Why the SEC Should Repeal Its Climate Disclosure Rule - The National Interest Compliance Week (Google News)
- CNIL Fines French Hospital €500K, 727K Records Hit [2026] - tech-insider.org Data Privacy (Google News)
- SEC Moves to Nix Rule on Investment Adviser, Political Donations - bloomberg.com Compliance Week (Google News)
- ISS Faces SEC Enforcement Action Over Document Refusal - coinfomania.com Compliance Week (Google News)
- Thailand’s SEC finalizes crypto Travel Rule, effective February 2027 - Bitget Compliance Week (Google News)
- Nutex Health Confirms Sensitive Data Stolen in August Cyberattack - The HIPAA Journal InfoSec Compliance (Google News)
- ICE plans for robodogs met with concern by privacy experts - FedScoop Data Privacy (Google News)
- SEC Moves to Scrap the Pay-to-Play Rule - thewealthadvisor.com Compliance Week (Google News)