SEC’s Default E-Delivery Proposal Shifts the Focus from Consent to Compliance Controls

AUG 11, 2026 | PRACTUS LLP

SEC’s Default E-Delivery Proposal Shifts the Focus from Consent to Compliance Controls

Authored by Robert Moreiro

The SEC’s e-delivery proposal would shift the compliance question from whether investors consented to whether firms can document and manage the controls behind electronic delivery.

What the SEC’s E-Delivery Proposal Would Do

On July 16, 2026, the Securities and Exchange Commission proposed Regulation E-Delivery. It would allow issuers, broker-dealers, investment advisers, investment companies, transfer agents, and other persons with federal securities-law delivery obligations to use electronic delivery as the default for covered disclosures. The SEC published the proposal in the Federal Register on July 21, 2026. Comments are due September 21, 2026.

Why the SEC’s E-Delivery Proposal Matters

The proposal could meaningfully change how firms deliver investor disclosures, but it would not take effect automatically. Until the SEC adopts a final rule and compliance dates arrive, existing delivery requirements apply. Even then, most firms could choose whether to use the default e-delivery framework—but any firm that does would have to satisfy the framework and all of its conditions.

What Firms Need to Assess Before Using Default E-Delivery

For firms that deliver investor disclosures at scale, the proposal is not simply a move toward digital delivery. It would require firms to evaluate whether their existing systems can support a defensible default-electronic delivery model. That means looking beyond delivery preference and assessing whether the firm can support appropriate address use, disclosure classification, paper election rights, secure access, and timely remediation when delivery fails.

What Information Would Be Covered by the SEC’s E-Delivery Proposal?

Proposed Regulation E-Delivery, which would be codified at 17 C.F.R. §§ 303.100–303.104, would apply to “covered information” required to be delivered to a current or prospective customer, client, investor, security holder, counterparty, or similar recipient under the federal securities laws. While deliberately broad, it is not a general electronic-communications safe harbor. For instance, the rule would not govern information merely filed with the Commission or delivery obligations that arise solely under FINRA, other self-regulatory organizations, state, tax, or other non-SEC regimes. An SRO rule incorporating SEC electronic-delivery standards may be affected indirectly.

What the Proposal Would Not Cover or Change

The proposal expressly excludes Regulation Crowdfunding materials, Rule 15c2-11 information, and the security-based swap trade-acknowledgment rule. It also would not change the required content, timing, antifraud, privacy, cybersecurity, fiduciary, or record-retention rules applicable to the underlying disclosure. The Commission proposes related changes to the fund shareholder-report, proxy, information-statement, and tender-offer frameworks, including rescission of Investment Company Act Rule 30e-3.

Before turning to the mechanics of the proposed framework, several practical points stand out for firms evaluating whether default e-delivery could work in practice.

Key Takeaways

  • The proposal would not change current delivery rules yet. Existing SEC delivery requirements and guidance would continue to apply unless and until a final rule becomes effective. Most firms could keep using paper delivery or affirmative-consent electronic delivery.
  • Affirmative consent would no longer be the main threshold. Instead, firms would need a recipient-provided or accepted electronic address, required advance disclosure, and no opt-out. The proposal would provide a limited exemption from E-SIGN consumer-consent requirements only for covered information delivered in compliance with Regulation E-Delivery.
  • Firms would need to prove where electronic addresses came from. The proposal focuses on whether the recipient provided or accepted the address for the covered entity’s disclosures. Firms should carefully review affiliate, intermediary, clearing, and legacy-data arrangements.
  • PFI would determine how information can be delivered. Non-PFI materials could be delivered directly or through a statement of availability. Materials containing personal financial information would need to be accessed through a safeguarded website or portal after a statement of availability.
  • Paper delivery would remain available. Recipients could elect paper delivery for any or all covered information, without charge, and request historical paper copies. Firms generally would have three business days to fulfill a request unless another federal rule provides a different timeline.
  • Transitioning paper recipients would take time. For recipients receiving paper as of the rule’s effective date, firms generally would need to provide an initial paper notice at least 180 days before default electronic delivery and a follow-up paper notice 30 days before the transition date.
  • Delivery failures would require documented controls. Firms would need written policies to identify and remediate failed electronic delivery. The regulated entity would remain accountable even when a vendor performs the delivery function.

How the SEC’s Proposed E-Delivery Framework Would Work

At a high level, the proposed framework would require firms to confirm the recipient’s electronic address, determine whether the information includes personal financial information, preserve paper and access rights, and maintain controls for failed delivery or website outages. It also includes transition rules for moving existing paper recipients into a default electronic-delivery model.

Step 1: Confirm the Recipient’s Electronic Address

A covered entity could use default electronic delivery only if the covered recipient has provided—or accepted for use—an electronic address to receive covered information and has not opted out. Email addresses, mobile numbers, application inboxes, portal inboxes, and similar identifiers may qualify. Before relying on the rule, the entity generally would have to provide a clear and conspicuous disclosure describing the types of covered information to be delivered electronically, the electronic-delivery methods it may use, and, where applicable, any consequences of requesting paper or opting out.

Because default e-delivery depends on the address the recipient provided or accepted, address governance would become the rule’s gateway. A firm would need a defensible answer to four related questions: who collected the address, for which relationship it was collected, which delivering entity may use it, and what the recipient was told. That inquiry may be particularly difficult in financial groups, introducing-clearing relationships, intermediary networks, wrap programs, and private-fund structures.

Step 2: Determine Whether the Disclosure Contains PFI

The proposal defines personal financial information (PFI) as information specific to a covered recipient’s personal financial matters, such as an account number or details of a particular securities transaction. PFI is a proposed delivery classification, not a term firms should assume is interchangeable with their existing Regulation S-P taxonomy. That distinction matters because it determines the delivery pathway:

Content Permitted delivery Core condition 
No PFI Direct delivery to the electronic address, or a statement of availability. Direct delivery must include the required notices and provide the information in a widely available, readable, printable, permanently retainable format. 
Contains PFI Statement of availability linking to a safeguarded website or portal. The recipient must complete a process reasonably designed to safeguard the PFI before the link leads directly to the covered information. 

Source: Proposed Regulation E-Delivery §§ 303.101–303.103.

When a firm uses a statement of availability, the notice itself would have to meet specific content and separation requirements.

A statement of availability must identify the sender and available information, flag any time-sensitive action, provide the website address, and explain paper-copy, opt-out, and address-update rights. Like direct delivery, a statement of availability generally must be sent separately from non-covered communications. The proposal permits a single statement to cover multiple items, but not a marketing message wrapped around a regulatory notice.

Step 3: Preserve Paper Rights, Website Access, and Failure Controls

  • Paper-copy and opt-out rights. Recipients could request one paper copy without charge for the applicable federal retention period—or, if none applies, the preceding two years—and could opt out for any or all covered information at any time. An opt-out must be honored promptly.
  • Website availability. When the statement-of-availability method is used, PFI materials generally must remain available for at least three years and non-PFI materials for at least one year, unless another federal rule supplies a different period. An SEC filing system alone would not qualify as the delivery website.
  • Access and retention. Website materials must be readable online, printable, and available for permanent electronic retention without charge. PFI requires a reasonable safeguard; the proposal does not prescribe a particular authentication technology.
  • Controls for delivery failures and website outages. Written policies and procedures must address both. An identified delivery failure requires prompt reasonable remediation, including obtaining a new electronic address or using paper until one is provided. Temporary website unavailability does not itself defeat compliance if the entity maintains availability procedures and promptly restores access after it knows or reasonably should know of the interruption.

Transition Timing for the SEC’s Proposed E-Delivery Framework

If a recipient is receiving covered information on paper as of the rule’s effective date and the firm already has an electronic address, the firm generally would need to send two stand-alone paper notices before moving that recipient to default electronic delivery. The initial notice would be due at least 180 days before the transition, followed by a second notice 30 days before the transition date. The notices must identify the types of information, the electronic address to be used, the delivery methods, the opt-out and address-update process, and the prospective transition date. A recipient who updates or confirms an electronic address after receiving the initial notice may be moved earlier, if the other conditions are met.

The Commission proposes a rule effective date 60 days after publication of a final rule and a two-year interim period before rescission of the 1995 and 1996 Commission e-delivery guidance. The proposal also would retain much of the 2000 guidance, rescind Rule 30e-3, and amend certain proxy, information-statement, and tender-offer rules to accommodate the new framework.

What the SEC E-Delivery Proposal Means for Market Participants

  • Investment Advisers and Private Fund Managers: Address Governance and Disclosure Scope. Brochures, Form CRS where applicable, and other required communications may be within scope. The question of which affiliate or manager may rely on an address will require careful governance in multi-entity structures.
  • Broker-Dealers and Dual Registrants: PFI, Confirmations, and Portal Delivery. Trade confirmations and other account-specific communications will often contain PFI and therefore require a portal-based pathway. Firms must also keep separate the federal securities-law delivery obligation from FINRA-only, state, tax, and contractual obligations.
  • Funds, Issuers, and Proxy Participants: Shareholder Reports, Proxy Materials, and Tender Offers. The proposal would reshape shareholder-report, proxy, information-statement, tender-offer, and intermediary-delivery practices. For proxy materials, it would eliminate the paper Notice of Internet Availability option, the business-combination exclusion, and the associated 40-day deadline, while requiring certain shareholder and beneficial-owner lists to include available electronic addresses. The effects on dissidents and third-party bidders merit separate operational review.
  • Service Providers and Financial Groups: Vendor Oversight and Delivery Controls. Vendor agreements and oversight should cover address provenance, document classification, preference synchronization, notice timing, access controls, availability, paper-service levels, outage response, records, subcontractors, and audit rights. Delegation does not transfer the legal delivery obligation.

What Firms Should Do Now to Prepare for the SEC E-Delivery Proposal

The rule remains proposed, but firms can use the comment period to test whether their systems could support default electronic delivery. A focused readiness assessment can identify operational constraints, governance gaps, and issues that may warrant comment. Priority workstreams include:

  • Inventory SEC delivery obligations. Map each required communication to its governing law, recipient, deadline, channel, retention period, and owner. Separate SEC obligations from FINRA, state, tax, and voluntary communications.
  • Trace electronic-address sources and permitted use. Identify the source, purpose, holder, and permitted use for each recipient address, including addresses supplied by an affiliate, intermediary, or vendor.
  • Classify documents for PFI and delivery method. Establish a workable PFI taxonomy and process that joins legal analysis with communications, operations, and cybersecurity controls.
  • Test paper, opt-out, and preference processes. Confirm that systems can receive and synchronize global and document-specific paper elections, update addresses, retrieve historical documents, and meet the proposed service level.
  • Assess delivery evidence, failures, and remediation controls. Test templates, statement-of-availability content, authentication, printability, retention, bounce-back queues, outage recovery, and evidence of remediation.
  • Focus SEC comments on operational tradeoffs. Address-source restrictions, PFI definition, separate-message requirements, paper turnaround, granular opt-outs, transition notices, and small-entity timing are natural targets for fact-based comment.

SEC E-Delivery Proposal FAQs

Is the SEC’s Regulation E-Delivery proposal final?

No. It is a proposal. Current delivery obligations and the Commission’s existing guidance remain controlling unless and until a final rule and applicable compliance dates take effect.

Would firms be required to use default electronic delivery under the SEC proposal?

No. Proposed Regulation E-Delivery generally would be optional. A firm could continue using paper or an affirmative-consent electronic-delivery model, subject to the rules otherwise applicable to the underlying information.

Is an onboarding email address enough for SEC default e-delivery?

Potentially, but not automatically. The proposal requires an electronic address the recipient has provided—or accepted for use—to receive covered information. Firms should not assume that an address received from an affiliate, intermediary, or third party qualifies for every delivering entity or communication.

Does PFI mean the same thing as nonpublic personal information under Regulation S-P?

Not necessarily. PFI is a distinct proposed term focused on information specific to the recipient’s personal financial matters. A firm will need to assess the proposal’s definition rather than simply re-label an existing Regulation S-P classification.

Can investors keep receiving paper disclosures under the SEC e-delivery proposal?

Yes. The recipient could opt out of electronic delivery for any or all covered information at any time and receive paper free of charge. The proposal also provides a right to requested historical paper copies.

What happens if electronic delivery fails under Regulation E-Delivery?

A bounce-back, invalid address, or other identified failure would require prompt reasonable remediation. The rule contemplates obtaining a new electronic address or delivering paper until the recipient supplies one.

Does SEC Regulation E-Delivery replace FINRA or state delivery requirements?

No. It addresses federal securities-law delivery obligations. Requirements imposed solely by FINRA, state law, tax law, another federal regulator, or contract remain subject to their own frameworks unless separately amended or incorporated.

Conclusion

Regulation E-Delivery would make electronic delivery easier to begin but more exacting to administer. Its practical value will depend on whether firms can connect legal requirements with address governance, content classification, user preferences, secure access, paper fulfillment, and exception handling. Firms should use the comment period to test those controls against their actual recipient populations, systems, and delivery arrangements, not simply against an idealized digital workflow.

About Robert Moreiro

Robert Moreiro is a financial services attorney with more than 20 years of experience advising registered investment advisers, broker-dealers, and associated persons on securities regulation, compliance, and enforcement matters. He counsels clients on SEC, FINRA, state registration, compliance policies, CCO matters, and regulatory examinations and investigations. Robert has served as an expert witness in FINRA arbitration, is recognized in the 2025 and 2026 editions of The Best Lawyers in America for Securities Regulation, and holds the Investment Adviser Certified Compliance Professional and Certified Securities Compliance Professional designations.

The Authors
Robert Moreiro
Read Full Bio

Practus, LLP provides this information as a service to clients and others for educational purposes only. It should not be construed or relied on as legal advice or to create an attorney-client relationship. Readers should not act upon this information without seeking advice from professional advisers.

Search Icon