PogoWasRight.org

Menu
  • About
  • Privacy
Menu

GunnAllen Financial executives settle with SEC over charges they failed to protect confidential customer information

Posted on April 8, 2011 by pogowasright.org

The Securities and Exchange Commission has charged three former brokerage executives for failing to protect confidential information about their customers.

The SEC’s investigation found that while Tampa-based GunnAllen Financial Inc. was winding down its business operations last year, former president Frederick O. Kraus and former national sales manager David C. Levine violated customer privacy rules by improperly transferring customer records to another firm. The SEC also found that former chief compliance officer Mark A. Ellis failed to ensure that the firm’s policies and procedures were reasonably designed to safeguard confidential customer information.

Kraus, Levine, and Ellis each agreed to settle the SEC’s charges against them. This is the first time that the SEC has assessed financial penalties against individuals charged solely with violations of Regulation S-P, an SEC rule that requires financial firms to protect confidential customer information from unauthorized release to unaffiliated third parties.

“Brokerage customers should be able to trust that sufficient safeguards are in place to protect their private information from unauthorized access and misuse,” said Eric I. Bustillo, Director of the SEC’s Miami Regional Office. “Protecting confidential customer information is particularly important when a broker-dealer is winding down operations.”

Glenn S. Gordon, Associate Director of the Miami Regional Office, added, “Kraus and Levine violated the law by transferring customers’ private information without giving them reasonable notice to opt out. GunnAllen did not have adequate policies or procedures in place to safeguard client information, ignoring several red flags from security breaches at the firm in prior years.”

According to the SEC’s orders instituting administrative proceedings, Kraus authorized Levine to take information from more than 16,000 GunnAllen accounts to his new employer as the firm wound down operations in April 2010. Levine downloaded customer names and addresses, account numbers, and asset values to a portable thumb drive, and provided the records to his new employer after resigning from GunnAllen. The SEC found that the record transfer violated Regulation S-P because account holders were only informed about it after the fact. The cases against Kraus and Levine mark the first time that the SEC has charged individuals with Regulation S-P violations arising when a departing representative takes customer information to a new employer without providing sufficient notice and opt-out procedures.

According to the SEC’s order against Ellis, GunnAllen’s policies and procedures to protect customer information were vague and did little more than recite a provision of Regulation S-P known as the Safeguard Rule. There were several serious security breaches at GunnAllen from July 2005 to February 2009, including the theft of three laptop computers belonging to GunnAllen’s registered representatives and the unlawful access of its e-mail system by a terminated employee using stolen password credentials. Despite the security breaches, Ellis failed to revise or supplement GunnAllen’s policies and procedures for safeguarding customer information.

The SEC’s orders found that Kraus, Levine, and Ellis willfully aided and abetted and caused GunnAllen’s violations of Rule 30(a) of Regulation S-P under the Securities Exchange Act of 1934, and that Kraus and Levine willfully aided and abetted the firm’s violations of Rules 7(a) and 10(a) of the same regulation.

Without admitting or denying the SEC’s findings, Kraus, Levine, and Ellis each consented to the entry of an SEC order that censures them and requires them to cease and desist from committing or causing any violations or future violations of the provisions charged. Kraus and Levine have been ordered to pay penalties of $20,000 each, and Ellis has been ordered to pay a $15,000 penalty.

This case was investigated by Sue Curtin and Teresa Verges of the SEC’s Miami Regional Office in coordination with an examination of the firm conducted by Debra Williamson, George Franceschini, Steven Bilezikjian, Anson Kwong, Michael Nakis, William Tudor and Nicholas Monaco of the Miami office.

Source:  SEC

Related Materials:

  • SEC Order Against Marc A. Ellis
  • SEC Order Against Frederick O. Kraus
  • SEC Order Against David C. Levine
Category: BreachesBusinessFeatured News

Post navigation

← Privacy dispute tests Obama’s earlier promises
Arkansas State Supreme Court strikes down law prohibiting cohabitors from adopting →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information

RSS Recent Posts on DataBreaches.net

  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy