Guide

The FTC Safeguards Rule, explained for tax preparers

If you prepare tax returns for a fee, federal regulators consider your practice a financial institution. That surprises a lot of preparers, and it comes with a concrete obligation: a written, working information security program.

Wait, my tax office is a "financial institution"?

Under the Gramm-Leach-Bliley Act (GLBA), a "financial institution" isn't just a bank. The law covers businesses that are significantly engaged in financial activities, and the FTC (which enforces the law for companies outside banking regulators' reach) has long said that includes professional tax preparers, accountants, and similar practices that handle customer financial information.

The Safeguards Rule is the part of GLBA that says how those businesses must protect customer information. It was substantially strengthened in recent years, with most of the detailed requirements enforceable since June 2023.

What the Rule actually asks for

At its core, the Rule requires a written information security program appropriate to your size and complexity. The main building blocks:

  • A qualified individual. One named person responsible for overseeing the program. In a small firm this is usually an owner or a trusted outside provider, but someone must own it.
  • A risk assessment. Identify where customer information lives in your practice and what could reasonably go wrong.
  • Specific safeguards. This is where the Rule gets concrete: access controls, an inventory of data and systems, encryption of customer information at rest and in transit, multi-factor authentication for systems containing customer data, secure disposal, change management, and monitoring of who's accessing what.
  • Testing and monitoring. Verify your safeguards actually work, through continuous monitoring or periodic testing.
  • Staff training. Your people are the front line; they need security awareness training.
  • Vendor oversight. Choose service providers that can protect the data, and hold them to it in your agreements.
  • An incident response plan. A written plan for what you'll do when something goes wrong.
  • Keeping it current. The program must be reevaluated as your business and threats change.

The small-firm provisions

Firms that maintain customer information on fewer than 5,000 consumers are exempt from a handful of the more formal requirements, such as the written risk assessment, continuous monitoring/penetration testing, and annual written reporting. Two cautions, though:

  • The exemption trims paperwork; it does not remove the duty to have a security program with the core safeguards (MFA, encryption, access controls, training, vendor oversight, and the rest).
  • Client counts add up faster than people expect: count consumers across years, not just this season's returns.

Breach notification is now part of the deal

Since 2024, the Rule also requires notifying the FTC within 30 days of discovering a security event involving the unencrypted information of 500 or more consumers. That's in addition to any state breach-notification laws that apply, and separate from the IRS's expectation that preparers report data theft to their IRS Stakeholder Liaison quickly.

Where the WISP fits

The written information security plan (the WISP) is the document that ties all of the above together: your risk assessment, your safeguards, your people, your vendors, and your incident plan, in one place you can maintain and, if asked, show. The IRS reinforces the same expectation for tax professionals in Publication 4557 and its Publication 5708 template.

This guide summarizes the Rule in general terms as of the review date above. Requirements vary by firm and change over time; confirm your specific obligations with a qualified professional.

Want to know where your firm stands?

Start with our free WISP Readiness Checklist, or skip ahead and let us assess your practice and build the plan with you.

See our WISP service