Skip to main content

Updated 5 min read

The FTC Safeguards Rule in Plain English: A Guide for Tax and CPA Firms

The short answer

If your firm prepares tax returns or keeps clients' financial information, the FTC Safeguards Rule applies to you. It asks for a written security plan (your WISP), one person in charge of it, MFA and encryption, staff training, an eye on your vendors and a plan for when something goes wrong. Firms holding information on fewer than 5,000 consumers can skip four parts, but not the written plan.

Two professionals working with laptops and calculators in a bright office

Plenty of firms are surprised the rule covers them at all. It comes from the Gramm-Leach-Bliley Act and talks about “financial institutions,” which sounds like banks, but the FTC counts tax preparers and accounting firms in that group. That includes firms that keep clients’ financial information for bookkeeping, payroll or advisory work. The updated rule has been in full effect since June 2023.

The Safeguards Rule checklist

The rule itself lists ten parts of an information security program:

  1. Put one person in charge: name a “Qualified Individual” to run the program.
  2. Write down your risks: what client information you have, where it lives and what could realistically go wrong.
  3. Put safeguards in place: the eight the rule names (listed below) to control those risks.
  4. Check that they work: monitor your systems continuously, or run a penetration test every year and vulnerability scans every six months.
  5. Train your team: regular, practical security training for everyone.
  6. Keep an eye on your vendors: choose ones that can protect client data, require it in their contracts and check on them from time to time.
  7. Keep the program current: adjust it as your firm, its technology and the threats change.
  8. Write an incident response plan: what you’ll do, and who does it, when something goes wrong.
  9. Report once a year: the Qualified Individual reports in writing to the firm’s owners or partners.
  10. Tell the FTC about a breach: within 30 days if unencrypted information about 500 or more consumers is taken (see below).

The Qualified Individual can be a partner, an office manager or an outside IT provider. If it’s an outside provider, someone senior at the firm still oversees their work.

The eight safeguards the rule names in step 3:

  • Give people access only to the client information their job needs.
  • Know what data, devices and systems you have.
  • Encrypt client information, both when it’s stored and when it’s sent.
  • If you build your own software, develop it securely.
  • Use multi-factor authentication (MFA) for anyone signing in to your systems.
  • Securely dispose of client information you no longer need, generally within two years of when it was last used.
  • Keep track of changes to your systems.
  • Log what people do on your systems, and watch for anything unusual.

If your firm is small

Firms that keep information on fewer than 5,000 consumers don’t have to do four of those ten: the written review of risks (step 2), the monitoring or testing schedule (step 4), the written incident response plan (step 8) and the annual written report (step 9).

Everything else still applies, including the written security program, the Qualified Individual, MFA and encryption. Even where they aren’t required, we’d still keep a short written review of risks and a one-page incident plan on file. A cyber insurer is likely to ask about both at renewal.

Where GLBA fits

The Safeguards Rule comes from the Gramm-Leach-Bliley Act (GLBA), the federal law that requires financial institutions to protect their customers’ information. The FTC’s rule is the part of it that covers financial businesses that aren’t banks, which is where tax preparers and accounting firms come in. So when a client, an insurer or a software vendor asks about GLBA, they almost always mean the Safeguards Rule.

For the tax and CPA firms we look after, our security practices are aligned with GLBA and the Safeguards Rule, and we help you write down what’s in place. The plan, and the decisions in it, stay yours.

If something goes wrong

Since May 2024, firms must tell the FTC within 30 days if they discover that unencrypted information about 500 or more consumers was taken without authorization. Information that was encrypted doesn’t count, as long as the encryption key wasn’t taken too. That’s one more reason encryption is near the top of the list.

California has its own breach notification law covering the clients themselves, so a real incident usually means talking to your attorney as well. If it happens, here’s how to handle the first hour.

Where the IRS fits in

The IRS expects tax professionals to protect taxpayer data and to have a written information security plan, usually called a WISP. The PTIN application and renewal form, Form W-12, asks preparers to confirm on line 11 that they know the law requires one, and in August 2026 the IRS and its Security Summit partners reminded tax professionals again.

IRS Publication 4557 explains the safeguards, and Publication 5708 includes a sample plan written for small tax and accounting practices. One well-written plan can cover both the IRS’s expectations and the FTC rule. Our step-by-step guide to writing a WISP walks through it.

Where to start

If this feels like a lot, these four steps cover most of the real risk:

  1. Turn on MFA for email, your tax software and any remote access.
  2. Check that your backups run, and that you can restore from them.
  3. Encrypt laptops, and send returns and statements through a secure portal instead of as email attachments.
  4. Write a short plan: who’s in charge, what you protect, and what you’ll do if something goes wrong. That’s the start of your WISP.

For what this looks like in a real office, see the seven gaps we find most often in accounting firms and our tax season IT checklist.

How we help

We help tax and CPA firms across Orange County with the day-to-day security the rule expects, and we’ll help you write the plan itself in plain language, sized to how your firm works. You won’t get a binder nobody reads, and we won’t push things you don’t need.

If you’d like to talk through where your firm stands, book a free IT check-in. You can also read more about our IT support for accounting and CPA firms.

This guide is general information, not legal advice. For questions about your firm’s specific obligations, talk to your attorney or compliance advisor.

Sources

  1. FTC Safeguards Rule: What Your Business Needs to Know (FTC)
  2. 16 CFR Part 314: Standards for Safeguarding Customer Information (eCFR)
  3. Safeguards Rule notification requirement now in effect (FTC, May 2024)
  4. IRS Publication 4557, Safeguarding Taxpayer Data
  5. IRS Publication 5708, Creating a Written Information Security Plan for your Tax and Accounting Practice
  6. IRS Form W-12 (Rev. October 2025), line 11
  7. IR-2026-92: IRS and Security Summit remind tax pros they need a written information security plan (August 18, 2026)

Frequently asked questions

Does the FTC Safeguards Rule apply to small tax practices?
Yes. The FTC treats tax preparers, CPA firms and bookkeepers who handle client financial information as financial institutions under the Gramm-Leach-Bliley Act. Firms that hold information on fewer than 5,000 consumers are excused from a few requirements, but not from having a written security program.
What is a WISP?
A Written Information Security Plan. It describes how your firm protects client information, who is responsible for it, and what you'll do if something goes wrong. The FTC rule calls for a written security program, and the IRS expects tax professionals to have a written plan too, so one well-written plan can cover both.
Is the FTC Safeguards Rule the same as GLBA compliance?
Close to it. The Gramm-Leach-Bliley Act (GLBA) is the law, and the Safeguards Rule is the FTC's rule under it for protecting customer information at businesses like tax and accounting firms. So for a firm like yours, the security side of GLBA mostly means following the Safeguards Rule. GLBA also has separate privacy notice rules, which are worth checking with your attorney. This is general information, not legal advice.
Do we need a full-time security person?
No. The rule asks you to name a Qualified Individual to oversee your security program. That can be someone at your firm or an outside provider. If you use a provider, someone senior at your firm still needs to oversee their work.
What happens if client data is stolen?
If unencrypted information about 500 or more consumers is taken without authorization, you must notify the FTC within 30 days of discovering it. California has its own rules for notifying the affected clients as well.