Back to Insights
RegulatoryUS·Oct 20266 min

The FTC Safeguards Rule and the Tax Sector: Moving Beyond Seasonal Awareness

While Cybersecurity Awareness Month serves as a timely IRS reminder, professional tax preparers must comply with permanent, federal statutory obligations, including the mandatory implementation of a Written Information Security Plan (WISP) under FTC regulations.

By T&C Consulting Group

1. Introduction: Awareness vs. Statutory Mandate

Every October, the United States Internal Revenue Service (IRS) aligns itself with the Cybersecurity Awareness Month campaign to remind both taxpayers and professional tax return preparers of the importance of protecting highly sensitive financial data. Along these lines, the Internal Revenue Service regularly encourages taxpayers to take simple steps to strengthen online security, with the clear intent of mitigating identity theft and widespread tax refund fraud. However, for professional tax practitioners, these recommendations do not constitute a mere catalog of optional best practices or passing seasonal initiatives. Instead, they represent the visible manifestation of a rigorous, permanent federal statutory framework that has governed the industry for more than two decades.

It is essential to avoid the common misconception that these data security requirements are recent legislative novelties or temporary trends. The information security obligations imposed on professional tax preparers are codified under the Federal Trade Commission (FTC) Safeguards Rule, originally promulgated under the authority of the Gramm-Leach-Bliley Act (GLBA) in 2002 and effective since May 2003. However, it is crucial to note that the highly specific technical requirements defining the modern WISP, such as detailed data encryption and multi-factor authentication, were formally introduced through FTC amendments that entered into force on June 9, 2023.

2. Historical Context: The Security Summit and the Evolution of Cyberthreats

To comprehend the current intensity of federal oversight regarding cybersecurity, it is necessary to examine the history and evolution of the cyberthreats that target the American tax system. In 2015, the IRS, alongside state tax administrators and private leaders from the tax software and preparation industries, formed the public-private alliance known as the Security Summit. This initiative was specifically engineered to combat systemic tax refund fraud driven by sophisticated identity theft rings.

As the Security Summit's initial countermeasures successfully secured the IRS's direct processing networks, cybercriminals adjusted their tactical approach. Realizing that breaching the central defenses of the federal government was increasingly difficult, they redirected their focus toward the systems of private tax practitioners. Tax preparation firms, ranging from multinational accounting practices to single-practitioner storefronts, store exceptionally valuable data deposits: Social Security numbers, bank routing information, payroll histories, and ownership records. Consequently, the weakest link in the tax data transmission chain became the primary target. Under these conditions, compliance with the FTC Safeguards Rule ceased to be an operational afterthought and emerged as the primary line of defense for the nation's financial and tax infrastructure.

3. The Regulatory Architecture: The FTC Safeguards Rule (16 CFR Part 314)

The primary legal cornerstone governing private tax return preparers is the FTC Safeguards Rule, codified in Title 16 of the Code of Federal Regulations (CFR), Part 314. Under the statutory terms of the Gramm-Leach-Bliley Act, any entity significantly engaged in financial services or financial advisory activities is legally designated as a "financial institution." Professional tax return preparers fall squarely within this regulatory definition, regardless of their annual revenue, business structure, or client volume.

The rule formally requires industry professionals to design and execute a documented information security plan to safeguard taxpayer information.

While all professional tax preparers are required to maintain a basic security program, the FTC Safeguards Rule provides a significant exemption. Under 16 CFR § 314.6, practices maintaining information on fewer than 5,000 consumers (defined strictly as individuals who obtain financial products or services for personal, family, or household purposes, thereby excluding commercial or corporate entities from this count) are exempt from certain formal requirements, such as producing written risk assessments, designing a formal written incident response plan, and submitting annual compliance reports.

4. The Written Information Security Plan (WISP)

The operational core of the FTC Safeguards Rule is the design, implementation, and continuous maintenance of a Written Information Security Plan (WISP). A WISP is far from a standard template downloaded from an online forum; it must be an active, tailored document that accurately reflects the operational realities and technological landscape of each individual tax practice.

To satisfy federal compliance audits, a WISP must comprehensively cover several mandatory operational areas:

  • Designating an Information Security Program Coordinator: Clearly appointing a specific employee or third-party consultant to oversee and enforce the data security program.
  • Risk Assessments: Performing continuous formal analyses of internal and external threats to the security, confidentiality, and integrity of client tax information.
  • Implementing Safeguards: Instituting specific controls to address identified risks, including data encryption both in transit and at rest, and strictly limiting sensitive data access to authorized personnel.
  • Regular Testing and Monitoring: Periodically auditing and testing the effectiveness of security protocols, hardware systems, and software safeguards.
  • Service Provider Oversight: Implementing contract clauses requiring all third-party vendors (such as cloud hosting partners or tax software companies) to maintain equivalent data protection standards.
  • Continuous Updates: Reviewing and adjusting the WISP to account for organizational changes, software upgrades, or newly identified digital threats.

5. Jurisdictional Boundaries: Distinguishing Private Preparer and Government Standards

Within the complex framework of federal tax administration, it is highly common to confuse different data protection rules. To prevent severe compliance failures, a clear line of demarcation must be drawn between the rules governing private tax preparation businesses and the standards mandated for public sector agencies that handle federal tax information.

Private tax return preparers are governed by the FTC Safeguards Rule, with practical implementation guidelines provided in IRS Publication 4557. Conversely, local, state, and federal government agencies that receive Federal Tax Information (FTI) directly from the IRS are governed by a distinct, strict compliance standard outlined in IRS Publication 1075. These public agencies have a different set of security obligations, which include mandatory annual employee training and security compliance certifications. In this context, IRS Publication 4557 details basic security steps for tax professionals and urges professionals to protect their clients and themselves, establishing the practical guide for tax professionals on safeguarding taxpayer data.

To outline these distinct regulatory paths and prevent audit confusion, the following comparative table of jurisdictional boundaries is presented:

CriteriaPrivate Sector: Publication 4557 (FTC Safeguards Rule)Government Agencies: IRS Publication 1075
Regulated PartiesPrivate tax return preparers, CPA firms, and tax software developers.Local, state, and federal governmental agencies receiving Federal Tax Information (FTI).
Oversight AuthorityFederal Trade Commission (FTC) in collaboration with the IRS.IRS Office of Safeguards.
Primary Legal BasisGramm-Leach-Bliley Act (GLBA) · 16 CFR Part 314.Internal Revenue Code (IRC) Section 6103.
Core ObligationDeveloping, implementing, and maintaining a customized Written Information Security Plan (WISP).Certifying annually that all agency employees understand and enforce secure physical and digital handling of FTI.
Security FocusOperational security, client file confidentiality, and business-level data breach prevention.Strict access controls, segregation of duties, physical facility security, and annual compliance reporting to the IRS.

IRS Publication 1075 must not be confused with IRS Publication 4557, as they are legally distinct instruments designed for entirely different institutional contexts.

6. The Consequences of Non-Compliance: Penalties and Credential Suspension

Failing to comply with the FTC Safeguards Rule exposes a professional tax practice to devastating legal, financial, and reputational damages. Safeguarding confidential information is, above all, a strict legal imperative. Federal Trade Commission regulations require professional tax preparers to create and enact security plans to protect client data. Every tax professional in the United States, whether a member of a major accounting firm or an owner of a one-person storefront, is a potential target. In the event of a cyberattack or data breach, if subsequent federal investigations reveal that a firm operated without a structured WISP, federal regulators can pursue severe administrative sanctions.

While the FTC remains the primary administrative body authorized to levy direct monetary fines for Gramm-Leach-Bliley Act violations, the IRS independently mandates data security as a compulsory condition for maintaining electronic filing privileges (EFIN). The IRS has the authority to suspend the Electronic Filing Identification Number (EFIN) of any tax professional found to be in violation of federal data protection standards. This process generally involves prior warning notices and opportunities to remedy deficiencies, except in cases of critical unmitigated security breaches or imminent risk of ongoing fraud. While the revocation of the Preparer Tax Identification Number (PTIN) or other serious professional credentials remains a possibility, such actions generally arise from subsequent disciplinary proceedings under Circular 230 for a lack of due diligence.

7. Practical Implications and Conclusion

Cybersecurity Awareness Month must be approached not as a fleeting annual event, but as a structured opportunity to review, test, and update data protection systems. Compliance with the FTC Safeguards Rule is a continuous legal duty that requires ongoing technical updates, professional guidance, and constant staff training.

Professional tax preparation practices must take immediate steps to audit their current compliance posture. Practitioners must ensure that they have a fully customized Written Information Security Plan (WISP) that complies with the detailed directives of IRS Publication 4557. Firms operating without a written plan face severe regulatory exposure, potential credential suspension, and extreme operational risk. In the modern financial and legal landscape, data security is no longer an auxiliary IT issue; it is one of the most critical legal obligations of professional practice.

Sources

  • irs.gov
  • irs.gov
  • irs.gov
  • irs.gov
  • irs.gov
  • irs.gov

Share this insight

LinkedInWhatsApp