Does the FTC Safeguards Rule Apply to Your Firm? Who Has to Comply

Last reviewed 2026-07-05 · 7 min read

The single biggest reason firms ignore the FTC Safeguards Rule is a misunderstanding of one phrase: "financial institution." It sounds like it means banks. Under the FTC's definition it means something much broader, and it very likely includes you.

June 2023enforceable now, not a future date
$53,088max penalty per violation
5,000consumer threshold for a few written waivers

The one-question test

Forget the label and ask one thing: does your firm collect or handle nonpublic personal information about individuals in order to provide a financial service? Tax returns, income figures, Social Security numbers, bank details, and financial statements all count. If the answer is yes, you are handling exactly the data the Rule exists to protect, and you are covered.

The test is not what you call yourself. It is whether you hold clients' nonpublic financial information.

Who is explicitly covered

A 2021 update widened the definition of "financial institution," and the covered categories now clearly include the accounting world:

If your practice touches tax or financial data for individuals, you are on this list in practice even if your exact title is not.

The excuses that do not work

None of these exempt you

Being a small or solo firm does not exempt you. A limited security budget does not exempt you. Having antivirus installed does not exempt you. And serving mostly business clients does not exempt you if you still handle individuals' nonpublic information. The Rule is about the data you hold, not your size, spend, or software.

The one real size-based break

The under-5,000-consumer exemption

If your firm maintains information on fewer than 5,000 consumers, you are exempt from a few of the written requirements: the written risk assessment, the testing obligation, the written incident-response plan, and the annual written report. You are not exempt from the Rule, and the core safeguards, including MFA and encryption, still apply.

The IRS layer on top

For tax preparers there is a second, separate obligation. The IRS requires paid preparers to maintain a Written Information Security Plan (WISP), tied to your PTIN and e-file participation, regardless of how many consumers you serve. So even a small tax firm that is exempt from the FTC's written risk assessment is still required by the IRS to have a WISP.

If you are covered, what next

Do not guess. Run the 3-minute check on this site to see which required elements you already meet and which are open, then work the gaps in order. Most firms are further along than they fear on some elements and further behind than they think on others.

This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.

Frequently asked questions

Does the FTC Safeguards Rule really apply to accountants?
Yes. The FTC's definition of "financial institution" explicitly includes accountants, tax-preparation services, and bookkeepers. If you handle clients' nonpublic financial information, you are covered.
Does it apply to tax preparers?
Yes, and more so. A tax preparer is covered by the FTC Safeguards Rule as a financial institution, and separately the IRS requires every paid preparer to keep a Written Information Security Plan (WISP) tied to your PTIN and e-file participation, no matter how few consumers you serve. That means two obligations to meet and keep current, which is why many preparers hand the whole program to a managed provider rather than track both themselves.
I am a small or solo firm. Am I too small to be covered?
No. There is no exemption from the Rule based on being small. Firms with information on fewer than 5,000 consumers are excused from a few written requirements, but the core safeguards still apply, and tax preparers still need a WISP.
I only serve business clients, not consumers. Am I still covered?
Very likely. If you handle nonpublic personal information about individuals in the course of your work, including owners, employees, or individual filers, you are handling the data the Rule protects.
I already have antivirus. Is that enough to comply?
No. Antivirus is one small control. The Rule requires a documented program with a Qualified Individual, access controls, MFA, encryption, training, vendor oversight, and more. Software alone does not satisfy it.
What if I outsource my IT to a provider?
You are still responsible for compliance. The Rule requires you to select providers capable of protecting client data and to require safeguards by contract. A provider can implement and document the program for you, but the obligation remains yours.

Check your firm in 3 minutes

← All guides · All FAQs