What Non-Compliance Costs: Penalties, Breach Reporting, and PTIN Exposure

Last reviewed 2026-07-04 · 7 min read

Non-compliance with the Safeguards Rule is not an abstract risk. It carries financial penalties, a federal reporting obligation when something goes wrong, and exposure to the credentials your practice depends on. Here is the real picture, without the scare tactics.

$53,088max civil penalty per violation
30 daysto report a qualifying breach
500consumers that trigger reporting

Civil penalties

Knowing violations of the FTC rules can carry civil penalties up to $53,088 per violation. That figure is adjusted for inflation each year, so it drifts upward. "Per violation" matters: exposure is not a single flat fine but can compound across affected records or repeated failures.

The 30-day breach-reporting duty

Since May 13, 2024, a covered financial institution must notify the FTC of a qualifying breach as soon as possible, and no later than 30 days after discovery. A qualifying event is the unauthorized acquisition of unencrypted customer information involving at least 500 consumers. The notice must include your firm's name and contact details, the types of information involved, the dates of the breach if known, the number of consumers affected, and a general description of the event.

Why encryption is a priority safeguard

The FTC reporting trigger is the acquisition of UNencrypted customer information. Properly encrypted data, where the key was not also accessed, can change whether an event is reportable at all. Encryption is not just a safeguard, it reduces your reporting exposure.

PTIN and e-file exposure

For tax preparers, the sharper risk is often not the fine. It is your credentials. Your PTIN renewal and IRS e-file participation assume a current Written Information Security Plan. Lacking one creates exposure around the very authorizations your practice runs on. Losing e-file eligibility mid-season is an existential problem for a tax firm in a way a fine is not.

For a tax firm, losing e-file eligibility mid-season is an existential problem in a way a fine is not.

The quieter costs

A breach at a firm that holds client financial data damages client trust and professional standing. Clients hand you their most sensitive information on the assumption you protect it. For a regulated practice, the reputational cost of a public breach, and the client departures that follow, often outweighs any regulatory penalty. There can also be state-level notification duties and professional consequences depending on your jurisdiction and credentials.

The point

None of this is meant to frighten you. It is meant to make the math obvious: the cost of closing the gaps is small and one-time. The cost of a penalty, a mandatory breach disclosure, a PTIN problem, or a client exodus is not. Compliance is the cheaper path by a wide margin.

This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.

Frequently asked questions

What is the maximum penalty for a Safeguards Rule violation?
Knowing violations of the FTC rules can carry civil penalties up to $53,088 per violation, a figure adjusted for inflation each year. Because it is per violation, exposure can compound.
Do I have to report a data breach, and to whom?
Yes. Since May 13, 2024, covered financial institutions must notify the FTC no later than 30 days after discovering a breach of unencrypted customer information affecting at least 500 consumers. State law may impose additional notification duties.
Can I lose my PTIN or e-file access over this?
PTIN renewal and IRS e-file participation assume a current WISP, so lacking one creates exposure around those authorizations. For a tax firm, losing e-file eligibility is often a bigger threat than a fine.
Does encryption change my breach-reporting exposure?
Yes. The FTC reporting trigger is the acquisition of unencrypted customer information. Properly encrypted data (where the key was not also accessed) changes whether an event is reportable, which is one more reason encryption is a priority safeguard.
Is compliance really cheaper than the alternative?
For almost every firm, yes, but not because getting compliant is trivial. Non-compliance is what is genuinely expensive: a civil penalty, a mandatory breach disclosure, a PTIN or e-file problem, and lost client trust are all costly and often recurring. Getting compliant and staying compliant is real, ongoing work: a written risk assessment, safeguards actually implemented and tested, staff training, vendor oversight, and a plan kept current as threats and rules change. The math still favors doing it, because the cost of doing the work, in-house or with a provider who handles it for you, is far smaller than the cost of a failure. The question is not whether to invest, but whether to carry that ongoing work yourself.

Check your firm in 3 minutes

← All guides · All FAQs