The FTC Safeguards Rule for Accounting and Tax Firms: A Complete Plain-English Guide

Last reviewed 2026-07-04 · 9 min read

If you prepare tax returns or handle client financial data, the FTC Safeguards Rule is not optional and it is not new. It is federal law, in force today, and it applies to far more firms than most owners realize. This guide explains what the Rule actually requires, in plain language, without the fear tactics and without the jargon.

The Safeguards Rule sits under the Gramm-Leach-Bliley Act (GLBA) and is codified at 16 CFR Part 314. It requires "financial institutions" under the Federal Trade Commission's jurisdiction to develop, implement, and maintain a written information security program that keeps customer information secure and confidential.

9required program elements
June 2023fully enforceable
$53,088max penalty per violation

Why the Rule applies to accountants and tax preparers

The phrase "financial institution" sounds like it means banks. Under the FTC's definition it is far broader. A 2021 update to the Rule expanded the definition, and the FTC guidance explicitly lists "an accountant or other tax preparation service" as a covered business. If your firm helps clients with their finances or taxes and collects information to do it, you are almost certainly covered.

Customer information here means any record containing nonpublic personal information about a client that you handle to provide your service. Names, Social Security numbers, income figures, bank details, and the contents of a tax return all qualify. It does not matter whether you store it on a server, in the cloud, in your email, or in a filing cabinet.

If your firm helps clients with their taxes and collects information to do it, you are almost certainly covered.

The nine required elements of a compliant program

Section 314.4 of the Rule lists nine elements your information security program must include. This is the checklist regulators measure you against:

The small-firm exemption most owners miss

The Rule scales with size. A firm that maintains customer information on fewer than 5,000 consumers is exempt from a few of the heavier written requirements: the written risk assessment, the continuous-monitoring-or-penetration-testing obligation, the written incident-response plan, and the annual written report. Many small accounting practices fall under that threshold.

The trap in the small-firm exemption

The exemption removes the written formality of a few items, not the duty to keep client data secure. Core safeguards like MFA and encryption still apply. And the IRS separately requires paid tax preparers to have a WISP regardless of client count, so a small firm can be exempt from the FTC written risk assessment yet still be required to have a WISP.

When it took effect, and the newest obligation

The updated Rule became fully enforceable on June 9, 2023. Since then the FTC added a breach-notification requirement, effective May 13, 2024: a covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, of a security breach involving the unencrypted information of at least 500 consumers.

What this means for your firm

You do not need to become a security expert. You need a named person accountable for the program, a short set of safeguards actually turned on, a plan for when something goes wrong, and documentation that proves it. Most firms are closer than they fear on some elements and further than they think on others. The only way to know is to check each element honestly.

This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.

Frequently asked questions

Does the FTC Safeguards Rule apply to accountants?
Yes. The FTC defines "financial institution" broadly, and its guidance explicitly lists accountants and CPAs as covered. If your firm handles clients' nonpublic financial information, you are almost certainly covered, and you are responsible for building and maintaining a written security program to prove it.
Does it apply to tax preparers?
Yes, and tax preparers carry a second, separate obligation on top of the FTC Rule. Beyond being covered as a "financial institution," the IRS requires every paid preparer to maintain a Written Information Security Plan (WISP), tied to your PTIN and e-file participation, regardless of firm size. So a tax preparer has to satisfy both the FTC Safeguards Rule and the IRS WISP mandate, and keep both current, not just meet one.
What counts as customer information under the Rule?
Any record with nonpublic personal information about a client that you handle to provide your service: names, Social Security numbers, income, bank details, and the contents of a tax return. The format does not matter, whether server, cloud, email, or paper.
Is my firm too small to be covered?
No firm is too small to be covered, but firms with information on fewer than 5,000 consumers are exempt from a few written requirements (the written risk assessment, testing, written incident-response plan, and annual report). The core safeguards still apply, and the IRS WISP requirement applies to paid preparers regardless of size.
What are the nine required elements of the Safeguards Rule?
A Qualified Individual, a written risk assessment, designed safeguards (access controls, encryption, MFA, disposal, monitoring and more), regular testing, staff training, service-provider oversight, keeping the program current, a written incident-response plan, and an annual written report to leadership.
When did the FTC Safeguards Rule take effect?
The updated Rule became fully enforceable on June 9, 2023. A breach-notification amendment took effect May 13, 2024, requiring notice to the FTC within 30 days of a breach affecting at least 500 consumers.

Check your firm in 3 minutes

← All guides · All FAQs