The FTC Safeguards Rule for Accounting and Tax Firms: A Complete Plain-English Guide
Last reviewed 2026-07-04 · 9 min read
If you prepare tax returns or handle client financial data, the FTC Safeguards Rule is not optional and it is not new. It is federal law, in force today, and it applies to far more firms than most owners realize. This guide explains what the Rule actually requires, in plain language, without the fear tactics and without the jargon.
The Safeguards Rule sits under the Gramm-Leach-Bliley Act (GLBA) and is codified at 16 CFR Part 314. It requires "financial institutions" under the Federal Trade Commission's jurisdiction to develop, implement, and maintain a written information security program that keeps customer information secure and confidential.
Why the Rule applies to accountants and tax preparers
The phrase "financial institution" sounds like it means banks. Under the FTC's definition it is far broader. A 2021 update to the Rule expanded the definition, and the FTC guidance explicitly lists "an accountant or other tax preparation service" as a covered business. If your firm helps clients with their finances or taxes and collects information to do it, you are almost certainly covered.
Customer information here means any record containing nonpublic personal information about a client that you handle to provide your service. Names, Social Security numbers, income figures, bank details, and the contents of a tax return all qualify. It does not matter whether you store it on a server, in the cloud, in your email, or in a filing cabinet.
If your firm helps clients with their taxes and collects information to do it, you are almost certainly covered.
The nine required elements of a compliant program
Section 314.4 of the Rule lists nine elements your information security program must include. This is the checklist regulators measure you against:
- Designate a Qualified Individual to oversee and enforce the program. This can be an employee, an owner, or an outside provider. No specific title or degree is required, only real competence.
- Base the program on a written risk assessment that identifies the reasonably foreseeable internal and external risks to client information.
- Design and implement safeguards to control those risks, including access controls, an inventory of where data lives, encryption of data at rest and in transit, secure development practices, multi-factor authentication, secure disposal, change management, and activity monitoring and logging.
- Regularly test or monitor the effectiveness of your safeguards. In practice this means continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months.
- Train your staff with security-awareness training and keep them current on threats.
- Oversee your service providers: select ones capable of protecting the data, require safeguards by contract, and reassess them periodically.
- Keep the program current by evaluating and adjusting it as your business, systems, and threats change.
- Establish a written incident-response plan for a security event.
- Require your Qualified Individual to report in writing, at least annually, to your ownership or governing body.
The small-firm exemption most owners miss
The Rule scales with size. A firm that maintains customer information on fewer than 5,000 consumers is exempt from a few of the heavier written requirements: the written risk assessment, the continuous-monitoring-or-penetration-testing obligation, the written incident-response plan, and the annual written report. Many small accounting practices fall under that threshold.
The exemption removes the written formality of a few items, not the duty to keep client data secure. Core safeguards like MFA and encryption still apply. And the IRS separately requires paid tax preparers to have a WISP regardless of client count, so a small firm can be exempt from the FTC written risk assessment yet still be required to have a WISP.
When it took effect, and the newest obligation
The updated Rule became fully enforceable on June 9, 2023. Since then the FTC added a breach-notification requirement, effective May 13, 2024: a covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, of a security breach involving the unencrypted information of at least 500 consumers.
What this means for your firm
You do not need to become a security expert. You need a named person accountable for the program, a short set of safeguards actually turned on, a plan for when something goes wrong, and documentation that proves it. Most firms are closer than they fear on some elements and further than they think on others. The only way to know is to check each element honestly.
This is educational information, not legal advice. Confirm your specific obligations with a qualified professional.
Frequently asked questions
- Does the FTC Safeguards Rule apply to accountants?
- Yes. The FTC defines "financial institution" broadly, and its guidance explicitly lists accountants and CPAs as covered. If your firm handles clients' nonpublic financial information, you are almost certainly covered, and you are responsible for building and maintaining a written security program to prove it.
- Does it apply to tax preparers?
- Yes, and tax preparers carry a second, separate obligation on top of the FTC Rule. Beyond being covered as a "financial institution," the IRS requires every paid preparer to maintain a Written Information Security Plan (WISP), tied to your PTIN and e-file participation, regardless of firm size. So a tax preparer has to satisfy both the FTC Safeguards Rule and the IRS WISP mandate, and keep both current, not just meet one.
- What counts as customer information under the Rule?
- Any record with nonpublic personal information about a client that you handle to provide your service: names, Social Security numbers, income, bank details, and the contents of a tax return. The format does not matter, whether server, cloud, email, or paper.
- Is my firm too small to be covered?
- No firm is too small to be covered, but firms with information on fewer than 5,000 consumers are exempt from a few written requirements (the written risk assessment, testing, written incident-response plan, and annual report). The core safeguards still apply, and the IRS WISP requirement applies to paid preparers regardless of size.
- What are the nine required elements of the Safeguards Rule?
- A Qualified Individual, a written risk assessment, designed safeguards (access controls, encryption, MFA, disposal, monitoring and more), regular testing, staff training, service-provider oversight, keeping the program current, a written incident-response plan, and an annual written report to leadership.
- When did the FTC Safeguards Rule take effect?
- The updated Rule became fully enforceable on June 9, 2023. A breach-notification amendment took effect May 13, 2024, requiring notice to the FTC within 30 days of a breach affecting at least 500 consumers.