Does the FTC Safeguards Rule Apply to My Firm?
By Cooper Kelley, Founder, Tailwater Tech · July 15, 2026
Short answer: if your firm prepares tax returns, keeps the books, or otherwise handles clients’ financial information, the FTC Safeguards Rule almost certainly applies to you. Most accountants and tax preparers are surprised by this, because nobody sent them a letter. The obligation has been in force since 2023 regardless.
The reason it catches people off guard is a single piece of legal wiring: under federal law, a tax or accounting practice counts as a financial institution. That one classification pulls you into the same data-security rulebook as a lender or a bank. Here is who is covered, the narrow exceptions, and what it actually means for a small firm.
Why accountants count as “financial institutions”
The Safeguards Rule (16 CFR Part 314) sits under the Gramm-Leach-Bliley Act, which defines a financial institution far more broadly than most people assume. It is not just banks. It covers any business “significantly engaged” in financial activities, and the FTC has been explicit that this includes tax preparers, accountants, bookkeepers, and CPAs, along with mortgage brokers, auto dealers, and financial advisors. If clients hand you their financial data, you are in.
The 2023 expansion that changed the stakes
The rule itself is not new, but it was significantly strengthened. The amended Safeguards Rule took full effect on June 9, 2023, adding specific, prescriptive requirements: multi-factor authentication, encryption, a named security lead, a written risk assessment, and more. It moved from “have reasonable safeguards” to a concrete checklist regulators can hold you to. That is the version in force today.
The IRS ties it to your PTIN
Even if the FTC feels distant, the IRS does not. IRS Publication 4557 (Safeguarding Taxpayer Data) states that professional tax preparers are required by law to have a written data security plan, and PTIN renewal now asks you to confirm you are aware of that responsibility. So the requirement reaches you through two doors at once: the FTC rule and your ability to keep preparing returns.
Is any firm exempt?
Almost none are fully exempt, but size does change the scope. Firms that maintain information on fewer than 5,000 consumers are relieved of a few of the heavier requirements:
- A written risk assessment (you still have to assess risk, just not formally document it the same way).
- Continuous monitoring or the annual penetration test plus twice-yearly vulnerability scans.
- A written incident response plan.
- The annual written report from your security lead to ownership.
Note what is not on that list: MFA, encryption, access controls, a designated security lead, service-provider oversight, and staff training still apply to everyone. And the 5,000-consumer threshold counts every client whose data you have ever held, so it is easier to cross than firms expect. In practice, most tax and accounting firms should build to the full standard, because it is also what your cyber insurer and your clients now expect.
What this means for a small firm
It does not mean you need a bank’s security budget. It means a specific set of controls has to be in place and documented: a written plan, MFA everywhere client data lives, encrypted devices, a named person accountable, and a few more. The firms that get burned are not the ones who tried and fell a little short. They are the ones who assumed the rule was for someone bigger.
Not sure your firm would pass?
The Safeguards Check scores your firm against the specific controls the FTC Safeguards Rule and IRS Pub 4557 require, in about two minutes, and emails a plain-English report of your biggest gaps. No sales call required to see where you stand.
Take the free Safeguards Check →Frequently asked questions
- Does the FTC Safeguards Rule apply to a solo tax preparer?
- Yes. There is no exemption for being small or solo. A one-person shop that prepares returns handles taxpayer financial data and is a financial institution under the rule. The scope of a few requirements is lighter under 5,000 consumers, but the core obligations apply.
- I only do bookkeeping, not taxes. Am I covered?
- Very likely yes. Bookkeeping and accounting services are financial activities under the Gramm-Leach-Bliley definition. If you handle clients’ financial information, the Safeguards Rule generally applies whether or not you file returns.
- When did this actually take effect?
- The Safeguards Rule has existed for years, but the strengthened version with specific technical requirements took full effect on June 9, 2023. The breach-notification piece was added in May 2024. The obligations are current and enforceable now.
- Who enforces it, and how would they find me?
- The Federal Trade Commission enforces the rule. In practice, small firms most often come onto the radar through a breach: a ransomware incident or a client complaint triggers scrutiny, and the first question is whether you had a compliant program in place.
Keep reading