FTC Safeguards Rule Penalties: What Happens If You Are Not Compliant?
By Cooper Kelley, Founder, Tailwater Tech · July 15, 2026
The honest answer to “what happens if I ignore the Safeguards Rule?” is not a surprise audit and an instant fine. Enforcement rarely works that way for small firms. The real exposure is what happens when something goes wrong, and how much worse a breach becomes when you cannot show you had a compliant program.
That said, the penalties are real and they stack. Here is the full picture: the direct FTC penalties, the new notification clock, and the quieter costs that usually hurt a small firm more than a fine ever would.
The direct FTC penalties
The Federal Trade Commission can seek civil penalties for Safeguards Rule violations, and they are assessed per violation and adjusted annually for inflation, running into the tens of thousands of dollars each (over $50,000 per violation in recent years). Because a single lapse can be counted as multiple violations, totals climb quickly. The FTC can also impose a consent order that puts your firm under years of mandated security requirements and outside audits.
The 30-day notification clock
As of May 2024, the rule requires covered firms to notify the FTC as soon as possible, and no later than 30 days, after discovering a security breach involving the unencrypted information of 500 or more consumers. That is a hard deadline that starts ticking at discovery. Firms without an incident response plan tend to freeze, miss the window, and turn a breach into a separate reporting violation on top of it. (Note the word unencrypted: encryption is often what keeps an incident out of reportable territory entirely.)
Your PTIN and your license
For tax preparers there is a second front. The IRS ties a written data security plan to your PTIN, and PTIN renewal asks you to acknowledge that duty. A serious data-security failure can put your standing with the IRS at risk, and for CPAs, state board and professional-conduct questions can follow a breach. The ability to keep doing the work is part of what is on the line.
The costs that actually sink small firms
In practice, the fine is often not the worst part. These are:
- The breach itself. Ransomware recovery, forensics, credit monitoring for affected clients, and downtime during your busiest weeks.
- Denied or voided insurance. Cyber policies now require these controls on the application. If you attested to MFA or encryption you did not have, a carrier can deny the claim when you need it most.
- Lost clients and referrals. A tax or accounting relationship runs on trust. A breach notification letter to every client is the kind of thing that ends relationships and reputations in a referral-driven business.
- The compliance scramble. Building a program under a regulator’s deadline, after an incident, costs far more and looks far worse than doing it quietly in advance.
How small firms actually get caught
Random FTC audits of small tax shops are not the common path. The common path is a breach: a phished login, a ransomware hit, a lost laptop, or a client complaint. That event triggers scrutiny, and the first question everyone asks, the FTC, your insurer, your client’s attorney, is the same: did you have a compliant security program in place? A yes turns a crisis into an incident. A no turns it into a violation.
Would your firm hold up after a breach?
The Safeguards Check scores your firm against the controls the FTC and IRS expect, in about two minutes, and emails a plain-English report of your biggest gaps, before an incident makes them everyone’s business. No sales call required to see where you stand.
Take the free Safeguards Check →Frequently asked questions
- How much are FTC Safeguards Rule fines?
- The FTC can seek civil penalties per violation, adjusted annually for inflation and running over $50,000 per violation in recent years. Because a single failure can be counted as multiple violations, and because a consent order can add years of mandated oversight, the total exposure is often much larger than any single number suggests.
- Will the FTC audit my small firm?
- Random audits of small firms are uncommon. Most enforcement follows a breach or a complaint. The practical risk is not a surprise inspection; it is what an investigation finds after an incident you did not prevent.
- What is the breach-notification deadline?
- As of May 2024, covered firms must notify the FTC as soon as possible and no later than 30 days after discovering a breach involving the unencrypted data of 500 or more consumers. Encryption can keep an incident from being reportable at all.
- Can non-compliance affect my PTIN?
- The IRS ties a written data security plan to your PTIN and asks you to acknowledge that responsibility at renewal. A serious data-security failure can jeopardize your standing with the IRS, and for CPAs it can raise state board and professional-conduct issues as well.
Keep reading