The FTC Safeguards Rule (16 CFR Part 314) requires tax and accounting firms to develop a written information security program with specific elements, including encryption of customer information, multi-factor authentication, activity logging, service provider oversight and, since May 2024, provide notice to the FTC after certain breaches. Tax preparers are covered because the rule treats tax preparation as a financial activity. The rule implements the Gramm-Leach-Bliley Act, so it is also called the GLBA Safeguards Rule. This guide breaks down the rule section by section and highlights where client email and file sharing come in.

Does the FTC Safeguards Rule apply to tax and accounting firms?

Yes. 16 CFR 314.2(h) gives as an example of a financial institution “an accountant or other tax preparation service that is in the business of completing income tax returns,” because “tax preparation services is a financial activity.”

The FTC’s guidance lists tax preparation firms as covered, and IRS Publication 4557 says the “financial institutions” definition “includes professional tax preparers.” IRS Publication 5708 says tax and accounting professionals are financial institutions “regardless of size.”

What does the Safeguards Rule require, section by section?

Section 314.3 sets the standard: a written program with administrative, technical and physical safeguards “appropriate to your size and complexity.” Section 314.4 lists the elements, paragraphs (a) through (j). Section 314.6 exempts firms with fewer than 5,000 consumers from some, but not all requirements – see below.

Section map of the FTC Safeguards Rule, 16 CFR Part 314, showing definitions in 314.2, the standard in 314.3, elements 314.4(a) through (j) and the small-firm exemptions in 314.6, with the email-related elements highlighted
ElementCitationRequired for firms under 5,000 consumers?How PreVeil supports it
Written information security program314.3(a)RequiredSupplies the email and file-sharing part of the written program
Qualified Individual314.4(a)RequiredFirm responsibility
Written risk assessment with criteria314.4(b)(1)Exempt (314.6)Firm responsibility
Periodic reassessment314.4(b)(2)RequiredFirm responsibility
Access controls314.4(c)(1)RequiredTrusted Community and approval-group protections
Data and system inventory314.4(c)(2)RequiredFirm responsibility
Encryption in transit and at rest314.4(c)(3)RequiredMessage contents, attachments and files encrypted end to end
Application security314.4(c)(4)RequiredFirm responsibility
Multi-factor authentication314.4(c)(5)RequiredDevice-bound keys with native device authentication support MFA requirements
Disposal within two years of last use314.4(c)(6)RequiredFirm responsibility
Change management314.4(c)(7)RequiredFirm responsibility
Monitor and log authorized users314.4(c)(8)RequiredAdmin console and activity logs
Testing or monitoring of safeguards314.4(d)(1)RequiredFirm responsibility
Continuous monitoring or annual penetration testing314.4(d)(2)Exempt (314.6)Firm responsibility
Training and qualified staff314.4(e)RequiredFirm responsibility
Service provider oversight314.4(f)RequiredPreVeil cannot read or expose customer data
Evaluate and adjust314.4(g)RequiredFirm responsibility
Written incident response plan314.4(h)Exempt (314.6)Firm responsibility
Annual report to owner or board314.4(i)Exempt (314.6)Firm responsibility
FTC notice of notification events314.4(j); 314.2(m)RequiredKeys stay on user devices, never on PreVeil’s servers

What does 314.4(c)(3) require for encryption?

16 CFR 314.4(c)(3) requires a tax or accounting firm to “protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest.” If encryption is infeasible, the firm may use effective alternative controls reviewed and approved by its Qualified Individual, the person the firm designates under 314.4(a) to oversee its security program. The rule defines encryption in 314.2(f) to include “appropriate safeguards for cryptographic key material.”

The key-material clause matters for email. Standard Outlook and Gmail protect messages with TLS, which encrypts the connection between mail servers, but messages sit readable in each mailbox. Encryption at rest on a provider’s servers helps, but the provider holds the keys. PreVeil encrypts message contents and attachments on the sender’s device and decrypts them only on recipients’ devices. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. PreVeil uses FIPS 140-3 validated cryptographic modules.

What do the MFA and logging requirements mean in practice?

Under the FTC Safeguards Rule, 16 CFR 314.4(c)(5) requires multi-factor authentication “for any individual accessing any information system,” unless the Qualified Individual approves “reasonably equivalent or more secure access controls” in writing. Section 314.4(c)(8) requires controls “designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information.”

Multi-factor authentication under 314.2(k) means at least two of three factor types: knowledge (something you know), possession (something you have) and inherence (something you are). PreVeil’s apps authenticate each device with a cryptographic key bound to that device, together with the device’s own sign-in. Device-bound keys with native device authentication support multi-factor authentication requirements. For (c)(8), PreVeil’s admin console and activity logs give the firm a record of user activity in email and files.

How does service provider oversight apply to an email vendor?

16 CFR 314.4(f) requires a firm to take reasonable steps to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to assess providers periodically. An email host, a file-sharing tool and a client portal are all service providers under 314.2(r) if they can access customer information.

The choice of provider changes how exposed client data is, because a provider that can read that data is one more place it can leak from. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices.

When does a tax firm have to notify the FTC?

Under 314.4(j), a firm must notify the FTC “as soon as possible, and no later than 30 days after discovery” of a notification event involving at least 500 consumers. The notice must describe the event, the types of information involved and the number of consumers affected.

A notification event, under 314.2(m), is the “acquisition of unencrypted customer information without the authorization of the individual to which the information pertains.” Customer information “is considered unencrypted for this purpose if the encryption key was accessed by an unauthorized person.” A firm’s breach procedures should record where its encryption keys live. With PreVeil, they stay on users’ devices, not on PreVeil’s servers.

Which parts can a small tax practice skip?

16 CFR 314.6 says paragraphs 314.4(b)(1), (d)(2), (h) and (i) “do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.” Those are the written risk assessment criteria, continuous monitoring or annual penetration testing, the written incident response plan and the annual report to the board.

Everything else applies: encryption, MFA, logging, access controls, vendor oversight, training and FTC notice; the exemption does not remove the written plan. IRS Publication 5708 still includes breach procedures as an attachment, and Publication 1345 still requires incident reporting to the IRS.

Frequently asked questions

Are tax preparers financial institutions under the Safeguards Rule?

Yes. 16 CFR 314.2(h) names “an accountant or other tax preparation service that is in the business of completing income tax returns” as a financial institution, because tax preparation is a financial activity.

Does the Safeguards Rule require encrypted email?

The FTC Safeguards Rule requires encryption of customer information “both in transit over external networks and at rest” under 314.4(c)(3), which includes customer information sent and stored by email.

What is a notification event?

Under 16 CFR 314.2(m) of the FTC Safeguards Rule, a notification event is the acquisition of unencrypted customer information without the customer’s authorization. Data counts as unencrypted if the encryption key was accessed by an unauthorized person. Events involving 500 or more consumers must be reported to the FTC within 30 days of discovery.

What does the 5,000-consumer exemption cover?

The 16 CFR 314.6 exemption applies to firms with customer information on fewer than 5,000 consumers and removes four items: the written risk assessment criteria, continuous monitoring or penetration testing, the written incident response plan and the annual report. The rest of 314.4 still applies: encryption, MFA, logging, access controls, vendor oversight, training and FTC notice, and the written information security plan

Does PreVeil make a tax firm compliant with the Safeguards Rule?

No product does. PreVeil supports specific elements, including encryption (c)(3), access controls (c)(1), logging (c)(8) and the vendor exposure side of (f). The firm runs the program and owns the plan.

Sources

Request a demo

To talk through your firm’s setup, request a demo.