The FTC Safeguards Rule (16 CFR Part 314) requires tax and accounting firms to develop a written information security program with specific elements, including encryption of customer information, multi-factor authentication, activity logging, service provider oversight and, since May 2024, provide notice to the FTC after certain breaches. Tax preparers are covered because the rule treats tax preparation as a financial activity. The rule implements the Gramm-Leach-Bliley Act, so it is also called the GLBA Safeguards Rule. This guide breaks down the rule section by section and highlights where client email and file sharing come in.
Does the FTC Safeguards Rule apply to tax and accounting firms?
Yes. 16 CFR 314.2(h) gives as an example of a financial institution “an accountant or other tax preparation service that is in the business of completing income tax returns,” because “tax preparation services is a financial activity.”
The FTC’s guidance lists tax preparation firms as covered, and IRS Publication 4557 says the “financial institutions” definition “includes professional tax preparers.” IRS Publication 5708 says tax and accounting professionals are financial institutions “regardless of size.”
What does the Safeguards Rule require, section by section?
Section 314.3 sets the standard: a written program with administrative, technical and physical safeguards “appropriate to your size and complexity.” Section 314.4 lists the elements, paragraphs (a) through (j). Section 314.6 exempts firms with fewer than 5,000 consumers from some, but not all requirements – see below.

| Element | Citation | Required for firms under 5,000 consumers? | How PreVeil supports it |
|---|---|---|---|
| Written information security program | 314.3(a) | Required | Supplies the email and file-sharing part of the written program |
| Qualified Individual | 314.4(a) | Required | Firm responsibility |
| Written risk assessment with criteria | 314.4(b)(1) | Exempt (314.6) | Firm responsibility |
| Periodic reassessment | 314.4(b)(2) | Required | Firm responsibility |
| Access controls | 314.4(c)(1) | Required | Trusted Community and approval-group protections |
| Data and system inventory | 314.4(c)(2) | Required | Firm responsibility |
| Encryption in transit and at rest | 314.4(c)(3) | Required | Message contents, attachments and files encrypted end to end |
| Application security | 314.4(c)(4) | Required | Firm responsibility |
| Multi-factor authentication | 314.4(c)(5) | Required | Device-bound keys with native device authentication support MFA requirements |
| Disposal within two years of last use | 314.4(c)(6) | Required | Firm responsibility |
| Change management | 314.4(c)(7) | Required | Firm responsibility |
| Monitor and log authorized users | 314.4(c)(8) | Required | Admin console and activity logs |
| Testing or monitoring of safeguards | 314.4(d)(1) | Required | Firm responsibility |
| Continuous monitoring or annual penetration testing | 314.4(d)(2) | Exempt (314.6) | Firm responsibility |
| Training and qualified staff | 314.4(e) | Required | Firm responsibility |
| Service provider oversight | 314.4(f) | Required | PreVeil cannot read or expose customer data |
| Evaluate and adjust | 314.4(g) | Required | Firm responsibility |
| Written incident response plan | 314.4(h) | Exempt (314.6) | Firm responsibility |
| Annual report to owner or board | 314.4(i) | Exempt (314.6) | Firm responsibility |
| FTC notice of notification events | 314.4(j); 314.2(m) | Required | Keys stay on user devices, never on PreVeil’s servers |
What does 314.4(c)(3) require for encryption?
16 CFR 314.4(c)(3) requires a tax or accounting firm to “protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest.” If encryption is infeasible, the firm may use effective alternative controls reviewed and approved by its Qualified Individual, the person the firm designates under 314.4(a) to oversee its security program. The rule defines encryption in 314.2(f) to include “appropriate safeguards for cryptographic key material.”
The key-material clause matters for email. Standard Outlook and Gmail protect messages with TLS, which encrypts the connection between mail servers, but messages sit readable in each mailbox. Encryption at rest on a provider’s servers helps, but the provider holds the keys. PreVeil encrypts message contents and attachments on the sender’s device and decrypts them only on recipients’ devices. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. PreVeil uses FIPS 140-3 validated cryptographic modules.
What do the MFA and logging requirements mean in practice?
Under the FTC Safeguards Rule, 16 CFR 314.4(c)(5) requires multi-factor authentication “for any individual accessing any information system,” unless the Qualified Individual approves “reasonably equivalent or more secure access controls” in writing. Section 314.4(c)(8) requires controls “designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information.”
Multi-factor authentication under 314.2(k) means at least two of three factor types: knowledge (something you know), possession (something you have) and inherence (something you are). PreVeil’s apps authenticate each device with a cryptographic key bound to that device, together with the device’s own sign-in. Device-bound keys with native device authentication support multi-factor authentication requirements. For (c)(8), PreVeil’s admin console and activity logs give the firm a record of user activity in email and files.
How does service provider oversight apply to an email vendor?
16 CFR 314.4(f) requires a firm to take reasonable steps to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to assess providers periodically. An email host, a file-sharing tool and a client portal are all service providers under 314.2(r) if they can access customer information.
The choice of provider changes how exposed client data is, because a provider that can read that data is one more place it can leak from. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices.
When does a tax firm have to notify the FTC?
Under 314.4(j), a firm must notify the FTC “as soon as possible, and no later than 30 days after discovery” of a notification event involving at least 500 consumers. The notice must describe the event, the types of information involved and the number of consumers affected.
A notification event, under 314.2(m), is the “acquisition of unencrypted customer information without the authorization of the individual to which the information pertains.” Customer information “is considered unencrypted for this purpose if the encryption key was accessed by an unauthorized person.” A firm’s breach procedures should record where its encryption keys live. With PreVeil, they stay on users’ devices, not on PreVeil’s servers.
Which parts can a small tax practice skip?
16 CFR 314.6 says paragraphs 314.4(b)(1), (d)(2), (h) and (i) “do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers.” Those are the written risk assessment criteria, continuous monitoring or annual penetration testing, the written incident response plan and the annual report to the board.
Everything else applies: encryption, MFA, logging, access controls, vendor oversight, training and FTC notice; the exemption does not remove the written plan. IRS Publication 5708 still includes breach procedures as an attachment, and Publication 1345 still requires incident reporting to the IRS.
Frequently asked questions
Are tax preparers financial institutions under the Safeguards Rule?
Yes. 16 CFR 314.2(h) names “an accountant or other tax preparation service that is in the business of completing income tax returns” as a financial institution, because tax preparation is a financial activity.
Does the Safeguards Rule require encrypted email?
The FTC Safeguards Rule requires encryption of customer information “both in transit over external networks and at rest” under 314.4(c)(3), which includes customer information sent and stored by email.
What is a notification event?
Under 16 CFR 314.2(m) of the FTC Safeguards Rule, a notification event is the acquisition of unencrypted customer information without the customer’s authorization. Data counts as unencrypted if the encryption key was accessed by an unauthorized person. Events involving 500 or more consumers must be reported to the FTC within 30 days of discovery.
What does the 5,000-consumer exemption cover?
The 16 CFR 314.6 exemption applies to firms with customer information on fewer than 5,000 consumers and removes four items: the written risk assessment criteria, continuous monitoring or penetration testing, the written incident response plan and the annual report. The rest of 314.4 still applies: encryption, MFA, logging, access controls, vendor oversight, training and FTC notice, and the written information security plan
Does PreVeil make a tax firm compliant with the Safeguards Rule?
No product does. PreVeil supports specific elements, including encryption (c)(3), access controls (c)(1), logging (c)(8) and the vendor exposure side of (f). The firm runs the program and owns the plan.
Sources
- 16 CFR 314.1, purpose and scope: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.1
- 16 CFR 314.2, definitions: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.2
- 16 CFR 314.3, standards: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.3
- 16 CFR 314.4, elements: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4
- 16 CFR 314.6, exceptions: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.6
- FTC, FTC Safeguards Rule: What your business needs to know: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
- IRS Publication 4557 (Rev. 6-2024): https://www.irs.gov/pub/irs-pdf/p4557.pdf
- IRS Publication 5708 (Rev. 8-2024): https://www.irs.gov/pub/irs-pdf/p5708.pdf
- IRS Publication 1345 (Rev. 12-2025): https://www.irs.gov/pub/irs-pdf/p1345.pdf
Request a demo
To talk through your firm’s setup, request a demo.