IRS Publication 4557, Safeguarding Taxpayer Data, is the IRS guide that explains how paid tax preparers meet the data security duties federal law already places on them, chiefly the FTC Safeguards Rule’s requirement for a written information security plan (WISP). Every preparer acknowledges that WISP requirement on Form W-12 when applying for or renewing a PTIN (Preparer Tax Identification Number, the ID every paid preparer must hold), and IRS Publication 1345 makes safeguarding taxpayer data an obligation of every Authorized IRS e-file Provider. This guide walks through each piece and shows where client email and file sharing fit.

What is IRS Publication 4557?

Publication 4557 (Rev. 6-2024) is the IRS guide to protecting taxpayer data in a tax practice. Publication 4557 summarizes the FTC Safeguards Rule, lists the elements of a written security plan, and gives practical steps: multi-factor authentication, encryption of sensitive files and emails, service provider oversight, staff training and a process for reporting data theft to the IRS.

The publication does not create a new legal duty on its own. It explains obligations that come from the Gramm-Leach-Bliley Act and the FTC’s Safeguards Rule at 16 CFR Part 314. It states that “the ‘financial institutions’ definition includes professional tax preparers” and that “the Safeguards Rule requires companies to develop a written information security plan that describes their program to protect customer information.”

For practices of every size, the most quoted line is the direct instruction on email: “Encrypt all sensitive files/emails, especially those with the taxpayer’s personally identifiable information.”

Does every paid tax preparer need a WISP?

Yes. The FTC Safeguards Rule treats tax preparation services as a financial activity, so a preparer who completes returns for compensation is a financial institution under 16 CFR 314.2(h). IRS Publication 5708 states that tax and accounting professionals “are considered financial institutions, regardless of size” and that “a requirement of the Safeguards Rule is implementing and maintaining a WISP.”

Size changes how detailed the plan needs to be, not whether one is required. The Safeguards Rule asks for a program “appropriate to your size and complexity” (16 CFR 314.3(a)), and Publication 5708 says a plan should be appropriate to “the company’s size, scope of activities, complexity, and the sensitivity of the customer data it handles.” A solo preparer working from a home office still needs a written plan; it can be shorter than a 20-person firm’s.

What does Form W-12 ask preparers to acknowledge?

Form W-12 is the PTIN application and renewal form. Line 11 of the October 2025 revision reads: “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.” The form is signed under penalties of perjury.

That line acknowledges a legal duty; it does not ask the preparer to confirm that a WISP already exists. Because the form is signed at every PTIN renewal, the WISP requirement comes back in front of each paid preparer in writing. The IRS says anyone who prepares or assists in preparing federal tax returns for compensation must have a valid PTIN, so the acknowledgment reaches everyone from a solo preparer to the seasonal staff of a multi-preparer firm.

What does Publication 1345 require of e-file providers?

Publication 1345 is the handbook for Authorized IRS e-file Providers, and it makes safeguarding taxpayer data an obligation of every Authorized IRS e-file Provider. It states that “protecting taxpayer data is required by law,” that providers subject to the Gramm-Leach-Bliley Act “must follow the FTC’s Financial Privacy and Safeguard Rules,” and that “violating a provision of this publication may subject the Authorized IRS e-file Provider (Provider) to sanctions.”

Flow diagram showing the Gramm-Leach-Bliley Act and FTC Safeguards Rule as the source of the WISP requirement, with IRS Publications 4557, 5708 and 1345 and Form W-12 line 11 each feeding into the firm's WISP

The handbook points providers to Publication 4557 “to help determine their data privacy and security needs.” It repeats the multi-factor authentication requirement from the Safeguards Rule and requires providers to report security incidents to the IRS “as soon as possible but not later than the next business day after confirmation of the incident.”

A practice that e-files should treat its WISP as the record of how it handles the safeguarding obligations Publication 1345 sets for providers, as well as the plan the FTC Safeguards Rule requires.

Which Publication 4557 controls apply to email and file sharing?

Four controls touch client email and file sharing directly: encryption of customer information in transit and at rest, access controls, multi-factor authentication, and logging of authorized user activity. A fifth, service provider oversight, applies to whichever email or file-sharing vendor the firm uses.

The table below maps each control to its source and shows how PreVeil supports it. The rest of the plan (risk assessment, training, incident response, disposal, device security) stays with the firm. In the table, the “Qualified Individual” is the person the firm designates to oversee its security program.

RequirementCitationRequired or conditionalHow PreVeil supports it
Written information security program16 CFR 314.3(a); Pub 5708RequiredSupplies the email and file-sharing sections of the plan; the firm writes and owns the plan
Access controls16 CFR 314.4(c)(1)RequiredTrusted Community and approval-group protections, managed from the admin console on the Business plan
Encryption in transit and at rest16 CFR 314.4(c)(3); Pub 4557Required, with compensating controls allowed if infeasible and approved by the Qualified IndividualMessage contents, attachments and files are encrypted end to end, including in the inbox and on the server
Multi-factor authentication16 CFR 314.4(c)(5); Pub 1345Required, unless the Qualified Individual approves an equivalent control in writingDevice-bound keys with native device authentication support multi-factor authentication requirements
Logging of authorized user activity16 CFR 314.4(c)(8)RequiredAdmin console and activity logs
Service provider oversight16 CFR 314.4(f)RequiredA provider that cannot read client data has less it can expose; the firm still selects, contracts with and reviews its providers
FTC notification after unauthorized acquisition of unencrypted customer data (a “notification event”)16 CFR 314.4(j); 314.2(m)Required for events involving 500 or more consumersKeys stay on user devices, which bears on whether data counts as “unencrypted” under 314.2(m)

Why is client email the usual gap in a WISP?

Client email is the usual gap because TLS protects a message only on the wire, not in the mailbox. Most tax practices run on Outlook or Gmail, which rely on TLS between mail servers, so the message sits readable in each mailbox. Portals keep files off email but ask clients to log in somewhere new, so many clients fall back to plain attachments.

PreVeil works inside Outlook, Gmail and Apple Mail, so staff keep the inbox they already use. PreVeil encrypts message contents and attachments end to end, so they stay encrypted in the mailbox, not just on the wire. Clients read and reply for free from their browser, and their replies stay encrypted.

Can PreVeil read client tax data?

No. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices. Message contents, attachments and files are encrypted end to end on the sender’s device and decrypted only on the recipient’s device.

This matters for two Safeguards Rule elements. Under 16 CFR 314.4(f), the firm oversees its service providers; a provider that cannot read client data has less client data it can expose. Under 16 CFR 314.2(m), customer information “is considered unencrypted for this purpose if the encryption key was accessed by an unauthorized person.” With PreVeil, those keys are not on PreVeil’s servers. PreVeil uses FIPS 140-3 validated cryptographic modules (certificate #5145, validated January 26, 2026).

How should a practice put this into its WISP?

Start from Publication 5708, fill in the firm’s own responsible officials and risk assessment, and write the email and file-sharing controls in terms of what the firm actually uses. Record who can access client data, how it is encrypted, how staff authenticate and where activity logs live.

For every WISP element in order, see IRS WISP requirements: a checklist for tax preparers. For the rule itself, see FTC Safeguards Rule for tax and accounting firms, section by section.

Frequently asked questions

Is IRS Publication 4557 a law?

No. Publication 4557 is IRS guidance. The legal duty comes from the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 CFR Part 314), which treat tax preparers as financial institutions. Publication 4557 explains how to meet that duty, and Publication 1345 makes safeguarding taxpayer data part of an e-file provider’s obligations.

Do solo tax preparers need a written information security plan?

Yes. Publication 5708 says tax and accounting professionals are financial institutions “regardless of size.” A solo practice’s plan can be shorter, because the Safeguards Rule scales the program to the firm’s size and complexity, but it must be written.

What does Form W-12 line 11 say?

Line 11 of Form W-12 (Rev. October 2025) reads: “I am aware that paid tax return preparers are required by law to create and maintain a written information security plan that provides data and system security protections for all taxpayer information.” Preparers acknowledge it when applying for or renewing a PTIN.

What does Publication 1345 require of e-file providers?

Publication 1345 makes safeguarding taxpayer data an obligation of every Authorized IRS e-file Provider. It states that protecting taxpayer data is required by law, that providers subject to the Gramm-Leach-Bliley Act must follow the FTC’s Financial Privacy and Safeguard Rules, and that security incidents must be reported to the IRS no later than the next business day after confirmation.

Does Publication 4557 require encrypted email?

Publication 4557 tells preparers to “encrypt all sensitive files/emails,” and 16 CFR 314.4(c)(3) requires encryption of customer information in transit and at rest, with compensating controls allowed only when encryption is infeasible and the Qualified Individual approves them.

Can PreVeil read the tax documents a firm sends?

No. PreVeil cannot access or decrypt customer data, because the encryption keys stay on users’ devices.

Sources

Request a demo

To talk through how your practice handles client email and files, request a demo.