Does this apply to me?
If you prepare tax returns, keep books, run payroll, or advise on money for other people, the short answer is almost certainly yes — including if you work alone. Here is the longer answer, and where the duty actually comes from.
Where the requirement comes from#
This gets stated loosely everywhere, and the loose version will cost you when you try to work out what you actually owe. So, precisely:
- Congress created the obligation. The Gramm‑Leach‑Bliley Act declares that every financial institution has “an affirmative and continuing obligation” to protect customers' nonpublic personal information, and directs agencies to write safeguards standards.
- The FTC wrote the rule. The Safeguards Rule is the standard that turns that obligation into specific requirements — a named Qualified Individual, access controls, a data inventory, encryption, multi-factor authentication, secure disposal, training, service provider oversight, and a written program.
- The IRS restates it and enforces it. Through the e‑file program. IRS publications describe the duty and give you a free template, and IRS Publication 3112 confirms that the Service monitors providers “through review of IRS records and during visits to Providers' offices.”
A correction worth making, because it is everywhere. You will read that “the IRS requires tax professionals to have a WISP.” That is a compression of the truth, and it points you at the wrong rulebook. The duty is created by GLBA and specified by the FTC Safeguards Rule. The IRS restates it and can suspend your e‑file privileges over it.
Related and often confused: Form W‑12, line 11, asks whether you are aware of your data security responsibilities. It is a mandatory yes/no, signed under penalties of perjury. What is sworn to is the awareness. It is not a certification that you have a plan — and reading it as one leads people to think a checked box is the end of the matter.
Are you a “financial institution”?#
Probably, and the word is misleading. Coverage turns on what you do, not what you call yourself. You do not need to be a bank. The rule reaches institutions “significantly engaged” in financial activities, and the FTC's own guide lists examples that explicitly include:
Tax preparation firms
Named explicitly in the FTC's list of covered examples.
Bookkeepers
Same list.
Financial advisors and planners
Where not regulated elsewhere — see below.
Credit counselors and mortgage brokers
Also named.
Four cases where the answer is less obvious#
“I'm a sole practitioner.”#
The Safeguards Rule sets no minimum headcount. There is no small-office exemption from the rule itself. Florida's breach statute is explicit that a “covered entity” includes sole proprietorships. If you hold client tax data on a laptop in a spare bedroom, you are holding customer information, and the obligation attaches to the data, not to the size of the office.
“I have fewer than 5,000 clients.”#
Then four specific requirements are excepted — the written risk assessment, the testing regime, the written incident response plan, and the annual written report. Not the rule. You still need the program, the Qualified Individual, the access controls, the encryption, the disposal discipline, the training, and the rest.
Two things to be careful about. The threshold counts consumers, not clients or returns filed, and the two numbers are not close — see the threshold numbers. And relying on the exception is a choice you should make on purpose and be able to explain, not a default you drift into.
“Someone else already regulates me.”#
This one is real, and most summaries skip it. The Safeguards Rule reaches institutions over which the FTC has rulemaking authority. It does not reach institutions answering to a different regulator under GLBA § 505 — an SEC‑registered investment adviser under Regulation S‑P, for instance, or certain mortgage entities under the CFPB. Those firms have comparable duties under a different rulebook. If that is you, you are not outside the obligation; you are in a different chapter of it.
“My vendor handles all of this.”#
The rule does not use the word “vendor.” It defines a service provider — an entity permitted access to customer information through services it provides to you — and attaches contract duties to that class. A supplier with no access to customer information is outside it. Your tax software platform is inside it. And oversight of a service provider is your obligation; it does not transfer with the data.
So what do you actually have to produce?#
A written program. The IRS gives away a template — Publication 5708 — and you should download it; it is free and it is a real starting point. What it gives you is the mandate and blank forms. What it does not give you is the part in between: what each requirement means in an office with four people and no IT department, which decisions are genuinely yours to make, and how to keep evidence that you did the work.
That gap is what the book is for.
Sources: 15 U.S.C. § 6801 · 16 CFR Part 314, particularly §§ 314.1(b), 314.2(h), 314.6 · FTC, Safeguards Rule: What Your Business Needs to Know · IRS Pub 3112 · IRS Form W‑12 · Fla. Stat. § 501.171. Linked and dated on the source status page.
This page describes general legal requirements. It is not legal advice, and whether a specific rule reaches your specific practice can turn on facts this page cannot know.