Home/Politics/Article
PoliticsSeptember 7, 2026

Tax professionals must maintain written security plans to protect client data

Federal law requires tax and accounting firms to implement security measures against data breaches.

YJ
Young Jang
Sep 7
Source: This report is based on an official public release from IRS Newswire. PULSE organizes and summarizes public government communications. Read the original release →

The Internal Revenue Service reminded tax professionals that federal law requires them to maintain Written Information Security Plans to protect client information from theft and data breaches.

Under the Gramm-Leach-Bliley Act, tax and accounting professionals are considered financial institutions and must implement data security plans that protect customer data, according to the IRS. Each firm must designate an employee to coordinate the information security program, assess risks to customer information, create and test security safeguards, and ensure service providers maintain appropriate protections, the agency said.

The IRS offers Publication 5708, Creating a Written Information Security Plan for Your Tax & Accounting Practice, which provides a template for developing plans. Plans should focus on three areas: employee management and training, information systems, and detecting and managing system failures, according to the agency.

Tax professionals should review, test, and update plans regularly based on operational changes or security testing results, and develop a data theft response plan including procedures for reporting security incidents to their IRS Stakeholder Liaison, the IRS said. Under the Federal Trade Commission's Safeguards Rule, covered financial institutions must report security events affecting 500 or more people to the FTC generally within 30 days of discovery.

SHARE: