Safeguarding Taxpayer Information: FTC Safeguards Rule and Professional Responsibilities

Categories: Ethics, IRS CE
Wishlist Share

About Course

This self-study ethics program examines the practitioner’s data security obligations under the Federal Trade Commission’s Safeguards Rule, issued under the Gramm-Leach-Bliley Act and applicable to tax return preparers as financial institutions, together with the professional responsibility dimension of these obligations under Circular 230. The course covers the required Written Information Security Program, the designated Qualified Individual and periodic risk assessment requirements, the specific technical and physical safeguards the Rule requires, reasonable oversight of service providers with access to taxpayer information, and the required elements of an incident response plan and breach notification obligations following a security event.

What Will You Learn?

  • Apply the FTC Safeguards Rule's classification of a tax return preparer as a financial institution subject to its requirements
  • Identify the required elements of a Written Information Security Program under the Safeguards Rule
  • Apply the designated Qualified Individual and periodic risk assessment requirements
  • Identify the required technical and physical safeguards, including access controls, encryption, and multi-factor authentication
  • Apply reasonable oversight standards for service providers with access to taxpayer information
  • Identify the required elements of a written incident response plan
  • Apply the breach notification obligations that arise following a security event
  • Integrate data security obligations with the practitioner's professional responsibility obligations under Circular 230

Course Content

Module 1 – The FTC Safeguards Rule Framework and the Written Information Security Program Requirement
This module introduces the FTC Safeguards Rule's applicability to tax practitioners and the core requirement to develop, implement, and maintain a Written Information Security Program scaled to firm size.

  • The FTC Safeguards Rule Framework and the Written Information Security Program Requirement

Module 2 – Required Technical and Physical Safeguards: Access Controls, Encryption, and Monitoring
This module covers the specific technical and physical safeguards the Rule requires, including access controls, encryption of taxpayer data in transit and at rest, and ongoing system monitoring.

Module 3 – Service Provider Oversight and Vendor Risk Management
This module addresses the obligation to oversee third-party service providers with access to covered taxpayer information, including vendor due diligence and contractual safeguards requirements.

Module 4 – Incident Response, Breach Notification, and the Professional Responsibility Overlay
This module reviews incident response planning, breach notification obligations, and how a data security failure intersects with the practitioner's separate professional responsibility obligations under Circular 230.

Final Assessment – Safeguarding Taxpayer Information: FTC Safeguards Rule and Professional Responsibilities
This final assessment consists of 10 multiple-choice questions covering all four modules of this course. A passing score of 70% or better is required.

Scroll to Top