WISP, GLBA & the FTC Safeguards Rule: What Every Tax Office Must Have
A Written Information Security Plan isn't optional — it's federal law for tax preparers. Here's what the FTC Safeguards Rule requires and how to stay compliant.
TaxWallet Newsroom
August 28, 2026
It's the law, not a suggestion
Under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule (16 CFR Part 314), every tax preparer is a “financial institution” and must maintain a Written Information Security Plan (WISP). The IRS also requires you to have one to keep your EFIN. This is enforced.
What a WISP must include
- A designated person responsible for your security program.
- A risk assessment of how client data is collected, stored, and transmitted.
- Safeguards: access controls, encryption of sensitive data, and multi-factor authentication.
- A plan to oversee service providers who touch client data.
- An incident response plan for a data breach.
- Regular review and updates.
Practical steps this week
- Write it down. IRS Publication 5708 provides a template designed for small offices.
- Turn on multi-factor authentication everywhere.
- Make sure client data is encrypted at rest and in transit.
- Train your staff — most breaches start with a phishing email.
How TaxWallet helps
Encryption, tokenized payments, MFA, and audited access are built into the platform, so a large part of your technical safeguards is handled for you. You still need your written plan — but the hard infrastructure is done.
Don't have a WISP? Write one before the season. Your EFIN depends on it.