Claremont SecurityManaged compliance · Enterprise AI protection
Defined terms · read against the primary source

Regulatory glossary for professional firms

Fifty-eight terms that decide outcomes. Each is defined in plain words from the document that sets it, with its citation.

58 terms7 categories16 CFR 314 · 26 CFR 301.7216 · 31 CFR 10 · 17 CFR 248.30 · 45 CFR 164 · Wis. Stat. 134.98 · Microsoft 365

All 58 terms

// FTC_Safeguards9 terms

FTC Safeguards Rule

16 CFR Part 314 · ABA v. FTC (D.C. Cir. 2005)

FTC Safeguards Rule

FTC Safeguards Rule

Also Safeguards Rule; 16 CFR Part 314

The Federal Trade Commission’s rule under the Gramm-Leach-Bliley Act (GLBA) for safeguarding customer information. Among those it covers are tax preparation firms and investment advisors not required to register with the SEC. Each must keep a written information security program with safeguards fitting its size and complexity, the nature and scope of its activities and the sensitivity of the information.

Financial institution

FTC Safeguards Rule

A business significantly engaged in a financial activity described in the Bank Holding Company Act. The Safeguards Rule names one outright: “An accountant or other tax preparation service that is in the business of completing income tax returns”. ABA v. FTC kept the practice of law outside the FTC’s GLBA authority but never names the Safeguards Rule; ask counsel.

Source 16 CFR 314.2(h)(1), (h)(2)(viii); ABA v. FTC, No. 04-5257 (D.C. Cir. Dec. 6, 2005) Primary source for Financial institution, opens in a new tab

On this site Which rules apply

See also FTC Safeguards RuleCustomer relationshipCustomer information

Customer relationship

FTC Safeguards Rule

A continuing relationship in which the firm provides a financial product or service to a consumer, an individual who uses it primarily for personal, family or household purposes. The rule’s own examples include a consumer who becomes the firm’s client for tax preparation. That client is a customer, so records holding their nonpublic personal information are customer information.

Nonpublic personal information

FTC Safeguards Rule

Personally identifiable financial information: anything a consumer gives the firm to obtain a financial product or service, or that the firm obtains about them in providing it. Even the fact that someone is or has been the firm’s customer counts. Publicly available information is left out, unless it appears on a list of consumers derived from nonpublic financial information.

Customer information

FTC Safeguards Rule

Any record, in paper, electronic or other form, containing nonpublic personal information about a customer of a financial institution. It counts when handled or maintained by or on behalf of the firm or its affiliates. For an individual tax client, that reaches the return, the source documents, the engagement correspondence and the portal copies.

Written information security plan (WISP)

FTC Safeguards Rule

Also WISP; information security program

The written information security program the Safeguards Rule requires: the safeguards a firm uses to handle customer information. It must be written “in one or more readily accessible parts” and include the elements in 16 CFR 314.4. IRS Publication 1345 points tax practices to Publication 5708, “Creating a Written Information Security Plan for Your Tax & Accounting Practice”.

Qualified Individual

FTC Safeguards Rule

The individual the firm designates to oversee, implement and enforce its information security program. That person may work for the firm, an affiliate or a service provider. With an affiliate or provider, the firm keeps responsibility, names a senior staff member to direct and oversee that person, and requires it to keep a program meeting the rule.

Service provider (Safeguards Rule)

FTC Safeguards Rule

Any person or entity that receives, maintains, processes or may otherwise access customer information by directly serving a firm covered by the Safeguards Rule. The firm must take reasonable steps to choose and keep providers that can maintain appropriate safeguards, and require those safeguards by contract. It assesses each provider periodically, on its risk and whether its safeguards remain adequate.

The 5,000-consumer exception

FTC Safeguards Rule

Also Safeguards Rule small-institution exception

Four paragraphs of the Safeguards Rule do not apply to a firm holding customer information on fewer than 5,000 consumers. They are 314.4(b)(1), (d)(2), (h) and (i): the written risk assessment, the fixed testing schedule, the written incident response plan and the annual written report. The risk assessment and the testing duty themselves remain.

// Security_Controls6 terms

Security controls in the Safeguards Rule

16 CFR 314.2 · 16 CFR 314.4 · IRS Pub. 1345

Risk assessment

Security controls

The study a Safeguards Rule program rests on: the reasonably foreseeable internal and external risks to customer information, and whether current safeguards control them. The firm repeats it periodically, and writes it down with criteria for rating risks and how each will be mitigated or accepted. Below 5,000 consumers it need not be written, but it is still required.

Encryption

Security controls

Making data unlikely to be understood without a protective process or key, to current cryptographic standards, with the key protected. The firm must encrypt all customer information in transit over external networks and at rest; where infeasible, its Qualified Individual approves effective compensating controls. Data whose key an unauthorized person accessed counts as unencrypted for FTC breach notice.

Multi-factor authentication (MFA)

Security controls

Also MFA

Proof of identity of at least two kinds: something you know (a password), something you have (a token) or something you are (a biometric). The Safeguards Rule requires it for any individual accessing any information system, unless the Qualified Individual approves in writing reasonably equivalent or more secure controls. IRS Publication 1345 repeats the requirement for anyone accessing taxpayer information.

Source 16 CFR 314.2(k), 314.4(c)(5); IRS Publication 1345 (Rev. 10-2024), ch. 2 Primary source for Multi-factor authentication (MFA), opens in a new tab

On this site Compliance map

See also Qualified IndividualFTC Safeguards Rule

Secure disposal

Security controls

The Safeguards Rule’s requirement for procedures that securely dispose of customer information, in any format, within two years after it was last used to serve that customer. Exceptions cover a legitimate business need, a legal duty to keep it, and records where targeted disposal is not reasonably feasible. The firm also reviews its retention policy periodically to minimize unnecessary retention.

Penetration testing

Security controls

A test in which assessors try to get past or defeat an information system’s security features, attempting to penetrate databases or controls from outside or inside the firm’s systems. Without effective continuous monitoring or similar change detection, the Safeguards Rule requires one each year, scoped by the risk assessment. Below 5,000 consumers that paragraph does not apply.

Vulnerability assessment

Security controls

Under the Safeguards Rule, a review of the firm’s information systems for publicly known security vulnerabilities, including systemic scans, based on the risk assessment. Without effective continuous monitoring, it is due at least every six months, after material changes to operations or business arrangements, and when circumstances may materially affect the program. Below 5,000 consumers that schedule does not apply.

// Breach_Notice6 terms

Breach notice

16 CFR 314 · 17 CFR 248.30 · Wis. Stat. 134.98 · IRS Pub. 1345

Notification event

Breach notice

Acquisition of unencrypted customer information without the authorization of the individual to which the information pertains. Data counts as unencrypted if someone unauthorized accessed the key; unauthorized access is presumed to be acquisition unless reliable evidence shows otherwise. At 500 or more consumers, the firm must notify the FTC as soon as possible, no later than 30 days after discovery.

Discovery

Breach notice

A notification event counts as discovered on the first day any employee, officer or other agent of the firm knows of it, other than the person committing the breach. The FTC’s 30-day clock runs from that day, not from the partners’ briefing. The SEC’s clock starts on becoming aware, Wisconsin’s on learning of the acquisition, the IRS’s on confirmation.

Source 16 CFR 314.4(j)(1)-(2); 17 CFR 248.30(a)(4)(iii); Wis. Stat. 134.98(3)(a); IRS Publication 1345 (Rev. 10-2024), ch. 2 Primary source for Discovery, opens in a new tab

On this site Breach Deadline Calculator

See also Notification eventReportable security incident (IRS)Personal information (Wisconsin)

Incident response plan

Breach notice

A written plan to promptly respond to and recover from any security event materially affecting the confidentiality, integrity or availability of customer information the firm controls. A security event means unauthorized access to, or disruption or misuse of, a system, its data or paper customer records. It must cover seven listed areas, and is not required below 5,000 consumers.

Reportable security incident (IRS)

Breach notice

Under IRS Publication 1345, an event that can result in unauthorized disclosure, misuse, modification or destruction of taxpayer information. Authorized IRS e-file Providers of individual income tax returns must report it to the IRS as soon as possible, by the next business day after confirmation. That clock runs from confirmation, not discovery; a later IRS revision exists, so check it.

Source IRS Publication 1345 (Rev. 10-2024), ch. 2, Reporting of Security Incidents

On this site Breach clocks

See also DiscoveryNotification eventPersonal information (Wisconsin)

Personal information (Wisconsin)

Breach notice

Last name and first name or initial, linked to a Social Security, driver’s license, state ID or financial account number, account code or password, DNA profile or unique biometric data. Publicly available, encrypted, redacted or unreadable elements do not count. Unauthorized acquisition can require notice within a reasonable time, at most 45 days after the firm learns of it.

Source Wis. Stat. 134.98(1)(b), (2)(a), (3)(a)

On this site Breach Deadline Calculator

See also Wisconsin exemption for regulated firmsDiscoveryNotification event

Wisconsin exemption for regulated firms

Breach notice

Wisconsin’s breach law excludes a firm “subject to, and in compliance with,” the Gramm-Leach-Bliley Act’s privacy and security requirements, if it has a breach policy in effect. It also excludes that firm’s contractors with such a policy, and HIPAA covered entities complying with 45 CFR part 164. A CPA firm may fall outside the statute this way; ask your counsel.

Source Wis. Stat. 134.98(3m); 15 USC 6801 to 6827; 45 CFR 164.104(a)

On this site Breach Deadline Calculator

See also Personal information (Wisconsin)FTC Safeguards RuleFinancial institution

// Section_721610 terms

Section 7216: tax return information

26 CFR 301.7216-1 to -3 · 26 U.S.C. 7216, 6713

Tax return information

Section 7216

Any information furnished for, or in connection with, preparing a client’s tax return, including name, address and identifying number, whoever supplies it. It includes what your firm derives or generates from it, and statistical compilations even when they identify no one. It counts if the client would not have given it to you except to have you prepare the return.

Tax return preparer

Section 7216

Under section 7216, anyone in the business of preparing income tax returns or providing auxiliary services for them, or otherwise paid to prepare one. Employees who assist count too: in the regulation’s example, the staff who type and e-file returns. A service that only incidentally relates to preparation does not make someone a preparer.

Auxiliary service provider

Section 7216

Anyone in the business of auxiliary services for tax return preparation, including tax software developers and any Authorized IRS e-file Provider, is a tax return preparer. Without consent, return information may go to one only if located in the United States: where its people who receive or view it are, not its headquarters. Whether a vendor qualifies is counsel’s call.

Disclosure (of tax return information)

Section 7216

The act of making tax return information known to any person in any manner whatever. “In any manner whatever” is why a paste into a chat window is inside the definition. Whether the recipient later trains on it is a separate question.

Use (of tax return information)

Section 7216

Use includes any case where a preparer refers to, or relies on, return information as the basis to take or permit an action. Section 7216 reaches use as well as disclosure. A law or accounting firm that prepares the return may, within its legal and ethical duties, use it in-house for other legal or accounting services to that client.

Substantive determination

Section 7216

“A substantive determination involves an analysis, interpretation, or application of the law.” Sharing return information with another firm without consent is allowed only for services that are not substantive determinations or advice affecting the tax the client reports. Sending a client’s return information to another firm to ask whether a deduction is allowed needs the client’s consent first.

Disclosure outside the United States

Section 7216

Before return information goes to a preparer outside the United States, even a colleague in your firm’s office abroad, the client must consent. A contractor’s employee abroad who only views it puts the disclosure outside the United States. Whether automated processing on a server abroad, with no person viewing it, is a disclosure has not been decided.

Social Security number rule for Form 1040 filers

Section 7216

Also SSN rule

Except as (b)(4)(ii) allows, a preparer in the United States “may not obtain consent” to disclose a Form 1040 series filer’s Social Security number to a preparer abroad. Even with consent for the rest, it must “redact or otherwise mask” the number before the information goes abroad. The free Clean Room swaps Social Security numbers it recognizes for tokens.

Penalties under sections 7216 and 6713

Section 7216

Section 7216 makes it a misdemeanor for a preparer to knowingly or recklessly disclose or use return information except to prepare returns. Maximum: a year in prison, a $1,000 fine, or both; section 6713 adds a civil penalty, $250 each, up to $10,000 a year. Tied to identity theft, the caps rise to $100,000, and $1,000 each up to $50,000.

// IRS_Practice9 terms

IRS practice and e-file

31 CFR Part 10 (Circular 230) · IRS Pub. 1345 · 26 CFR 301.7216

Circular 230

IRS practice

Also 31 CFR Part 10

The Treasury rules for practice before the IRS, published as 31 CFR Part 10. Practice includes preparing and filing documents, corresponding with the IRS and representing a client at conferences, hearings and meetings. Its duties bind practitioners: the attorneys, CPAs, enrolled agents and others listed in section 10.3(a) to (f).

Office of Professional Responsibility

IRS practice

Also OPR

The IRS office with general responsibility for “matters related to practitioner conduct” under Circular 230. It also has “exclusive responsibility for discipline, including disciplinary proceedings and sanctions.” For your firm, that means any Circular 230 discipline of your practitioners runs through OPR.

Due diligence as to accuracy

IRS practice

A practitioner must exercise due diligence in preparing, approving and filing returns and other IRS papers. It also covers checking that what they tell Treasury, and clients about IRS matters, is correct. Relying on another person’s work is presumed diligent if the practitioner took reasonable care engaging, supervising, training and evaluating them, subject to sections 10.34 and 10.37.

Firm procedures under Circular 230

IRS practice

Also 31 CFR 10.36

Whoever has principal authority over a firm’s tax practice must take reasonable steps to ensure the firm has adequate procedures for everyone to comply with Circular 230. If the firm names no one, the IRS may identify who is responsible. Discipline needs willfulness, recklessness or gross incompetence, and a pattern or practice of noncompliance at the firm.

Authorized IRS e-file Provider

IRS practice

Also Provider

“A firm accepted to participate in IRS e-file.” Providers of individual income tax returns must report a security incident to the IRS as soon as possible, no later than the next business day after confirming it. Under the section 7216 regulations, every Authorized IRS e-file Provider is a tax return preparer.

Source IRS Pub. 1345 (Rev. 10-2024), ch. 2 and definitions; 26 CFR 301.7216-1(b)(2)(i)(B)

On this site Breach clocks

See also Electronic Return OriginatorElectronic Filing Identification NumberAuxiliary service provider

Electronic Return Originator

IRS practice

Also ERO

“An Authorized IRS e-file Provider that originates the electronic submission of returns to the IRS.” Without the client’s consent, an ERO may pass return information to a Transmitter or Intermediate Service Provider located in the United States, for e-filing. An ERO-only Provider reports a security incident by contacting its local stakeholder liaison.

Source IRS Pub. 1345 (Rev. 10-2024), ch. 2, ch. 3 and definitions; 26 CFR 301.7216-2(d)(1)

On this site Breach clocks

See also Authorized IRS e-file ProviderElectronic Filing Identification Number

Electronic Filing Identification Number

IRS practice

Also EFIN

“An identification number assigned by the IRS to accepted applicants for participation in IRS e-file.” A dropped EFIN is one “no longer valid due to inactivity or other administrative action.”

Source IRS Pub. 1345 (Rev. 10-2024), definitions

See also Authorized IRS e-file ProviderElectronic Return Originator

IRS Publication 4557

IRS practice

Also Safeguarding Taxpayer Data

Safeguarding Taxpayer Data, A Guide for Your Business: an IRS publication on safeguarding taxpayer data, “including how to create a data security plan”. Publication 1345 says it covers security standards and best practice guidelines, with links to NIST publications. For the written plan itself, the IRS points tax and accounting practices to Publication 5708.

Source IRS Pub. 1345 (Rev. 10-2024), ch. 2

On this site WISP Builder

See also Authorized IRS e-file ProviderCircular 230

// SEC_HIPAA_Ethics8 terms

SEC, HIPAA and legal ethics

17 CFR 248.30 · 45 CFR 160, 164 · ABA Model Rule 1.6

Covered institution

SEC, HIPAA, ethics

Any broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission (the SEC) or another appropriate regulatory agency. An affiliated SEC-registered adviser puts a second safeguards regime, with its own clocks, on any systems the accounting firm shares with it.

Sensitive customer information

SEC, HIPAA, ethics

Any part of customer information, alone or combined with other information, whose compromise could create a reasonably likely risk of substantial harm or inconvenience to the person it identifies. Examples: Social Security and taxpayer ID numbers. After unauthorized access or use, the covered institution must notify each affected person, whatever the count, unless it finds harmful use not reasonably likely.

Service provider (Regulation S-P)

SEC, HIPAA, ethics

Any person or entity that receives, keeps, processes or is otherwise allowed to access customer information by serving a covered institution directly. The institution’s policies must be reasonably designed so the provider reports a breach of its customer information systems as soon as possible, within 72 hours of becoming aware. Making sure affected people are notified stays the institution’s duty.

Covered entity (HIPAA)

SEC, HIPAA, ethics

A health plan, a health care clearinghouse, or a health care provider that transmits any health information electronically in connection with a transaction the HIPAA rules cover. The HIPAA security, privacy and breach rules in 45 CFR Part 164 apply to it. Wisconsin’s breach notice law, Wis. Stat. 134.98, does not apply to one that complies with Part 164.

Business associate (HIPAA)

SEC, HIPAA, ethics

An outside person or firm that handles protected health information for a covered entity’s HIPAA-regulated work. It also includes a firm doing legal, accounting, consulting or financial work for one, where the work involves receiving protected health information. If your firm is one, the client may share that information with you only under a written business associate agreement.

Protected health information

SEC, HIPAA, ethics

Also PHI; the electronic part is ePHI (electronic protected health information)

Identifiable information, in any form, about a person’s health, care or payment for care, created or received by a health care provider, health plan, employer or health care clearinghouse. Exclusions include FERPA education records, employment records a covered entity holds as an employer, and information on anyone dead over 50 years. What is kept or sent electronically is ePHI.

Breach (HIPAA)

SEC, HIPAA, ethics

Acquiring, accessing, using or disclosing protected health information in a way HIPAA’s privacy rules do not permit, compromising its security or privacy. Apart from three exclusions, this is presumed a breach unless a risk assessment shows a low probability of compromise. For unsecured information, the covered entity must notify affected people without unreasonable delay, within 60 calendar days of discovery.

Information relating to the representation

SEC, HIPAA, ethics

The category the duty of confidentiality protects: all information relating to the representation, not only what the client marked confidential. Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, that information. Each state adopts its own version and the state’s text governs.

// M365_And_AI10 terms

Microsoft 365 and AI

Microsoft, OpenAI and Anthropic documentation

Tenant

Microsoft 365 and AI

Also Microsoft 365 tenant

Your firm’s own Microsoft 365. Microsoft keeps each tenant’s content logically separate through Microsoft Entra permission controls. Microsoft stores Microsoft 365 Copilot prompts and responses at rest in your tenant’s geography, but the model that answers them runs outside your tenant.

Microsoft Entra

Microsoft 365 and AI

The sign-in and access settings for your firm’s Microsoft 365. Your administrator can use Microsoft Entra ID security groups to limit who may use an outside AI provider, such as Anthropic, in Microsoft 365 Copilot.

Source What is Microsoft Entra?; Assign AI provider access to users and groups (Microsoft 365 Copilot docs)

On this site Microsoft 365 licensing

See also TenantSubprocessor

Microsoft Purview

Microsoft 365 and AI

Microsoft’s family of compliance services for Microsoft 365, including Microsoft Purview Data Loss Prevention, Information Protection and eDiscovery. Microsoft stores each Microsoft 365 Copilot prompt and response in the user’s Exchange Online mailbox, so an administrator can search them and set retention policies for them in Purview.

Source Microsoft Product Terms (Microsoft 365 Compliance Services); Data, Privacy, and Security for Microsoft 365 Copilot

On this site Governed vs ungoverned Copilot

See also Sensitivity labelsCustomer LockboxCopilot prompts and responses at rest

Customer Lockbox

Microsoft 365 and AI

A Microsoft 365 feature that, once turned on, makes a Microsoft support engineer get your firm’s explicit approval before reaching your content; unanswered requests expire. Microsoft says it covers Microsoft 365 Copilot interactions; where the model runs is outside it. It comes with Microsoft 365 or Office 365 E5, or the Microsoft Purview Suite for Business Premium add-on.

Source Microsoft Learn: Customer Lockbox; Microsoft 365 blog: Announcing Customer Lockbox for Office 365; Microsoft Purview Suite for Business Premium

See also Microsoft PurviewWhere the model runs (processing)Copilot prompts and responses at rest

Copilot prompts and responses at rest

Microsoft 365 and AI

Also content of interactions

What Microsoft calls the “content of interactions”: a user’s prompt to Microsoft 365 Copilot and Copilot’s response. Microsoft stores them in the user’s Exchange Online mailbox, and commits to store them at rest in the United States for U.S. tenants. That answers where they are stored, not where the model runs.

Source Data, Privacy, and Security for Microsoft 365 Copilot; Data Residency for Microsoft 365 Copilot and Copilot Chat; Microsoft Product Terms Primary source for Copilot prompts and responses at rest, opens in a new tab

On this site Governed Copilot vs Claude

See also Where the model runs (processing)Data residencyMicrosoft PurviewTenant

Where the model runs (processing)

Microsoft 365 and AI

Also processing location

The separate question from storage: where the AI model does its work on a prompt. Microsoft 365 Copilot’s requests go to a model outside your tenant, routed to the closest data centers in the region or, at busy times, other regions. For U.S. tenants, U.S.-only processing is expected by the end of 2026, not committed.

Source Data, Privacy, and Security for Microsoft 365 Copilot; Microsoft 365 blog: in-country data processing for Copilot Primary source for Where the model runs (processing), opens in a new tab

On this site Governed Copilot vs Claude

See also Copilot prompts and responses at restData residencyEU Data BoundaryAuxiliary service provider

Data residency

Microsoft 365 and AI

Also storage location

Where your data is stored at rest, a separate question from where the model runs. OpenAI’s business plans offer the two as separate opt-in settings (ChatGPT Enterprise and Edu: new workspaces only); a consumer account has neither. Anthropic documents a U.S.-only processing setting for its API, where the default is global routing, and neither control for Team and Enterprise.

Source OpenAI: Enterprise privacy; Claude Platform Docs: Data residency

On this site Client tax data in ChatGPT

See also Copilot prompts and responses at restWhere the model runs (processing)EU Data Boundary

EU Data Boundary

Microsoft 365 and AI

Microsoft’s commitment, for its EU Data Boundary services, to store and process customer data inside the EU and EFTA. For EU customers, Microsoft 365 Copilot is one, but Anthropic models in it are currently excluded. For a U.S. tenant, Microsoft commits to where Microsoft 365 Copilot prompts and responses are stored at rest, not where they are processed.

Source Microsoft Products and Services Data Protection Addendum (Location of Customer Data); Data, Privacy, and Security for Microsoft 365 Copilot; Anthropic as a subprocessor for Microsoft Online Services

On this site Governed Copilot vs Claude

See also Data residencyWhere the model runs (processing)Subprocessor

Subprocessor

Microsoft 365 and AI

A company Microsoft hires for part of the work, contractually limited to using your data for it. Microsoft’s terms let it transfer data to “the United States or any other country in which Microsoft or its Subprocessors operate.” Anthropic is one, on by default for most commercial tenants outside the EU, EFTA and UK; your administrator can turn it off.

Source Microsoft Products and Services Data Protection Addendum; Anthropic as a subprocessor for Microsoft Online Services

On this site Governed Copilot vs Claude

See also Where the model runs (processing)EU Data BoundaryService provider (Regulation S-P)

// Questions8 answers

Questions about these terms

Each answer draws only on the definitions above.

What is the difference between data residency and where the model runs?

They are two separate questions. Data residency is where your data is stored at rest. Where the model runs is where the AI model does its work on a prompt. Microsoft stores Microsoft 365 Copilot prompts and responses in the user’s Exchange Online mailbox. It commits to store them at rest in the United States for U.S. tenants. Microsoft 365 Copilot’s requests go to a model outside your tenant. For U.S. tenants, U.S.-only processing is expected by the end of 2026, not committed.

Terms Data residencyWhere the model runs (processing)Copilot prompts and responses at rest

What counts as tax return information?

Under 26 CFR 301.7216-1, tax return information is any information furnished for, or in connection with, preparing a client’s tax return, whoever supplies it. It includes the client’s name, address and identifying number. It also includes what your firm derives or generates from it, and statistical compilations even when they identify no one. It counts if the client would not have given it to you except to have you prepare the return.

Terms Tax return informationDisclosure (of tax return information)Use (of tax return information)

Is pasting return information into an AI chat a disclosure?

The section 7216 regulations define disclosure as “the act of making tax return information known to any person in any manner whatever.” “In any manner whatever” is why a paste into a chat window is inside the definition. Whether the recipient later trains on it is a separate question. Section 7216 reaches use as well as disclosure.

Terms Disclosure (of tax return information)Use (of tax return information)Tax return information

When does sharing tax return information need the client’s consent?

Before return information goes to a preparer outside the United States, even a colleague in your firm’s office abroad, the client must consent. A contractor’s employee abroad who only views it puts the disclosure outside the United States. Sending a client’s return information to another firm to ask whether a deduction is allowed needs the client’s consent first. The consent is written, knowing and voluntary, signed and dated before the disclosure or use. Whether a particular disclosure needs consent is a conclusion for your firm’s counsel.

Terms Disclosure outside the United StatesSubstantive determinationTaxpayer consent under 26 CFR 301.7216-3Social Security number rule for Form 1040 filers

What is a notification event, and when does the FTC clock start?

Under the FTC Safeguards Rule, a notification event is acquisition of unencrypted customer information without the authorization of the individual to which the information pertains. Data counts as unencrypted if someone unauthorized accessed the key. At 500 or more consumers, the firm must notify the FTC as soon as possible, no later than 30 days after discovery. The event counts as discovered on the first day any employee, officer or other agent of the firm knows of it, other than the person committing the breach.

Terms Notification eventDiscoveryEncryption

Who is the Qualified Individual under the Safeguards Rule?

It is the individual the firm designates to oversee, implement and enforce its information security program. That person may work for the firm, an affiliate or a service provider. With an affiliate or provider, the firm keeps responsibility, names a senior staff member to direct and oversee that person, and requires it to keep a program meeting the rule. The Qualified Individual can also approve, in writing, reasonably equivalent or more secure controls in place of multi-factor authentication.

Terms Qualified IndividualWritten information security plan (WISP)Multi-factor authentication (MFA)

Does the FTC Safeguards Rule apply to an accounting or tax firm?

The rule names tax preparation firms among those it covers. Its definitions say “An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution”. Each covered firm must keep a written information security program, with safeguards fitting its size and complexity, the nature and scope of its activities and the sensitivity of the information. For law firms, ABA v. FTC kept the practice of law outside the FTC’s GLBA authority but never names the Safeguards Rule; ask counsel.

Terms FTC Safeguards RuleFinancial institutionWritten information security plan (WISP)

What changes for a firm with fewer than 5,000 consumers?

Four paragraphs of the Safeguards Rule do not apply to a firm holding customer information on fewer than 5,000 consumers. They are the written risk assessment, the fixed testing schedule, the written incident response plan and the annual written report. The risk assessment and the testing duty themselves remain.

Terms The 5,000-consumer exceptionRisk assessmentIncident response plan

The map behind our engagements shows the control that satisfies each obligation and the evidence that proves it.

See the mapMachine-readableTalk to us

General reference, not legal or tax advice. Each definition was written from the document it cites, and each regulatory entry was checked against the text of the rule or publication it cites. The Microsoft, OpenAI and Anthropic entries follow those companies’ own documentation, which changes; check the current page before relying on one. Claremont Security does not perform audits, issue certifications, or attest to any examination.

16 CFR 314.4(j) · 30 days to notify the FTC of a notification event of 500 or more consumers16 CFR 314.6 · below 5,000 consumers, 314.4(b)(1), (d)(2), (h) and (i) do not apply; every other paragraph does16 CFR 314.2(m) · encrypted customer information with the key intact is not a notification event16 CFR 314.4(c)(5) · multi-factor authentication for any individual accessing any information system, unless an equivalent control is approved in writing16 CFR 314.4(c)(6) · secure disposal within two years of last use, unless a named exception applies16 CFR 314.4(f) · service providers bound by contract to maintain safeguards, and reassessed26 U.S.C. §6713 · $250 per disclosure of return information, $10,000 per calendar year26 CFR §301.7216-2(d)(1), (d)(3) · return information goes without consent only to a preparer located in the United States; a contractor’s employee abroad who only views it puts the disclosure outside the United States