Legal & Compliance
Every legal and compliance page requires review by an attorney licensed in South Carolina before publication. Several describe obligations that must genuinely be in place rather than merely described. This is drafted content, not executed policy, and it is not legal advice.
Paid tax preparers are financial institutions under the Gramm-Leach-Bliley Act and are directly subject to the FTC Safeguards Rule.
The Safeguards Rule
This firm maintains a Written Information Security Plan (WISP) in accordance with the FTC Safeguards Rule at 16 CFR Part 314, as amended in 2022 and fully enforced since June 2023. IRS Publication 4557 sets the guidance, Publication 5708 provides a sample WISP for sole proprietors, and Publication 5709 is a build guide.
What the WISP includes
- A designated qualified individual responsible for the WISP
- A written risk assessment
- Access controls authentication, authorization, and least-privilege access
- Encryption of customer information in transit and at rest
- Multi-factor authentication
- Secure disposal of data no longer needed
- Service provider oversight vendors evaluated and contracted under the Safeguards Rule
- Regular monitoring and testing of safeguards
- Workforce training
- A written incident response plan
Annual review
The WISP is reviewed annually and updated as needed. The current version and prior versions are retained.
PTIN certification
Since 2023, Form W-12 PTIN renewal requires certifying that a data security plan exists. Falsely certifying is perjury. This firm's WISP is maintained and certified at PTIN renewal.
Tax return information
Return information is used only to prepare your return. It is not disclosed or used for any other purpose without your prior written consent in the form required by IRC §7216. Unauthorized disclosure or use of tax return information is a criminal offense.
Secure portal only
Tax documents are exchanged only through a secure client portal never by email or through website forms. The portal provides encryption in transit and at rest, multi-factor authentication, per-user access controls, and audit logging.