Document Security

Data Privacy Regulations Every Financial and Tax Firm Should Know

Illustration for Data Privacy Regulations Every Organization Should Know

Short answer: US financial, mortgage and tax firms are mainly governed by the Gramm-Leach-Bliley Act (GLBA) and its FTC Safeguards Rule, which require a written information security program to protect customer information. On top of that sit state privacy laws, state breach notification laws, and IRS guidance for tax professionals. HIPAA and GDPR apply only in specific situations.

This article is general information, not legal advice. Which rules apply to your firm depends on what you do and where your customers are.

Privacy rules can look like a wall of acronyms. In practice, most small financial and professional firms in the United States need to understand five things. This guide covers each in plain language: who it applies to, what it asks for, and what to do about it.

At a glance

RuleWho it applies toWhat it asks for
GLBA Privacy RuleFinancial institutions, a term that includes lenders, mortgage brokers and tax preparersTell customers how you collect and share their information
FTC Safeguards RuleThe same financial institutions under FTC jurisdictionRun a written information security program
State privacy lawsBusinesses that meet a state's thresholdsGive residents rights over their personal data
State breach notification lawsAlmost any business holding residents' personal dataNotify people when their data is breached
IRS guidance (Publications 4557 and 5708)Tax professionalsSafeguard taxpayer data and keep a written security plan

1. The Gramm-Leach-Bliley Act

The Gramm-Leach-Bliley Act is the main federal privacy law for the financial sector. It uses a broad definition of "financial institution" that covers far more than banks: mortgage lenders and brokers, loan servicers, tax preparers and some financial advisors are included.

Two parts matter day to day.

The Privacy Rule requires you to give customers a clear notice explaining what information you collect, who you share it with and how you protect it.

The Safeguards Rule requires you to actually protect that information. This is the part with the most operational weight.

2. The FTC Safeguards Rule

The FTC Safeguards Rule requires covered firms to develop, implement and maintain a written information security program. The FTC's guidance lists what that program should include. In summary:

  • Name a qualified individual to run the program.
  • Assess the risks to customer information, in writing.
  • Limit and review who can access customer information.
  • Encrypt customer information in transit and at rest.
  • Use multi-factor authentication for anyone accessing customer information.
  • Dispose of customer information securely when it is no longer needed.
  • Train your staff.
  • Oversee your service providers, and require them by contract to protect the data.
  • Keep a written incident response plan.

The rule also requires covered firms to notify the FTC of certain security events affecting 500 or more consumers.

Smaller firms sometimes assume the rule is aimed at large institutions. It is not. The FTC's guidance is written with small businesses in mind, and some requirements scale with size.

3. State privacy laws

A growing number of states, including California, Virginia, Colorado and Texas, have passed their own consumer privacy laws. They vary, but most give residents the right to know what personal data a business holds, to correct or delete it, and to opt out of certain uses such as targeted advertising.

Two points are easy to miss:

  • Thresholds differ. Many laws apply only above a certain revenue or number of consumers. Check each state where you have customers.
  • GLBA carve-outs differ. Some states exempt data already covered by GLBA; others exempt the institution. The difference matters, so check rather than assume.

4. State breach notification laws

Every US state has a law requiring businesses to notify residents when their personal information is breached. The triggers, deadlines and required content vary by state.

For a small firm, the practical step is to know in advance which states your customers live in, and to have a short plan for who decides, who notifies and how quickly.

5. IRS guidance for tax professionals

Tax preparers have two documents to keep within reach.

Publication 4557, Safeguarding Taxpayer Data, explains the safeguards expected of tax professionals. Publication 5708 walks through writing a Written Information Security Plan (WISP) for a tax and accounting practice. A WISP is also how most small practices meet the Safeguards Rule's requirement for a written program.

When HIPAA and GDPR apply

HIPAA protects health information held by healthcare providers, health plans and the businesses that handle that information for them. A financial or tax firm is usually not covered unless it processes health information on behalf of one of those entities. If you are, you need tools that support HIPAA and a Business Associate Agreement with each vendor.

GDPR is the European Union's privacy law. It can apply to a US firm that offers services to people in the EU. If your clients are all in the United States, it is unlikely to apply to you.

What these rules have in common

Strip away the acronyms and the same five habits appear in almost every rule.

  1. Know what you hold. List the kinds of customer data you collect and where each is stored.
  2. Limit access. Only the people who need a record should be able to open it.
  3. Encrypt. In transit and at rest.
  4. Write it down. A short, accurate plan beats a long one nobody follows.
  5. Check your vendors. Their security becomes part of yours.

Questions to ask any vendor that will hold customer data

  1. Is data encrypted in transit and at rest, and which parts are covered?
  2. Who can access customer data, and how is access reviewed?
  3. Has the vendor completed an independent examination, such as a SOC 2 Type 2, and can we read the report under an NDA?
  4. Which third parties, including AI providers, process our customers' data?
  5. What happens to data when we delete it or leave?
  6. Is the service suitable for health information, and will the vendor sign a Business Associate Agreement?
  7. Will the vendor notify us of a security incident, and how fast?

Where SafeVault fits

A document platform is one control inside your security program. It does not make a firm compliant on its own. Here is what SafeVault does and does not do, so you can map it to your own plan.

  • Documents are encrypted in transit using TLS and at rest using AES-256.
  • Access is granted to named people, sharing can be withdrawn, and document actions are recorded in an activity log inside the product.
  • AmitaSoft, LLC has received a SOC 2 Type 2 report covering Security, Availability, Processing Integrity and Confidentiality. See our security page.
  • Our Privacy Policy names every service provider that processes customer data, including the AI providers used to read and classify documents.
  • SafeVault is not HIPAA compliant and does not offer a Business Associate Agreement. Do not use it for protected health information.
  • SafeVault is offered to users in the United States.

For profession-specific guidance, see client portals for accountants and secure file sharing for law firms.

Key takeaways

  • GLBA and the FTC Safeguards Rule are the core privacy rules for US financial, mortgage and tax firms.
  • The Safeguards Rule requires a written information security program, including encryption, access limits and multi-factor authentication.
  • State privacy laws and breach notification laws add obligations that vary by state.
  • Tax professionals should keep IRS Publications 4557 and 5708 on hand.
  • HIPAA and GDPR apply only in specific situations.
  • No software makes a firm compliant by itself. Tools support the program; they are not the program.

Frequently asked questions

Which data privacy regulations apply to tax preparers?

In the United States, tax preparers are treated as financial institutions under the Gramm-Leach-Bliley Act and must follow the FTC Safeguards Rule. IRS Publications 4557 and 5708 give tax-specific guidance, and state privacy and breach notification laws may also apply.

What does the FTC Safeguards Rule require?

A written information security program that includes a qualified individual in charge, a risk assessment, access controls, encryption, multi-factor authentication, staff training, oversight of service providers and an incident response plan.

Does GDPR apply to US financial firms?

Only if the firm offers services to people in the European Union. A firm with only US customers is unlikely to be covered.

Does using secure software make a firm compliant?

No. Secure tools support your obligations, but compliance depends on your firm's own written program, policies, training and oversight.

This article is general information, not legal advice.

Thanks for reading! Let's connect and continue the conversation.

Email support-safevault@amitasoft.com

Phone +1 408-430-3650

Ready to organize important documents before you need them?

Explore SafeVault or contact our team to see how secure document workflows can support families, professionals, and service providers.

Explore Products Contact Us