Tax preparers must securely destroy taxpayer data once it's no longer needed for the purpose it was collected, using methods that make the information unreadable and unrecoverable. This obligation comes from three overlapping sources: the Federal Trade Commission (FTC) Safeguards Rule, the FACTA Disposal Rule, and Internal Revenue Service (IRS) Publication 4557 requirements 2026 guidance on safeguarding taxpayer data. For paper records, that generally means cross-cut shredding, not the trash or recycling bin. For digital records, client files, hard drives, old backups, USB drives, decommissioned copiers with internal storage, it means sanitizing the media to a recognized standard, not just deleting files or reformatting a drive.
Getting this wrong isn't a minor paperwork gap. Improperly disposed records are one of the more common ways sensitive taxpayer data ends up exposed after a firm closes, moves offices, or replaces equipment, and it's the kind of failure regulators and state breach-notification laws treat seriously.
Quick Answer
Tax preparers are required to dispose of taxpayer data securely once it's no longer needed, under the FTC Safeguards Rule (16 CFR Part 314) and the FACTA Disposal Rule, and are further guided by IRS Publication 4557. Paper records need cross-cut shredding or a certified destruction vendor. Digital media, drives, backups, old devices, needs sanitization that meets a recognized standard such as NIST Special Publication 800-88, not a simple delete or reformat. Document your destruction process in your written information security plan (WISP).
The regulatory framework behind destruction requirements
Most paid tax preparers meet the FTC's definition of a "financial institution" under the Gramm-Leach-Bliley Act, which means they fall under the FTC Safeguards Rule. The Safeguards Rule requires firms to develop, implement, and maintain a written information security program, and one specific element of that program is disposing of customer information within a reasonable time after it's no longer needed for business or legal purposes.
A separate but related requirement, the FTC Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA), applies to any business that uses consumer report information, which covers most tax firms, and requires reasonable measures to prevent unauthorized access to or use of that information when it's discarded. The rule doesn't mandate one specific technology, but it does expect the destruction method to actually work: burning, pulverizing, or shredding paper, and destroying or erasing electronic media so the information can't practicably be read or reconstructed.
IRS Publication 4557Safeguarding Taxpayer Data, ties these obligations back to preparer-specific practice, and IRS Publication 5708 walks preparers through building a compliant WISP template that includes a data retention and destruction policy. None of these sources are optional guidance for firms handling Social Security numbers, Employer Identification Numbers, bank account details, or prior-year returns.
What counts as "secure" destruction
Deleting a file or emptying the recycle bin does not destroy data, it removes the pointer to the file while the underlying data typically remains recoverable with basic forensic tools. Secure destruction needs to make the data unrecoverable, and the right method depends on the media.
Paper records
- Use a cross-cut or micro-cut shredder rather than a strip-cut model, which is easier to reconstruct.
- For high volume, use a destruction vendor certified under the National Association for Information Destruction (NAID) AAA standard and get a certificate of destruction for your files.
- Never place client tax documents in general office recycling or trash, even temporarily.
Digital media
- Follow NIST Special Publication 800-88Guidelines for Media Sanitization, which defines three sanitization levels, clear, purge, and destroy, based on how sensitive the data is and whether the media will be reused.
- For drives being retired or resold, use software that performs a verified multi-pass overwrite or cryptographic erase, not a standard format.
- For drives that held highly sensitive data and won't be reused, physical destruction (degaussing or shredding the drive itself) removes any recovery risk entirely.
- Don't forget office copiers and scanners with internal hard drives, old backup tapes, and decommissioned point-of-sale or accounting workstations, these are commonly overlooked sources of residual taxpayer data.
Retention comes before destruction
Destruction only applies once your legitimate retention period has ended. Circular 230 and Internal Revenue Code Section 6107 generally require paid preparers to keep copies of returns, or a list of taxpayers and the types of returns prepared, for at least three years. Many firms retain records longer, often five to seven years, to align with IRS audit windows, state statutes of limitations, and professional liability considerations. This is a business and risk decision that should be documented in your written information security plan; a qualified tax or legal advisor can help you set a retention schedule appropriate for your practice, since the right period varies by state and engagement type.
Once a document or file passes its retention date, it should move into your destruction workflow rather than sitting indefinitely in a filing cabinet or on an old server, which only expands the amount of data exposed if a breach occurs.
Secure Destruction Action Checklist
- Set a documented retention schedule for returns, workpapers, and client PII, confirmed with your tax or legal advisor
- Use a cross-cut or micro-cut shredder for all paper containing taxpayer data before disposal
- Sanitize retired drives, backups, and devices to NIST SP 800-88 standards before reuse or resale
- Physically destroy media that held highly sensitive data and won't be reused
- Include copiers, scanners, and point-of-sale devices with internal storage in your destruction inventory
- Get a certificate of destruction from any third-party vendor and keep it on file
- Document your destruction process and retention schedule in your WISP
Document it in your WISP, and vet your vendor
A destruction policy that exists only in someone's head doesn't satisfy the Safeguards Rule's written program requirement, and it won't hold up if a regulator, cyber insurer, or client asks how your firm handles disposal. Your written information security plan should spell out what gets retained, for how long, how it's destroyed, and who's responsible for verifying it happened. Firms that skip this step are exposed to the same gaps outlined in our breakdown of WISP penalties for missing or incomplete plans.
If you use a third-party shredding or e-waste destruction vendor, ask for NAID AAA certification, a signed certificate of destruction for every job, and confirmation of how they handle chain of custody between pickup and destruction. If you're clearing your own drives in-house, use tools that produce a verifiable log rather than trusting a one-click "format" option. Building or updating a WISP that covers destruction alongside access control, incident response, and vendor management doesn't have to start from scratch, see our IRS WISP template walkthrough or the Bellator WISP, custom-built for practices with up to 5 users starting at $749, with larger firms quoted separately.
Improper disposal can trigger breach notification
If taxpayer data is discarded in a way that leaves it accessible, unshredded paper in the trash, a resold laptop with a recoverable drive, that can be treated as an unauthorized disclosure under state breach notification laws, separate from any FTC Safeguards Rule enforcement exposure. Confirm your state's specific notification triggers with legal counsel; requirements vary and are not something a security vendor can advise on.
Get Your WISP Destruction Policy Reviewed
Bellator Cyber Guard builds custom written information security plans for tax and accounting firms, including documented data retention and destruction procedures that align with FTC Safeguards Rule and IRS Publication 4557 expectations.
Frequently Asked Questions
No. Deleting a file or emptying the recycle bin removes the reference to it, but the underlying data is typically still recoverable with basic tools. Secure destruction requires sanitization methods, such as those in NIST SP 800-88, that make the data unrecoverable, or physical destruction of the media.
Circular 230 and IRC Section 6107 generally require paid preparers to keep copies of returns, or a list of clients and return types, for at least three years. Many firms retain records longer to cover IRS audit windows and state statutes of limitations. A tax or legal advisor can help set the right schedule for your practice.
No. Under the FACTA Disposal Rule and the FTC Safeguards Rule, taxpayer records need to be destroyed using methods that prevent the information from being read or reconstructed, such as cross-cut shredding. General trash or recycling doesn't meet that standard.
It's a strong practice, though not universally mandated by a single named rule. A certificate of destruction documents that the destruction occurred, when, and by what method, which supports the written records the FTC Safeguards Rule expects and gives you documentation if a client or regulator asks.
At minimum: a retention schedule by record type, approved destruction methods for paper and digital media, vendor vetting requirements, who is responsible for verification, and how destruction is logged. IRS Publication 5708 outlines this as part of a full written information security plan.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



