Data Backup Plan for Tax Preparers
Security Six requirement #5: Regular backups of all client data with offsite storage. Ransomware, hardware failure, or natural disaster — backups are your recovery lifeline.
The 3-2-1 backup rule
The IRS recommends the 3-2-1 backup strategy as the foundation of your data protection plan:
Critical: All backups must be encrypted. An unencrypted backup is a complete copy of every client’s sensitive data sitting in one place. And test your restores regularly — a backup you can’t restore from is worthless.
Backup best practices for tax offices
Automate your backups
Manual backups get forgotten. Use automated backup software that runs daily (or more frequently during tax season) without requiring human action.
Encrypt everything
Both local and cloud backups must be encrypted. Use AES-256 encryption and store encryption keys separately from the backup data.
Test restores quarterly
Verify you can actually restore from your backups. Pick random files and restore them to confirm the process works. Document each test in your WISP.
Retain for 7 years
The IRS requires tax preparers to retain client records and related security logs for a minimum of 7 years. Plan your backup retention accordingly.
Backup FAQ for tax preparers
Daily at minimum. During tax season, consider backing up multiple times per day. The goal is that if something goes wrong, you lose no more than one day’s work. Automated backup solutions can run continuously in the background.
No. An external hard drive connected to your computer can be encrypted by ransomware along with your main drive. You need at least one offsite or disconnected backup. The 3-2-1 rule requires different media types and an offsite copy. A local drive plus encrypted cloud backup is a good minimum setup.
Tax software cloud backups cover the data within that application, but not everything else: client documents, emails, scanned forms, and your WISP/compliance documentation. You need a comprehensive backup strategy that covers all client data, not just what’s in one application.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
