Data Encryption for Tax Preparers
Security Six requirement #4: All client data must be encrypted at rest and in transit. This means tax returns, SSNs, financial records, and backups — everywhere they exist.
Encryption at rest vs. in transit
Encryption at Rest
Data stored on your devices, servers, and backups. Use full-disk encryption (BitLocker on Windows, FileVault on Mac) and encrypted cloud storage. If a device is stolen, encryption makes the data unreadable.
Encryption in Transit
Data being sent between systems — emails, file uploads, web connections. Use TLS/SSL for web traffic, encrypted email (TLS or S/MIME), and SFTP for file transfers. Never send client data over unencrypted channels.
The FTC Safeguards Rule explicitly requires encryption of "all customer information" in both states. This is one of the 9 mandatory elements — not a recommendation. If an auditor or breach investigation finds unencrypted client data, you’re in violation.
Where encryption is required in your practice
Computer hard drives
Enable BitLocker (Windows) or FileVault (Mac) on every device. Full-disk encryption protects data if a device is lost or stolen.
Email communications
Use encrypted email services or ensure TLS is enabled. Never email unencrypted tax documents — use secure portals or encrypted attachments.
Cloud storage
Verify your cloud provider encrypts data at rest and in transit. ShareFile, SmartVault, and most business cloud services include this.
Backup files
Backups contain all your client data. They must be encrypted too — an unencrypted backup is a single point of failure for your entire practice.
Encryption FAQ for tax preparers
No. PDF password protection is weak and easily bypassed. True encryption uses AES-256 or similar standards to make data mathematically unreadable without the encryption key. Full-disk encryption (BitLocker, FileVault) and encrypted cloud storage provide real protection. Password-protected PDFs are not sufficient for IRS or FTC compliance.
You should never send unencrypted tax documents via email. The best practice is to use a secure client portal (ShareFile, SmartVault) for document exchange. If you must email documents, use encrypted email services or encrypted attachments with the password shared via a separate channel (phone or text).
The IRS and FTC don’t specify a single standard, but AES-256 is the industry benchmark and the minimum you should use. For data in transit, TLS 1.2 or higher is required. Most modern software and cloud services use these standards by default — verify with your vendors and document it in your WISP.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
