{
  "question_id": "CG-MCE-132",
  "slug": "what-data-security-a-bookkeeping-or-tax-practice-owes-its-clients-records",
  "display_title": "What data-security obligations does a bookkeeping or tax practice have for its clients' records, and what has to be written down?",
  "format": "article-v2",
  "applies_to": {
    "countries": [
      "US"
    ],
    "frameworks": [],
    "tax_year": null,
    "platforms": []
  },
  "general_concept": false,
  "summary": "A practice that completes income tax returns is a financial institution under the FTC's Safeguards Rule, and IRS Publication 5708 says size does not matter. It must keep a written information security program covering the rule's elements, including a Qualified Individual, risk assessment and service-provider oversight. Below 5,000 consumers four requirements fall away, but Publication 5708 still calls for written incident and notification plans. Breaches can trigger FTC, IRS and state notices. Bookkeeping-only practices must check coverage.",
  "body": "## Is my practice covered, even if I work alone?\n\nThe Safeguards Rule, 16 CFR Part 314, applies to the handling of customer information by all financial institutions over which the Federal Trade Commission has jurisdiction and that are not subject to another regulator's enforcement authority under section 505 of the Gramm-Leach-Bliley Act. Its scope names tax preparation firms, and in its examples an accountant or other tax preparation service in the business of completing income tax returns is a financial institution. IRS Publication 5708 says tax and accounting professionals are considered financial institutions, regardless of size, and that a sole practitioner can use a more abbreviated and simplified plan than a 10-partner accounting firm.\n\n### What if I only keep books?\n\nThe rule gives no bookkeeping-only example. The FTC's business guide says what matters is the types of activities your business undertakes, not how you or others categorize your company, and asks whether they are financial in nature or incidental to financial activities as described in section 4(k) of the Bank Holding Company Act of 1956. It says section 314.2(h) lists 13 examples of financial institutions and four examples of businesses that are not: compare your services with both, with professional advice, rather than assume either answer. Preparing returns adds the IRS duties below, and state laws have coverage tests of their own.\n\n### What does the 5,000-consumer exception change?\n\nSection 314.6 says sections 314.4(b)(1), (d)(2), (h) and (i) do not apply to institutions that maintain customer information concerning fewer than five thousand consumers: the written risk assessment, the testing intervals, the written incident response plan and the Qualified Individual's report. Every other element applies at any size.\n\n\"Consumer\" and \"customer\" are defined terms in section 314.2. A consumer is an individual who obtains or has obtained a financial product or service from you that is to be used primarily for personal, family or household purposes, or that individual's legal representative. A customer is a consumer with a customer relationship with you, which the rule's examples say includes becoming your client to obtain tax preparation. The rule does not say how business clients, their owners or clients' employees whose payroll you process are counted, so take professional advice before relying on the exception. The same question of who counts as a consumer applies to the FTC notice, but there you count the consumers whose information was involved in the event.\n\n## What must the written plan contain?\n\nSection 314.3(a) requires you to develop, implement and maintain a comprehensive information security program, written in one or more readily accessible parts, with administrative, technical and physical safeguards appropriate to your size and complexity, the nature and scope of your activities and the sensitivity of the customer information. It must include the elements of section 314.4, and the customer information it protects includes paper records. Security tools do not replace the written program. Check a plan against each element:\n\n| Element | What the plan must cover | Below 5,000 consumers |\n|---|---|---|\n| (a) Qualified Individual | Who oversees, implements and enforces the program | Applies |\n| (b) Risk assessment | Foreseeable internal and external risks and whether safeguards suffice, reassessed periodically | Applies, but not the written form or the (b)(1) criteria |\n| (c)(1) Access controls | Technical and, as appropriate, physical controls, periodically reviewed, that authenticate and permit access only to authorized users and limit them to the customer information their duties need (customers to their own) | Applies |\n| (c)(2) Inventory | Data, personnel, devices, systems and facilities, managed by importance to business objectives and your risk strategy | Applies |\n| (c)(3) Encryption | All customer information in transit over external networks and at rest, or compensating controls your Qualified Individual reviews and approves where encryption is infeasible | Applies |\n| (c)(4) Applications | Secure development for in-house applications, and procedures for evaluating or testing the security of outside applications you use for customer information | Applies |\n| (c)(5) Multi-factor authentication | Anyone accessing any information system, unless your Qualified Individual approves reasonably equivalent or more secure controls in writing | Applies |\n| (c)(6) Disposal | Secure disposal procedures within the limit and exceptions paragraph (c)(6) sets, and periodic review of your data retention policy | Applies |\n| (c)(7) Change management | Procedures for change management | Applies |\n| (c)(8) User monitoring | Logging authorized users' activity and detecting unauthorized access, use or tampering | Applies |\n| (d) Testing | Regular testing or monitoring of key controls; without effective continuous monitoring or other systems detecting changes that may create vulnerabilities, annual penetration testing, and vulnerability assessments at least every six months and after material changes, and whenever circumstances you know or have reason to know may have a material impact on the program | (d)(1) applies; (d)(2) does not |\n| (e) Personnel | Awareness training updated for assessed risks, qualified security personnel, updates and training for them, and checks that they keep current | Applies |\n| (f) Service providers | Selection, contract and periodic assessment | Applies |\n| (g) Evaluation | Adjusting the program after testing, business changes, reassessments and other material circumstances | Applies |\n| (h) Incident response plan | Written, covering the seven areas below | Not required by the rule; Publication 5708 still calls for incident and notification plans |\n| (i) Qualified Individual's report | In writing, at least annually, to the board or, without one, a senior officer | Not required |\n| (j) FTC notice | A notification event involving 500 or more consumers | Applies |\n\n## Who must be designated, and can it be me?\n\nSection 314.4(a) says the Qualified Individual may be employed by you, an affiliate or a service provider. If a service provider or affiliate fills the role, you must retain responsibility for compliance, designate a senior member of your personnel to direct and oversee the Qualified Individual, and require the provider or affiliate to maintain a program that protects you as the rule requires. The FTC's business guide says the person doesn't need a particular degree or title: what matters is real-world know-how suited to your circumstances, and a small business's choice may have a different background from someone running a large corporation's system.\n\nThe rule does not speak to a practice of one. Read with the guide, the owner can hold the role if they have that know-how; otherwise, use a service provider on the three conditions above. Name the holder in the plan, as Publication 5708's outline does.\n\n## What must the risk assessment consider, and what record of it is kept?\n\nSection 314.4(b) bases the program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could lead to its unauthorized disclosure, misuse, alteration, destruction or other compromise, and assesses whether the safeguards in place are sufficient. At 5,000 consumers or more it must be written and include:\n\n- Criteria for evaluating and categorizing identified security risks or threats\n- Criteria for assessing the confidentiality, integrity and availability of your information systems and customer information, including the adequacy of existing controls\n- Requirements describing how identified risks will be mitigated or accepted, and how the program will address them\n\nAt any size, section 314.4(b)(2) requires periodic additional assessments that reexamine the risks and reassess the safeguards. Publication 5708's outline puts the assessment in every plan: list the types of information your office handles, list potential areas for data loss, and outline procedures to monitor and test risks. Below 5,000 consumers, keep each dated assessment with the plan as the record that it happened.\n\n## How do cloud platforms and outsourced processors fit in?\n\nThe rule defines a service provider as any person or entity that receives, maintains, processes or otherwise is permitted access to customer information through its provision of services directly to a financial institution subject to the rule. Cloud software, document storage, payroll processors and IT support that you engage, and that reach client data through their services to you, fit those words, and Publication 5708 has you set policies for your internet service provider, cloud hosting provider and other services connected to stored client data. If most client data sits with them, a plan limited to your own machines leaves most of it out. Where a client holds the subscription and gives you a login, the vendor serves the client, and the rule does not say how it treats that; record in the plan which systems you engaged and which belong to clients.\n\nSection 314.4(f) sets three duties for each provider you engage:\n\n- **Selection.** Take reasonable steps to select and retain providers capable of maintaining appropriate safeguards for the customer information at issue.\n- **Contract.** Require them by contract to implement and maintain those safeguards.\n- **Monitoring.** Assess them periodically, based on the risk they present and the continued adequacy of their safeguards.\n\nKeep a file per provider showing how it was chosen, the contract terms and each assessment, resting on evidence you check yourself rather than the provider's own account alone. Setting up a client portal is a separate question.\n\n## What must be set out before an incident?\n\nAt 5,000 consumers or more, section 314.4(h) requires a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity or availability of customer information in your control. It must address these seven areas:\n\n- The plan's goals\n- Internal processes for responding to a security event\n- Clear roles, responsibilities and levels of decision-making authority\n- External and internal communications and information sharing\n- Requirements for remediating identified weaknesses in information systems and associated controls\n- Documentation and reporting of security events and related response activities\n- Evaluation and revision of the plan as necessary after a security event\n\nBelow that threshold, keep a written path anyway. Section 314.6 does not exempt the FTC notice, IRS Publication 1345 says its incident-reporting standard is mandated for all Authorized IRS e-file Providers, and Publication 5708 tells tax and accounting practices to create both an incident response plan and a breach notification plan. It says the plans should at a minimum include the steps to re-secure your devices, data, passwords and networks and who will take them, and has you describe the coordinator's duties to notify outside agencies such as the IRS Stakeholder Liaison, the FTC, the state attorney general, the FBI local field office for a cybercrime, and local law enforcement.\n\n## Who must be told after a breach, and on what trigger?\n\nEach recipient has its own trigger and clock:\n\n| Recipient | Trigger | Deadline | Set by |\n|---|---|---|---|\n| FTC | A notification event involving the information of at least 500 consumers, counting consumers as defined above | As soon as possible, and no later than 30 days after discovery | Safeguards Rule, section 314.4(j) |\n| IRS | For an Authorized IRS e-file Provider of individual income tax returns, an event that can result in unauthorized disclosure, misuse, modification or destruction of taxpayer information | As soon as possible, and not later than the next business day after confirmation of the incident | IRS Publication 1345 |\n| Affected people and state officials | As each state's law defines it | As each state's law sets | Each state's law |\n\nUnder the rule, a notification event is acquisition of unencrypted customer information without the authorization of the individual it concerns. Information counts as unencrypted if the encryption key was accessed by an unauthorized person, and unauthorized access to unencrypted customer information is presumed to be acquisition unless you have reliable evidence that there has not been, or could not reasonably have been, unauthorized acquisition. The event is discovered on the first day it is known to you, and it is known to you once any employee, officer or other agent of yours, other than the person committing the breach, knows of it. The notice is made electronically on a form on the FTC's website; the FTC's business guide says to report what you know and submit an updated report when you have more details.\n\n## What should I do when a breach is suspected or confirmed?\n\nEach report runs on its own clock from its own trigger, so do not hold the FTC or IRS report back until containment or an expert's findings are complete; each state's law sets its own timing. Time letters to affected individuals with law enforcement, as the IRS data theft page says. Take these steps, in no fixed order:\n\n- **Secure your systems.** The FTC's Data Breach Response guide says to move quickly to secure your systems and fix vulnerabilities that may have caused the breach, and to update authorized users' credentials and passwords. It also says to take all affected equipment offline immediately but not to turn any machines off until the forensic experts arrive; the Safeguards Rule presumes acquisition from unauthorized access to unencrypted customer information unless you have reliable evidence showing otherwise. If an e-file provider's website caused the incident, Publication 1345 requires it to stop collecting taxpayer information through the website immediately and until the causes are resolved.\n- **Report to the IRS.** If you are an Authorized IRS e-file Provider of individual income tax returns, Publication 1345 requires a report as soon as possible and no later than the next business day after confirmation; the IRS data theft page tells tax professionals to report client data theft to their local IRS stakeholder liaison. Publication 1345 sends providers that are EROs only to their local stakeholder liaison, and providers with several roles to the IRS instructions for submitting incident reports. The IRS's data theft page for tax professionals says speed is critical: if reported quickly, the IRS can take steps to block fraudulent returns using your clients' information.\n- **Call the police.** The FTC's Data Breach Response guide says to call your local police department immediately; the IRS page also lists the FBI's local office and, if directed, the Secret Service's.\n- **Count for the FTC.** From the day of discovery, work out how many consumers' information may be involved, and file the FTC notice if it reaches 500.\n- **List the states.** Each state's clock runs on its own terms, so list affected people's states now, by the method below.\n- **Bring in help.** The IRS page lists a security expert to determine the cause and scope and stop the breach, and your insurance company, to report the breach and check whether your policy covers mitigation expenses.\n- **Tell affected individuals.** The IRS page says to send each victim an individual letter but work with law enforcement on timing, and that certain states require offering credit monitoring or identity theft protection.\n\nA bookkeeping-only practice runs the same list without the IRS report.\n\n## How often must the plan be reviewed, and what forces an earlier revision?\n\nSection 314.4(g) requires you to evaluate and adjust the program in light of testing and monitoring results, any material changes to your operations or business arrangements, the results of periodic risk assessments, and any other circumstances you know or have reason to know may have a material impact on it. The FTC's business guide names changes in personnel among them. The rule gives no fuller list, so treat adding a cloud platform or processor, moving office, starting return preparation and any security event as prompts to run the evaluation.\n\nThe rule's fixed review and testing intervals apply only at 5,000 consumers or more: the Qualified Individual's written report at least annually and, without effective continuous monitoring, annual penetration testing and six-monthly vulnerability assessments. At any size, Publication 5708's template says to review and update the plan at least annually.\n\n## What must the practice be able to produce to show compliance?\n\nThe rule requires records to exist rather than listing documents to hand over, so keep one file holding:\n\n- The written program, naming the Qualified Individual and any overseeing senior member — required: 16 CFR 314.3(a) and 314.4(a)\n- The written risk assessment, at 5,000 consumers or more — required: 16 CFR 314.4(b)(1)\n- A dated record of each reassessment, and of each assessment below 5,000 consumers — recommended\n- Written approval of any alternative to multi-factor authentication — required: 16 CFR 314.4(c)(5)\n- A record of any compensating controls for encryption your Qualified Individual approved — recommended\n- Each provider contract requiring safeguards — required: 16 CFR 314.4(f)(2)\n- The rest of each provider file — recommended\n- Training records, including staff acknowledgments updated at annual training — recommended (Publication 5708)\n- The written incident response plan, at 5,000 consumers or more — required: 16 CFR 314.4(h)\n- A breach notification plan, and an incident response plan below 5,000 consumers — recommended (Publication 5708)\n- Records of each security event and the response — recommended\n- The Qualified Individual's reports, at 5,000 consumers or more — required: 16 CFR 314.4(i)\n- A dated log of each evaluation and change to the plan — recommended (Publication 5708 keeps changes as an addendum)\n- A copy of any FTC notice you filed — recommended\n\nPublication 5708 recommends keeping the plan in a format others can easily read, with a copy offsite or in the cloud, signed and dated by the principal operating officer or owner and the coordinator.\n\n## Who enforces the rule, and what kind of consequence follows?\n\nThe FTC enforces the rule, which covers institutions within its enforcement jurisdiction under section 505(a)(7) of the Gramm-Leach-Bliley Act. IRS Publication 1345 says that under the rule tax return preparers must create and enact security plans, that failing to do so may result in an FTC investigation, and that not taking necessary steps to implement or correct a security program may bring FTC sanctions. It adds that failures leading to an unauthorized disclosure may bring penalties under Internal Revenue Code sections 7216 and/or 6713. E-file providers face a further IRS route: violating Publication 1345 may bring sanctions.\n\n## How do state laws add to this, and which states apply?\n\nThe FTC's Data Breach Response guide says all states, the District of Columbia, Puerto Rico and the Virgin Islands have enacted legislation requiring notification of security breaches involving personal information. Each law sets its own trigger, recipients and timing, and a state may also have a data-security law, so no one state's rule stands for the rest. Work through these steps in order:\n\n1. List the states where every person whose personal information you hold lives. That means everyone named in the records, not only individual clients, clients' employees whose payroll you handle and your own staff; for example, others named on returns, owners and partners of business clients, and contractors or vendors whose details you hold for clients. In an incident, narrow the list to the people whose information was involved.\n2. For each state, read its breach-notification statute, its attorney general's guidance and any data-security law, including each law's scope and exemptions.\n3. If you prepare returns, add each state in which you prepare returns: the IRS data theft page has you report to state tax agencies and decide whether to notify each such state's attorney general.\n4. Record the result in the plan, since Publication 5708's implementation clause adds any state regulatory requirements that apply.\n\nCalifornia shows the pattern. The California Attorney General's undated breach-reporting page says California law requires a business to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person, and that a business required to notify more than 500 California residents about a single breach must electronically submit a single sample copy of the notice, excluding personally identifiable information, to the Attorney General. California Civil Code section 1798.81.5 separately requires a business that owns, licenses or maintains personal information about a California resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to protect it from unauthorized access, destruction, use, modification or disclosure. A business disclosing such information under a contract with a nonaffiliated third party not itself subject to that duty must require the same by contract. The section excludes, among others, a financial institution as defined in Financial Code section 4052 and subject to the California Financial Information Privacy Act. It also excludes a business regulated by state or federal law giving personal information greater protection than the section does on the subjects it addresses. A practice under the Safeguards Rule should check whether either exclusion removes it from this section.\n\n## What confidentiality duties does a credential or licence add?\n\nLicensing duties are set state by state and body by body, so read the conduct rules of whoever licenses or credentials you, such as a state board, a professional membership body and, where you practice before it, the IRS, whose Circular 230 governs that practice. As one example, California Business and Professions Code section 5063.3, in its chapter on accountants, bars a licensee from disclosing confidential information obtained in their professional capacity about a client or prospective client without that person's written permission, except in seven cases it lists, such as a court-enforceable subpoena or summons or an official inquiry from a federal or state regulatory agency. It binds licensees under California's accountancy chapter. Its subsection (b) adds that where confidential client information may be disclosed to persons or entities outside the United States in connection with the services, the licensee must inform the client in writing and obtain the client's written permission. Check that against any provider that stores or processes client data abroad.\n\n## Is a records-retention policy part of this obligation?\n\nNot as a substitute. The rule requires periodic review of your data retention policy to minimize unnecessary retention, and Publication 5708 lists data collection and retention among the plan's policies and suggests a separate records retention policy as an attachment, so the policy sits inside the plan. But it satisfies no other security element, and the duty to keep records for a period comes from other instruments. For a tax return preparer, 26 U.S.C. 6107(b) requires keeping, for a period the statute sets, a completed copy of each return or claim for refund prepared, or a list of the taxpayers' names and identification numbers, and making it available for inspection on request by the Secretary. How long to keep client records is a separate question.",
  "sources": [
    {
      "id": "REF::1",
      "url": "https://www.govinfo.gov/content/pkg/CFR-2026-title16-vol1/pdf/CFR-2026-title16-vol1-part314.pdf",
      "title": "16 CFR Part 314, Standards for Safeguarding Customer Information",
      "publisher": "Federal Trade Commission, published by the Office of the Federal Register and U.S. Government Publishing Office",
      "published": "16 CFR Ch. I (1-1-26 Edition)",
      "retrieved_at": "2026-09-28T16:41:03+00:00",
      "sha256": "dfcdbfc1825eacd9a12141e58ceb3c9230408176e9c6ab82a006d6a7fa6a87e0",
      "supports": [
        "C1",
        "C2",
        "C3",
        "C4",
        "C10",
        "C11",
        "C12",
        "C13",
        "C14",
        "C15",
        "C16",
        "C17",
        "C18",
        "C19",
        "C20",
        "C21",
        "C22",
        "C23",
        "C24",
        "C25",
        "C26",
        "C27",
        "C28",
        "C29",
        "C30",
        "C31",
        "C32",
        "C33",
        "C34",
        "C35",
        "C36",
        "C37",
        "C38",
        "C39",
        "C40",
        "C41",
        "C42",
        "C43",
        "C44",
        "C45",
        "C46",
        "C47",
        "C48",
        "C49",
        "C50",
        "C51",
        "C52",
        "C53",
        "C54",
        "C55",
        "C56",
        "C57",
        "C58",
        "C59",
        "C60",
        "C61",
        "C62",
        "C70",
        "C71",
        "C73",
        "C74",
        "C75",
        "C76",
        "C77",
        "C78",
        "C79",
        "C80",
        "C86",
        "C87",
        "C91",
        "C92",
        "C93",
        "C94",
        "C95",
        "C96",
        "C97",
        "C113",
        "C114",
        "C115",
        "C116",
        "C124",
        "C157",
        "C158",
        "C160",
        "C161"
      ]
    },
    {
      "id": "REF::2",
      "url": "https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know",
      "title": "FTC Safeguards Rule: What Your Business Needs to Know",
      "publisher": "Federal Trade Commission",
      "published": "December 2024",
      "retrieved_at": "2026-09-28T16:41:03+00:00",
      "sha256": "c08d01f90f138e663fb1451415e0251eb133027aaff7b570a9defb8c938743c1",
      "supports": [
        "C7",
        "C8",
        "C9",
        "C63",
        "C64",
        "C65",
        "C98",
        "C117",
        "C159"
      ]
    },
    {
      "id": "REF::3",
      "url": "https://www.ftc.gov/business-guidance/resources/data-breach-response-guide-business",
      "title": "Data Breach Response: A Guide for Business",
      "publisher": "Federal Trade Commission",
      "published": "August 2023",
      "retrieved_at": "2026-09-28T16:41:04+00:00",
      "sha256": "85891172ed592f291df3b8ffb91a2633eea722e8dcd878c414d90c3b2a7be379",
      "supports": [
        "C99",
        "C100",
        "C106",
        "C132",
        "C162"
      ]
    },
    {
      "id": "REF::4",
      "url": "https://www.irs.gov/pub/irs-pdf/p5708.pdf",
      "title": "Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice",
      "publisher": "Internal Revenue Service",
      "published": "Rev. 8-2024",
      "retrieved_at": "2026-09-28T16:41:03+00:00",
      "sha256": "fa44a6cf525f7b2deb0b22e0bbb7cd4a7316628993e0114d419698192eb962bf",
      "supports": [
        "C5",
        "C6",
        "C66",
        "C67",
        "C68",
        "C69",
        "C72",
        "C82",
        "C83",
        "C84",
        "C85",
        "C118",
        "C119",
        "C120",
        "C121",
        "C122",
        "C123",
        "C135",
        "C151",
        "C152"
      ]
    },
    {
      "id": "REF::5",
      "url": "https://www.irs.gov/pub/irs-pdf/p1345.pdf",
      "title": "Publication 1345, Authorized IRS e-file Providers of Individual Income Tax Returns",
      "publisher": "Internal Revenue Service",
      "published": "Rev. 12-2025",
      "retrieved_at": "2026-09-28T16:41:04+00:00",
      "sha256": "5eba9554edbe18104a4676fa79df15aa97d280ab11abb18ed118ee48fe9e9067",
      "supports": [
        "C81",
        "C88",
        "C89",
        "C90",
        "C101",
        "C102",
        "C103",
        "C125",
        "C126",
        "C127",
        "C128",
        "C129"
      ]
    },
    {
      "id": "REF::6",
      "url": "https://www.irs.gov/individuals/data-theft-information-for-tax-professionals",
      "title": "Data theft information for tax professionals",
      "publisher": "Internal Revenue Service",
      "published": "page last reviewed or updated 26-Mar-2026",
      "retrieved_at": "2026-09-28T16:41:05+00:00",
      "sha256": "9347c6e18cb0aab9c1096e1b486ce630ac792d78fbd5a4377fd2a3ecd1c5092c",
      "supports": [
        "C104",
        "C105",
        "C107",
        "C108",
        "C109",
        "C110",
        "C111",
        "C112",
        "C133",
        "C134",
        "C163",
        "C165"
      ]
    },
    {
      "id": "REF::7",
      "url": "https://www.govinfo.gov/content/pkg/USCODE-2024-title26/html/USCODE-2024-title26-subtitleF-chap61-subchapB-sec6107.htm",
      "title": "26 U.S.C. 6107, Tax return preparer must furnish copy of return to taxpayer and must retain a copy or list",
      "publisher": "Office of the Law Revision Counsel, U.S. House of Representatives, published on govinfo",
      "published": "United States Code, 2024 Edition",
      "retrieved_at": "2026-09-28T16:41:04+00:00",
      "sha256": "e136262d14aa0f4f73b13ef76f2790ebd103f79e6dbc2cf178f15c7c46d825db",
      "supports": [
        "C153",
        "C154",
        "C155",
        "C156"
      ]
    },
    {
      "id": "REF::8",
      "url": "https://oag.ca.gov/privacy/databreach/reporting",
      "title": "Data Security Breach Reporting",
      "publisher": "State of California Department of Justice, Office of the Attorney General",
      "published": "undated",
      "retrieved_at": "2026-09-28T16:41:03+00:00",
      "sha256": "555c5a3bef0fcfe3f437fa60a28302ad70f2f11e907b7ca0bf1b0383ebd368a6",
      "supports": [
        "C136",
        "C137",
        "C138"
      ]
    },
    {
      "id": "REF::9",
      "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.81.5",
      "title": "California Civil Code section 1798.81.5",
      "publisher": "California Legislature",
      "published": "amended by Stats. 2021, Ch. 527, Sec. 2 (AB 825), effective January 1, 2022",
      "retrieved_at": "2026-09-28T16:41:04+00:00",
      "sha256": "d8b031bc71dd40f9e1c7bde261663b84beb08a43f4a47432fd142d617d2a9d57",
      "supports": [
        "C139",
        "C140",
        "C141",
        "C142",
        "C143",
        "C164"
      ]
    },
    {
      "id": "REF::10",
      "url": "https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=5063.3",
      "title": "California Business and Professions Code section 5063.3",
      "publisher": "California Legislature",
      "published": "amended by Stats. 2023, Ch. 510, Sec. 74 (SB 887), effective January 1, 2024",
      "retrieved_at": "2026-09-28T16:41:04+00:00",
      "sha256": "bc53d8dc26b98b031812d54884b7445b7f51c633aee920bc19cbce5308ee769c",
      "supports": [
        "C144",
        "C145",
        "C146",
        "C147",
        "C148",
        "C149",
        "C150"
      ]
    }
  ],
  "related": [
    {
      "question_id": "CG-P1B-FULL-005",
      "slug": "how-long-a-tax-preparer-or-accounting-firm-must-keep-client-records",
      "display_title": "How long must a tax preparer, accountant, or bookkeeping firm keep client records and copies of client returns?"
    },
    {
      "question_id": "CG-P1B-FULL-018",
      "slug": "how-to-set-up-and-use-a-client-portal-in-your-accounting-platform",
      "display_title": "How do I set up and use a client portal in my accounting platform so clients can exchange and access their documents?"
    },
    {
      "question_id": "CG-MCE-143",
      "slug": "how-a-bookkeeping-or-accounting-firm-offboards-a-client-it-is-disengaging",
      "display_title": "How should a bookkeeping or accounting firm offboard a client it is disengaging — what must be handed over, what does the firm keep, and how is access ended?"
    },
    {
      "question_id": "CG-MCE-120",
      "slug": "how-to-remove-a-departing-bookkeeper-or-employees-access-to-your-books",
      "display_title": "A bookkeeper or employee is leaving — how do I remove their access to my books and financial accounts, and what else do I need to change?"
    }
  ],
  "review_class": "consequential",
  "review_class_trigger": "pre_publication_professional_review_required",
  "provenance": {
    "author_model": "claude-opus-5-5",
    "reviewer_model": "claude-opus-5-5",
    "review_verdict": "ACCEPT",
    "review_source": "closure",
    "review_verdict_on_sha256": "bf8dd35ae11db981ddc13565cfd1eb10223dd43a1e355c2c4dee5bec27f04e27",
    "editorial_disposition": "ACCEPT",
    "corrections": 1,
    "approved_by": null,
    "approved_at": null,
    "article_sha256": "bf8dd35ae11db981ddc13565cfd1eb10223dd43a1e355c2c4dee5bec27f04e27",
    "source_map_sha256": "1e01db5fd1a75b49ab9fb361babec2513887eca084f8818136a442d1a1a4e315",
    "transform_sha256": "5460688469749ae5228c793d8879d5fd60a9e6662405edb747130c39fe2adb37"
  },
  "offer": "ask",
  "offer_id": null,
  "sample_target_id": null,
  "datePublished": "2026-09-30T21:19:08Z",
  "reviewed_at": "2026-09-30T21:19:08Z",
  "content_sha": "25d4c02d1f8b404f76fa6d4551182d90e0786975b6e3cedc3ed3dfd22baf81ea",
  "release": "2.13.0",
  "slug_provenance": "minted at first publication",
  "question_text": "What data-security obligations does a bookkeeping or tax practice have for its clients' records, and what has to be written down?",
  "jsonld_types": [
    "Article"
  ],
  "related_question_ids": [
    "CG-P1B-FULL-005",
    "CG-P1B-FULL-018",
    "CG-MCE-143",
    "CG-MCE-120",
    "Q-2011"
  ],
  "aliases": [],
  "alias_provenance": [],
  "notice": "This guide is general information, not tax or legal advice. Confirm with a qualified professional before acting."
}
