Data Security & FTC Safeguards Compliance
Overview
Keeping your books means handling some of the most sensitive information a business has: bank and credit-card activity, revenue and payroll, tax records, and the accounting logins behind them. Protecting that information is not a courtesy at Cecilio Books LLC — it is a legal obligation we build our practice around.
Because we handle consumer financial information, federal law treats a bookkeeping practice like ours as a "financial institution" under the Gramm-Leach-Bliley Act and the FTC Safeguards Rule. That status carries specific, enforceable data-security duties. This page explains those duties, the safeguards we use to meet them, and where our full written plan lives.
Why these rules apply to a bookkeeper
The Safeguards Rule (16 CFR Part 314) defines a "financial institution" broadly: any business that is significantly engaged in activities that are financial in nature. The rule lists tax preparation services — including accountants who complete tax returns — as examples, and the FTC declined to exempt small firms when it updated the rule. The IRS states it plainly in Publication 5709: "Federal law, enforced by the Federal Trade Commission, requires professional tax preparers to create and maintain a written data security plan."
The same duty reaches a bookkeeping practice that handles customer financial information — regardless of size. A very small firm can claim a partial exemption from a few requirements when it holds information on fewer than 5,000 consumers. We do not rely on that exemption. We build and maintain the full program described below.
The required elements — and how our plan meets them
A compliant WISP is not a one-line promise. It is a defined set of elements, drawn from the FTC Safeguards Rule (16 CFR 314.4) and the IRS Publication 5708 template. Our plan is built on that template and covers every element below.
The plan itself
- Objective, purpose, and scope — the data we handle, the systems that hold it, where it lives, and how long we keep it.
- A designated security coordinator — one named person accountable for the program and its results.
- A written risk assessment — the threats to the confidentiality, integrity, and availability of your data, each matched to a control.
- An inventory of systems and devices — what equipment and services can reach your information, kept current.
- An implementation and review clause — an effective date, a scheduled review, and how the plan is updated and approved.
Technical safeguards
- Encryption in transit and at rest — your information is encrypted while it moves and while it is stored.
- Multi-factor authentication — accounts that can reach your data need more than a password to sign in.
- Anti-malware, firewalls, and prompt patching — the baseline "Security Six" protections the IRS sets for practices like ours.
- Tested backups — so a failure, loss, or ransomware event does not put your records out of reach.
- Activity logging — our plan calls for using the access logs of the systems that hold your data to review who reaches your information.
Administrative safeguards
- Least-privilege, role-based access — unique credentials per person, no shared logins, and access limited to what the work requires.
- Confidentiality and security training — everyone who handles your data is bound to protect it and trained to recognize threats such as phishing, with access removed promptly when it is no longer needed.
- Service-provider oversight — we choose vendors that publish strong security programs, and our plan requires us to confirm their safeguards and reassess them over time. The specific providers we use are listed in our Privacy Policy.
- Secure client access — documents move to us encrypted, and we work in your QuickBooks through an accountant invitation, signing in with our own credentials. We never ask for or store your QuickBooks password, and you can review or revoke our access at any time.
Physical safeguards
- Controlled access to workspaces and devices — equipment is protected, screens lock when idle, and portable devices are encrypted.
- Secure retention and disposal — records are kept only as long as they are needed, then destroyed securely, on paper and in electronic form.
Testing, response, and review
- Monitoring and testing — our plan requires us to check our safeguards over time so a control that stops working is found and fixed; our backups, for example, are restore-tested.
- A written incident response plan — defined steps and roles for detecting, containing, and recovering from a security event.
- Annual review — the plan sets a schedule to be reviewed at least yearly, and whenever our business, tools, vendors, or the law change.
The standards and frameworks we follow
Our program is built on the rules and frameworks that govern a practice handling financial information — not on badges or self-issued certificates:
- FTC Safeguards Rule (16 CFR Part 314) — the federal data-security rule for financial institutions, which the FTC applies to accounting and tax-preparation businesses.
- Gramm-Leach-Bliley Act (GLBA) — the federal law that establishes the duty to protect the nonpublic personal financial information a business collects.
- IRS Publication 5708 and Publication 5709 — the Security Summit WISP template and guidance built for tax and accounting practices. The IRS explains the requirement in its WISP overview.
- Massachusetts 201 CMR 17.00 — the Massachusetts standard requiring a written security program and encryption of personal information in transit and on portable devices.
If a security incident happens
No one can promise that nothing will ever happen. What we can promise is a plan and a duty to act on it. If a security incident affects your information, we work to detect and contain it quickly, notify the people affected, and report to the authorities the law requires.
Those duties are specific. Under the Safeguards Rule, a covered firm must notify the FTC of a security event involving the unencrypted information of 500 or more consumers, and the IRS asks tax professionals to report a data theft to their IRS Stakeholder Liaison. Massachusetts and other state laws add their own breach-notification requirements. We treat these as obligations, not options.
Data retention and your rights
We keep the information you share for as long as our working relationship is active, and for a reasonable period afterward to meet legal, accounting, and reporting requirements. You may ask us to access or delete your information at any time. How we collect, use, and retain your data — and how to make a request — is covered in our Privacy Policy.
Where our written plan lives
The full WISP names who is responsible, inventories the information we protect, and spells out every safeguard and procedure summarized here. We keep the plan itself internal for a simple security reason: publishing the details of your defenses helps the people you are defending against. We make the plan available to regulators on request, and we can confirm its existence and scope to clients and partners who ask.
Contact
Questions about how we protect your data, or want to report a security concern? Email debora@ceciliobooks.com.