GLBA Compliance for Accounting Firms: What the Law Requires
Key Takeaways
- GLBA compliance applies to tax preparation firms and other non-bank financial institutions, and the FTC enforces it for most accounting practices.
- The law has three parts: the Financial Privacy Rule, the Safeguards Rule, and a prohibition on pretexting.
- Privacy notices, information-sharing limits, and client opt-out rights come from the Financial Privacy Rule, and licensed CPAs are exempt from its notice requirements.
- Pretexting targets the staff who answer client calls and emails, so documented identity verification belongs in every firm’s procedures.
- GLBA sits alongside IRS Section 7216 and state privacy laws, and meeting one doesn’t satisfy the others.
GLBA compliance comes up for accounting firms more often than you may expect.
Client questionnaires ask about it, cyber insurers reference it, and IRS guidance points back to it. Yet many firms only know one piece of the law: the requirement to have a written security plan. The Gramm-Leach-Bliley Act covers more than that. It also governs how your firm tells clients what it does with their information, when it can share that information, and how staff must respond to anyone trying to obtain client data under false pretenses.
This post is for firm owners, managing partners, tax professionals, and operations leads who want the full picture.
In this post, we’ll cover:
- What GLBA is
- Why it applies to accounting and tax firms
- The three parts of GLBA compliance, including the exemption for CPAs
- How GLBA compliance overlaps with IRS and state obligations
- A practical checklist for staying compliant
What Is the Gramm-Leach-Bliley Act?
The Gramm-Leach-Bliley Act (GLBA) is a 1999 federal law that requires financial institutions to protect the privacy and security of consumers’ nonpublic personal information. Its privacy provisions, found in Title V, do three things: require clear privacy notices, limit information sharing with outside parties, and require safeguards that keep customer information secure.
“The Gramm-Leach-Bliley Act requires financial institutions—companies that offer consumers financial products or services like loans, financial or investment advice, or insurance—to explain their information-sharing practices to their customers and to safeguard sensitive data.” FTC.gov
Congress passed GLBA mainly to modernize banking, but Title V reaches well beyond banks. It covers any business significantly engaged in financial activities, including many businesses that would never describe themselves as financial institutions. Federal agencies turned the statute into specific regulations, and those regulations are where most of your firm’s day-to-day obligations come from. The FTC’s GLBA guidance links to each of them.
Why GLBA Compliance Applies to Accounting Firms
GLBA defines a financial institution by its activities. Tax preparation is one of those activities, and the FTC Safeguards Rule lists tax preparation firms among the non-bank financial institutions it covers. That’s why most accounting practices that prepare returns fall within GLBA’s scope.
Firms that offer bookkeeping, payroll, financial planning, or advisory services should review their coverage too, since those services involve the same kinds of nonpublic personal information. That information includes Social Security numbers, income and account details, and any personal data a client provides to obtain a financial service.
For accounting firms, the Federal Trade Commission is the primary GLBA regulator. The FTC oversees non-bank financial institutions that no other federal agency supervises, which puts tax preparers, bookkeepers, and most CPA firms under its authority.
The Three Parts of GLBA Compliance
GLBA compliance breaks into three parts. Each one creates a different kind of obligation, and each needs its own place in your firm’s policies.
1. The Financial Privacy Rule
The Financial Privacy Rule governs what you tell clients about their information and what you can do with it. Its core requirements include:
- Privacy notices: Give customers a clear notice of your privacy practices when the relationship begins. The notice explains what information you collect, who you share it with, and how you protect it.
- Annual notices, with an exception: Financial institutions historically had to send a privacy notice every year. A 2015 amendment created an exception for institutions that only share information in limited, permitted ways and haven’t changed their practices since their last notice.
- Opt-out rights: Before sharing nonpublic personal information with nonaffiliated third parties outside of permitted exceptions, you must give consumers a chance to opt out.
- Limits on reuse: Information you receive from another financial institution comes with limits on how you can use and disclose it.
The rule distinguishes between consumers, who obtain a financial product or service for personal or household purposes, and customers, who have a continuing relationship with your firm. Notice obligations differ between the two groups, so it’s worth mapping which of your clients fall into each.
For most non-bank financial institutions, including tax preparation firms, these privacy requirements now sit in the Consumer Financial Protection Bureau’s Regulation P, while the FTC keeps enforcement authority over the firms it oversees.
The privacy notice exemption for CPAs
Licensed CPAs have an important exception. Since 2006, GLBA has exempted certified public accountants from its privacy notice requirements when they’re licensed by a state and subject to state laws or professional conduct rules that already bar disclosing client information without consent. The Journal of Accountancy reported at the time that the change covers both initial and annual notices.
The exemption is narrow. It removes the notice requirement only. CPA firms still fall under the Safeguards Rule and the pretexting provisions, and their state confidentiality rules still limit what they can share. Tax preparers and bookkeepers who aren’t CPAs generally don’t qualify, so firms with a mix of CPA and non-CPA services should confirm how the exemption applies to each.
2. The Safeguards Rule
The Safeguards Rule is the security half of GLBA. Issued by the FTC as 16 CFR Part 314, it requires covered firms to maintain a written information security program with administrative, technical, and physical safeguards for customer information. The FTC revised the rule in 2021 and added a breach notification requirement that took effect in May 2024.

The rule lists nine specific program elements, including a Qualified Individual, a written risk assessment, multifactor authentication, encryption, and an incident response plan. For the full element-by-element breakdown, exemptions for smaller firms, and breach notification details, see our FTC Safeguards Rule compliance checklist.
Most tax professionals meet the Safeguards Rule through a written information security plan (WISP). Our guide to WISP requirements for accountants explains what that document needs to include, and our on-demand WISP readiness webinar walks through putting one into practice. Firms that want help building and maintaining the plan can also look at Rightworks WISP services.
3. The pretexting provisions
GLBA also makes it illegal to obtain, or attempt to obtain, customer information from a financial institution through false pretenses. This practice is called pretexting.
What is pretexting?
Pretexting is a social engineering technique. An attacker may invent a believable scenario—maybe impersonating a client over the phone, or using forged or stolen documents—to trick staff into revealing sensitive information. Pretexting violations can carry criminal penalties, including fines and imprisonment.
For accounting firms, pretexting is a practical risk every tax season. A caller claims to be a client who “just needs a copy of last year’s return,” or an email that looks like it’s from a client’s spouse asks for account details. These are the same tactics behind most social engineering scams and phishing attacks aimed at firms, and they often feed identity theft and refund fraud.
GLBA’s pretexting provisions give firms a clear reason to formalize identity verification. Every staff member who handles client requests should follow a documented process for confirming who they’re talking to before releasing information. The Safeguards Rule separately requires security awareness training for staff, and Security Awareness Training is the most direct way to build that verification habit across your team. Our Security Awareness Training tips for accounting firms cover what an effective program includes.
How GLBA Overlaps With Other Obligations
GLBA compliance is only one layer of the rules that govern client data at an accounting firm. Three others often apply at the same time.
1. IRS Section 7216
Internal Revenue Code Section 7216 and its regulations limit how tax return preparers can use and disclose tax return information. For tax return information, Section 7216 is often stricter than GLBA and can require specific written client consent before a disclosure. A firm can satisfy GLBA’s privacy rules, or qualify for the CPA exemption, and still fall short of Section 7216.
2. IRS Publication 4557 and the WISP
IRS guidance ties directly to the Safeguards Rule. Publication 4557 explains how tax professionals should protect taxpayer data, and paid preparers confirm awareness of their WISP obligations when they renew a PTIN. The IRS guidance helps you implement GLBA’s security requirements, but the legal requirement comes from GLBA and the FTC rule.
3. State privacy and breach notification laws
According to the Rightworks compliance map, 19 comprehensive state privacy laws were in force as of January 1, 2026. Many include some form of GLBA exemption, but those exemptions vary. Some exempt a GLBA-covered firm entirely. Others exempt only the specific data GLBA already covers, which leaves other personal data in scope. Every state also has its own breach notification law, which applies alongside the FTC’s breach notification requirement.
GLBA Compliance Checklist for Accounting Firms
Use this checklist to confirm your firm has covered all three parts of the law.
- Confirm your status. Document which of your services make your firm a financial institution under GLBA, and whether the CPA exemption applies to any of them.
- Inventory client information. Identify what nonpublic personal information you collect, where you store it, and who can access it.
- Review your sharing practices. List every third party that receives client information, and confirm each disclosure fits a permitted exception or comes after proper notice and opt-out.
- Settle your privacy notice obligations. If the CPA exemption doesn’t apply, deliver an initial notice to new customers and confirm whether your firm qualifies for the annual notice exception.
- Meet the Safeguards Rule. Maintain a written information security program covering all nine elements of 16 CFR Part 314.
- Train staff on pretexting. Set a documented identity verification process for phone, email, and portal requests, and train every client-facing employee on it.
- Check vendor contracts. Make sure service providers, including outsourced and offshore staff, are contractually required to protect client information and limit its use.
- Map overlapping rules. Review Section 7216 consent requirements and the state privacy laws that apply to your clients.
- Review annually. Revisit your privacy practices, sharing arrangements, and security program at least once a year and after any major change to your firm.
Who Enforces GLBA for Accounting Firms
For most accounting and tax firms, the FTC enforces GLBA’s privacy and security requirements. It can investigate firms, bring enforcement actions, and require consent orders that impose years of compliance obligations and outside assessments. Firms that violate those orders can face civil penalties. Pretexting violations are a separate matter and can be prosecuted criminally.
GLBA isn’t the only source of consequences after a failure. Tax professionals can also face IRS scrutiny, state attorney general action, state board of accountancy inquiries, and cyber insurance complications. A firm that documents its privacy practices, security program, and staff procedures is in a far stronger position with every one of these parties.
Make GLBA Compliance Part of How Your Firm Operates
GLBA compliance asks accounting firms to do three things well:
- Tell clients how their information is handled, or confirm the CPA exemption covers you
- Protect that information with a documented security program
- Stop anyone trying to obtain it under false pretenses
Most firms have made progress on security. Fewer have reviewed their privacy practices, sharing arrangements, and identity verification procedures with the same rigor. Working through all three parts now, and seeing how they fit with IRS and state requirements, gives your firm a complete answer when a client, regulator, or insurer asks how you protect their data. For an example of a firm that replaced aging servers with a managed, secure environment, read the Rudler PSC customer story.
FAQ: GLBA Compliance
No. The FTC Safeguards Rule is one part of GLBA compliance. It covers the written information security program. GLBA compliance also includes the Financial Privacy Rule, which governs privacy notices and information sharing, and the pretexting provisions, which prohibit obtaining customer information through false pretenses.
Usually not. Since 2006, licensed CPAs who are subject to state confidentiality rules have been exempt from GLBA’s privacy notice requirements. Non-CPA tax preparers and bookkeepers that qualify as financial institutions generally must give customers a notice when the relationship begins, though annual notices aren’t required if the firm meets the exception created in 2015.
Pretexting is obtaining, or trying to obtain, customer information from a financial institution through false pretenses, such as impersonating a client or using fake documents. GLBA prohibits the practice and can impose criminal penalties. For accounting firms, it’s the main reason to document how staff verify a caller’s or sender’s identity before releasing client information.
The Federal Trade Commission enforces GLBA for tax preparers and most other non-bank financial institutions that no other federal agency supervises. The FTC can investigate firms, bring enforcement actions, and require consent orders. Tax preparers may also face IRS, state, and professional consequences after a data security failure.
No. Many state privacy laws include a GLBA exemption, but the scope varies by state. Some exempt GLBA-covered businesses entirely, while others exempt only data already covered by GLBA. Every state also has its own breach notification law, which can apply in addition to federal FTC notification requirements.
