Skip to content

Title›Note:

Inadvertent Unauthorized Disclosures and Losses or Thefts of IT Assets, BYOD Assets and…

Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence · 2026-10-03 edition · updated 2026-10-04 · United States

It is critical to report an incident/data breach as soon as actionable information is available so a response/reaction can be initiated. Incident/data breach updates and any additional notifications to TIGTA and/or Law Enforcement (see (3) and (4) below) can be completed after the initial report to the Office of Privacy, Governmental Liaison and Disclosure/Incident Management Office (PGLD/IM), the Situational Awareness Management Center (SAMC), or the Computer Security Incident Response Center (CSIRC) is submitted.

IRS employees are required to report incidents and data breaches immediately upon discovery to their manager and to one of the following offices based on what was lost, stolen, destroyed, or disclosed:

The Office of Privacy, Governmental Liaison and Disclosure (PGLD) Incident Management Office (IM). Report the data breach to PGLD/IM using the PII Breach Reporting Form if the data breach involves: erroneous taxpayer correspondence involving the disclosure of SBU data, including PII and tax information, i.e., a notice, letter, or transcript, which was mailed, emailed, faxed, EEFaxed, or generated or transmitted via the Income Verification Express Service (IVES), Return and Income Verification Services (RAIVS), Transcript Delivery System (TDS), Secure Data Transport (SDT), or other electronic transmission, to the wrong address or addressee; or notices, letters, transcripts, faxes, or other electronic/digital documents sent with mixed entity information such as correct taxpayer information is on page one, but unrelated taxpayer information is on page two; two letters for different taxpayers in the same envelope; the attachment in the correspondence is for a different taxpayer, etc.; or an inadvertent unauthorized disclosure of SBU data, including PII and tax information, such as a verbal disclosure, or an email sent to the wrong person or not properly encrypted; or the loss, theft, or unauthorized destruction of documents containing SBU data, including PII and tax information, such as hardcopy records, documents, or case files, packages lost or stolen during UPS or FedEx shipment, or lost or stolen remittances; or an electronic disclosure of SBU data, including PII and tax information, in IRMs, Training Materials, PowerPoints, IRS Source, SharePoint, etc., or on external systems/sites such as WhatsApp, GitHub, etc., or SBU data, including PII and tax information, shared with, or input or uploaded to, Artificial Intelligence (AI) or other internet tools or sites used for translation, document conversion, etc.

Get a plain-English answer with a citation back to this text.

Ask AI about this code
▸Contents — Internal Revenue Manual Part 10. Security, Privacy, Assurance and Artificial Intelligence

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.