SECTION 6. EXAMPLES
Internal Revenue Bulletin 2008-29 · 2026-10-03 edition · updated 2026-10-04 · United States
.01 The application of this revenue procedure is illustrated by the following examples:
(1) Example 1 . Preparer P offers tax preparation services over the Internet. P wishes to use information the taxpayer provides during tax preparation of the taxpayer’s Form 1040 to generate targeted banner advertisements ( i.e., electronic advertisements appearing on the computer screen based on the taxpayer’s tax return information). In the course of advertising services and products, P wishes also to disclose to other third parties information that the taxpayer provides.
(a) P posts, in pertinent part, the following consent on the computer screen for taxpayers to indicate approval. If a taxpayer does not indicate approval, the tax return preparation software does not permit the taxpayer to use the software.
move or “deselect” disclosures or uses that the taxpayer does not wish to be made, i.e., an “opt-out” consent, is not permitted.
(3) Signature. All consents to disclose or use tax return information must be signed by the taxpayer.
(a) For consents on paper, the taxpayer’s consent to a disclosure or use must contain the taxpayer’s signature.
(b) For electronic consents, a taxpayer must sign the consent by any method prescribed in section 5, below.
(4) Incomplete consents. A tax return preparer shall not present a consent form with blank spaces related to the purpose of the consent to the taxpayer for signature.
.05 Special rule for multiple disclosures within a single consent form or multiple uses within a single consent form. Section 301.7216–3(c)(1) provides that a taxpayer may consent to multiple uses within the same written document, or multiple disclosures within the same written document. Multiple disclosure consents and multiple use consents must provide the taxpayer with the opportunity, within the separate written document, to affirmatively select each separate disclosure or use. Further, the taxpayer must be provided the information in section 4.04 for each separate disclosure or use. The mandatory statements required in section 4.04(1) relating to use or disclosure need only be stated once in a multiple disclosure or multiple use consent.
.06 Disclosure of entire return. If, under §301.7216–3(c)(2), a consent authorizes the disclosure of a copy of the taxpayer’s entire tax return or all information contained within a return, the consent must provide that the taxpayer has the ability to request a more limited disclosure of tax return information as the taxpayer may direct.
.07 Adequate data protection safeguard. Pursuant to §301.7216–3T(b)(4), a tax return preparer located within the United States, including any territory or possession of the United States, may disclose a taxpayer’s SSN to a tax return preparer located outside of the United States or any territory or possession of the United States with the taxpayer’s consent only when both the tax return preparer located within the United States and the tax return preparer located outside of the United States
maintain an adequate data protection safeguard at the time the taxpayer’s consent is obtained and when making the disclosure. An “adequate data protection safeguard” is a security program, policy and practice that has been approved by management and implemented that includes administrative, technical and physical safeguards to protect tax return information from misuse or unauthorized access or disclosure and that meets or conforms to one of the following privacy or data security frameworks:
(1) The United States Department of Commerce “safe harbor” framework for data protection (or successor program);
(2) A foreign law data protection safeguard that includes a security component, e.g., the European Commission’s Directive on Data Protection;
(3) A framework that complies with the requirements of a financial or similar industry-specific standard that is generally accepted as best practices for technology and security related to that industry, e.g., the BITS (Financial Services Roundtable) Financial Institution Shared Assessment Program;
(4) The requirements of the AICPA/CICA Privacy Framework;
(5) The requirements of the most recent version of IRS Publication 1075, Tax In- formation Security Guidelines for Federal, State and Local Agencies and Entities ; or
(6) Any other data security framework that provides the same level of privacy protection as contemplated by one or more of the frameworks described in (1) through (5).
Get a plain-English answer with a citation back to this text.
Ask AI about this code