Section 8. SAFEGUARDS AND RECORD KEEPING REQUIREMENTS
0426 Publ 3373 (PDF) · 2026-10-03 edition · updated 2026-10-04 · United States
All FTI obtained under Section 6103(l)(7) of the Code, namely information received from the IRS and the Social Security Administration, is subject to safeguarding, record keeping, and reporting requirements of Section 6103(p)(4) of the Code. Information on the implementation of these statutory requirements may be found in IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies (as revised). Visit www.irs.gov and search for the keyword “Safeguards.” The FTI does not lose its character as FTI simply because the accuracy of the data has been “verified” by a third party. Rather, agencies should look to the source of the data as the determinant of whether information must be treated as FTI. If the IRS has provided data from its records, then the data is FTI. If a third party provides data from their records, the data provided is not considered to be FTI. The third party cannot simply attest to the accuracy of the data submitted but must provide data from their own records in order for the data to be considered “independently verified” and thus not subject to the safeguard requirements. Since FTI must be safeguarded in accordance with the provisions of Section 6103(p)(4) of the Code, it is necessary to accurately categorize the information as to its source.
If the FTI becomes a part of the agency’s case file regarding a specific taxpayer, because physical separation is impractical, the entire case file must be safeguarded. These files should be clearly labeled to indicate that FTI is included, and care should be taken to remove all such FTI, when appropriate, to preclude access by unauthorized persons.
All computers and computer systems which process, store, or transmit FTI must meet or exceed standards identified in IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies (as revised).
Each agency receiving FTI pursuant to Section 6103(l)(7) of the Code must submit a Safeguard Security Report (SSR) at least 90 days prior to the initial scheduled receipt of FTI and must be current with their SSR filing requirement at the time of agreement Reestablishments/Renewals. The most current template may be requested by sending an e-mail to SafeguardReports@irs.gov . The SSR shall detail the security afforded to the FTI, the individuals who may request and have access to the FTI, the flow of the FTI once the agency has received it, as well as other information which will give a comprehensive picture of the need for, the use of, and the disposal of the FTI. The IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies (as revised), provides additional information about the SSR and may be obtained by sending an e-mail to SafeguardReports@irs.gov , or by visiting http://www.irs.gov , search keyword: Safeguards.
The agency must update and submit the SSR annually to encompass any changes that impact the protection of FTI. Example changes include but are not limited to:
• Newly established, re-established, and renewed data exchange agreements; • New…¶
from an embedded IT operation
DIFSLA TY 2025 8
The following information must be updated in the SSR to reflect updates or changes regarding the agency or regarding safeguarding procedures within the reporting period:
• Changes to information or procedures previously reported • Current annual period…¶
SSR Update Submission Date
The SSR submission and all associated attachments must be sent annually to identify changes to safeguarding procedures, including:
• Submission due dates are defined according to geographic locations or if the¶
• The annual update portion of the SSR should include a description of updates or¶
changes that have occurred during the applicable reporting period.
SSR Due Dates¶
Federal Agencies
All State Agencies and Territories
| AK, AL, AR, AS, AZ, CA | February 1 through January 31 | February 28 |
|---|---|---|
MP, CO CT DC, DE, FL, GA |
March 1 through February 28 |
March 31 |
GU, HI, IA, ID, IL, IN, KS |
April 1 through March 31 |
April 30 |
KY, LA, MA, MD, ME, MI |
May 1 through April 30 |
May 30 |
MN, MO, MS, MT, NE |
June 1 through May 31 |
June 30 |
NC, NH, NJ, NM, NV, NY |
July 1 through June 30 |
July 31 |
ND, OH, OK, OR |
August 1 through July 31 |
August 31 |
PA, PR, RI, SC, SD, TN |
September 1 through August 31 |
September 30 |
TX, UT, VA, VI, VT, WA |
October 1 through September 30 |
October 31 |
WI, WV, WY |
November 1 through October 31 |
November 30 |
Pursuant to Section 6103(p)(4) of the Code, the IRS has the authority to ensure compliance with applicable laws and regulations through the conduct of safeguard reviews of all recipient agencies at the federal, state, and local levels.
Procedures for submitting Safeguards Report files using IRS approved secure file transfer method are detailed in Publication 1075 and summarized in Attachment 5 of this publication.
DIFSLA TY 2025 9
Get a plain-English answer with a citation back to this text.
Ask AI about this code