Skip to content

Table Of Contents

Section 8. SAFEGUARDS AND RECORD KEEPING REQUIREMENTS

0426 Publ 3373 (PDF) · 2026-10-03 edition · updated 2026-10-04 · United States

  1. All FTI obtained under Section 6103(l)(7) of the Code, namely information received from the IRS and the Social Security Administration, is subject to safeguarding, record keeping, and reporting requirements of Section 6103(p)(4) of the Code. Information on the implementation of these statutory requirements may be found in IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies (as revised). Visit www.irs.gov and search for the keyword “Safeguards.” The FTI does not lose its character as FTI simply because the accuracy of the data has been “verified” by a third party. Rather, agencies should look to the source of the data as the determinant of whether information must be treated as FTI. If the IRS has provided data from its records, then the data is FTI. If a third party provides data from their records, the data provided is not considered to be FTI. The third party cannot simply attest to the accuracy of the data submitted but must provide data from their own records in order for the data to be considered “independently verified” and thus not subject to the safeguard requirements. Since FTI must be safeguarded in accordance with the provisions of Section 6103(p)(4) of the Code, it is necessary to accurately categorize the information as to its source.

  2. If the FTI becomes a part of the agency’s case file regarding a specific taxpayer, because physical separation is impractical, the entire case file must be safeguarded. These files should be clearly labeled to indicate that FTI is included, and care should be taken to remove all such FTI, when appropriate, to preclude access by unauthorized persons.

  3. All computers and computer systems which process, store, or transmit FTI must meet or exceed standards identified in IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies (as revised).

  4. Each agency receiving FTI pursuant to Section 6103(l)(7) of the Code must submit a Safeguard Security Report (SSR) at least 90 days prior to the initial scheduled receipt of FTI and must be current with their SSR filing requirement at the time of agreement Reestablishments/Renewals. The most current template may be requested by sending an e-mail to SafeguardReports@irs.gov . The SSR shall detail the security afforded to the FTI, the individuals who may request and have access to the FTI, the flow of the FTI once the agency has received it, as well as other information which will give a comprehensive picture of the need for, the use of, and the disposal of the FTI. The IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies (as revised), provides additional information about the SSR and may be obtained by sending an e-mail to SafeguardReports@irs.gov , or by visiting http://www.irs.gov , search keyword: Safeguards.

  5. The agency must update and submit the SSR annually to encompass any changes that impact the protection of FTI. Example changes include but are not limited to:

• Newly established, re-established, and renewed data exchange agreements; • New…

from an embedded IT operation

DIFSLA TY 2025 8

The following information must be updated in the SSR to reflect updates or changes regarding the agency or regarding safeguarding procedures within the reporting period:

• Changes to information or procedures previously reported • Current annual period…

SSR Update Submission Date

The SSR submission and all associated attachments must be sent annually to identify changes to safeguarding procedures, including:

• Submission due dates are defined according to geographic locations or if the

• The annual update portion of the SSR should include a description of updates or

changes that have occurred during the applicable reporting period.

Exceptions & meaning →

SSR Due Dates

Federal Agencies

All State Agencies and Territories

AK, AL, AR, AS, AZ, CA February 1 through January 31 February 28







MP, CO CT DC, DE, FL, GA




March 1 through February 28


March 31







GU, HI, IA, ID, IL, IN, KS




April 1 through March 31

April 30






KY, LA, MA, MD, ME, MI




May 1 through April 30


May 30





MN, MO, MS, MT, NE



June 1 through May 31


June 30






NC, NH, NJ, NM, NV, NY




July 1 through June 30


July 31




ND, OH, OK, OR




August 1 through July 31


August 31






PA, PR, RI, SC, SD, TN




September 1 through August 31


September 30






TX, UT, VA, VI, VT, WA




October 1 through September 30


October 31



WI, WV, WY




November 1 through October 31


November 30
  1. Pursuant to Section 6103(p)(4) of the Code, the IRS has the authority to ensure compliance with applicable laws and regulations through the conduct of safeguard reviews of all recipient agencies at the federal, state, and local levels.

  2. Procedures for submitting Safeguards Report files using IRS approved secure file transfer method are detailed in Publication 1075 and summarized in Attachment 5 of this publication.

DIFSLA TY 2025 9

Exceptions & meaning →

Get a plain-English answer with a citation back to this text.

Ask AI about this code
▸Contents — 0426 Publ 3373 (PDF)

GoCodebook provides public access, search, citation, multilingual explanation, and practical interpretation of legally adopted building regulations. It is not a substitute for the official ICC or California code publications.