Two professional women engaged in a discussion at a laptop in a modern office setting.

How to Talk to Your Clients About Data Privacy

August 27, 2026

A client hands you their Social Security number, tax returns, and bank statements and then asks, "So how do you protect all of this?" Most CPAs pause. Not because they don't care about data security, but because their IT setup has never been documented well enough to answer that question with confidence. This guide gives you the framework, the answers, and the infrastructure checklist to fix that and to make data privacy for CPAs in Orange County a genuine competitive advantage.

Orange County clients are asking CPA firms direct questions about data privacy because high-profile accounting breaches, the California Consumer Privacy Act, and repeated personal data incidents have made consumers more informed and more skeptical. This is no longer a compliance checkbox, it is a client retention and business development issue for any accounting firm taking on new clients.

The California Consumer Privacy Act and Orange County Clients

California Consumer Privacy Act (CCPA): A California state law that gives residents the right to know what personal data businesses collect about them, how it is used, and who it is shared with.

The CCPA has created a baseline of privacy awareness among California residents that does not exist at the same level in most other states. Orange County clients, whether they run a business in Newport Beach or manage personal investments in Irvine, have been educated by years of CCPA notices, opt-out requests, and data deletion rights.

That education transfers directly to how they think about their CPA. When a client has already exercised CCPA rights with a tech company, asking their accountant "where does my data go?" is a natural next step.

Why This Is a Business Development Issue, Not Just a Compliance One

Accounting firms that can answer data privacy questions confidently win client trust during onboarding. Firms that stumble through the answer, or defer to "we use antivirus and it's all fine", raise doubts that are hard to walk back.

High-profile breaches at tax preparation firms and accounting software vendors have made this real for clients. When a client has been burned before, they are not asking to be difficult. They are asking because they have reason to.

What the FTC Safeguards Rule Actually Requires Your Firm to Do

The updated FTC Safeguards Rule, effective June 2023, requires CPA firms and tax preparers that handle nonpublic personal financial information to implement a formal written information security program, designate a security coordinator, encrypt client data, and conduct annual risk assessments. Most small firms are not fully compliant.

FTC Safeguards Rule: A federal rule issued by the Federal Trade Commission that requires financial institutions, including CPA firms and tax preparers, to protect the security and confidentiality of customer financial information.

The Four Requirements Small Firms Most Often Miss

  • Written Information Security Program (WISP): A WISP is a documented plan that describes how your firm collects, stores, accesses, and protects client data. The FTC Safeguards Rule requires one. Most small CPA firms do not have a written version, they have informal habits.
  • Designated Security Coordinator: The rule requires your firm to name a specific person responsible for overseeing the information security program. At a small firm, this is often the owner by default but "by default" is not the same as documented and accountable.
  • Encryption of Client Data in Transit and at Rest: Encryption in transit means data sent over email or through web applications is scrambled while moving. A default Outlook configuration without enforced TLS transport encryption does not meet this standard. Encryption at rest means files stored on servers or in the cloud are unreadable without decryption keys.
  • Annual Risk Assessment: The FTC Safeguards Rule requires firms to identify threats to client data at least once per year and document the results. A risk assessment is not a vulnerability scan, it is a formal review of what could go wrong and what controls exist to prevent it.

Each of these requirements has a direct IT implication. Getting them right is not a legal exercise, it is an infrastructure exercise. Shift Computer Services provides FTC Safeguards Rule compliance support built specifically for firms like yours.

How to Build a Data Privacy Conversation Into Your Client Onboarding

The most effective way for a CPA firm to handle data privacy questions is to answer them before clients ask by including a one-page "How We Protect Your Data" document in the engagement letter package. This document serves as both a compliance artifact and a trust signal during new client onboarding.

What the "How We Protect Your Data" Document Should Cover

  • Data storage location: Where client files are stored and what platform manages them.
  • Access controls: Who can access client data and what authentication requirements apply.
  • Encryption practices: How data is protected both when transmitted and when stored.
  • Breach notification process: What the firm will do and how quickly clients will be notified if a breach occurs.
  • IT partner: The name of the managed IT provider overseeing the firm's security infrastructure.

This document should not be written from memory by the CPA. The factual inputs (storage platform names, encryption standards, incident response timelines) come from your managed IT provider, who has configured and documented these controls.

A "How We Protect Your Data" document also gives you something tangible to reference during a client conversation instead of trying to recall details under pressure. It positions your firm as organized, accountable, and ahead of the question which is exactly where you want to be when a client hands over their financial life.

What a Managed IT Partner Does That Makes These Conversations Possible

A managed IT provider delivers three specific outputs that make credible client data privacy conversations possible: a documented Written Information Security Program, monitored access logs, and a tested incident response plan. A break-fix IT vendor does not provide any of these and the difference is visible the moment a client asks a direct question.

Break-Fix IT Vendor vs. Managed IT Provider: What CPAs Actually Get

Capability Break-Fix IT Vendor Managed IT Provider (e.g., Shift Computer Services)
Written Information Security Program (WISP) Not provided Documented, maintained, and updated annually
Access log monitoring Not monitored Continuously monitored; reportable on demand
Incident response plan Not built Documented and tested
Encryption configuration Default settings only Configured and verified for compliance
Client-facing privacy documentation Not available Supplied as inputs to firm onboarding documents
Employee offboarding access revocation Ad hoc, if requested Process-driven and documented

The gap between "we use antivirus" and "here is our documented WISP, access logs, and incident response plan" is not a gap in intention, it is a gap in infrastructure and process. Consumer-grade tools, default Microsoft 365 settings, and a one-person break-fix vendor cannot close it.

Shift Computer Services provides cybersecurity services that include the monitored access controls and incident response capabilities your firm needs to answer client questions with documented facts rather than reassurances. For firms evaluating a full-service approach to IT services for financial and accounting firms in Orange County, Shift brings the compliance documentation angle that generic IT support simply does not offer.

Book Your Free 15-Minute Discovery Call