Twenty states have comprehensive consumer privacy laws in effect in 2026, and the newest three, Indiana, Kentucky, and Rhode Island, all took effect on January 1, 2026. A multi-state accounting firm inherits the state layer of every state its clients live in, not just the states where it keeps offices. The federal floor, the FTC Safeguards Rule plus the IRS’s breach-response expectations, is identical in all 50 states.
Key takeaways
Twenty states have comprehensive consumer privacy laws in effect in 2026.
Indiana, Kentucky, and Rhode Island took effect January 1, 2026.
Your firm inherits the privacy law of every state where a client lives, not just where its offices sit.
The federal floor never moves: the FTC Safeguards Rule and IRS Publication 4557 apply in all 50 states.
A current WISP is the base document every state obligation builds on.
Table of Contents
What Is the Same for Your Firm in Every State?
The federal floor doesn’t move. The FTC Safeguards Rule (16 CFR Part 314) requires a written information security program from every professional tax preparer in all 50 states, and IRS Publication 4557 expects the same safeguards. Breach duties are federal too: the FTC must be notified of large breaches within 30 days.
Before any state law enters the picture, your firm already answers to two federal authorities, and they say the same thing in Boise that they say in Boston. The FTC Safeguards Rule treats professional tax preparers as financial institutions and requires a written information security program with named elements: a qualified individual who oversees it, a written risk assessment, encryption of client data at rest and in transit, multi-factor authentication, and a written incident response plan (16 CFR 314.4). IRS Publication 4557 points preparers to the same controls and to the WISP that documents them.
The breach side is federal as well. Under the amended Safeguards Rule, a security breach involving unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery. And the IRS’s own data theft guidance walks a breached firm through reporting to its IRS Stakeholder Liaison and contacting the attorney general in each state where it prepares returns, noting that most states require attorney general notification of a data breach.
Requirement
Where it comes from
Where it applies
Written information security plan (WISP)
FTC Safeguards Rule, 16 CFR Part 314; IRS Pub 4557
All 50 states
Qualified individual overseeing the program
16 CFR 314.4
All 50 states
Encryption of client data at rest and in transit
16 CFR 314.4
All 50 states
Multi-factor authentication
16 CFR 314.4
All 50 states
FTC notice within 30 days of a breach of unencrypted data affecting 500+ consumers
16 CFR Part 314
All 50 states
IRS Stakeholder Liaison report plus state attorney general contact after data theft
IRS data theft guidance
All 50 states
If your WISP is current under IRS Publication 4557, this floor is already under you. Everything a state adds in 2026 is an addendum to that document, not a rebuild of it.
Which State Privacy Laws Take Effect in 2026?
Twenty states have comprehensive consumer privacy laws in effect in 2026. Three are new this year: Indiana, Kentucky, and Rhode Island all took effect on January 1, 2026. The other seventeen were already live before the year started, so most multi-state firms are inside at least one of them today.
MultiState’s 2026 tracker puts the count at twenty comprehensive state privacy laws in effect during 2026, with three newcomers on New Year’s Day.
State
Comprehensive privacy law effective
Status in 2026
Indiana
January 1, 2026
New this year
Kentucky
January 1, 2026
New this year
Rhode Island
January 1, 2026
New this year
17 additional states
Before January 1, 2026
Already in effect
Two honest caveats belong next to that table. First, whether a given state’s law actually reaches your firm depends on that statute’s own applicability thresholds and how it treats data already regulated under federal financial privacy law. Several state laws carve some or all of that data out; several don’t. [VERIFY: per-state applicability thresholds and financial-data exemptions need each statute checked before any state-specific claim ships.] Second, a full 50-state matrix mapping every comprehensive privacy law and breach-notification statute is the natural companion to this post. It needs statute-by-statute verification, so it ships separately rather than as a guess here.
What the count tells you without any statute reading: the state layer is now the norm, not the exception. Twenty states in effect means a firm with clients in even a handful of states is statistically likely to touch at least one.
Why Does Your Firm Inherit Every State Its Clients Live In?
State privacy laws protect residents, so what matters is where each client lives, not where your offices sit. A firm with two offices and Form 1040 clients in a dozen states inherits the state layer of every one of those states that has a comprehensive law in effect in 2026.
Comprehensive privacy laws are consumer-protection statutes. They attach to the residents whose data a business handles, which means your exposure map is your client list, not your lease agreements. A firm headquartered in Ohio with a second office in Kentucky doesn’t get to stop at two states: if it prepares returns for clients who live in Indiana and Rhode Island, both of those January 1, 2026 laws belong on its checklist too.
Federal guidance already thinks this way. The IRS data theft checklist measures a firm’s footprint in client states, directing a breached preparer to contact the attorney general in each state where it prepares returns. The states you’d owe a call to after an incident are the same states whose privacy laws you should be tracking before one.
Three things quietly grow that map for a 25-to-150-person firm:
Remote work moved your clients. A client who relocated to Indiana in 2025 and kept your firm brought Indiana’s January 1, 2026 law with them.
Remote work moved your staff. Preparers working from home in a third or fourth state add operational ties your office list doesn’t show.
Mergers import client bases. Acquire a book of business and you acquire its states on day one, before the letterhead changes.
The practical upshot is calmer than it sounds. You don’t need fifty legal opinions; you need one accurate client-residency report and a WISP that already covers the federal floor. Which states could reach you is a data question your tax software answers in minutes. Whether each one’s statute actually applies is the narrow question to put to counsel for the short list that report produces.
What Should a Multi-State Firm Do Before Year End?
Five moves cover it: pull a client-residency report from your tax software, confirm your WISP is current, check Indiana, Kentucky, and Rhode Island against that client list, write state attorney general notification into your incident response plan, and confirm client data is encrypted at rest and in transit everywhere it lives.
Pull a client-residency report. Every major tax package can count Form 1040 clients by state of residence. That one report is your exposure map for all twenty states with laws in effect in 2026.
Confirm the WISP is current. The written plan the FTC Safeguards Rule and IRS Publication 4557 both expect is the base document; a state addendum bolts onto a current WISP in pages, not weeks.
Check the three new states against the list. Indiana, Kentucky, and Rhode Island took effect January 1, 2026. If the residency report shows clients in any of them, put that state’s statute in front of counsel.
Write state notification into the incident response plan. The IRS already expects a breached firm to contact the attorney general in each state where it prepares returns, so name the states and the contacts before an incident, not during one.
Confirm encryption everywhere client data lives. The federal breach duty keys off unencrypted information, and encryption at rest and in transit is a required Safeguards Rule control (16 CFR 314.4), so this one control does double duty.
None of these five require new software or a consultant on retainer. Firms that centralize client data on one hosted environment tend to finish the list fastest, because there’s one place to check instead of forty laptops.
“Verito’s outstanding feature is its ability to facilitate remote work, offering a secure environment that supports my team with top-notch customer service that goes above and beyond their scope of responsibility. … I love that I can access the same data from multiple locations, whether I am at the office, home, or traveling globally.”
SOC 2 is the secondary frame, not the starting point. The FTC Safeguards Rule already expects your firm to oversee its service providers. A current SOC 2 Type II report from your hosting vendor is the cleanest way to show that oversight to a client, an insurer, or a regulator in any state.
For firms in the 25-to-150-person range, SOC 2 questions usually arrive from the outside: a business client’s audit committee, a cyber insurance renewal, or a PE owner’s diligence list. A SOC 2 Type II report answers those questions the same way in every state at once, which is exactly what a multi-state firm wants: one audited artifact instead of a separate security questionnaire per relationship.
It also satisfies a federal requirement you already carry. Service provider oversight is a named element of the Safeguards Rule program (16 CFR 314.4), and holding your hosting vendor’s current SOC 2 Type II report is the concrete form that oversight takes. It complements the WISP rather than replacing it: the WISP is your firm’s plan, the SOC 2 report is your vendor’s proof.
How Does Verito Cover the Federal Floor for a Multi-State Firm?
VeritShield WISP is a $999 per year subscription: a custom written information security plan delivered in 5 business days, with unlimited revisions as your firm changes. VeritComplete adds hosting and managed IT from $129 per user per month, on infrastructure designed to support IRS Pub 4557 and FTC Safeguards requirements.
The state layer keeps moving, so the useful thing is a federal floor that doesn’t. VeritShield WISP is built around your firm’s actual software, offices, and workflow rather than a template, covers IRS Publication 4557 and the FTC Safeguards Rule, and arrives in 5 business days. Because it’s an annual subscription with unlimited revisions, the plan gets updated when your client map changes: add an office, absorb a merger, or pick up a cluster of clients in a new state, and the document moves with you at no extra charge.
VeritComplete puts the infrastructure under the plan: hosting and managed IT in one agreement at $129, $199, or $249 per user per month, with the full $999-per-year WISP included on every tier. Pro adds an annual FTC Safeguards audit; Elite makes it bi-annual and adds 24/7 SOC monitoring, dark web monitoring, and a named account manager. Underneath every tier sits a dedicated private server with 256-bit encryption, multi-factor authentication, and automatic backups, on infrastructure that is SOC 2 Type II and ISO 27001 certified. Your team signs into the same desktop from any office or any state, which is how a two-office firm keeps client data in one governed place instead of scattered across every location.
Verito serves tax and accounting firms in all 50 states, so the multi-state shape of your practice is the normal case, not an edge case: 1,000+ firms run on this infrastructure, it has held 100% uptime since 2016, and a real person answers support in under 60 seconds.
“I use Verito to host Drake Accounting, Drake Tax, and TaxDome … Everything runs smoothly, and the performance is exactly what I need for my tax practice. As a tax professional, reliability and security are everything, and Verito has delivered both perfectly.”
Crystal Gilbert · Google, Dec 2025
The state count will keep climbing past twenty, and each new legislature will add its own wrinkles. Firms with the federal floor written down and their client map current absorb each new state as a revision. If the FTC, the IRS, or a state attorney general asks, you have an answer.
Camren Majors is co-founder and Chief Revenue Officer of Verito Technologies, a cloud hosting and managed IT company built exclusively for tax and accounting firms. He is the co-author of Beyond Best Practices: Modernizing the Successful Accounting Firm (2026). His work has been featured in NATP TAXPRO Magazine and he has presented for NATP, NAEA, and NSA.