Glossary

Customer information: definition for WISP compliance

Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution. Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP. 16 CFR 314.2(d) defines customer information as records containing nonpublic personal information about a customer, in paper, electronic, or other form.

Key facts

  • Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution.
  • Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP.
  • The term should be used consistently in the WISP, incident response plan, and access control policy.

Key takeaways

  • Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution.
  • Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP.
  • The term should be used consistently in the WISP, incident response plan, and access control policy.
  • Definitions are operational: they should help a small firm decide what to do and what evidence to keep.

What does customer information mean?

Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution.

Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP.

16 CFR 314.2(d) defines customer information as records containing nonpublic personal information about a customer, in paper, electronic, or other form.

Worked example

A tax office's client portal exports, scanned driver licenses, bank-feed files, e-file acknowledgments, and retained workpapers are all treated as customer-information locations in the WISP inventory.

The example belongs in the policy packet only if it matches the firm's actual systems, vendors, and evidence records. Otherwise, it should become a remediation or counsel-review note.

What small firms get wrong

Small firms often count only tax software or a core system and miss email attachments, paper files, backup exports, and vendor support access.

The fix is to tie the term to a concrete record: a system inventory, access list, vendor list, incident log, training record, or dated control screenshot.

Customer information in context
Where it appearsWhy it mattersProof example
WISP16 CFR 314.2(d) defines customer information as records containing nonpublic personal information about a customer, in paper, electronic, or other form.Annual review record
Access Control PolicyConnects roles to permissionsUser access list
Incident Response PlanGuides escalation and notice decisionsIncident log

FAQ

Is this legal advice?

No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.

Does a small firm still need a written plan?

Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.

What if a control is not in place yet?

A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.

Sources

Turn definitions into working policies.

Policywright uses clear terms and source-cited clauses across the full policy packet.

See a sample
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.