Customer information: definition for WISP compliance
Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution. Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP. 16 CFR 314.2(d) defines customer information as records containing nonpublic personal information about a customer, in paper, electronic, or other form.
Key facts
- Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution.
- Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP.
- The term should be used consistently in the WISP, incident response plan, and access control policy.
Key takeaways
- Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution.
- Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP.
- The term should be used consistently in the WISP, incident response plan, and access control policy.
- Definitions are operational: they should help a small firm decide what to do and what evidence to keep.
What does customer information mean?
Customer information means nonpublic personal information about a customer, whether in paper, electronic, or other form, handled by or for a financial institution.
Tax records, bank feeds, payroll files, portals, and client identity documents can all fall inside the practical scope of a firm's WISP.
16 CFR 314.2(d) defines customer information as records containing nonpublic personal information about a customer, in paper, electronic, or other form.
Worked example
A tax office's client portal exports, scanned driver licenses, bank-feed files, e-file acknowledgments, and retained workpapers are all treated as customer-information locations in the WISP inventory.
The example belongs in the policy packet only if it matches the firm's actual systems, vendors, and evidence records. Otherwise, it should become a remediation or counsel-review note.
What small firms get wrong
Small firms often count only tax software or a core system and miss email attachments, paper files, backup exports, and vendor support access.
The fix is to tie the term to a concrete record: a system inventory, access list, vendor list, incident log, training record, or dated control screenshot.
| Where it appears | Why it matters | Proof example |
|---|---|---|
| WISP | 16 CFR 314.2(d) defines customer information as records containing nonpublic personal information about a customer, in paper, electronic, or other form. | Annual review record |
| Access Control Policy | Connects roles to permissions | User access list |
| Incident Response Plan | Guides escalation and notice decisions | Incident log |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
Explore this cluster
Sources
- FTC Safeguards Rule, 16 CFR Part 314 (eCFR)
- FTC, Safeguards Rule: What Your Business Needs to Know
- FTC, Safeguards Rule notification requirement now in effect (16 CFR 314.4(j), eff. May 13, 2024)
- IRS Publication 5708, Creating a Written Information Security Plan
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Form W-12, PTIN Application and Renewal
- IRS Publication 1345, Handbook for Authorized IRS e-file Providers
Turn definitions into working policies.
Policywright uses clear terms and source-cited clauses across the full policy packet.
See a sample