PTIN and EFIN

PTIN, EFIN, and which one carries the security duty

These two numbers get conflated constantly, and the difference matters because the security obligations attached to each come from different documents, apply to different parties, and renew on different schedules. A PTIN identifies you as an individual paid preparer and is renewed every year. An EFIN authorises your firm to transmit returns electronically and does not. The written information security plan duty attaches to neither number directly: it attaches to the firm, through the FTC Safeguards Rule.

Key facts

  • A PTIN identifies an individual paid preparer and is renewed annually.
  • An EFIN authorises a firm to transmit returns through IRS e-file and does not expire annually.
  • The written plan duty runs through the FTC Safeguards Rule and applies to the firm, not to a number.

Key takeaways

  • Authorized IRS e-file Providers carry additional safeguarding obligations under Publication 1345.

What each number is

A PTIN is personal and annual. An EFIN belongs to the firm and persists.

Anyone who prepares or assists in preparing federal returns for compensation needs a PTIN, and it is tied to the person. If you move firms, your PTIN goes with you.

An EFIN is issued to a firm that has been accepted as an Authorized IRS e-file Provider, and it authorises electronic transmission of returns. It is not renewed on the same annual cycle and it does not follow an individual.

What happens when someone else transmits for you

Using another firm's EFIN does not move your security obligation to them. It adds them to your plan as a service provider.

Plenty of small practices prepare returns and hand transmission to a larger firm or a software provider that holds the EFIN. That is a normal arrangement and it does not reduce what you owe. Your firm still holds the taxpayer information, so 16 CFR 314.3(a) still puts a written program on you.

What it does change is that the transmitting firm becomes a service provider under 16 CFR 314.4(f), which requires you to select providers capable of maintaining appropriate safeguards and to periodically assess them. In practice that means your vendor register names them, you have asked for and read something describing their security, and there is a date on when you last looked.

The same logic applies to your tax software, your document portal, your cloud backup, and anyone else who can reach client data. A plan that lists only the systems you log into yourself is missing the half of the attack surface you rent.

Where the security obligations attach

The written plan requirement attaches to the firm through the Safeguards Rule. The e-file safeguarding obligations attach to the Authorized e-file Provider through Publication 1345.

16 CFR 314.3(a) puts the written program on the covered financial institution, which is the practice. The PTIN acknowledgment at Line 11 of Form W-12 is how an individual preparer is annually reminded of it, but the duty itself is the firm's.

If your firm holds an EFIN, Publication 1345 adds its own expectations around safeguarding taxpayer data in transmission and storage. These sit on top of the Safeguards Rule rather than replacing it, and a plan that covers one and ignores the other is incomplete.

PTIN and EFIN side by side
PTINEFIN
Belongs toThe individual preparerThe firm
Renewed annuallyYesNo
Required to prepare returns for compensationYesNo
Required to transmit through IRS e-fileNoYes
Carries an annual security acknowledgmentYes, Form W-12 Line 11No
Adds Publication 1345 safeguarding expectationsNoYes

FAQ

Do I need both?

You need a PTIN to prepare returns for compensation. You need an EFIN only if your firm transmits returns electronically itself rather than going through another provider. Many small practices hold both.

Does an EFIN expire like a PTIN?

No. An EFIN does not run on the annual renewal cycle that PTINs do. It persists once the firm is accepted as an Authorized IRS e-file Provider, though the IRS can suspend or revoke it.

I am a one-person shop. Does this still apply?

Yes. 16 CFR 314.3(a) requires a written program of covered financial institutions with no exemption for size. A firm holding information on fewer than 5,000 consumers is relieved of four specific written obligations under 16 CFR 314.6, but the written program itself is not one of them.

Is IRS Publication 5708 enough on its own?

Publication 5708 is a genuinely useful sample and the IRS says plainly that it is a sample. It leaves the tailoring to you: your systems, your vendors, your staff, your actual safeguards. A plan that still contains the sample's placeholders is evidence that nobody did the work, which is worse than a shorter plan that is true.

Sources

Cover both in one packet

The questionnaire asks whether you hold an EFIN and adds the Publication 1345 provisions when you do, cited like everything else.

Start the questionnaire
Policywright is a documentation product, not a law firm, and nothing here is legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.