WISP requirements in District of Columbia
DC is a high-detail regulator-notice jurisdiction, not a simple resident-letter state. A Policywright DC incident file should preserve the resident count for the 50-resident OAG trigger, the written OAG notice fields, any consultation supporting a no-likely-harm determination, the 1,000-person consumer-reporting-agency trigger, security-freeze language, and the 18-month identity-theft-protection analysis for breaches involving Social Security or taxpayer identification numbers. The same file should also connect the response to DC's reasonable-security-safeguards and vendor-contract requirements.
Key facts
- District of Columbia firms should keep a written security program tied to the FTC Safeguards Rule and IRS taxpayer-data guidance.
- Resident notice in the most expedient time possible and without unreasonable delay, subject to law-enforcement delay and scope/restoration needs; DC Attorney General notice for 50+ District residents no later than resident notice; consumer-reporting-agency notice without unreasonable delay for more than 1,000 persons.
- Provide written notice to the DC Attorney General if the breach affects 50 or more District residents, in the most expedient manner possible, without unreasonable delay, and no later than when District resident notice is provided; include the statutory incident details and a sample resident notice.
Key takeaways
- District of Columbia firms should keep a written security program tied to the FTC Safeguards Rule and IRS taxpayer-data guidance.
- Resident notice in the most expedient time possible and without unreasonable delay, subject to law-enforcement delay and scope/restoration needs; DC Attorney General notice for 50+ District residents no later than resident notice; consumer-reporting-agency notice without unreasonable delay for more than 1,000 persons.
- Provide written notice to the DC Attorney General if the breach affects 50 or more District residents, in the most expedient manner possible, without unreasonable delay, and no later than when District resident notice is provided; include the statutory incident details and a sample resident notice.
- The WISP should preserve evidence, remediation steps, and annual review records.
Do District of Columbia tax preparers need a WISP?
Yes, if they are covered by the FTC Safeguards Rule or IRS tax-data security expectations, they should maintain a written plan. District of Columbia state breach-notice duties make incident planning especially important.
The WISP should start with federal obligations because the Safeguards Rule supplies the security-program structure.
DC requires written notice to the Office of the Attorney General when a breach affects 50 or more District residents, no later than when resident notice is provided; if more than 1,000 persons are notified, nationwide consumer reporting agencies must also receive timing, distribution, and content notice.
What is specific to District of Columbia?
Resident notice in the most expedient time possible and without unreasonable delay, subject to law-enforcement delay and scope/restoration needs; DC Attorney General notice for 50+ District residents no later than resident notice; consumer-reporting-agency notice without unreasonable delay for more than 1,000 persons. The plan should identify who evaluates state notice, who contacts counsel, and where the decision record is kept.
State breach-notification law does not replace the Safeguards Rule. It adds a state-specific response layer when an incident affects District of Columbia residents.
District residents whose personal information was included in the breach of the security system, subject to the statutory secure-data and no-likely-harm exceptions.
Provide written notice to the DC Attorney General if the breach affects 50 or more District residents, in the most expedient manner possible, without unreasonable delay, and no later than when District resident notice is provided; include the statutory incident details and a sample resident notice.
What should the WISP say?
It should describe real safeguards, assign responsibility, map vendors and systems, and include an incident-response path that reaches state-law review quickly.
For a small firm, the strongest plan is plain and evidence-backed: MFA records, backup tests, access reviews, training, vendor lists, and remediation dates.
The plan should never promise a control that is not actually in place.
| Topic | District of Columbia planning note | Evidence |
|---|---|---|
| Federal WISP | Use 16 CFR Part 314 as the program backbone | WISP and annual review |
| IRS tax data | Account for taxpayer records, PTIN practice, portals, and e-file workflows | System inventory and access list |
| Breach notice | Resident notice in the most expedient time possible and without unreasonable delay, subject to law-enforcement delay and scope/restoration needs; DC Attorney General notice for 50+ District residents no later than resident notice; consumer-reporting-agency notice without unreasonable delay for more than 1,000 persons. | Incident clock and counsel review record |
| Regulator path | Provide written notice to the DC Attorney General if the breach affects 50 or more District residents, in the most expedient manner possible, without unreasonable delay, and no later than when District resident notice is provided; include the statutory incident details and a sample resident notice. | Notification decision log |
| State statute | D.C. Code §§ 28-3851 through 28-3853, including § 28-3852 | Source URL retained in page sources |
FAQ
Is this legal advice?
No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.
Does a small firm still need a written plan?
Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.
What if a control is not in place yet?
A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.
Does District of Columbia have its own WISP law?
This page does not claim a standalone District of Columbia WISP statute for every firm. It explains how federal WISP duties should be paired with District of Columbia breach-notification planning.
Who reviews District of Columbia breach notice?
The incident plan should route state-law decisions through qualified counsel and preserve any Office of the Attorney General for the District of Columbia regulator-notice analysis.
Sources
- FTC Safeguards Rule, 16 CFR Part 314 (eCFR)
- FTC, Safeguards Rule: What Your Business Needs to Know
- FTC, Safeguards Rule notification requirement now in effect (16 CFR 314.4(j), eff. May 13, 2024)
- IRS Publication 5708, Creating a Written Information Security Plan
- IRS Publication 4557, Safeguarding Taxpayer Data
- IRS Form W-12, PTIN Application and Renewal
- IRS Publication 1345, Handbook for Authorized IRS e-file Providers
- District of Columbia Code § 28-3852
- District of Columbia Code § 28-3851
- District of Columbia Consumer Protections chapter
- Office of the Attorney General for the District of Columbia
- DC OAG Blackbaud data breach settlement
Build a District of Columbia-aware WISP packet.
Policywright generates a source-cited WISP and incident response plan you can review with counsel.
Start the questionnaire