IRS Publication 1075 is the security manual the Internal Revenue Service issues to every federal, state, and local government agency that receives confidential tax data, setting out in detail how those agencies must protect it. It runs more than 200 pages, covers locked cabinets through encrypted networks, and is grounded in the confidentiality rules of Internal Revenue Code Section 6103. It is not a form taxpayers file. It is the rulebook the IRS hands to its data-sharing partners, along with the authority to inspect whether they are actually following it.
Who Publication 1075 Applies To
The full title is “Tax Information Security Guidelines for Federal, State and Local Agencies.” Its stated purpose is to “promote taxpayer confidence in the integrity of the tax system by ensuring the confidentiality of IRS information provided to federal, state, and local agencies.”1Internal Revenue Service. Publication 1075 – Tax Information Security Guidelines for Federal, State and Local Agencies
Any government agency that receives tax data from the IRS falls under it. That includes state revenue departments doing tax administration, state Medicaid and TANF agencies determining eligibility, child support enforcement offices, SNAP and SSI programs, certain housing and veterans’ benefit administrators, and ACA marketplace operators. The IRS shares data with each of these under a specific subsection of Section 6103, and in every case the receiving agency has to satisfy Publication 1075 before any data moves.
These disclosures happen through agency-level agreements, often formal Computer Matching Agreements under the Privacy Act, not through individual taxpayer requests.2U.S. Department of Health and Human Services (HHS.gov). Computer Matching Agreement Between the Department of Health and Human Services Centers for Medicare and Medicaid Services and the Department of the Treasury Internal Revenue Service If you searched for Publication 1075 expecting a taxpayer authorization document, that is a different track: Form 2848 (power of attorney) and Form 8821 (tax information authorization) are the forms individuals use to authorize disclosure of their own returns.
The Statute Behind It: IRC Section 6103
The whole framework rests on 26 U.S.C. § 6103, which declares that returns and return information “shall be confidential” and cannot be disclosed by any government officer or employee except where the code specifically authorizes it.3Office of the Law Revision Counsel. 26 U.S. Code 6103 – Confidentiality and Disclosure of Returns and Return Information Dozens of subsections carve out narrow exceptions for specific agencies and purposes.
Section 6103(p)(4) is the safeguard hook. It requires every recipient agency to keep standardized records of requests and disclosures, store data securely, restrict access to those who need it, file compliance reports with the IRS, and return or destroy the data when it is no longer needed. Publication 1075 turns those statutory demands into concrete controls.
What Counts as Federal Tax Information
Federal Tax Information, or FTI, is broader than agencies often assume. Under IRC 6103(b)(2), “return information” covers a taxpayer’s identity, income amounts and sources, deductions, credits, assets, liabilities, net worth, tax payments, and even whether a return is under examination or investigation. Effectively, anything the IRS collects, records, or generates about a taxpayer is in scope.
The definition also travels. Per the IRS, FTI “includes any information created by the [receiving agency] that is derived from return or return information.”4Internal Revenue Service. Safeguarding Federal Tax Information (FTI) in ACA Printed Notices A downstream list an agency builds from IRS-supplied income data is itself FTI and has to be protected on the same terms. This is where agencies most often stumble during compliance reviews.
The Safeguard Requirements
Publication 1075 layers requirements across physical space, technology, personnel, and paperwork. Weakness in any one layer can jeopardize an agency’s access to the data.
Physical Security
FTI has to sit in a secure area with controlled access. Agencies keep visitor logs, maintain authorized-access lists, control keys and combinations, and use specified locking systems for secured spaces.1Internal Revenue Service. Publication 1075 – Tax Information Security Guidelines for Federal, State and Local Agencies Moving FTI between locations, such as during an office relocation, triggers separate transit protocols.
Information Technology
The IT rules track federal standards from the National Institute of Standards and Technology. Data in transit has to be protected with FIPS 140-validated encryption, transmission integrity and confidentiality must be preserved, and cryptographic keys have to be managed under NIST guidelines. Remote access to systems holding FTI requires a VPN with two-factor authentication combining something the user knows with something the user has.5Internal Revenue Service. Encryption Requirements of Publication 1075
Access Controls and Recordkeeping
Under IRC 6103(p)(4)(A), agencies maintain a permanent, standardized log of every request for tax information, why it was made, and when. Access is limited to employees whose duties actually require it, and Publication 1075 requires background investigations for anyone (employee or contractor) who will handle FTI.
How the IRS Verifies Compliance
The IRS Office of Safeguards conducts on-site safeguard reviews. Reviewers interview staff, walk through storage areas and data centers, test security controls, check background investigation records, and spot-check files containing tax information.6Internal Revenue Service. Internal Revenue Manual 11.3.36 – Safeguard Review Program Scheduling is risk-based after an agency first begins receiving FTI.
Between IRS visits, agencies run their own internal inspections on a fixed cycle. Local offices receiving FTI must be inspected at least every three years; headquarters facilities and contractor sites at least every 18 months. Inspection reports and corrective action records have to be kept for at least five years.
When a review turns up problems, each finding gets a risk category with a resolution deadline attached:
- Critical findings: resolved within 3 months of the review closing conference.
- Significant findings: 6 months.
- Moderate findings: 9 months.
- Limited findings: 12 months.
The agency submits a Corrective Action Plan and updates it every six months until every finding is closed. If an agency refuses to file required reports, or its deficiencies are severe enough to threaten tax administration, the IRS can suspend or permanently cut off access to tax data, either for the whole agency or just the piece where the problem lives.
Breach Reporting: The 24-Hour Clock
When a potential breach involving FTI is identified, the agency has to contact both the Treasury Inspector General for Tax Administration and the IRS Office of Safeguards within 24 hours.7Internal Revenue Service. Reporting Unauthorized Accesses, Disclosures or Data Breaches
Notification to affected individuals runs through the agency’s own incident response policy, since the data is in the agency’s hands. But the agency has to tell the Office of Safeguards about planned notifications before sending them and share the text of any media releases before distribution. The IRS keeps oversight of how breaches of its data are communicated.
Destroying FTI When It Is No Longer Needed
Once an agency finishes with FTI, it either returns the data to the IRS or destroys it and confirms the destruction in writing. Publication 1075 is specific about what counts as destruction:
- Paper records: burning, mulching, pulping, or shredding to pieces no larger than 5/16 of an inch wide.
- Microfilm and microfiche: burning only.
- Electronic media: sanitizing under NIST-aligned guidelines before the media leaves agency control, with every third piece of physical media verified.
Hand-tearing, routine recycling, and burying in a landfill are all explicitly prohibited. When a contractor performs destruction, the contract has to include the Publication 1075 safeguard language, and an agency employee has to witness the work unless the contractor holds NAID certification.
Penalties for Unauthorized Disclosure or Inspection
Enforcement reaches individual employees, not just the agencies that employ them.
Criminal
Under 26 U.S.C. § 7213, unauthorized disclosure of tax returns or return information is a felony punishable by a fine of up to $5,000, imprisonment of up to five years, or both, plus prosecution costs. Federal officers and employees convicted under this section are subject to mandatory dismissal on top of the sentence.8Office of the Law Revision Counsel. 26 U.S. Code 7213 – Unauthorized Disclosure of Information
Unauthorized inspection is a separate misdemeanor under 26 U.S.C. § 7213A, carrying a fine of up to $1,000, imprisonment of up to one year, or both, plus costs. Federal employees convicted of unauthorized inspection also face mandatory dismissal.9Office of the Law Revision Counsel. 26 USC 7213A – Unauthorized Inspection of Returns or Return Information
Civil
Under 26 U.S.C. § 7431, taxpayers can sue for unauthorized disclosure or inspection. A successful plaintiff recovers the greater of $1,000 per act or actual damages sustained. Willful or grossly negligent violations open the door to punitive damages, and the defendant pays litigation costs and, in some cases, reasonable attorney fees.10Office of the Law Revision Counsel. 26 U.S. Code 7431 – Civil Damages for Unauthorized Inspection or Disclosure of Returns and Return Information Publication 1075 requires agencies to train staff on these consequences.
If You Were Looking for a Taxpayer Form
Publication 1075 does not authorize anyone to access your tax records. If you want to give another person permission to see or act on your tax information, the IRS forms are Form 2848 (Power of Attorney and Declaration of Representative), for someone who will represent you before the IRS, and Form 8821 (Tax Information Authorization), for someone who only needs to inspect or receive information.11Internal Revenue Service. Disclosure Laws If a benefit program asks to check your tax data, the agency usually pulls that data itself through the channels governed by IRC 6103 and Publication 1075, and no separate IRS form is required from you.