What Is FTI Data? Safeguards, Penalties, and Breach Response

Federal Tax Information, or FTI, is the answer to the question “what is FTI data”: it’s any return or return-related information the IRS collects, maintains, or shares with other agencies, plus taxpayer identity details like your name, address, and Social Security number. Federal law treats it as one of the most tightly restricted categories of personal information the government holds, and the rules reach well beyond the IRS itself to dozens of federal, state, and local agencies that use tax data to run programs like Medicaid, federal student aid, SNAP, and child support enforcement.

What Counts as FTI

The legal definition lives in Section 6103 of the Internal Revenue Code, which splits FTI into two parts: return information and taxpayer identity.1Office of the Law Revision Counsel. 26 USC 6103 – Confidentiality and Disclosure of Returns and Return Information Return information is the broad category. It covers essentially anything the IRS knows about your tax situation: the nature and amount of your income, deductions, credits, assets, liabilities, tax payments, whether your return is under examination, and any other data the IRS has recorded in connection with determining a tax liability. Taxpayer identity information is narrower and covers your name, mailing address, and taxpayer identifying number.

In practice, FTI includes wages, filing status, adjusted gross income, pension distributions, IRA withdrawals, and similar figures. The category also stretches further than many people expect. When an agency receives IRS-sourced data and stores it alongside its own records, the entire mixed dataset must be protected as FTI under the commingling rules in IRS Publication 1075.2Internal Revenue Service. Publication 1075 – Tax Information Security Guidelines for Federal, State and Local Agencies Any value an agency calculates from IRS data that could be used to reverse-engineer the original tax figures is also FTI.

The Voluntary-Data Boundary

One point that trips people up: information you voluntarily provide to an agency is not FTI, even when it’s the same data that appears on your return. If you hand a state benefits office a pay stub, that pay stub is the agency’s own record. If the same agency later pulls your income from IRS systems, that IRS-sourced copy is FTI. The distinction hinges on where the data came from, not on what it says.

Who Receives FTI Beyond the IRS

The IRS is the primary custodian, but Section 6103 authorizes it to share tax data with a long list of other agencies for specific purposes. Each disclosure is tightly scoped: the IRS doesn’t hand an agency a copy of your full return, only the specific data elements that agency is authorized to receive.1Office of the Law Revision Counsel. 26 USC 6103 – Confidentiality and Disclosure of Returns and Return Information

  • The Social Security Administration receives wage and self-employment income data to administer benefits and handle return processing agreements.
  • The Department of Education receives income and tax data through the FAFSA to determine eligibility for Pell Grants, student loans, and income-driven repayment plans.
  • The Department of Health and Human Services receives return information to verify eligibility for state Medicaid programs, CHIP, and Affordable Care Act marketplace plans.
  • Agencies administering SNAP benefits and HUD housing assistance receive FTI for income verification.
  • State child support enforcement agencies use FTI to locate noncustodial parents and set support obligations.
  • State tax departments receive FTI to administer their own tax systems.

Contractors and subcontractors working for any of these agencies are bound by the same confidentiality rules as the agencies themselves.

How FTI Must Be Protected

IRS Publication 1075 is the governing security document. Every agency that receives tax data from the IRS must follow its requirements, and compliance is enforced through the IRS Office of Safeguards.2Internal Revenue Service. Publication 1075 – Tax Information Security Guidelines for Federal, State and Local Agencies The requirements cover the full life of the data, from receipt through destruction.

Access Restrictions

Access to FTI is limited to individuals with both authorization and a specific need to see the data for their official duties. Agencies must use role-based access controls so each employee can view only the FTI elements their work requires. Everyone who handles FTI, including contractors, must pass a background investigation and complete safeguarding training before touching any tax data.

Technical Requirements

Encryption is required for FTI both in transit across networks and at rest on storage devices. Agencies must maintain audit logs showing who accessed FTI, when, and what they did with it. The IRS also requires agencies to label FTI within their databases so administrators can identify protected records, enforce access controls at the data-element level, and determine which systems fall within compliance reviews.3Internal Revenue Service. Protecting Federal Tax Information FTI in Databases Through Labeling

Physical Security and Disposal

Facilities where FTI is stored or processed must have restricted access, secure storage, and visitor controls. Ordinary disposal is not acceptable. Paper records must be cross-cut shredded, pulped, or incinerated, and electronic media must be physically destroyed; wiping a drive is not sufficient on its own.4Internal Revenue Service. Media Sanitization Guidelines

On-Site Reviews

The IRS Office of Safeguards conducts on-site reviews of agencies that handle FTI roughly every three years, covering every IT system that processes, stores, receives, or transmits the data, including third-party providers like cloud hosts, call centers, and print vendors.5IRS Safeguards. Safeguards Review IT Scoping An agency that fails a review can lose access to IRS data entirely.

Penalties for Unauthorized Access or Disclosure

Federal law separates two types of violations: unauthorized disclosure (sharing FTI with someone who shouldn’t have it) and unauthorized inspection (looking at it without a legitimate reason, even without sharing it). Disclosure penalties are harsher, but both are criminal offenses.

Criminal Penalties

Willfully disclosing a return or return information to an unauthorized person is a felony, punishable by a fine of up to $5,000, up to five years in prison, or both. Federal employees convicted of this offense are automatically dismissed. The same penalties apply to state and local agency employees who receive FTI under Section 6103, and to private individuals who obtain and then publish FTI without authorization.6Office of the Law Revision Counsel. 26 USC 7213 – Unauthorized Disclosure of Information

Unauthorized inspection, sometimes called “browsing,” is a misdemeanor. Even if the employee never shares what they saw, looking at someone’s tax information without authorization carries a fine of up to $1,000, up to one year in prison, or both. Federal employees convicted of browsing are also terminated.7Office of the Law Revision Counsel. 26 USC 7213A – Unauthorized Inspection of Returns or Return Information

Civil Damages You Can Recover

Separate from criminal prosecution, you can sue for civil damages when someone inspects or discloses your tax information without authorization. The statute sets a floor of $1,000 per unauthorized act, regardless of whether you can prove actual harm. If your actual damages exceed that amount, you recover the higher figure. In cases involving willful misconduct or gross negligence, punitive damages are also available, and the court can award attorney’s fees and litigation costs.8Office of the Law Revision Counsel. 26 USC 7431 – Civil Damages for Unauthorized Inspection or Disclosure of Returns and Return Information

What Happens After an FTI Breach

When an agency discovers or suspects that FTI has been accessed or disclosed without authorization, it must notify the Treasury Inspector General for Tax Administration (TIGTA) and the IRS Office of Safeguards within 24 hours. The clock starts as soon as the agency identifies a possible issue; it does not wait for an internal investigation to confirm FTI was involved.9Internal Revenue Service. Reporting Unauthorized Accesses, Disclosures or Data Breaches

The Office of Safeguards then coordinates with the agency on containment. If the agency plans to notify affected individuals or issue a media statement, it must share those plans and the text of any communications with the Office of Safeguards before releasing them. Federal law does not set a single nationwide deadline for notifying the individuals whose data was exposed; that timing depends on the agency’s own incident response policy. If you receive a breach notification involving your tax information, the $1,000 per-act civil damages provision gives you a legal remedy even before any measurable financial loss.