Section 7216: What CPA Firms Must Know Before Sending Return Data Offshore
Offshore tax preparation is legal and common. But it needs written client consent first, in a specific format, with specific wording, and the liability stays with your firm.
By Acceler8 Global Team

Sending return data to an offshore team is standard practice. It is also one of the few things in tax practice that carries a criminal penalty if you get the paperwork wrong.
The rule is Section 7216 of the Internal Revenue Code. It is short, old and strict: a tax return preparer may not disclose or use a client's return information without the client's consent.
Not "should not." May not.
What it costs to get wrong
| PROVISION | TYPE | AMOUNT |
|---|---|---|
| IRC §7216 | Criminal, misdemeanour | Up to $1,000 and up to one year imprisonment, per violation, plus prosecution costs |
| IRC §6713 | Civil | $250 per disclosure, capped at $10,000 per calendar year |
| IRC §6713, identity theft related | Civil, enhanced | $1,000 per disclosure, capped at $50,000 per year, on top of the standard cap |
26 CFR §301.7216-1(a) and 26 U.S.C. §6713. The civil penalty applies whether or not the disclosure was intentional.
Read the civil penalty carefully. It's $250 per disclosure. A firm that sends 200 returns offshore under an invalid consent has made 200 disclosures.
The sequence that keeps you compliant
The operative guidance is Revenue Procedure 2013-14, still current in 2026. It sets out exactly what a consent must contain and how it must look.
The offshore rule most firms miss
Here's the part that trips up firms that have otherwise done everything right.
A consent to disclose return information to a preparer outside the United States must not include the taxpayer's Social Security Number, unless both firms maintain an adequate data protection safeguard.
That's the default position. You can include the SSN only if both your firm and the offshore preparer maintain an adequate data protection safeguard, and the consent says so.
The recognised frameworks include the AICPA/CICA Privacy Framework and equivalent standards. If you rely on this route, the consent must also warn the client that US federal agencies may not be able to enforce US privacy protections against the offshore preparer.
Every offshore consent must include this statement, in substance:
What a valid consent has to contain
Section 7216 is not the only rule
It's the one with the criminal penalty, so it gets the attention. But three other obligations apply at the same time.
The security obligations that come with it
Under the GLBA Safeguards Rule, every tax preparer must have a written information security plan. Not a policy folder, an actual written plan.
The IRS publishes a 28-page sample template as Publication 5708, and a broader checklist as Publication 4557. Between them they cover the practical requirements:
- A named individual responsible for the programme
- A documented risk assessment
- Access controls, encryption, multi-factor authentication and secure disposal
- Continuous monitoring, or annual penetration testing and twice-yearly vulnerability scans
- Staff training, and oversight of service providers, including your offshore team
- An incident response plan, and annual reporting to the firm's owners or board
There's also a breach notification duty: report to the FTC within 30 days of discovering a breach affecting 500 or more consumers.
Common failure modes
Consent buried in the engagement letter
A consent has to be a separate, knowing act. Folding it into an engagement letter the client signs to start work makes it hard to argue it was voluntary.
One consent, reused for years
The default duration is one year from the date signed. If you didn't state a longer period, last season's consent expired.
The offshore provider changed and nobody re-papered
The consent identifies the recipient. Change the recipient and you need a new consent.
Data sent to "get a quote"
Sending a sample return to a prospective offshore provider during procurement is a disclosure. It needs consent like any other.
A practical checklist before this filing season
- Confirm your consent form matches Rev. Proc. 2013-14 in both format and wording.
- Confirm the offshore mandatory language is present, word for word.
- Decide whether you are sending SSNs. If yes, document the data protection safeguard on both sides.
- Check the duration on last year's consents. Re-paper anything expired.
- Confirm your written information security plan exists and has been reviewed this year.
- Check whether your state board has its own disclosure rule.
- Log which returns went offshore, under which consent, on what date.
That last one is the cheapest insurance in the list. If the question ever comes up, the log is the answer.
The takeaway
Key takeaways
- Consent must be written, knowing, voluntary, and obtained before the data moves.
- Offshore consents must carry specific mandatory wording, and cannot include the SSN without documented safeguards on both sides.
- The civil penalty is per disclosure, so volume multiplies exposure fast.
- Section 7216 sits alongside GLBA, the AICPA Code and any state board rule. All four apply at once.
- Liability stays with the firm, not the provider.
Sources
1. Internal Revenue Service. Section 7216 Information Center. https://www.irs.gov/tax-professionals/section-7216-information-center
2. Internal Revenue Service. Revenue Procedure 2013-14. https://www.irs.gov/pub/irs-drop/rp-13-14.pdf
3. eCFR. 26 CFR §301.7216-3, Disclosure or use permitted by consent. https://www.ecfr.gov/current/title-26/chapter-I/subchapter-F/part-301/subpart-ECFRa197f7a9e2c9460/subject-group-ECFR32261461a26e430/section-301.7216-3
4. Cornell Legal Information Institute. 26 U.S.C. §6713, Disclosure or use of information by preparers of returns. https://www.law.cornell.edu/uscode/text/26/6713
5. Federal Trade Commission. FTC Safeguards Rule: What Your Business Needs to Know. https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know
6. Internal Revenue Service. Tax pros must have a Written Information Security Plan. https://www.irs.gov/newsroom/irs-security-summit-remind-tax-pros-they-must-have-a-written-information-security-plan-to-protect-client-data
7. North Carolina Administrative Code. 21 NCAC 08N.0214, use of a third party. https://regulations.justia.com/states/north-carolina/title-21/chapter-08/subchapter-n/section-0200/section-08n-0214
This article is a general overview and is not legal or tax advice. Confirm the current text of Rev. Proc. 2013-14, your state board's rules and your own consent forms with qualified counsel before this filing season.
Keep reading
Payroll Savings You May Be Missing: 9 Tax Credits Most Employers Never Claim
A fast 2026 guide to the federal credits tied to leave, childcare, hiring, retirement, health coverage, R&D and clean energy.
Read articleTaxBusy Season Capacity: How Firms Scale Without Overhiring for Four Months
Hiring for the peak means overstaffing all year. Hiring for the average means drowning every January. Here's what firms are actually doing instead.
Read articleTaxR&D Tax Credit Eligibility: What Actually Qualifies
The R&D credit is one of the most under-claimed credits in the tax code, mostly because companies assume it only applies to formal research. It doesn't.
Read article