By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 25, 2026
Quick Answer
Accounting firms in the US and Canada operate under overlapping professional conduct obligations and statutory privacy laws that require documented cybersecurity controls. AICPA and CPA Canada codes set the professional standard; GLBA, PIPEDA, and state and provincial privacy laws add statutory teeth. A documented cybersecurity programme is the evidence that these obligations were taken seriously and that client data was protected to the standard each jurisdiction requires. The good news for firms is that these regimes converge on the same core controls, so one programme can answer to all of them.
Key Takeaways
- US CPA firms are subject to AICPA confidentiality rules and, for consumer financial data, the Gramm-Leach-Bliley Act Safeguards Rule.
- Canadian CPA firms follow CPA Canada and provincial body conduct requirements, PIPEDA at the federal level, and Quebec Law 25 where applicable.
- Firms serving clients across borders face layered obligations from multiple jurisdictions simultaneously.
- Regulators and courts interpret “reasonable safeguards” to include MFA, encryption, access management, incident response plans, and independent security testing.
- A single documented cybersecurity programme can satisfy professional conduct obligations, statutory privacy requirements, client questionnaires, and cyber insurance requirements across jurisdictions.
What Do Professional Conduct Codes Require?
AICPA Code of Professional Conduct (United States)
The AICPA Code of Professional Conduct requires CPAs to maintain client confidentiality and prohibits disclosure of client information without consent except in specific circumstances. The obligation applies to all client information obtained in the course of an engagement, regardless of format or medium, and a breach of that client data is not just a security event but a potential conduct matter. It is one reason accounting firms are such a breach of that client data concern for attackers in the first place.
The AICPA Code does not specify a technical standard for protecting that information, but it establishes a duty of competence that extends to the technology practitioners use. A CPA who uses cloud-based tax preparation software without understanding its security configuration, or who stores client records on unencrypted portable media, is exposed to a conduct finding if a breach results.
State CPA licensing boards have their own conduct rules that align with the AICPA Code, and some states have added explicit cybersecurity requirements for licensed practitioners. Firms with multi-state practices need to account for the strictest state standard that applies to their operations.
CPA Canada and Provincial Bodies (Canada)
CPA Canada’s Code of Professional Conduct requires members to protect client confidential information and to apply safeguards appropriate to the sensitivity of the data and the risks of the environment in which it is held. Provincial CPA bodies adopt this framework with variations, and practice inspection programmes now include explicit questions about data security controls.
Canadian regulators have moved steadily toward treating cybersecurity as a core component of confidentiality obligations. A practice that relies on a third-party IT provider without documented security standards, or that has not assessed the security of its cloud platforms, is unlikely to satisfy a regulator examining whether “appropriate safeguards” were in place following a breach.
What Statutory Privacy Laws Apply to Accounting Firms?
Gramm-Leach-Bliley Act Safeguards Rule (United States)
The Gramm-Leach-Bliley Act and its implementing Safeguards Rule apply to financial institutions, a category that the FTC has confirmed includes accounting firms, tax preparers, and financial advisors that collect nonpublic personal financial information from individual clients. The Safeguards Rule requires covered firms to implement a written information security programme with specific elements.
The 2023 amendments to the Safeguards Rule significantly raised the bar. Firms must now designate a qualified individual to oversee the programme, conduct a risk assessment, implement specific technical controls including MFA and encryption, test and monitor the programme, and provide written reports to the board or equivalent governing body at least annually.
Firms that have not assessed whether GLBA applies to their practice, or that have not updated their information security programme since the 2023 amendments, carry an unaddressed compliance gap. The FTC has enforcement authority over Safeguards Rule violations, and state attorneys general in many jurisdictions have parallel authority.
PIPEDA (Canada, Federal)
The Personal Information Protection and Electronic Documents Act applies to the collection, use, and disclosure of personal information in the course of commercial activities across Canada except in provinces with substantially similar legislation. For most accounting firms handling personal tax data, payroll records, and financial information about individuals, PIPEDA applies.
PIPEDA requires organizations to protect personal information with safeguards appropriate to the sensitivity of the information and to notify the Privacy Commissioner of Canada and affected individuals of breaches that create a real risk of significant harm. Personal financial information is generally treated as highly sensitive, making the notification threshold relatively easy to reach in a breach scenario.
Quebec Law 25
Quebec’s Act Respecting the Protection of Personal Information in the Private Sector applies to firms with Quebec clients or operations and imposes requirements that are in several respects stricter than PIPEDA. These include the appointment of a person responsible for personal information protection, mandatory privacy impact assessments for certain technology projects, and a confidentiality incident reporting obligation with timelines shorter than the federal standard.
Firms that added Quebec clients in recent years without reviewing their Law 25 obligations carry a compliance gap. The Commission d’acces a l’information has been active in enforcement, and a regulatory finding against a professional services firm carries reputational consequences that extend beyond the immediate penalty.
US State Privacy Laws
Several US states have enacted comprehensive privacy laws that may apply to accounting firms handling personal information about residents of those states. California’s CPRA, Colorado’s Privacy Act, Virginia’s CDPA, and a growing list of similar statutes impose obligations around data subject rights, privacy notices, data minimization, and security requirements. The patchwork is complex for multi-state practices, though data already covered by GLBA is exempt under several of these state laws.
The practical consequence for accounting firms with clients or staff in multiple states is that the strictest applicable state standard often sets the effective floor for the firm’s data protection programme. A programme built to satisfy GLBA and SOC 2 requirements will typically meet or exceed most state privacy law security requirements, and it is the same evidence base that answers client security questionnaires, but legal review of specific state obligations is advisable for firms with significant multi-state operations.
GDPR for Firms with European Clients
Accounting firms advising on transactions, audits, or tax matters involving European entities or individuals may be subject to the General Data Protection Regulation. GDPR imposes strict requirements around lawful basis for processing, data subject rights, breach notification within 72 hours, and the appointment of a Data Protection Officer in certain circumstances. Cross-border advisory and M&A work in particular can bring European data within GDPR scope without the firm realizing it.
How Does the Regulatory Landscape Translate to Cybersecurity Controls?
Across jurisdictions, the controls that regulators treat as reasonable safeguards for financial and personal information share significant common ground. A cybersecurity programme built around this common core satisfies the majority of applicable requirements without needing to be rebuilt for each jurisdiction.
Multi-factor authentication on all systems containing client data is required by the GLBA Safeguards Rule and treated as baseline by Canadian regulators and privacy commissioners. Encryption of personal and financial information at rest and in transit is similarly required across frameworks. Access management with documented provisioning, deprovisioning, and periodic review controls appears in GLBA, SOC 2 Trust Services Criteria, ISO 27001, and PIPEDA guidance.
A written incident response plan with defined notification timelines is required by the GLBA Safeguards Rule and expected by PIPEDA and Law 25. Annual risk assessments and independent security testing, including penetration testing, are required by the 2023 Safeguards Rule and effectively expected by SOC 2 auditors and cyber insurers.
The written information security programme that GLBA requires, the documented controls that SOC 2 audits validate, and the evidence packages that cyber insurers request at renewal are all drawing from the same underlying controls. A firm that implements those controls once and documents them properly from a single control set satisfies the requirements across frameworks without duplicating effort.
What Does a Cross-Jurisdictional Cybersecurity Programme Look Like?
Armour Cybersecurity works with accounting firms that have clients, staff, and regulatory obligations across Canada, the US, and internationally to build the cybersecurity programmes the profession now requires. The starting point is a gap assessment that maps the firm’s specific obligations across applicable professional conduct codes, federal and provincial or state privacy laws, and client-imposed requirements.
The assessment produces a remediation roadmap that addresses all applicable frameworks from a single control set. Policy documentation, technical control implementation, staff training, vendor risk assessment, and independent testing are structured to generate evidence that can be used for GLBA compliance, PIPEDA breach response, SOC 2 audits, and client questionnaire responses.
The vCISO service provides ongoing governance leadership: monitoring regulatory developments across jurisdictions, updating the programme as requirements evolve, preparing the written annual report that the GLBA Safeguards Rule requires, and advising on cross-border data handling questions that arise in advisory and audit engagements.
Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the firms that handle a multi-jurisdiction regulatory landscape without drowning in it are the ones that stopped treating each law as a separate project. They built one documented control set, mapped it to every obligation at once, and let a single annual cycle of evidence answer the FTC, the Privacy Commissioner, the SOC 2 auditor, and the insurer alike, instead of rebuilding the same safeguards five times under five different names.
Frequently Asked Questions
Does GLBA really apply to our CPA firm?
If your firm collects nonpublic personal financial information from individual clients, the FTC’s position is that you are a financial institution subject to the Safeguards Rule. Tax preparation, personal financial planning, and individual client advisory work all bring a firm within scope. The FTC has brought enforcement actions against tax preparers and financial services firms, and the 2023 amendments significantly increased the specificity of what the programme must include. A compliance assessment is the right starting point.
How do we manage obligations when we have clients in multiple jurisdictions?
The practical approach is to identify the strictest applicable standard across your client jurisdictions and build the programme to that standard. In most cases, a programme that satisfies the GLBA Safeguards Rule, PIPEDA, and SOC 2 requirements will meet or exceed what other applicable frameworks require. Where specific jurisdictions impose unique requirements, such as Quebec Law 25’s designated privacy officer or GDPR’s 72-hour breach notification, those elements are added to the baseline programme.
What is the written information security programme that GLBA requires?
The GLBA Safeguards Rule requires a written programme that includes a designated qualified individual overseeing it, a written risk assessment, safeguards addressing identified risks, service provider oversight, an incident response plan, and an annual written report to governing leadership. Armour’s compliance programme produces all of these components and maintains them as the firm’s risk environment evolves.
What happens if we have a breach and our programme is not documented?
Without a documented programme, a breach investigation by a regulator, insurer, or plaintiff attorney has no evidence of the controls that were in place. The absence of documentation is typically treated as an absence of controls. A firm with a documented programme, even one that was not perfect, is in a fundamentally different position: it can demonstrate that it identified risks, implemented safeguards, and took reasonable steps to protect client data. Documentation is the evidence that obligations were taken seriously.
The Bottom Line
An accounting firm serving clients across borders is not choosing which confidentiality regime to follow; it is subject to all of them at once, from the AICPA and CPA Canada codes to GLBA, PIPEDA, Law 25, state privacy statutes, and sometimes GDPR. The mistake is treating each as a separate compliance project. Every one of these regimes converges on the same core safeguards, MFA, encryption, access management, a tested incident response plan, and independent testing, documented in a written programme. Build that programme once, map it to each obligation, and the same evidence answers the regulator, the auditor, the enterprise client, and the insurer. Armour Cybersecurity helps accounting firms and CPA practices build the cybersecurity programmes that satisfy professional conduct obligations and statutory privacy requirements across Canada, the United States, and internationally, so a cross-jurisdictional client base becomes a strength the firm can defend rather than a compliance liability it hopes never gets tested.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.

