top of page

DATA RETENTION & DISPOSAL POLICY

E.P. Tax Consultants

Effective Date: 11/29/25
Last Updated: 11/29/25

1. Purpose

The purpose of this Data Retention & Disposal Policy is to ensure that E.P. Tax Consultants properly retains, stores, and destroys client information in accordance with IRS regulations, federal privacy laws, and industry best practices.

2. Scope

This policy applies to:

  • All employees, contractors, and temporary staff

  • All client tax records, financial documents, and identifying information

  • Both electronic and physical records stored or processed by E.P. Tax Consultants

3. Data Retention Requirements

3.1 Client Tax Records

E.P. Tax Consultants retains client tax records for a minimum of 7 years, unless otherwise required by state or federal law.

Includes:

  • Tax returns

  • Source documents (W-2s, 1099s, receipts, statements)

  • Business financials

  • Payroll and accounting documents

  • Engagement letters

  • Client correspondence related to tax filings

3.2 Internal Business Records

Internal administrative records are retained according to the following schedule:

Record TypeRetention Period

Firm financials 7 years

Employee records 7 years after termination

Security documentation (risk assessments, training logs, policies)5 years

Vendor contractsFor the duration of the contract + 3 years

3.3 Electronic Communications

Emails containing client data must be retained for 7 years unless archived into secure storage sooner.

4. Storage Requirements

4.1 Physical Documents

  • Stored in locked, secure filing cabinets.

  • Access restricted to authorized personnel only.

  • Documents must not be left unattended or visible in open work areas.

4.2 Electronic Data

  • All client files must be stored on encrypted devices or encrypted cloud platforms.

  • Backups must be encrypted and stored securely.

  • Public or unsecured personal devices are prohibited for data storage.

5. Data Disposal Procedures

5.1 Physical Document Disposal

When the retention period expires, documents must be securely destroyed using:

  • Cross-cut shredders, or

  • A certified document destruction service

Burning, tearing, or discarding in standard trash is strictly prohibited.

5.2 Electronic Data Disposal

Electronic data must be destroyed using methods compliant with NIST 800-88, including:

  • Cryptographic erasure

  • Secure overwriting

  • Certified data destruction tools

Simply deleting a file is not sufficient.

5.3 Device Disposal

Before any device is discarded, sold, or transferred:

  • All storage must be encrypted and securely wiped

  • Device must be reset to factory settings

  • A destruction certificate should be obtained when possible

6. Policy Enforcement

Violations of this policy may result in disciplinary action, including loss of access privileges, training requirements, or termination.

7. Review Schedule

This policy will be reviewed annually and updated as needed to maintain compliance.

 

 

ACCESS CONTROL POLICY

 

E.P. Tax Consultants

Effective Date: 11/29/25

Last Updated 11/29/25

1. Purpose

This Access Control Policy establishes rules for granting, managing, and revoking access to systems, client data, and physical workspaces at E.P Tax Consultants. The goal is to protect sensitive client information from unauthorized access.

2. Scope

Applies to:

  • All employees, contractors, and temporary workers

  • All computers, software, cloud services, and storage systems

  • All physical office locations and file storage areas

3. Access Principles

E.P. Tax Consultants follows the principle of least privilege, which means:

  • Users receive only the minimum access needed to perform their job.

  • Access is role-based and documented.

  • Access privileges must be reviewed regularly.

4. Account & Login Requirements

4.1 Unique User Accounts

  • Every person must use their own username and password.

  • Shared accounts are strictly prohibited.

4.2 Multi-Factor Authentication (MFA)

MFA is required for:

  • Email accounts

  • Tax software

  • Cloud document storage

  • Any system containing client data

4.3 Password Policy

  • Minimum 12 characters

  • Must include upper/lowercase letters, numbers, and symbols

  • No reuse of the previous 3 passwords

  • Passwords changed every 90 days

  • Password managers are strongly encouraged

4.4 Remote Access

Remote access must:

  • Use encrypted connections (VPN or secure portal)

  • Be from secure, updated, and trusted devices

  • Never be performed using public Wi-Fi unless using a VPN

5. Physical Access Controls

5.1 Office Security

  • Offices and storage rooms must remain locked when unattended.

  • Only authorized staff may access areas containing client records.

  • Visitors must be escorted at all times.

5.2 Document Access Restrictions

  • Physical files must remain in locked storage when not in use.

  • Files cannot be removed from the office without written approval.

6. Access Approval & Revocation

6.1 New Access Approval

  • Access is granted based on job role.

  • Supervisor approval required.

  • Access logged and documented.

6.2 Access Review

  • Access permissions reviewed quarterly.

  • Adjusted or revoked when job duties change.

6.3 Termination of Access

Immediately upon termination or resignation:

  • All accounts disabled

  • Physical keys/keycards collected

  • Email forwarding and data access removed

  • Devices returned and inspected

7. Monitoring & Audit

E.P Tax Consultants will monitor:

  • Login attempts

  • Unusual access patterns

  • Failed authentication attempts

  • Unauthorized file access

Any suspicious activity must be reported immediately.

8. Policy Enforcement

Violations may result in:

  • Loss of system access

  • Mandatory retraining

  • Formal discipline or termination

  • Reporting to authorities if required

9. Review Schedule

This policy will be reviewed annually and revised when new technology or legal requirements arise.

Untitled design (1)_edited_edited_edited
Untitled design (1)_edited_edited.png
bottom of page