Texas Data Breach Notification

Texas divides a covered data breach into two notice tracks. A business generally has no more than 60 days after determining that a breach occurred to notify affected individuals. A breach involving at least 250 Texas residents also requires an electronic report to the Texas Attorney General as soon as practicable and no later than 30 days after that determination.

Those duties come from Texas Business and Commerce Code § 521.053, part of the Texas Identity Theft Enforcement and Protection Act. Your response depends on the compromised information, who owns it, how many people were affected, where they live, and what investigators can establish about unauthorized acquisition.

Texas can impose substantial penalties for a failed response. Texas Business and Commerce Code § 521.151 sets civil penalties from $2,000 to $50,000 per violation. A person who fails to take reasonable action to provide required consumer notice can also face as much as $100 per affected person for each consecutive day of delay, subject to a $250,000 cap for one breach.

The Notice Trigger

Texas defines a breach of system security as unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information. You should determine whether an unauthorized person acquired the protected information or reasonably appears to have acquired it. Downloads, exports, file transfers, copied records, attacker communications, access logs, and forensic artifacts can support that determination.

Encrypted data can qualify when the unauthorized person also obtained the key required to decrypt it. Your investigation should determine which files were encrypted, where the keys were stored, whether the attacker accessed those keys, and whether usable copies existed elsewhere.

Good faith acquisition by an employee or agent for a legitimate business purpose falls outside the definition unless that person uses or discloses the information without authorization. Before relying on that exception, you should document the employee's authority, purpose, access, and treatment of the information.

Sensitive Personal Information

For breach notification purposes, Texas defines sensitive personal information more narrowly than many privacy laws define personal data. It includes a person's first name or first initial and last name combined with an unencrypted Social Security number, driver's license number, government identification number, or financial account number with the code or password required to access the account.

The definition also covers information that identifies someone and concerns physical or mental health, health care, or payment for health care. Lawfully available federal, state, and local government records fall outside the definition.

Names and email addresses alone may produce contractual, customer service, platform, or reputational consequences without triggering Chapter 521 consumer notice. You should compare every compromised field against the statutory definition before making the notice determination.

Notice to Affected Individuals

A person that conducts business in Texas and owns or licenses computerized data containing sensitive personal information must notify each individual whose information was, or reasonably appears to have been, acquired by an unauthorized person. Notice must proceed without unreasonable delay and generally no later than the 60th day after the person determines that the breach occurred.

Texas permits additional time when necessary to determine the breach's scope and restore reasonable system integrity. A law enforcement agency may also request a delay after determining that notice would impede a criminal investigation. Once the agency determines that notice won't compromise the investigation, the responsible person must proceed.

You should send notice as soon as reliable facts support it. Waiting until day 60 compresses regulator filings, customer support, credit monitoring, and notices required under other states' laws.

Notice from Vendors and Data Custodians

A different rule governs a vendor that maintains sensitive personal information owned by someone else. The vendor must notify the owner or license holder immediately after discovering a breach when an unauthorized person acquired the information or reasonably appears to have acquired it.

That notice begins the owner's response. The owner must determine whether consumer, Attorney General, consumer reporting agency, contractual, and out of state notices apply.

Vendor agreements can define a specific reporting period because immediately can become a point of dispute during an incident. A period of 48 to 72 hours after discovery, followed by continuing updates as the vendor confirms new facts, can leave the customer time to investigate and meet applicable deadlines. The contract can identify notice recipients and require evidence preservation, forensic cooperation, access to relevant findings, and assistance with consumer and regulator notices.

Notice to the Texas Attorney General

A breach involving at least 250 Texas residents requires an electronic report to the Texas Attorney General. The report is due as soon as practicable and no later than 30 days after determining that the breach occurred.

Your report must describe the breach and any use of the compromised information. It must also state how many Texas residents were affected, how many received direct notice, what measures you took, what measures you plan to take, and whether law enforcement is investigating.

Since September 1, 2023, covered organizations have submitted reports through the Attorney General's electronic reporting form. The Attorney General publishes a listing of reported breaches, and the completed form may qualify as an open record. You should maintain regulatory accuracy while protecting privileged analysis, sensitive security details, and unconfirmed conclusions.

The Attorney General report may come due before you finish the consumer notice process. Your filing should distinguish confirmed facts from reasonable estimates and identify information under investigation.

Notice to Consumer Reporting Agencies

A person required to notify more than 10,000 people at one time must also notify each nationwide consumer reporting agency that maintains consumer files. That notice must describe the timing, distribution, and content of the consumer notices, and it must proceed without unreasonable delay.

The threshold counts every person receiving notice at one time. It doesn't count Texas residents alone, so a national incident can trigger the requirement even when fewer than 10,000 Texans were affected.

Consumer Notice Content

Texas leaves much of the consumer letter's content to the sender. A useful notice explains what happened, when the incident occurred, when you discovered it, which information was involved, what you've done to investigate and contain the incident, what the recipient can do, and how the recipient can contact you.

If the incident involved Social Security numbers, driver's license numbers, or financial account information, you should address credit freezes, fraud alerts, account monitoring, credential replacement, and IdentityTheft.gov. Health information may bring additional duties under HIPAA, medical privacy statutes, insurance requirements, or contracts.

You should state confirmed facts with precision. Speculation can alarm customers and weaken your position, while vague language invites regulator questions and customer distrust.

Delivery Methods

Texas permits written notice at the individual's last known address. Electronic notice also qualifies when it complies with the federal electronic signature law, including any consent and disclosure requirements that apply to the recipient.

The statutory methods are written notice, compliant electronic notice, and qualifying substitute notice. A call center can answer questions after notice goes out, but a telephone call by itself lacks a statutory basis under Chapter 521.

A person may follow notification procedures maintained as part of an information security policy when those procedures satisfy Texas timing requirements. You should rely on that provision only if the policy covers the incident and identifies an authorized delivery method. The procedure must also predate the breach and operate in practice.

Substitute Notice

Substitute notice becomes available when direct notice would cost more than $250,000, more than 500,000 people were affected, or sufficient contact information isn't available. Under those conditions, Texas permits email notice when addresses are available, a conspicuous website posting, or publication or broadcast through major statewide media.

The statute treats those methods as alternatives. You may combine them when one method would leave many affected people uninformed.

Multistate Breaches

Every state and the District of Columbia has a breach notification statute. A national incident can produce different definitions, deadlines, regulator filings, notice contents, risk exceptions, and consumer reporting agency thresholds.

Texas allows an affected resident of another state to receive notice under that state's law or under Texas law. That flexibility applies to consumer notice under § 521.053(b). Another state's regulator filings, timing rules, and content requirements continue to apply.

Colorado, Florida, and New York can require consumer notice within 30 days, subject to their respective exceptions. New York's limit took effect on December 21, 2024, and permits delay for law enforcement needs. Texas also recognizes necessary work to determine scope and restore system integrity.

Teams handling multistate responses commonly organize the timetable around the earliest applicable deadline. A requirements chart can identify every affected jurisdiction, consumer due date, regulator filing, content rule, and available exception.

The Chapter 542 Cybersecurity Safe Harbor

Texas enacted a limited cybersecurity safe harbor through Senate Bill 2610, effective September 1, 2025. Chapter 542 applies to business entities in Texas with fewer than 250 employees that own or license computerized data containing sensitive personal information.

A qualifying business can avoid exemplary damages in a civil action arising from a security breach if it proves that it implemented and maintained a compliant cybersecurity program when the breach occurred. The protection applies to causes of action accruing on or after September 1, 2025.

Section 542.004 requires administrative, technical, and physical safeguards. Your program must protect covered information, address threats to its integrity, and address unauthorized access or acquisition that would produce a material risk of identity theft or fraud.

Employee count affects the requirements. A business with fewer than 20 employees receives simplified requirements that include password policies and appropriate employee cybersecurity training. A business with 20 to 99 employees must meet moderate requirements, including CIS Controls Implementation Group 1. A business with 100 to 249 employees must conform to a qualifying industry framework.

Qualifying frameworks include the NIST Cybersecurity Framework, NIST Special Publications 800-171 and 800-53, FedRAMP, CIS Controls, the ISO/IEC 27000 series, HITRUST, SOC 2, the Secure Controls Framework, and similar cybersecurity standards. Applicable programs under HIPAA, HITECH, the Gramm-Leach-Bliley Act, FISMA, or PCI DSS can also qualify.

A small business should document compliance with the baseline safeguards and its employee tier. Password policies and annual training establish part of the program, while the statutory defense depends on the complete program and evidence that the business maintained it when the breach occurred.

Chapter 542 limits exemplary damages. A plaintiff may continue to seek compensatory damages, and the Attorney General may continue to pursue Chapter 521 enforcement and injunctive relief. Existing causes of action and legal duties remain unchanged.

Incident Response Planning

Your incident response plan should identify who makes legal determinations, preserves evidence, contacts the insurer, retains forensic investigators, drafts notices, submits regulator filings, and communicates with customers. Each person should know who can authorize an investigation and who can speak for the business.

You should separate a security event from a legally reportable breach. Your team needs enough technical evidence to determine what information was involved, whether an unauthorized person acquired it, who owned it, which individuals were affected, and where they lived.

Vendor escalation deserves a separate procedure. A vendor that waits 30 days to notify you can consume the entire period available under another state's law. Your contracts should require prompt notice, continuing updates, evidence preservation, forensic cooperation, and allocation of response costs.

You should track the Texas Attorney General and consumer deadlines separately. The 30 day regulator filing may come due while you're finishing individual notices, and each submission must reflect the facts known at that point.

Cyber insurance can cover forensic services, legal fees, notices, call center services, credit monitoring, regulatory proceedings, and litigation defense. Confirmation before an incident establishes which expenses the policy covers, and a breach involving several thousand people can produce six figure incident costs before litigation begins.

This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.

Need advice tied to your business issue?

Share the issue. Get direct attorney review. Receive a concrete recommendation.

Submit an Inquiry