Texas Data Breach Notification Law

The Texas data breach notification law — part of the Texas Identity Theft Enforcement and Protection Act, in Chapter 521 of the Texas Business and Commerce Code — requires any business that owns or licenses computerized data containing sensitive personal information to notify affected individuals after a breach of that data, and to notify the Texas Attorney General when the breach reaches 250 Texas residents.

What Counts as Sensitive Personal Information

The obligation is triggered by a defined category of data, not by any loss of information. Sensitive personal information means an individual’s first name or first initial and last name in combination with a Social Security number, a driver’s license or government-issued identification number, or an account or card number together with the code that would permit access to that account. It separately covers information about an individual’s physical or mental health, the health care provided to them, or payment for that care.

A breach of a marketing list is not a notification event. A breach of a client file containing names alongside Social Security numbers is.

The Two Deadlines

Texas sets two clocks, and firms routinely conflate them:

  • Affected individuals must be notified without unreasonable delay and in each case no later than the 60th day after the date the business determines that the breach occurred.
  • The Texas Attorney General must be notified as soon as practicable and no later than the 30th day after that same determination, if the breach involves at least 250 Texas residents.

Both clocks run from the date the business determines a breach occurred, not from the date of the intrusion. That distinction decides whether a firm has a month or a weekend, and it rewards firms that can establish scope quickly.

The Attorney General Notification Is a Form, Not an Email

Since September 2023, notification to the Attorney General must be submitted electronically through the form on the Attorney General’s website. A letter or an email to a general inbox does not satisfy the requirement.

The form asks for a detailed description of the nature and circumstances of the breach, the number of Texas residents affected, the measures taken in response, any measures the business intends to take afterward, and whether law enforcement is engaged. A firm that has not tracked which records were exposed cannot complete it.

Breaches Become Public

The Attorney General maintains a public listing of reported breaches, updated within thirty days of receiving a notification and carried for one year. Reporting is therefore not a private regulatory exchange. For a professional firm whose clients search its name, the listing is a reputational event as much as a compliance one, which is another reason the response narrative in the form deserves care.

How It Interacts With Federal and Sector Rules

The Texas law applies alongside federal and sector rules, never instead of them. One incident at a DFW investment firm can trigger Texas notification, SEC Regulation S-P notification, and a contractual obligation to a custodian or institutional client, each with its own deadline and its own definition of what was compromised. An accounting firm may add the FTC Safeguards Rule reporting obligation on top.

The deadlines do not align, and the shortest one governs the pace of the whole response. An incident response plan that names only one regime will miss the others under pressure.

What Actually Slows Firms Down

The thirty days are rarely lost to drafting. They are lost to three questions: which systems were accessed, which records those systems held, and which of those records belonged to Texas residents. Firms that answer quickly have retained logs of sufficient duration, a data inventory that maps where sensitive personal information lives, and a retention practice that has already removed what is no longer needed.

Firms without those three spend the month reconstructing, and often over-notify because they cannot prove a narrower scope.

Why the Texas Breach Notification Law Matters for Investment & Professional Firms

For DFW investment and professional firms, the Texas law is a baseline obligation that applies regardless of industry or regulator. DKBinnovative has supported compliance-intensive firms since 2004 and builds incident response plans that map every applicable notification requirement — state, federal, and sector — with the logging and data inventory that make the deadlines achievable, for firms in Frisco, Plano, Irving, and Las Colinas.

Related DKBinnovative Resources

External references: Texas Attorney General — Data Breach Reporting · NIST Cybersecurity Framework

Sales & Support
(888) 352-4832