Skip to content

Texas Data Breach Notification Law: Who You Must Tell, and How Fast

By Donovan Brown
September 9, 2026
10 sections
Code on a dark monitor — cybersecurity threat surface
Photo: Markus Spiske on Unsplash
01

Introduction

LAYERLOGIX Texas Data BreachNotification Law: WhoYou Must Tell, and How… Texas managed IT & cybersecurity

Something moved through the file server that shouldn’t have. Containment starts immediately — but the moment you know what actually left the building, a second clock starts, written into Chapter 521 of the Business & Commerce Code.

Texas breach notification is governed by Business & Commerce Code § 521.053. Notify affected individuals without unreasonable delay and no later than the 60th day after you determine the breach occurred. If at least 250 Texas residents are affected, also notify the Texas Attorney General electronically by the 30th day after that same determination date.

02

Who You Must Notify, and By When

Who you must notifyWhat triggers itDeadline
Affected individualsSensitive personal information you own or license was, or is reasonably believed to have been, acquired by an unauthorized person (§ 521.053(b))Without unreasonable delay, and not later than the 60th day after you determine the breach occurred
Texas Attorney GeneralYou owe individual notice and at least 250 Texas residents are involved (§ 521.053(i))As soon as practicable, and not later than the 30th day after that determination
The data owner or license holderYou maintain data containing sensitive personal information you do not own (§ 521.053(c))Immediately after discovering the breach — no day count
Nationwide consumer reporting agenciesYou must notify more than 10,000 persons at one time (§ 521.053(h))Report the timing, distribution, and content of the notices
03

Read the Trigger Language Carefully

Both clocks run from “the date on which the person determines that the breach occurred” — the exact phrasing in § 521.053(b) and § 521.053(i). Determination is not discovery, and the gap is usually days or weeks of forensics. Document the date you determined it, and how. The statute uses the other word once: § 521.053(c), the duty you owe holding someone else’s data, runs from discovering the breach.

The 60-day individual deadline took effect January 1, 2020 under H.B. 4390, which struck the old standard of “as quickly as possible.” The 30-day Attorney General deadline took effect September 1, 2023 under S.B. 768, halving a prior 60 days. If your incident response plan still gives you 60 days to reach the AG, it was written against superseded law.

04

What Counts as a Breach, and Where Encryption Helps

Section 521.053(a) defines “breach of system security” as unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information. Good-faith internal access is carved out: acquisition by an employee or agent for the person’s own purposes is excluded, unless that person then uses or discloses it in an unauthorized manner. An engineer pulling a customer table to debug an export job is not reportable. The same engineer emailing it to a personal account is.

The encryption safe harbor lives in the definition, not the notice section. Under § 521.002(a)(2)(A), sensitive personal information means a first name or initial and last name combined with a Social Security number, a driver’s license or government-issued ID number, or an account or card number plus the code permitting account access — if the name and the items are not encrypted. Encrypted, the data falls outside the definition.

Two limits before you lean on that. Section 521.053(a) pulls encrypted data back in when the attacker also holds the decryption key — a stolen laptop with full-disk encryption is a very different posture from a compromised admin account that could decrypt at will. And that qualifier sits only in subparagraph (A); subparagraph (B), covering health information, carries none.

05

The Attorney General Notice Has Six Required Contents

Since September 1, 2023, § 521.053(i) requires the AG notification to be submitted electronically on a form accessed through the Attorney General’s website. It must include:

  • A detailed description of the nature and circumstances of the breach, or of the use of the information acquired
  • The number of Texas residents affected at the time of notification
  • The number already sent a disclosure by mail or other direct method at the time of notification
  • The measures you have taken regarding the breach
  • Any measures you intend to take after this notification
  • Whether law enforcement is investigating

That third item was added by H.B. 3746 effective September 1, 2021. It quietly rewards organizations that start individual notice early rather than batching everything at day 59. Assume the filing goes public: § 521.053(j) requires the Attorney General to post a listing showing entity name, the types of information affected, the number of Texans affected, and whether consumers were notified.

06

Out-of-State Residents, and How Notice Gets Delivered

Section 521.053(b) imposes the duty as to any individual whose information was acquired, with no limitation to Texas residents — S.B. 1610 removed the old residency limitation effective June 14, 2013. Under subsection (b-1), if the individual resides in a state that requires breach notice, you may notify under that state’s law or under subsection (b). For a Houston company with customers in four states, the analysis is per-resident.

Section 521.053(e) permits written notice to the last known address or electronic notice consistent with 15 U.S.C. § 7001. Substitute notice under subsection (f) — email, website posting, or major statewide media — opens up only if notice would cost more than $250,000, affected persons exceed 500,000, or you lack contact information. Subsection (g) lets you follow your own notification procedures, but only if they meet this section’s timing.

07

What Missing the Deadline Costs

Under § 521.151(a), a person who violates the chapter is liable to the state for a civil penalty of at least $2,000 and not more than $50,000 per violation, attaching to any provision of Chapter 521. Section 521.151(a-1) then adds up to $100 for each individual to whom notification is due, for each consecutive day you fail to take reasonable action to comply with § 521.053(b), capped at $250,000 per breach. The Attorney General may also seek an injunction and recover attorney’s fees, court costs, and investigatory costs.

08

What to Do in the First Days

  • Start a determination log the moment you suspect unauthorized acquisition — timestamps, who knew what, and what evidence supported it.
  • Get a per-state resident count early — the 250-Texan threshold and subsection (b-1) both turn on it.
  • Confirm whether encryption keys were reachable from the compromised account — that one fact can change the notice analysis.
  • Preserve logs before remediation overwrites them — restoring integrity and preserving evidence pull against each other unless someone directs traffic.

Our incident response work splits the same way — containment on one track, the determination record and notification math on the other. If ransomware is the vector, our first 72 hours guide and ransomware recovery practice cover the operational side; a security assessment finds where this data lives beforehand. Texas obligations don’t stop at Chapter 521 — see our notes on the TDPSA. This is educational material, not legal advice, so confirm how it applies with your own counsel.

10

Frequently Asked Questions

How long do I have to notify individuals after a data breach in Texas?

Under Tex. Bus. & Com. Code § 521.053(b), disclosure is due without unreasonable delay and not later than the 60th day after the date you determine the breach occurred. Subsection (d) allows delay at law enforcement’s request, and subsection (b) allows the time needed to determine the breach’s scope and restore the system’s reasonable integrity.

When do I have to report a breach to the Texas Attorney General?

Only if the breach involves at least 250 residents of Texas. Under § 521.053(i), notice is due as soon as practicable and not later than the 30th day after the date you determine the breach occurred, submitted electronically through a form on the Attorney General’s website.

Does encryption exempt us from Texas breach notification?

Often, but not always. Section 521.002(a)(2)(A) defines the name-plus-identifier category only where the name and items are not encrypted. But § 521.053(a) includes encrypted data if the person accessing it has the decryption key, and that qualifier does not appear in the health information definition at § 521.002(a)(2)(B).

What if we only host the data for another company?

Section 521.053(c) applies a stricter standard. A person maintaining computerized data containing sensitive personal information they do not own must notify the owner or license holder immediately after discovering the breach, if it was or is reasonably believed to have been acquired by an unauthorized person. There is no day count.

If you are working through a live incident, or want the determination log and notification workflow written down before you need it, our incident response practice covers both. See the full range of our cybersecurity services for what sits around it.

Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call