Texas Updates Data Breach Notification Requirements

Effective January 1, 2020, the Texas legislature will impose new notification requirements on businesses that maintain personal information of customers. House Bill 4390 amends the Texas Identity Theft Enforcement and Protection Act by requiring that Texas residents be notified of a data security breach within sixty (60) days of the determination that a breach has occurred. A "breach of system security" is defined as the "unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data." This Amendment marks a substantial departure from section 521.053(b) of the former law, which only required that businesses notify impacted individuals "as quickly as possible" − in effect allowing businesses greater flexibility in reporting a given data security incident.

Additionally, if a breach impacts more than 250 Texas residents, the business responsible for maintaining the sensitive personal information must provide notice of the incident to the Texas Attorney General within the same 60-day time period that governs notification of Texas residents. The notification to the Texas Attorney General must include the following information:

A detailed description of the breach or the use of sensitive information acquired during the breach The number of Texas residents affected Measures taken to date regarding the breach Any measures that will...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT