Texas Breach Notification Law: What It Means for Your Organization

If you conduct business in Texas and own or license computerized data that includes sensitive personal information, Texas law requires you to notify affected individuals after a breach without unreasonable delay and no later than 60 days after you determine the breach occurred. If at least 250 Texas residents are involved, you must also notify the Texas Attorney General within 30 days, using the Attorney General’s online form. If you notify more than 10,000 people at one time, you must also notify the nationwide consumer reporting agencies. The rules sit in Texas Business and Commerce Code Section 521.053. ALCON DTS can help you prepare before a breach and respond with clear records when something happens.

Talk with ALCON DTSSee what you need in place

At a glance

  • Requirement: Texas Business and Commerce Code Sec. 521.053, Notification Required Following Breach of Security of Computerized Data
  • Who it applies to: A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information (Sec. 521.053(b)), plus anyone who maintains that data for someone else (Sec. 521.053(c))
  • Individuals: Without unreasonable delay and no later than the 60th day after you determine the breach occurred (Sec. 521.053(b))
  • Texas Attorney General: If at least 250 Texas residents are involved, as soon as practicable and no later than the 30th day after that determination, submitted electronically through the Attorney General’s website (Sec. 521.053(i))
  • Consumer reporting agencies: If you notify more than 10,000 persons at one time, notify each nationwide consumer reporting agency without unreasonable delay (Sec. 521.053(h))
  • Enforced by: the Texas Attorney General (Sec. 521.151)
  • Official text: Texas Business and Commerce Code, Chapter 521
  • Last reviewed: September 30, 2026

What is the Texas breach notification law?

Texas Business and Commerce Code Chapter 521, the Identity Theft Enforcement and Protection Act (Sec. 521.001), sets duties for businesses that handle sensitive personal information, including these two. The first is to protect it: a business must “implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information collected or maintained by the business in the regular course of business” (Sec. 521.052(a)). The second is to tell people when that protection fails. That is Section 521.053.

The law defines a “breach of system security” this way:

“unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data.” (Sec. 521.053(a))

Good faith acquisition by your own employee or agent for your purposes is not a breach, unless that person then uses or discloses the information in an unauthorized way (Sec. 521.053(a)).

The notice deadlines have changed over time. A 2019 amendment set the 60-day outer limit for notifying individuals and added the Attorney General notice. A 2021 amendment added more detail to the Attorney General notice and created the Attorney General’s public listing of reported breaches. The most recent amendment, Senate Bill 768 (effective September 1, 2023), shortened the Attorney General deadline from 60 days to 30 days and required reports to be filed electronically through the Attorney General’s website. As of September 30, 2026, no later amendment to Section 521.053 appears in the statute.

What does the law cover, and what doesn’t it?

It covers: sensitive personal information in computerized form. Under Sec. 521.002(a)(2), that means:

  • a person’s first name or first initial and last name, together with a Social Security number, a driver’s license or government-issued ID number, or a financial account or card number with any code or password needed to access the account, if the name and those items are not encrypted, or
  • information that identifies a person and relates to their physical or mental health or condition, the health care they receive, or payment for that care.

It is not:

  • Limited to Texas residents. The duty in Sec. 521.053(b) runs to “any individual” whose sensitive personal information was, or is reasonably believed to have been, acquired. For residents of another state that has its own breach notice law, you may notify under that state’s law or under Texas law (Sec. 521.053(b-1)).
  • About publicly available government records. Information lawfully made available to the public by a federal, state or local government is not sensitive personal information under Chapter 521 (Sec. 521.002(b)).
  • Only about hackers. The definition turns on unauthorized acquisition of computerized data that compromises sensitive personal information, not on how the acquisition happened.
  • Automatically avoided by encryption. Encrypted data can still be part of a breach if the person who took it also has the key (Sec. 521.053(a)).

Does the Texas breach notification law apply to you?

Section 521.053 places duties on two groups:

  1. Owners and licensees. A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information must notify affected individuals (Sec. 521.053(b)), and may also owe notice to the Attorney General and the consumer reporting agencies.
  2. Those who maintain data for others. A person who maintains computerized data that includes sensitive personal information it does not own must notify the owner or license holder “immediately after discovering the breach” (Sec. 521.053(c)). Service providers such as billing firms, payroll processors and IT providers often fall here.

Quick check: does this apply to you?

  • You conduct business in Texas.
  • You keep names together with Social Security numbers, driver’s license numbers, financial account or card details, or health information, in any electronic form: email, file storage, business applications, backups or devices.

If both are true, the Texas breach notification law very likely applies to you. The statute has no small-business exemption. Whether a particular incident is a “breach of system security,” and when you “determined” it occurred, are legal questions that depend on the facts. Confirm with your attorney.

What do you need to have in place?

The statute sets who you notify, by when and how. The table below brings those duties together.

Duties and deadlines from Texas Business and Commerce Code Sec. 521.053, as amended through Senate Bill 768 (2023). Review how they apply to a specific incident with your attorney.
Who you notify When it applies Deadline How and what
Affected individuals (Sec. 521.053(b)) You own or license the data and a person’s sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person Without unreasonable delay and no later than the 60th day after you determine the breach occurred Written notice to the last known address, or electronic notice that meets the federal E-SIGN Act (15 U.S.C. 7001) (Sec. 521.053(e))
The data owner (Sec. 521.053(c)) You maintain the data for someone else Immediately after discovering the breach Notice to the owner or license holder of the information; ask your attorney whether an Attorney General report is also required (Sec. 521.053(i))
Texas Attorney General (Sec. 521.053(i)) The breach involves at least 250 Texas residents As soon as practicable and no later than the 30th day after you determine the breach occurred Electronic form on the Attorney General’s website, with the six items listed below
Nationwide consumer reporting agencies (Sec. 521.053(h)) You must notify more than 10,000 persons at one time Without unreasonable delay Notice of the timing, distribution and content of the notices to individuals

What does the Attorney General notice include?

The report must be submitted electronically using the form on the Attorney General’s website and must include (Sec. 521.053(i)):

  1. a detailed description of the nature and circumstances of the breach, or the use of sensitive personal information acquired in it,
  2. the number of Texas residents affected at the time of notification,
  3. the number of affected residents who have been sent notice by mail or another direct method at the time of notification,
  4. the measures you have taken regarding the breach,
  5. any measures you intend to take after the notification, and
  6. whether law enforcement is investigating the breach.

The Attorney General’s reporting page adds practical points. The form cannot be saved, so plan to complete it in one sitting. Submit a separate report for each breach. If you update an earlier report, the new one should show the total number of affected and notified people to date. Your completed report is potentially an open record. The Attorney General also posts a public listing of reported breaches, without sensitive personal information or details that could compromise a system’s security, and removes a listing after one year if no additional breach is reported in that time (Sec. 521.053(j)).

Can the deadline be delayed?

Two situations are written into the law:

  • Law enforcement request. You may delay notice under Sec. 521.053(b) or (c) at the request of a law enforcement agency that determines the notice will impede a criminal investigation. Notice is then made as soon as the agency determines it will not compromise the investigation (Sec. 521.053(d)). Subsection (d) refers only to the notices under (b) and (c). It does not mention the Attorney General notice under Sec. 521.053(i), so talk with your attorney before assuming the 30-day Attorney General deadline is paused.
  • Scope and restoration. The 60-day notice to individuals allows for the time “necessary to determine the scope of the breach and restore the reasonable integrity of the data system” (Sec. 521.053(b)).

Neither exception gives a set number of extra days, and the scope-and-restoration language appears only in the 60-day individual notice rule, not in the 30-day Attorney General rule. Talk with your attorney before relying on either one.

What if you cannot reach everyone directly?

If you can show that direct notice would cost more than $250,000, that more than 500,000 people are affected, or that you do not have enough contact information, the law allows notice by email where you have addresses, a conspicuous posting on your website, or notice published in or broadcast on major statewide media (Sec. 521.053(f)). If your information security policy includes your own notification procedures that meet the statute’s timing, notifying under that policy complies with the section (Sec. 521.053(g)).

What happens if notice is late?

The Texas Attorney General enforces Chapter 521 and can seek civil penalties, including for failing to give notice on time, as well as injunctions (Sec. 521.151). Ask your attorney what that could mean for your organization.

What should you prepare before a breach?

The statute sets deadlines, and meeting them is much easier with a few things decided in advance:

  • Know where sensitive personal information lives. Email, file storage, business applications, backups, laptops and phones.
  • Know which data you own and which you maintain for others. That decides whether you notify individuals or notify the owner.
  • Keep logs and records. You will need to establish what was accessed, when and how many people are affected.
  • Write a response plan. Name who decides, who calls your attorney and insurer, and who gathers the facts for the Attorney General form.
  • Keep contact information current so direct notice is possible.
  • Review your vendor contracts so service providers that hold your data know to tell you right away.

How can ALCON DTS help you?

You keep the compliance decisions. We run the controls. Deciding whether an incident is a breach, who must be notified and what the notices say stays with you and your attorney. ALCON DTS can help you reduce the chance of a breach, spot one sooner, and have the facts ready when your attorney, insurer or the Attorney General asks.

Breach notification need What ALCON DTS provides
Knowing where sensitive information lives A review of identity and access, email, devices, file storage, backups and vendor access
Reasonable procedures to protect data (Sec. 521.052(a)) Identity and access with multifactor authentication and tight administrator rights; email authentication and mailbox controls; devices kept updated, protected and encrypted
Spotting an incident early Monitoring that routes alerts to a named owner who can act
Responding when something happens When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control.
Facts for your notices and the Attorney General form Logging and backups, so you know what is logged, what is backed up and who can restore
Restoring your systems Tested backup and recovery
People and access changes Joiner, mover and leaver changes handled promptly, plus guest and vendor access kept under control
Written procedures Written procedures and an organized evidence file you can share with your attorney or insurer

The exact controls in your environment depend on your ALCON DTS plan and any project work, and we will show you which are in place today and which would close a gap. ALCON DTS does not provide legal advice and does not send breach notices on your behalf.

Want to know how ready you are for a breach? We will look at where your sensitive information lives, what is logged and backed up, and who would get the call.

Talk with ALCON DTS

How does Texas breach notification fit with other rules?

  • HIPAA Breach Notification Rule (45 CFR 164.400 to 164.414). If you are a HIPAA covered entity, a breach of unsecured protected health information has its own federal notice duties: individuals without unreasonable delay and no later than 60 calendar days after discovery (164.404), prominent media outlets if more than 500 residents of a state are involved (164.406), and the HHS Secretary, at the same time as individual notice for 500 or more people or within 60 days after the end of the calendar year for fewer than 500 (164.408). Business associates notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery (164.410). Health information that identifies a person is also sensitive personal information under Texas law (Sec. 521.002(a)(2)(B)), and Section 521.053 does not include an exemption for HIPAA covered entities, and a HIPAA notice does not replace the separate 30-day Texas Attorney General report when at least 250 Texas residents are involved, so review both with your attorney after an incident.
  • Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). Texas business entities with fewer than 250 employees that own or license computerized data that includes sensitive personal information (Sec. 542.002) can qualify for a defense against exemplary damages in a breach lawsuit by maintaining a qualifying cybersecurity program. The safe harbor uses the same definition of breach as Section 521.053 (Sec. 542.001). It does not change your notice duties. See Texas SB 2610 Cybersecurity Safe Harbor.
  • Texas medical records privacy law (Texas Health and Safety Code Ch. 181). If you handle protected health information in Texas, Chapter 181 adds state duties such as workforce training on privacy law and, for electronic disclosures, notice to individuals and, in many cases, a separate authorization for each disclosure. Talk with your attorney about how it applies to you.
  • Contracts and cyber insurance. Customer contracts, business associate agreements and insurance policies can set their own reporting deadlines. Check them alongside the statute.
  • Regulatory Compliance. Program support for the Texas and federal rules your organization answers to.

Frequently asked questions

Without unreasonable delay and no later than the 60th day after you determine the breach occurred (Sec. 521.053(b)). A law enforcement request can delay notice (Sec. 521.053(d)).

When a breach involves at least 250 Texas residents. The statute makes the report due as soon as practicable and no later than the 30th day after you determine the breach occurred, using the electronic form on the Attorney General’s website (Sec. 521.053(i)). The Attorney General’s reporting page describes the deadline as 30 days after “the discovery of the breach.” The statute’s wording controls, but because discovery can come before a determination, planning to file within 30 days of discovery keeps you inside both readings. Confirm the timing for your incident with your attorney.

Yes. Senate Bill 768 shortened it from 60 days to 30 days and required electronic filing, effective September 1, 2023.

When you must notify more than 10,000 persons at one time. You notify each nationwide consumer reporting agency of the timing, distribution and content of the notices, without unreasonable delay (Sec. 521.053(h)).

The Texas duty covers any individual whose sensitive personal information was acquired. For residents of a state with its own breach notice law, you may notify under that state’s law or under Texas law (Sec. 521.053(b-1)).

A person that maintains sensitive personal information for someone else must notify the owner immediately after discovering the breach (Sec. 521.053(c)). As the owner, you then have the notice duties to individuals and, where the thresholds are met, the Attorney General and the consumer reporting agencies. The Attorney General notice applies to any person “required to disclose or provide notification of a breach … under this section,” so a vendor should also ask its attorney whether it owes a report.

Not always. Names with the listed identifiers count only if they are not encrypted (Sec. 521.002(a)(2)(A)), but encrypted data is still part of a breach if the person who took it has the key (Sec. 521.053(a)). The health-related category in Sec. 521.002(a)(2)(B) does not include the “not encrypted” condition that applies to names with the listed identifiers. The statute does not define “encrypted,” and whether encrypted data was compromised depends on the facts, including who had the key. Ask your attorney how this applies to your incident.

The Attorney General’s reporting page says a completed report is potentially an open record. The Attorney General also posts a public listing of reported breaches, without sensitive personal information (Sec. 521.053(j)).

Sources

Last reviewed: September 30, 2026

This page is general information about Texas breach notification law and related rules, not legal advice for your situation.

Talk with ALCON DTS about breach readiness

Not sure what you would do in the first hour of a breach, or whether you could answer the Attorney General’s questions in 30 days? We will walk through where your sensitive information lives, what you can see today and what would close the gaps.

Email: info@alcondts.com · Phone: 512-892-6900

Talk with ALCON DTS