Texas Breach Notification Law: What It Means for Your Organization
If you conduct business in Texas and own or license computerized data that includes sensitive personal information, Texas law requires you to notify affected individuals after a breach without unreasonable delay and no later than 60 days after you determine the breach occurred. If at least 250 Texas residents are involved, you must also notify the Texas Attorney General within 30 days, using the Attorney General’s online form. If you notify more than 10,000 people at one time, you must also notify the nationwide consumer reporting agencies. The rules sit in Texas Business and Commerce Code Section 521.053. ALCON DTS can help you prepare before a breach and respond with clear records when something happens.
This page answers:
At a glance
- Requirement: Texas Business and Commerce Code Sec. 521.053, Notification Required Following Breach of Security of Computerized Data
- Who it applies to: A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information (Sec. 521.053(b)), plus anyone who maintains that data for someone else (Sec. 521.053(c))
- Individuals: Without unreasonable delay and no later than the 60th day after you determine the breach occurred (Sec. 521.053(b))
- Texas Attorney General: If at least 250 Texas residents are involved, as soon as practicable and no later than the 30th day after that determination, submitted electronically through the Attorney General’s website (Sec. 521.053(i))
- Consumer reporting agencies: If you notify more than 10,000 persons at one time, notify each nationwide consumer reporting agency without unreasonable delay (Sec. 521.053(h))
- Enforced by: the Texas Attorney General (Sec. 521.151)
- Official text: Texas Business and Commerce Code, Chapter 521
- Last reviewed: September 30, 2026
What is the Texas breach notification law?
Texas Business and Commerce Code Chapter 521, the Identity Theft Enforcement and Protection Act (Sec. 521.001), sets duties for businesses that handle sensitive personal information, including these two. The first is to protect it: a business must “implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information collected or maintained by the business in the regular course of business” (Sec. 521.052(a)). The second is to tell people when that protection fails. That is Section 521.053.
The law defines a “breach of system security” this way:
“unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data.” (Sec. 521.053(a))
Good faith acquisition by your own employee or agent for your purposes is not a breach, unless that person then uses or discloses the information in an unauthorized way (Sec. 521.053(a)).
The notice deadlines have changed over time. A 2019 amendment set the 60-day outer limit for notifying individuals and added the Attorney General notice. A 2021 amendment added more detail to the Attorney General notice and created the Attorney General’s public listing of reported breaches. The most recent amendment, Senate Bill 768 (effective September 1, 2023), shortened the Attorney General deadline from 60 days to 30 days and required reports to be filed electronically through the Attorney General’s website. As of September 30, 2026, no later amendment to Section 521.053 appears in the statute.
What does the law cover, and what doesn’t it?
It covers: sensitive personal information in computerized form. Under Sec. 521.002(a)(2), that means:
- a person’s first name or first initial and last name, together with a Social Security number, a driver’s license or government-issued ID number, or a financial account or card number with any code or password needed to access the account, if the name and those items are not encrypted, or
- information that identifies a person and relates to their physical or mental health or condition, the health care they receive, or payment for that care.
It is not:
- Limited to Texas residents. The duty in Sec. 521.053(b) runs to “any individual” whose sensitive personal information was, or is reasonably believed to have been, acquired. For residents of another state that has its own breach notice law, you may notify under that state’s law or under Texas law (Sec. 521.053(b-1)).
- About publicly available government records. Information lawfully made available to the public by a federal, state or local government is not sensitive personal information under Chapter 521 (Sec. 521.002(b)).
- Only about hackers. The definition turns on unauthorized acquisition of computerized data that compromises sensitive personal information, not on how the acquisition happened.
- Automatically avoided by encryption. Encrypted data can still be part of a breach if the person who took it also has the key (Sec. 521.053(a)).
Does the Texas breach notification law apply to you?
Section 521.053 places duties on two groups:
- Owners and licensees. A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information must notify affected individuals (Sec. 521.053(b)), and may also owe notice to the Attorney General and the consumer reporting agencies.
- Those who maintain data for others. A person who maintains computerized data that includes sensitive personal information it does not own must notify the owner or license holder “immediately after discovering the breach” (Sec. 521.053(c)). Service providers such as billing firms, payroll processors and IT providers often fall here.
Quick check: does this apply to you?
- You conduct business in Texas.
- You keep names together with Social Security numbers, driver’s license numbers, financial account or card details, or health information, in any electronic form: email, file storage, business applications, backups or devices.
If both are true, the Texas breach notification law very likely applies to you. The statute has no small-business exemption. Whether a particular incident is a “breach of system security,” and when you “determined” it occurred, are legal questions that depend on the facts. Confirm with your attorney.
What do you need to have in place?
The statute sets who you notify, by when and how. The table below brings those duties together.
| Who you notify | When it applies | Deadline | How and what |
|---|---|---|---|
| Affected individuals (Sec. 521.053(b)) | You own or license the data and a person’s sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person | Without unreasonable delay and no later than the 60th day after you determine the breach occurred | Written notice to the last known address, or electronic notice that meets the federal E-SIGN Act (15 U.S.C. 7001) (Sec. 521.053(e)) |
| The data owner (Sec. 521.053(c)) | You maintain the data for someone else | Immediately after discovering the breach | Notice to the owner or license holder of the information; ask your attorney whether an Attorney General report is also required (Sec. 521.053(i)) |
| Texas Attorney General (Sec. 521.053(i)) | The breach involves at least 250 Texas residents | As soon as practicable and no later than the 30th day after you determine the breach occurred | Electronic form on the Attorney General’s website, with the six items listed below |
| Nationwide consumer reporting agencies (Sec. 521.053(h)) | You must notify more than 10,000 persons at one time | Without unreasonable delay | Notice of the timing, distribution and content of the notices to individuals |
What does the Attorney General notice include?
The report must be submitted electronically using the form on the Attorney General’s website and must include (Sec. 521.053(i)):
- a detailed description of the nature and circumstances of the breach, or the use of sensitive personal information acquired in it,
- the number of Texas residents affected at the time of notification,
- the number of affected residents who have been sent notice by mail or another direct method at the time of notification,
- the measures you have taken regarding the breach,
- any measures you intend to take after the notification, and
- whether law enforcement is investigating the breach.
The Attorney General’s reporting page adds practical points. The form cannot be saved, so plan to complete it in one sitting. Submit a separate report for each breach. If you update an earlier report, the new one should show the total number of affected and notified people to date. Your completed report is potentially an open record. The Attorney General also posts a public listing of reported breaches, without sensitive personal information or details that could compromise a system’s security, and removes a listing after one year if no additional breach is reported in that time (Sec. 521.053(j)).
Can the deadline be delayed?
Two situations are written into the law:
- Law enforcement request. You may delay notice under Sec. 521.053(b) or (c) at the request of a law enforcement agency that determines the notice will impede a criminal investigation. Notice is then made as soon as the agency determines it will not compromise the investigation (Sec. 521.053(d)). Subsection (d) refers only to the notices under (b) and (c). It does not mention the Attorney General notice under Sec. 521.053(i), so talk with your attorney before assuming the 30-day Attorney General deadline is paused.
- Scope and restoration. The 60-day notice to individuals allows for the time “necessary to determine the scope of the breach and restore the reasonable integrity of the data system” (Sec. 521.053(b)).
Neither exception gives a set number of extra days, and the scope-and-restoration language appears only in the 60-day individual notice rule, not in the 30-day Attorney General rule. Talk with your attorney before relying on either one.
What if you cannot reach everyone directly?
If you can show that direct notice would cost more than $250,000, that more than 500,000 people are affected, or that you do not have enough contact information, the law allows notice by email where you have addresses, a conspicuous posting on your website, or notice published in or broadcast on major statewide media (Sec. 521.053(f)). If your information security policy includes your own notification procedures that meet the statute’s timing, notifying under that policy complies with the section (Sec. 521.053(g)).
What happens if notice is late?
The Texas Attorney General enforces Chapter 521 and can seek civil penalties, including for failing to give notice on time, as well as injunctions (Sec. 521.151). Ask your attorney what that could mean for your organization.
What should you prepare before a breach?
The statute sets deadlines, and meeting them is much easier with a few things decided in advance:
- Know where sensitive personal information lives. Email, file storage, business applications, backups, laptops and phones.
- Know which data you own and which you maintain for others. That decides whether you notify individuals or notify the owner.
- Keep logs and records. You will need to establish what was accessed, when and how many people are affected.
- Write a response plan. Name who decides, who calls your attorney and insurer, and who gathers the facts for the Attorney General form.
- Keep contact information current so direct notice is possible.
- Review your vendor contracts so service providers that hold your data know to tell you right away.
How can ALCON DTS help you?
You keep the compliance decisions. We run the controls. Deciding whether an incident is a breach, who must be notified and what the notices say stays with you and your attorney. ALCON DTS can help you reduce the chance of a breach, spot one sooner, and have the facts ready when your attorney, insurer or the Attorney General asks.
| Breach notification need | What ALCON DTS provides |
|---|---|
| Knowing where sensitive information lives | A review of identity and access, email, devices, file storage, backups and vendor access |
| Reasonable procedures to protect data (Sec. 521.052(a)) | Identity and access with multifactor authentication and tight administrator rights; email authentication and mailbox controls; devices kept updated, protected and encrypted |
| Spotting an incident early | Monitoring that routes alerts to a named owner who can act |
| Responding when something happens | When an alert fires, ALCON DTS opens a ticket, contacts your named owner and works the issue with you until it is back under control. |
| Facts for your notices and the Attorney General form | Logging and backups, so you know what is logged, what is backed up and who can restore |
| Restoring your systems | Tested backup and recovery |
| People and access changes | Joiner, mover and leaver changes handled promptly, plus guest and vendor access kept under control |
| Written procedures | Written procedures and an organized evidence file you can share with your attorney or insurer |
The exact controls in your environment depend on your ALCON DTS plan and any project work, and we will show you which are in place today and which would close a gap. ALCON DTS does not provide legal advice and does not send breach notices on your behalf.
Want to know how ready you are for a breach? We will look at where your sensitive information lives, what is logged and backed up, and who would get the call.
How does Texas breach notification fit with other rules?
- HIPAA Breach Notification Rule (45 CFR 164.400 to 164.414). If you are a HIPAA covered entity, a breach of unsecured protected health information has its own federal notice duties: individuals without unreasonable delay and no later than 60 calendar days after discovery (164.404), prominent media outlets if more than 500 residents of a state are involved (164.406), and the HHS Secretary, at the same time as individual notice for 500 or more people or within 60 days after the end of the calendar year for fewer than 500 (164.408). Business associates notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery (164.410). Health information that identifies a person is also sensitive personal information under Texas law (Sec. 521.002(a)(2)(B)), and Section 521.053 does not include an exemption for HIPAA covered entities, and a HIPAA notice does not replace the separate 30-day Texas Attorney General report when at least 250 Texas residents are involved, so review both with your attorney after an incident.
- Texas Cybersecurity Safe Harbor (SB 2610, Bus. and Com. Code Ch. 542). Texas business entities with fewer than 250 employees that own or license computerized data that includes sensitive personal information (Sec. 542.002) can qualify for a defense against exemplary damages in a breach lawsuit by maintaining a qualifying cybersecurity program. The safe harbor uses the same definition of breach as Section 521.053 (Sec. 542.001). It does not change your notice duties. See Texas SB 2610 Cybersecurity Safe Harbor.
- Texas medical records privacy law (Texas Health and Safety Code Ch. 181). If you handle protected health information in Texas, Chapter 181 adds state duties such as workforce training on privacy law and, for electronic disclosures, notice to individuals and, in many cases, a separate authorization for each disclosure. Talk with your attorney about how it applies to you.
- Contracts and cyber insurance. Customer contracts, business associate agreements and insurance policies can set their own reporting deadlines. Check them alongside the statute.
- Regulatory Compliance. Program support for the Texas and federal rules your organization answers to.
Frequently asked questions
How long do you have to notify people after a breach in Texas?
When do you have to notify the Texas Attorney General?
Did the Attorney General deadline change?
When do you have to notify the consumer reporting agencies?
Do you have to notify people who live outside Texas?
What if a vendor that holds your data has the breach?
Does encryption mean you do not have to notify?
Is your Attorney General report public?
Sources
- Texas Business and Commerce Code, Chapter 521, Unauthorized Use of Identifying Information, including Secs. 521.002, 521.052, 521.053 and 521.151 (Texas Constitution and Statutes)
- Senate Bill 768, 88th Legislature, enrolled version (Texas Legislature Online)
- House Bill 3746, 87th Legislature, enrolled version (Texas Legislature Online)
- House Bill 4390, 86th Legislature, enrolled version (Texas Legislature Online)
- Data Breach Reporting (Office of the Texas Attorney General)
- Texas Business and Commerce Code, Chapter 542, Cybersecurity Program (Texas Constitution and Statutes)
- Texas Health and Safety Code, Chapter 181, Medical Records Privacy (Texas Constitution and Statutes)
- 45 CFR Part 164, Subpart D, Notification in the Case of Breach of Unsecured Protected Health Information (eCFR)
Last reviewed: September 30, 2026
This page is general information about Texas breach notification law and related rules, not legal advice for your situation.
Talk with ALCON DTS about breach readiness
Not sure what you would do in the first hour of a breach, or whether you could answer the Attorney General’s questions in 30 days? We will walk through where your sensitive information lives, what you can see today and what would close the gaps.
Email: info@alcondts.com · Phone: 512-892-6900

