Texas
Texas Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 13 primary sources cited on this page. How we verify our legal content

Texas requires businesses to notify affected individuals of a data breach without unreasonable delay and no later than 60 days after determining one occurred under Tex. Bus. & Com. Code 521.053. Breaches affecting 250 or more Texas residents also require notice to the Attorney General within 30 days.
Texas operates one of the most actively enforced data breach notification frameworks in the country. The state's breach notification law, part of the Identity Theft Enforcement and Protection Act, requires businesses to notify affected Texans and, in many cases, the Attorney General after a security incident exposes sensitive personal information.
What sets Texas apart from most states is the dual-timeline structure. Businesses face a 60-day deadline for individual notifications and a shorter 30-day deadline for reporting to the AG. Combined with an attorney general's office that has secured more than $2.7 billion in privacy-related settlements since 2022, these reporting rules carry real consequences for non-compliance.
This article breaks down the full notification framework, including who must report, what triggers the obligation, how penalties work, and what defenses are available under Texas law.
Who Must Comply With Texas Breach Notification Law
The notification obligation under Section 521.053 applies to any person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. The statute does not define "conducts business" narrowly, meaning out-of-state companies that handle data belonging to Texas residents are subject to the law.
State agencies and local governments face additional requirements under Government Code Section 2063.302. A state agency or local government that owns computerized data containing sensitive personal information must comply with Section 521.053 and must also notify the Texas Cyber Command within 48 hours after discovering a cybersecurity incident, or notify the secretary of state instead when election data is involved. A follow-up report analyzing the cause is due by the 10th business day after eradication, closure, and recovery.
That section carries the duty that used to sit in Government Code Section 2054.1125. It was transferred and redesignated out of Chapter 2054 effective September 1, 2023, and redesignated again effective September 1, 2025, so guidance still pointing to Section 2054.1125 or to the Department of Information Resources as the recipient is out of date.
Section 2063.302(c) carves out one case: an incident a local government is required to report to an independent organization certified under Utilities Code Section 39.151 is exempt from this notification duty.
Third-party data custodians have a separate obligation. Under Section 521.053(c), any person who maintains data that it does not own must notify the data owner immediately after discovering a breach. The 60-day clock then starts for the owner, not the custodian.
What Qualifies as a Breach Under Texas Law
A "breach of system security" is defined under Section 521.053(a) as the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person.
The key word is "acquisition." Unauthorized access alone may not trigger the notification requirement. Texas requires that data was actually acquired, not merely accessed or viewed, in a way that compromises its security.
One important caveat: even encrypted data can qualify as a breach if the unauthorized person also obtained the encryption key. The statute explicitly includes "data that is encrypted if the person accessing the data has the key required to decrypt the data."
What Data Triggers the Notification Obligation
Section 521.002 defines "sensitive personal information" in two categories.
Category One: Name Plus Identifier
An individual's first name (or first initial) and last name combined with one or more of the following unencrypted elements:
- Social Security number
- Driver's license number or government-issued identification number
- Account number, credit card number, or debit card number combined with any required security code, access code, or password that would permit access to the individual's financial account
Category Two: Health Information
Information that identifies an individual and relates to:
- The individual's physical or mental health condition
- The provision of health care to the individual
- Payment for health care provided to the individual
What Is Excluded
Sensitive personal information does not include publicly available information that is lawfully made available to the public from the federal government or a state or local government.
The Encryption Safe Harbor
Texas provides a meaningful encryption safe harbor. The definition of sensitive personal information under Section 521.002 reaches the listed name-plus-identifier combination only "if the name and the items are not encrypted," so encrypted data falls outside the definition. If the compromised data was properly encrypted and the encryption key was not also acquired, the notification obligation does not apply.
This safe harbor has limits. The encryption must have been in place at the time of the breach. Businesses cannot encrypt data after the fact and claim the exemption. And if an attacker obtains both the encrypted data and the decryption key, the safe harbor vanishes.
Dual-Timeline Notification Requirements

Texas is one of a handful of states that impose separate deadlines for individual and government notification, with the government deadline being shorter.
60-Day Deadline: Individual Notification
Under Section 521.053(b), a business must disclose the breach to each affected individual "without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred."
The clock starts when the business determines a breach occurred, not when it first suspects one. However, the "without unreasonable delay" language means that a business cannot deliberately slow its investigation to push notifications closer to the 60-day limit.
30-Day Deadline: Attorney General Notification
Under Section 521.053(i), when a breach affects 250 or more Texas residents, the business must notify the Texas Attorney General "as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred."
Effective September 1, 2023 (following SB 768), all AG notifications must be submitted electronically through the AG's official Data Breach Report form. The report must include:
- A detailed description of the nature and circumstances of the breach
- The number of Texas residents affected at the time of notification
- The number of affected residents who have already been sent direct notification
- Measures taken in response to the breach
- Measures the business intends to take after notification
- Whether law enforcement is investigating the breach
The AG publishes reported breaches on a publicly accessible website, creating both transparency and reputational incentive for compliance.
Methods of Notification
Section 521.053(e) permits several notification methods:
- Written notice sent to the individual's last known address
- Electronic notice that complies with the federal Electronic Signatures in Global and National Commerce Act (E-SIGN Act)
- Alternative notice under the substitute notification rules
Substitute Notification
Section 521.053(f) allows substitute notification when:
- The cost of direct notification would exceed $250,000
- The number of affected persons exceeds 500,000
- The business lacks sufficient contact information for direct notification
Substitute notification may be given by any of the following methods: email notification where the business has an email address on file, conspicuous posting on the business's website, or publication in or broadcast through major statewide media. The statute lists these disjunctively, so any one method satisfies the substitute notice requirement.
Consumer Reporting Agency Notice
Under Section 521.053(h), when a breach requires notification to more than 10,000 individuals at one time, the business must also notify all nationwide consumer reporting agencies (the three major credit bureaus) of the timing, distribution, and content of the notification sent to individuals.
Law Enforcement Delay
Section 521.053(d) permits a delay in notification if a law enforcement agency determines that the notification would impede a criminal investigation. The notification must be made as soon as the law enforcement agency determines it will no longer interfere with the investigation.
Penalties and Enforcement

Texas enforces breach notification requirements through civil penalties, injunctions, and cost recovery that the Attorney General pursues under Chapter 521 itself.
Civil Penalties Under Chapter 521
Under Section 521.151, a person who violates Chapter 521 is liable for a civil penalty of at least $2,000 but not more than $50,000 for each violation.
For notification failures specifically, an additional penalty structure applies: up to $100 per individual per day for each consecutive day the business fails to comply with the notification requirements. These penalties may not exceed $250,000 for all individuals to whom notification is due after a single breach.
Injunctions and Cost Recovery
The Attorney General's other remedies also come from Chapter 521, not from the Deceptive Trade Practices Act. Section 521.151(b) allows the Attorney General to sue in the name of the state to restrain a violation by temporary restraining order or by temporary or permanent injunction, and Section 521.151(e) lets the court grant other equitable relief to prevent further harm or to satisfy a judgment.
Section 521.151(f) entitles the Attorney General to recover reasonable expenses, including reasonable attorney's fees, court costs, and investigatory costs, incurred in obtaining injunctive relief or civil penalties.
The Narrow Deceptive Trade Practices Act Hook
Chapter 521 contains one link to the Deceptive Trade Practices Act (DTPA), and it is narrower than it is often described. Section 521.152 provides that a "violation of Section 521.051 is a deceptive trade practice actionable under Subchapter E, Chapter 17."
Section 521.051 covers the unauthorized use or possession of another person's personal identifying information. It is not the notification provision. The DTPA hook therefore does not reach Section 521.053, so a failure to send a breach notice on time is not made actionable under the DTPA by Chapter 521.
Private Right of Action
Chapter 521 does not give consumers a private right of action for a breach notification failure. Enforcement of Section 521.053 belongs to the Attorney General under Section 521.151, and the chapter's only deceptive trade practice provision reaches Section 521.051 instead.
That does not mean a Texas breach never produces private litigation. Plaintiffs generally sue on other theories, such as negligence, breach of contract, or a DTPA claim built on a company's own representations about its security practices. Those claims stand or fall on their own elements rather than on a missed 60-day deadline.
AG Enforcement Track Record

The Texas Attorney General's office has demonstrated an aggressive enforcement posture on data privacy. While the $1.4 billion Meta settlement and $1.375 billion Google settlement involved biometric privacy rather than breach notification, they signal the AG's willingness to pursue maximum penalties.
For breach notification specifically, the AG settled investigations with Experian and T-Mobile for over $1.5 million combined. The AG's Data Privacy and Security Initiative, launched in 2024, has investigated the data practices of more than 200 companies.
The Cybersecurity Safe Harbor (SB 2610)
Texas Senate Bill 2610, effective September 1, 2025, created a cybersecurity safe harbor for qualifying businesses. This is a significant development for companies defending against breach-related litigation.
Who Qualifies
The safe harbor applies to businesses operating in Texas with fewer than 250 employees, organized into three tiers:
| Tier | Employee Count | Requirements |
|---|---|---|
| Tier 1 | Under 20 | Basic cybersecurity program |
| Tier 2 | 20 to 99 | Moderate program aligned to recognized framework |
| Tier 3 | 100 to 249 | Comprehensive program with regular assessments |
Recognized Frameworks
The law recognizes compliance with established cybersecurity frameworks, including the NIST Cybersecurity Framework and the HITRUST CSF, as meeting the safe harbor requirements.
What the Safe Harbor Provides
A qualifying business that implemented and maintained a compliant cybersecurity program at the time of a breach is shielded from punitive damages in breach-related litigation. The safe harbor does not eliminate liability entirely. Businesses can still face compensatory damages, AG enforcement, and statutory civil penalties.
The Catch
The business must demonstrate it had the cybersecurity program in place before the breach occurred. Implementing a program after the fact provides no protection. Documentation of compliance, regular risk assessments, and evidence of program maintenance are critical.
How TDPSA Interacts With Breach Notification
The Texas Data Privacy and Security Act (TDPSA), which took effect July 1, 2024, does not create its own breach notification requirements. The existing framework under Chapter 521 remains the sole breach notification statute.
However, the TDPSA intersects with breach notification in two practical ways. First, the TDPSA's data security requirements under Chapter 541 may establish the standard of care for what constitutes "reasonable" security practices, which affects both the likelihood of breaches and the available defenses. Second, TDPSA violations carry penalties of up to $7,500 per violation, adding another layer of exposure for companies that suffer breaches due to inadequate data protection.
A company that violates TDPSA data security requirements and then suffers a breach could face both TDPSA penalties for the security failure and Chapter 521 penalties for any notification deficiencies.
This article provides general legal information about Texas data breach notification requirements. It is not legal advice. If you need guidance about a specific breach incident, compliance obligations, or potential liability, consult an attorney licensed in Texas.
Related: Texas Data Privacy Laws | Data Privacy Laws by State | Data Breach Notification Laws
More Texas Laws
Frequently Asked Questions
How long does a Texas business have to report a data breach?
Texas imposes two separate deadlines. Businesses must notify affected individuals within 60 days of determining a breach occurred under Tex. Bus. & Com. Code 521.053(b). When 250 or more Texas residents are affected, the business must also notify the Texas Attorney General within 30 days. Both clocks start when the business determines the breach occurred, not when it first suspects one.
What personal information triggers Texas breach notification requirements?
Texas defines sensitive personal information as an individual's name (first name or initial plus last name) combined with an unencrypted Social Security number, driver's license or government ID number, financial account number with required security credentials, or health-related information. Encrypted data is exempt only if the encryption key was not also compromised in the breach.
Can individuals sue for a data breach in Texas?
Not under the breach notification statute. Chapter 521 does not create a private right of action for a late or missing breach notice, and enforcement of Section 521.053 belongs to the Attorney General under Section 521.151. The chapter's deceptive trade practice provision, Section 521.152, applies only to Section 521.051, which covers the unauthorized use or possession of personal identifying information. People who sue after a Texas breach generally do so on other theories, such as negligence or breach of contract.
Does encrypting data eliminate the need to send breach notifications in Texas?
In most cases, yes. Texas provides an encryption safe harbor that exempts properly encrypted data from the definition of sensitive personal information. If the compromised data was encrypted and the encryption key was not also acquired during the breach, the notification obligation does not apply. If the attacker obtained both the data and the key, the exemption does not apply.
What penalties can a Texas business face for failing to report a data breach?
Civil penalties range from $2,000 to $50,000 per violation under Section 521.151. For notification failures specifically, an additional penalty of up to $100 per individual per day applies, and the total may not exceed $250,000 for all individuals to whom notification is due after a single breach. Under Section 521.151, the Attorney General can also seek an injunction and recover reasonable attorney's fees, court costs, and investigatory costs. These are state enforcement remedies, not amounts individuals can collect.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the enforcement discussion: Chapter 521's civil penalties, injunctions and fee recovery run to the Attorney General under Section 521.151 rather than through the Deceptive Trade Practices Act, the DTPA hook in Section 521.152 reaches only Section 521.051 so there is no private right of action for a late breach notice, the encryption safe harbor sentence was inverted, and the state and local government reporting duty was updated from the repealed Government Code Section 2054.1125 to Section 2063.302 (48-hour report to the Texas Cyber Command).
Corrected the consumer-reporting-agency notice trigger: Texas law requires notice to the credit bureaus when a breach affects more than 10,000 people, not 10,000 or more. The Government Code citation for state/local government incident-reporting duties, which could not be confirmed against the statute's own site, was swapped for a working citation to the Texas Department of Information Resources' official reporting page, which independently confirms the underlying requirement.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Removed a fabricated quotation attributed to the encryption safe-harbor statute and corrected the subsection cited for the 30-day Attorney General notification deadline (521.053(i), not 521.053(b-1)).
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Texas Business & Commerce Code
§ 521.053NOTIFICATION REQUIRED FOLLOWING BREACH OF SECURITY OF COMPUTERIZED DATAIn forcecited in 2 of our articles
(a) In this section, "breach of system security" means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data. Good faith acquisition of sensitive personal information by an employee or agent of the person for the purposes of the person is not a breach of system security unless the person uses or discloses the sensitive personal information in an unauthorized manner. (b) A person who conducts business in this state and owns or licenses computerized data that includes sensitive personal information shall disclose any breach of system security, after discovering or receiving notification of the breach, to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2014
Opinions citing this section in our collection:
- Bliss & Glennon Inc. v. Ashley (Court of Appeals of Texas 2014, 420 S.W.3d 379)“…ved to have been, acquired by an unauthorized person .... Tex. Bus. & Com.Code Ann. § 521.053 (West Supp.2013). This section is part…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Texas Attorney General Opens Data-Breach Investigation Into Carnival, Issues Civil Investigative Demand (2026)
§ 521.002DEFINITIONSIn force
(a) In this chapter: (1) "Personal identifying information" means information that alone or in conjunction with other information identifies an individual, including an individual's: (A) name, social security number, date of birth, or government-issued identification number; (B) mother's maiden name; (C) unique biometric data, including the individual's fingerprint, voice print, and retina or iris image; (D) unique electronic identification number, address, or routing code; and (E) telecommunication access device as defined by Section 32.51, Penal Code.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 2 court opinions in our collectionLatest citing opinion in our collection: 2014
Opinions citing this section in our collection:
- Texas Comptroller of Public Accounts v. Attorney General of Texas and the Dallas Morning News, Ltd. (Texas Supreme Court 2010, 54 Tex. Sup. Ct. J. 245)“…"sensitive personal information,” in-eludes date of birth. Tex. Bus. & Com.Code § 521.002(a)(1). . Prior to 2001, the Trans…”
- Bliss & Glennon Inc. v. Ashley (Court of Appeals of Texas 2014, 420 S.W.3d 379)“…certain types of data are acquired by unauthorized persons. Tex. Bus. & Com.Code Ann. § 521.002-.053 (West 2009 & West Supp.2013). B &…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 521.151CIVIL PENALTY; INJUNCTIONIn forcecited in 2 of our articles
(a) A person who violates this chapter is liable to this state for a civil penalty of at least $2,000 but not more than $50,000 for each violation. The attorney general may bring an action to recover the civil penalty imposed under this subsection. (a-1) In addition to penalties assessed under Subsection (a), a person who fails to take reasonable action to comply with Section 521.053(b) is liable to this state for a civil penalty of not more than $100 for each individual to whom notification is due under that subsection for each consecutive day that the person fails to take reasonable action to comply with that subsection. Civil penalties under this section may not exceed $250,000 for all individuals to whom notification is due after a single breach. The attorney general may bring an action to recover the civil penalties imposed under this subsection.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2014
Opinions citing this section in our collection:
- In re Target Corp. Customer Data Security Breach Litigation (District Court, D. Minnesota 2014, 66 F. Supp. 3d 1154)“…ivil penalt[-y,-ies] imposed under this *1169 subsection,” Tex. Bus. & Com.Code Ann. § 521.151(a), (a-1), and that “the attorney gener…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Texas Identity Theft Laws: Penalties and Victim Rights
Explore the law
This article also draws on these acts and chapters (opening at their first section): Texas Government Code § 2054.001 (LEGISLATIVE FINDINGS AND POLICY)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Tex. Bus. & Com. Code 521.053 - Notification Required Following Breach of Security(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code 521.002 - Definitions (Sensitive Personal Information)(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code 521.151 - Civil Penalty; Injunction(statutes.capitol.texas.gov).gov
- Texas AG Data Breach Reporting Portal(texasattorneygeneral.gov).gov
- Texas Identity Theft Enforcement and Protection Act(texasattorneygeneral.gov).gov
- SB 768 - AG Electronic Notification Requirements (88th Legislature)(capitol.texas.gov).gov
- SB 2610 - Cybersecurity Safe Harbor for Small Businesses (89th Legislature)(capitol.texas.gov).gov
- Texas Deceptive Trade Practices Act (Chapter 17)(statutes.capitol.texas.gov).gov
- Texas AG $1.4B Meta Biometric Settlement(texasattorneygeneral.gov).gov
- Texas AG $1.375B Google Privacy Settlement(texasattorneygeneral.gov).gov
- Texas AG Experian and T-Mobile Breach Settlements(texasattorneygeneral.gov).gov
- Texas Data Privacy and Security Act (TDPSA)(texasattorneygeneral.gov).gov
- Texas DIR Cybersecurity Incident Management and Reporting(dir.texas.gov).gov
- Tex. Gov't Code 2063.302 - Cybersecurity Incident Notification by State Agency or Local Government(tcss.legis.texas.gov)
- Tex. Bus. & Com. Code Chapter 521 - Identity Theft Enforcement and Protection Act (full chapter text)(tcss.legis.texas.gov)