EnglishEspañol
Texas flag

Texas

Texas Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 13 primary sources cited on this page. How we verify our legal content

Texas Data Breach Notification Laws: Reporting Rules & Timelines (2026)

Frequently Asked Questions

How long does a Texas business have to report a data breach?

Texas imposes two separate deadlines. Businesses must notify affected individuals within 60 days of determining a breach occurred under Tex. Bus. & Com. Code 521.053(b). When 250 or more Texas residents are affected, the business must also notify the Texas Attorney General within 30 days. Both clocks start when the business determines the breach occurred, not when it first suspects one.

What personal information triggers Texas breach notification requirements?

Texas defines sensitive personal information as an individual's name (first name or initial plus last name) combined with an unencrypted Social Security number, driver's license or government ID number, financial account number with required security credentials, or health-related information. Encrypted data is exempt only if the encryption key was not also compromised in the breach.

Can individuals sue for a data breach in Texas?

Not under the breach notification statute. Chapter 521 does not create a private right of action for a late or missing breach notice, and enforcement of Section 521.053 belongs to the Attorney General under Section 521.151. The chapter's deceptive trade practice provision, Section 521.152, applies only to Section 521.051, which covers the unauthorized use or possession of personal identifying information. People who sue after a Texas breach generally do so on other theories, such as negligence or breach of contract.

Does encrypting data eliminate the need to send breach notifications in Texas?

In most cases, yes. Texas provides an encryption safe harbor that exempts properly encrypted data from the definition of sensitive personal information. If the compromised data was encrypted and the encryption key was not also acquired during the breach, the notification obligation does not apply. If the attacker obtained both the data and the key, the exemption does not apply.

What penalties can a Texas business face for failing to report a data breach?

Civil penalties range from $2,000 to $50,000 per violation under Section 521.151. For notification failures specifically, an additional penalty of up to $100 per individual per day applies, and the total may not exceed $250,000 for all individuals to whom notification is due after a single breach. Under Section 521.151, the Attorney General can also seek an injunction and recover reasonable attorney's fees, court costs, and investigatory costs. These are state enforcement remedies, not amounts individuals can collect.

Affected by a data breach or biometric privacy violation?

If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.

Updates

Corrected the enforcement discussion: Chapter 521's civil penalties, injunctions and fee recovery run to the Attorney General under Section 521.151 rather than through the Deceptive Trade Practices Act, the DTPA hook in Section 521.152 reaches only Section 521.051 so there is no private right of action for a late breach notice, the encryption safe harbor sentence was inverted, and the state and local government reporting duty was updated from the repealed Government Code Section 2054.1125 to Section 2063.302 (48-hour report to the Texas Cyber Command).

Corrected the consumer-reporting-agency notice trigger: Texas law requires notice to the credit bureaus when a breach affects more than 10,000 people, not 10,000 or more. The Government Code citation for state/local government incident-reporting duties, which could not be confirmed against the statute's own site, was swapped for a working citation to the Texas Department of Information Resources' official reporting page, which independently confirms the underlying requirement.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Removed a fabricated quotation attributed to the encryption safe-harbor statute and corrected the subsection cited for the 30-day Attorney General notification deadline (521.053(i), not 521.053(b-1)).

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Tex. Bus. & Com. Code 521.053 - Notification Required Following Breach of Security(statutes.capitol.texas.gov).gov
  2. Tex. Bus. & Com. Code 521.002 - Definitions (Sensitive Personal Information)(statutes.capitol.texas.gov).gov
  3. Tex. Bus. & Com. Code 521.151 - Civil Penalty; Injunction(statutes.capitol.texas.gov).gov
  4. Texas AG Data Breach Reporting Portal(texasattorneygeneral.gov).gov
  5. Texas Identity Theft Enforcement and Protection Act(texasattorneygeneral.gov).gov
  6. SB 768 - AG Electronic Notification Requirements (88th Legislature)(capitol.texas.gov).gov
  7. SB 2610 - Cybersecurity Safe Harbor for Small Businesses (89th Legislature)(capitol.texas.gov).gov
  8. Texas Deceptive Trade Practices Act (Chapter 17)(statutes.capitol.texas.gov).gov
  9. Texas AG $1.4B Meta Biometric Settlement(texasattorneygeneral.gov).gov
  10. Texas AG $1.375B Google Privacy Settlement(texasattorneygeneral.gov).gov
  11. Texas AG Experian and T-Mobile Breach Settlements(texasattorneygeneral.gov).gov
  12. Texas Data Privacy and Security Act (TDPSA)(texasattorneygeneral.gov).gov
  13. Texas DIR Cybersecurity Incident Management and Reporting(dir.texas.gov).gov
  14. Tex. Gov't Code 2063.302 - Cybersecurity Incident Notification by State Agency or Local Government(tcss.legis.texas.gov)
  15. Tex. Bus. & Com. Code Chapter 521 - Identity Theft Enforcement and Protection Act (full chapter text)(tcss.legis.texas.gov)
Share: