Texas
For Texas, statute citation is Tex. Bus. & Com. Code § 521.053; individual notice deadline is not later than the 60th day after the date on which the person determines that the breach occurred; individual notice hard deadline (days) is 60; ag / regulator notice deadline is not later than the 60th day after the date on which the person determines that the breach occurred; ag notice resident-count trigger is at least 250 residents of this state, recorded from its source on 2026-08-18.
- State
- Texas
- Statute citation
- Tex. Bus. & Com. Code § 521.053
- Individual notice deadline
- not later than the 60th day after the date on which the person determines that the breach occurred verified
- Individual notice hard deadline (days)
- 60 our reading
- AG / regulator notice deadline
- not later than the 60th day after the date on which the person determines that the breach occurred verified
- AG notice resident-count trigger
- at least 250 residents of this state
- Encryption safe harbor
- yes our reading
- Notes
- Source is HB 4390 (86th Legislature, 2019), the enrolled bill that amended § 521.053. The individual notice deadline text includes a bracketed deletion '[as quickly as possible]' reflecting the bill's amendment of existing law. our reading
Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.
What the source says
(b)AAA person who conducts business in this state and owns or 9 licenses computerized data that includes sensitive personal 10 information shall disclose any breach of system security, after 11 discovering or receiving notification of the breach, to any 12 individual whose sensitive personal information was, or is 13 reasonably believed to have been, acquired by an unauthorized 14 person. The disclosure shall be made without unreasonable delay and 15 in each case not later than the 60th day after the date on which the 16 person determines that the breach occurred [as quickly as 17 possible], except as provided by Subsection (d) or as necessary to 18 determine the scope of the breach and restore the reasonable 19 integrity of the data system. 20 (i)AAA person who is required to disclose or provide 21 notification of a breach of system security under this section 22 shall notify the attorney general of that breach not later than the 23 60th day after the date on which the person determines that the 24 breach occurred if the breach involves at least 250 residents of 1 H.B.ANo.A4390 1 this state. The notification under this subsection must include: 2 (1)AAa detailed description of the nature and 3 circumstances of the breach or the use of sensitive personal 4 information acquired as a result of the breach; 5 (2)AAthe number of residents of this state affected by 6 the breach at the time of notification; 7 (3)AAthe measures taken by the person regarding the 8 breach; 9 (4)AAany measures the person intends to take regarding 10 the breach after the notification under this subsection; and
— capitol.texas.gov, retrieved 2026-08-18
Source
- capitol.texas.govhttps://capitol.texas.gov/tlodocs/86R/billtext/pdf/HB04390F.pdf