Texas Breach Notification Law Amended, Changes Effective September 1, 2021

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
Texas's data breach notification law was recently amended to require the state's Attorney General to post notice of data breaches on a public website within 30 days of receiving notice of the data breach.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

Texas's data breach notification law was recently amended to require the state's Attorney General to post notice of data breaches on a public website within 30 days of receiving notice of the data breach. It also requires companies to provide the AG with more information when notifying the AG of a breach.

Under existing Texas law, data breaches that impact 250 or more Texas residents must be reported to the state Attorney General within 60 days of becoming aware of the breach. Such notice currently requires companies to describe the breach, steps taken “regarding the breach,” whether law enforcement was involved, and the number of impacted state residents. Under the amended law, businesses will also be required to report the number of impacted Texans who were sent notice of the breach.

The new amendment also requires the Texas Attorney General to maintain a publicly accessible list of breach notifications submitted to the Attorney General's Office. Within 30 days of receiving a data breach notification, the Texas AG must post a notice of such breach to their website. In posting such notice, the AG is instructed to exclude reported sensitive personal information, information that may compromise a system's security or information that is confidential by law. Such notice is to be removed from the website after one year if the business reporting such breach does not report another breach during that period.

Putting it Into PracticeThis change means that Texas, like Puerto Rico, will now require the Attorney General to publicly post the breach notices it receives from companies. While other states' AGs do engage in this practice, it will be mandated under Texas law. Companies should keep this in mind when drafting any potentially required notice to the Texas AG.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More