Back to Blog
Compliance GuideApril 1, 20269 min readReviewed by the PrivacyLawMap editorial teamLast reviewed April 1, 2026

Texas Data Breach Notification Law: Compliance Requirements and 60-Day Deadline

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

Overview: Texas Data Breach Notification Requirements

Texas has one of the most actively enforced data breach notification laws in the United States. Under Texas Business & Commerce Code Chapter 521 (Identity Theft Enforcement and Protection Act), any person or business that owns, licenses, or maintains computerized data that includes sensitive personal information must notify affected individuals when a breach occurs. With the Texas Attorney General’s office securing over $2.7 billion in privacy-related settlements in recent years—including the landmark $1.375 billion Google settlement and $1.4 billion Meta settlement—compliance is not optional.

This guide covers everything you need to know about the Texas data breach notification law: who must comply, what triggers notification, the 60-day deadline, AG reporting requirements, penalties, and a practical incident response plan. If your business holds data on Texas residents, use our Privacy Law Calculator to check which state laws apply to you.

Who Must Comply?

The Texas data breach notification law applies broadly to any person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. Unlike some state privacy laws, there is no minimum revenue or data-processing threshold. If you hold personal data on even one Texas resident, this law applies to you.

The law covers:

  • Businesses of all sizes—from sole proprietors to multinational corporations
  • Government entities—state and local agencies have separate notification obligations under Texas Government Code §2054.1125
  • Data processors—third parties that maintain data on behalf of another entity must notify the data owner within 60 days of discovering the breach
  • Health-related entities—covered entities under the Texas Medical Privacy Act (THIPA) have additional obligations under Health & Safety Code §181.202

What Triggers a Notification Obligation?

A notification is required when there is unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information. Texas law defines “breach of system security” as unauthorized acquisition of computerized data that compromises sensitive personal information maintained by the person.

Covered Personal Information

Under §521.002, “sensitive personal information” means an individual’s first name or initial and last name combined with one or more of the following:

  • Social Security number
  • Driver’s license number or government-issued ID number
  • Account number or credit/debit card number combined with any required security code, access code, or password
  • Information that identifies an individual and relates to their physical or mental health, health care provision, or health care payment (added by HB 300)

The information must be unencrypted (or encrypted with a compromised key). If the data was encrypted and the encryption key was not breached, notification is generally not required.

The 60-Day Deadline for Notifying Individuals

Texas has two deadlines, not one: 60 days to notify the affected individuals under § 521.053(b), and 30 days to notify the attorney general under § 521.053(i) once a breach involves at least 250 Texas residents. This section covers the first; the AG deadline is 30 days and is the one most guides get wrong.

For individuals, Texas requires notification without unreasonable delay and in each case no later than the 60th day after the date the person determines the breach occurred. That 60-day deadline was established by HB 4390 (effective January 1, 2020) and replaced the previous “without unreasonable delay” standard that had no hard outer limit.

The 60-day clock starts when the entity determines or should have determined that a breach occurred—not when the breach itself happened. Exceptions to the timeline:

  • Law enforcement delay—notification may be delayed if law enforcement determines it would impede a criminal investigation, but only for the duration of the investigation
  • Investigation period—the entity may take reasonable time to determine the scope of the breach, but the total time from discovery to notification must not exceed 60 days

Compare this to California’s stricter 30-day deadline under SB 1223, or see our complete state-by-state comparison.

Attorney General Reporting: A 30-Day Deadline, Not 60

The Texas attorney general must be notified within 30 days, not 60. If a breach involves at least 250 Texas residents, Tex. Bus. & Com. Code § 521.053(i) requires notice to the attorney general “as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred”—half the time you have to notify the affected people. In Texas the regulator is normally told first, and a response plan built around the 60-day consumer clock will miss the AG deadline by up to a month.

This is the single most-conflated point in the statute, because two different amendments moved two different clocks: H.B. 4390 (effective January 1, 2020) set the 60-day deadline for notifying individuals, and S.B. 768 (effective September 1, 2023) is what cut the attorney-general deadline from 60 days to 30.

  • Who must be told: The Texas Attorney General, electronically on the form it publishes
  • At what headcount: 250 or more residents
  • By when: As soon as practicable and no later than 30 days after determining the breach occurred
  • Does the filing become public? Yes — the statute requires a public listing
  • Read it yourself: Tex. Bus. & Com. Code § 521.053(i)-(j), retrieved August 15, 2026

Tex. Bus. & Com. Code § 521.053(i)(1)-(6) sets out what the filing must contain. It is a closed list of 6 items, and two of them are counts you have to take on the day you file rather than facts you can prepare in advance:

  1. A detailed description of the nature and circumstances of the breach, or of the use of sensitive personal information acquired as a result of it
  2. The number of Texas residents affected by the breach at the time of notification
  3. The number of those affected residents who have already been sent a disclosure by mail or other direct method at the time of notification
  4. The measures the filer has taken regarding the breach
  5. Any measures the filer intends to take regarding the breach after this notification
  6. Whether law enforcement is engaged in investigating the breach

Note: unlike California, which requires AG notification at 500 or more residents, Texas binds at 250—and the comparator matters as much as the number. The statute says “at least 250,” so a breach touching exactly 250 Texans is reportable.

Your Filing Becomes a Public Listing

Filing with the Texas attorney general is not a private disclosure. § 521.053(j) orders the attorney general to publish a listing of the notices it receives, to update that listing within 30 days of each new report, and to remove an entry only on the first anniversary of its posting—and then only if the filer has reported no further breaches in the meantime. Sensitive personal information, anything that would compromise a data system’s security, and information made confidential by law are excluded from what is published; the fact of your breach is not. Practically, that means the filing needs communications and legal sign-off inside the 30-day window, not after it, and that a second breach within a year keeps the first one listed.

How to Notify Affected Individuals

Texas provides several acceptable methods of notification:

  • Written notice sent to the last known address of the individual
  • Electronic notice if consistent with federal E-SIGN Act requirements
  • Substitute notice (if the cost exceeds $250,000, more than 500,000 people are affected, or the entity lacks sufficient contact information): requires email notification when available, conspicuous posting on the entity’s website, and notification to major statewide media

The notification must include a description of the breach, the type of personal information involved, and contact information for the entity, credit reporting agencies, and the FTC.

Penalties for Non-Compliance

The Texas Attorney General can bring enforcement actions for failure to comply with the breach notification law. Penalties include:

  • $2,000 to $50,000 for each violation of Chapter 521 (§ 521.151(a))
  • Up to $100 per individual, per consecutive day of failing to take reasonable action to comply with the individual-notice duty in § 521.053(b), capped at $250,000 for all individuals after a single breach (§ 521.151(a-1)). This one stacks on top of the per-violation penalty above rather than replacing it, and it is keyed to the consumer notice—a late attorney-general filing is exposed under § 521.151(a) instead
  • Injunctive relief—the AG can seek court orders to compel compliance
  • Deceptive trade practices—failure to notify may also constitute a violation of the Texas Deceptive Trade Practices Act, opening additional liability

Beyond breach notification, the Texas AG has demonstrated a willingness to pursue massive privacy enforcement actions. The $1.375 billion settlement with Google over unauthorized biometric data collection and the $1.4 billion settlement with Meta over facial recognition violations show that Texas takes data privacy violations extremely seriously. These settlements were brought under a combination of the TDPSA, CUBI (Capture or Use of Biometric Identifier Act), and the Deceptive Trade Practices Act.

For a complete overview of privacy enforcement penalties by state, see our state privacy law penalties guide or visit our enforcement actions tracker.

Texas vs. Other States: Breach Notification Comparison

Requirement Texas California Florida New York
Deadline to notify individuals 60 days 30 days (SB 1223) 30 days “Expedient” (no hard deadline)
Deadline to notify the AG 30 days (§ 521.053(i)) Not separately fixed 30 days Not separately fixed
AG Notification Threshold 250 or more residents 500 residents 500 residents All breaches (any size)
Private Right of Action No (AG only) Yes (CCPA §1798.150) No No
Maximum Penalty $50,000/violation, plus up to $100/individual/day capped at $250,000 per breach $7,500/violation (AG) $500,000 total $5,000/violation
Encryption Safe Harbor Yes Yes Yes Yes

Use our State Privacy Law Comparison Tool to compare additional dimensions across all 21 comprehensive state privacy laws.

Practical 60-Day Incident Response Plan

When a potential data breach is discovered, follow this timeline to ensure compliance with the Texas 60-day deadline:

Phase 1: Detection and Containment (Days 1–3)

  • Isolate affected systems to prevent ongoing unauthorized access
  • Preserve forensic evidence (logs, access records, affected data sets)
  • Engage your incident response team and outside counsel
  • Begin documenting the timeline of events

Phase 2: Investigation and Scope Assessment (Days 4–20)

  • Conduct forensic analysis to determine the extent of the breach
  • Identify all categories of personal information compromised
  • Determine the number of Texas residents affected
  • Assess whether data was encrypted and whether the encryption key was compromised
  • Evaluate whether law enforcement notification is warranted (may delay consumer notification)

Phase 3: Notification Preparation and the AG Filing (Days 21–30)

This phase is short because it is governed by the shorter clock. If 250 or more Texas residents are affected, § 521.053(i) requires the attorney-general filing by day 30, so the AG notice is prepared, cleared and submitted here—before most of the individual notifications go out.

  • Draft notification letters with all required content
  • Prepare the AG filing against the six-item list in § 521.053(i), including the two same-day counts: residents affected, and residents already directly notified
  • Obtain legal and communications sign-off, remembering that § 521.053(j) puts the filing on a public listing for a year
  • Submit the AG notification electronically by day 30—not with the consumer notices
  • Arrange credit monitoring or identity theft protection services if appropriate
  • Set up a dedicated call center or FAQ page for affected individuals

Phase 4: Individual Notification Delivery (Days 31–55)

  • Send individual notifications via mail or email
  • If using substitute notice, post to website and notify media outlets
  • Notify the nationwide consumer reporting agencies if more than 10,000 people are being notified at one time (§ 521.053(h))
  • Verify delivery and document all notifications sent

Phase 5: Post-Notification and Remediation (Days 56–60+)

  • Monitor for and respond to inquiries from affected individuals
  • Implement measures to prevent similar breaches (patch vulnerabilities, update access controls)
  • Conduct a lessons-learned review and update your incident response plan
  • Consider engaging a third-party auditor to verify remediation

Interaction with the Texas Data Privacy and Security Act (TDPSA)

The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, is a separate comprehensive privacy law that requires businesses to implement reasonable data security practices. While the TDPSA does not have its own breach notification provisions, a data breach may indicate a failure to maintain the “reasonable administrative, technical, and physical data security practices” required under §541.101. This means a single breach event could trigger both:

  • Notification obligations under Chapter 521 (breach notification law)
  • Enforcement action under TDPSA for inadequate data security

Use our Texas compliance checklist to ensure you meet both sets of requirements, or generate a customized privacy policy that covers both laws.

Key Steps for Texas Breach Notification Compliance

  1. Inventory your data—know what sensitive personal information you hold on Texas residents and where it’s stored
  2. Encrypt sensitive data—encryption provides a safe harbor from notification requirements
  3. Prepare an incident response plan—have both timelines (30 days to the attorney general, 60 to individuals), templates, and contact information ready before a breach happens
  4. Know your AG reporting threshold and clock—250 or more affected Texas residents triggers AG notification, due within 30 days of determining the breach occurred
  5. Document everything—maintain records of your investigation, decisions, and notifications in case of AG inquiry
  6. Train employees—ensure staff know how to recognize and report potential breaches immediately
  7. Review vendor contracts—ensure data processors are contractually required to notify you within a timeframe that allows you to meet the 60-day deadline

Frequently Asked Questions

How do I report a data breach to the Texas Attorney General?

Electronically, on the form the attorney general publishes on its website—§ 521.053(i) requires the notification to be “submitted electronically using a form accessed through the attorney general’s Internet website,” so there is no mail-in or free-form option. You must file if the breach involves at least 250 Texas residents, and you have until the 30th day after you determine the breach occurred. The form asks for the six items listed above; two of them—how many residents are affected, and how many have already been directly notified—are counts “at the time of notification,” so they have to be taken on the day you file rather than pulled from an earlier draft.

How long do I have to notify the Texas Attorney General of a data breach?

30 days, not 60. § 521.053(i) requires notice to the attorney general “as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred.” The 60-day figure that appears in most Texas breach guides is the deadline for notifying the affected individuals under § 521.053(b). They were the same number until S.B. 768 took effect on September 1, 2023 and halved the attorney-general clock, which is why older guidance still says 60.

Is a Texas data breach notification public?

Yes. § 521.053(j) requires the attorney general to post a listing of the notices it receives on its public website, to update that listing within 30 days of each new report, and to remove an entry no earlier than the first anniversary of its posting—and only if the filer has reported no further breach in the meantime. The published listing excludes sensitive personal information, anything that would compromise a data system’s security, and information made confidential by law, but not the fact that your organization filed.

Does the 60-day deadline apply to all businesses?

Yes. Any person or business that conducts business in Texas and owns, licenses, or maintains computerized data containing sensitive personal information of Texas residents must comply with the 60-day deadline. There is no size exemption.

What if I discover a breach but determine no sensitive personal information was compromised?

If the breached data does not include sensitive personal information as defined by §521.002 (e.g., only names without Social Security numbers, financial account data, or health information), notification is not required under Chapter 521. However, you should still document your investigation and determination.

Can I delay notification if law enforcement asks me to?

Yes. If a law enforcement agency determines that notification would impede a criminal investigation, you may delay notification. However, once law enforcement clears you to notify, the 60-day clock resumes. The delay does not restart the deadline—it pauses it.

Are there specific requirements for health-related data breaches?

Yes. If the breach involves protected health information covered by HIPAA or the Texas Medical Privacy Act (THIPA), additional notification requirements apply under Health & Safety Code §181.202, including notifying the Texas AG within 60 days regardless of the number of individuals affected.

What should I do if I’m unsure whether a breach occurred?

The law applies when there is “unauthorized acquisition” of data that “compromises the security, confidentiality, or integrity” of sensitive personal information. If you are unsure, conduct a thorough investigation. The 60-day clock starts from when you knew or should have known the breach occurred. Delaying investigation does not extend the deadline.

Use our DSAR Request Manager to track consumer data requests that may follow a breach, and our Deletion Request Generator to help affected individuals exercise their rights under the Texas TDPSA.

Last updated: August 15, 2026. The Chapter 521 deadlines, the 250-resident attorney-general trigger and the § 521.053(i) filing-contents list on this page were verified against the statute text at statutes.capitol.texas.gov on August 15, 2026.

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly