Texas cybersecurity laws sit in four places: the Identity Theft Enforcement and Protection Act (Business & Commerce Code Chapter 521) requires businesses to notify people and the state after a data breach; the Texas Data Privacy and Security Act (Chapter 541), effective July 1, 2024, gives consumers rights over their personal data; Penal Code Chapter 33 criminalizes hacking and online impersonation; and Government Code Chapter 2054 imposes training and rapid incident-reporting duties on state and local government entities. Penalties run from a $500 fine to first-degree felony prison time on the criminal side, and from $2,000 per violation up to $250,000 per breach on the civil side.
Data Breach Notification Duties
Chapter 521 applies to any person or business that conducts business in Texas and owns or licenses computerized data containing sensitive personal information. Sensitive personal information means a person’s first name or initial plus last name combined with at least one of the following: a Social Security number, a driver’s license or government ID number, a financial account number together with any access code or password, or unique biometric data like a fingerprint or retina scan.
A breach is the unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of that information. Encrypted data still counts as breached if the person who accessed it also holds the decryption key. A good-faith acquisition by an employee acting within their job is not a breach unless the employee then uses or shares the information without authorization.1State of Texas. Texas Business and Commerce Code Section 521.053 – Notification Required Following Breach of Security of Computerized Data
Two Deadlines That Run on Different Clocks
You must notify each affected individual no later than 60 days after you determine the breach occurred.1State of Texas. Texas Business and Commerce Code Section 521.053 – Notification Required Following Breach of Security of Computerized Data Separately, if the breach affects 250 or more Texas residents, you must report it to the Attorney General within 30 days of discovery, filed electronically through the AG’s online portal.2Office of the Attorney General of Texas. Data Breach Report Law enforcement can request a delay of individual notifications if disclosure would interfere with a criminal investigation, but the AG deadline is firm.
If you only maintain someone else’s data rather than own it, your job is different: notify the data owner or license holder immediately after discovering the breach, and the owner handles consumer notifications from there.
Civil Penalties for Failing to Notify
The Attorney General can pursue two tracks at once. The baseline civil penalty is $2,000 to $50,000 for each violation of Chapter 521. On top of that, a business that fails to make reasonable efforts to notify affected individuals faces an additional penalty of up to $100 per person per day of noncompliance, capped at $250,000 for all individuals affected by a single breach.3State of Texas. Texas Business and Commerce Code Section 521.151 – Civil Penalty; Injunction The AG can also seek injunctive relief, attorney’s fees, and investigation costs.4Office of the Attorney General of Texas. Identity Theft Enforcement and Protection Act
Consumer Data Rights Under the TDPSA
Chapter 541 applies to any company that does business in Texas or sells products and services consumed by Texas residents and that processes consumers’ personal data.5Office of the Attorney General of Texas. Texas Data Privacy and Security Act Several categories are exempt: small businesses as defined by the federal Small Business Administration (though even they must obtain consent before selling sensitive data),6State of Texas. Texas Business and Commerce Code Section 541.107 – Requirements for Small Businesses state agencies, political subdivisions, financial institutions under the Gramm-Leach-Bliley Act, HIPAA-regulated entities, nonprofits, and institutions of higher education.
What Consumers Can Ask For
Texas residents can submit requests to any covered business to confirm whether it is processing their personal data and get a copy, correct inaccuracies, delete data the consumer provided or the business obtained, and opt out of targeted advertising, data sales, and profiling that produces legal or similarly significant effects. Businesses must offer a clear, conspicuous method on their website for consumers to exercise these rights.7Texas Public Law. Texas Code Business and Commerce Code Chapter 541 – Consumer Data Protection
A business has 45 days to respond to a request. It can extend the window by another 45 days for a complex or high-volume request, as long as it tells the consumer about the delay and the reason within the original timeframe. If the business denies the request, it must offer an internal appeals process, and a denied appeal has to be communicated within 60 days along with a way to complain to the Attorney General.7Texas Public Law. Texas Code Business and Commerce Code Chapter 541 – Consumer Data Protection
Sensitive Data Requires Consent
The TDPSA treats certain categories as sensitive and requires explicit consent before processing. That covers information revealing racial or ethnic origin, religious beliefs, health conditions or diagnoses, sexuality, citizenship or immigration status, genetic or biometric data used to identify a person, personal data of children under 13, and precise geolocation data. Businesses must also conduct data protection assessments for high-risk processing, including targeted advertising, data sales, profiling with foreseeable risks, and any sensitive data processing. The AG can request those assessments.5Office of the Attorney General of Texas. Texas Data Privacy and Security Act
Enforcement, the 30-Day Cure Period, and Penalties
The Attorney General has exclusive enforcement authority under the TDPSA. There is no private right of action, so consumers cannot sue businesses directly for violations.8Justia. Texas Business and Commerce Code Section 541.151 – Enforcement Authority Exclusive Before filing suit, the AG must send a written notice identifying the alleged violation and give the company 30 days to cure it. A company that fails to fix the problem, or that later breaches a written statement it provided to the AG, faces civil penalties of up to $7,500 per violation, plus possible injunctive relief, attorney’s fees, and costs.5Office of the Attorney General of Texas. Texas Data Privacy and Security Act Companies that respond quickly and genuinely remediate within the cure window can avoid penalties.
Criminal Penalties for Hacking and Impersonation
Penal Code Chapter 33 targets the people who break into systems and those who misuse others’ identities online.
Breach of Computer Security
Knowingly accessing a computer, network, or system without the owner’s consent is an offense under Section 33.02. The baseline is a Class B misdemeanor, punishable by up to 180 days in county jail. It becomes a state jail felony if the defendant has two or more prior convictions under the chapter, or if the target is a government entity or a critical infrastructure facility.9State of Texas. Texas Penal Code Section 33.02 – Breach of Computer Security
When the access is committed with intent to defraud, harm, or damage property, the penalty scales with the dollar amount of harm, running from a Class C misdemeanor for losses under $100 up to a first-degree felony (five to 99 years in prison) for losses of $300,000 or more. Government or critical-infrastructure targets and multi-system identity theft trigger the higher tiers regardless of dollar amount.9State of Texas. Texas Penal Code Section 33.02 – Breach of Computer Security
Online Impersonation
Section 33.07 makes it a crime to use another person’s name or identity online without consent and with intent to harm, defraud, intimidate, or threaten. Creating a fake social media profile or website in someone else’s name is a third-degree felony. Sending messages that appear to come from another person, such as spoofed emails or texts, is a Class A misdemeanor, and jumps to a third-degree felony if the intent is to trigger an emergency response.10State of Texas. Texas Penal Code Section 33.07 – Online Impersonation
Rules for State and Local Government Entities
Government Code Chapter 2054 imposes obligations on state agencies and local governments that go beyond private-sector duties, centered on training and incident reporting.
Annual Cybersecurity and AI Training
State agencies must identify every employee who uses a computer for at least 25% of their duties. Those employees, plus all elected and appointed officers, must complete a cybersecurity training program certified by the Department of Information Resources at least once per year. Local governments, including counties, school districts, and special districts, must do the same for employees and officials who have access to a government computer system and use a computer for at least 25% of their work.11State of Texas. Texas Government Code Section 2054.5191 – Cybersecurity and Artificial Intelligence Training Required: Certain Employees and Officials The statute now also requires an artificial intelligence training program alongside the cybersecurity coursework. Entities that fail to complete annual training can be listed as non-compliant, which may affect eligibility for state grants and funding.
48-Hour Incident Reporting
State agencies and local governments must report qualifying security incidents to DIR within 48 hours of discovery. The 48-hour clock applies when an incident is assessed to spread to other state systems, result in criminal violations, involve unauthorized disclosure of confidential information such as sensitive personal information, or compromise or destroy information systems or applications.12Cornell Law Institute. 1 Texas Administrative Code 202.23 – Security Reporting
Filing a Breach Report With the Attorney General
Breaches affecting 250 or more Texas residents must be reported electronically through the Attorney General’s online breach reporting portal.2Office of the Attorney General of Texas. Data Breach Report Certified mail is no longer accepted. Only an owner, manager, attorney, or authorized agent of the breached organization can file.
The portal asks for the number of Texas residents affected, the categories of sensitive personal information compromised, the date range of the breach, and the remediation steps taken. Gather all of that before starting the submission; incomplete filings can prompt follow-up scrutiny from the AG’s office. The AG maintains a publicly searchable list of reported breaches involving 250 or more Texas residents, updated as reports come in and revised as investigations develop.13Office of the Attorney General. Data Breach Reporting After a report is filed, the AG’s office may follow up to confirm that the remediation described was actually carried out.