Enhance your TRUST relationship with PRIVACY and SECURITY. Privacy Made Simple!

   +1 866 267 0049   830 NE Pop Tilton Place, Jensen Beach, FL 34957

Texas
Privacy Laws

Overview

BREACH NOTIFICATION – Mandated Timeframe
Within 30 days

FINES & PENALTIES – Violations
$2,000 – $50,000

Legal

Regulation Levels

  • Breach Reporting

    Breach Reporting

  • Consumer Notification

    Consumer Notification

  • Vendor Management

    Vendor Management

  • Vendor Contract Required

    Vendor Contract Required

PRIVACY AND SECURITY LAWS

Laws related to personal information and privacy and security.

QUICK FACTS

Texas Privacy Law Information

PRIVACY PROGRAM

Organizations must have procedures in place for the protection of sensitive personal information, including processes for responding to potential risks or a breach or suspected breach of security. Organizations must have processes in place for the disposal of customer information no longer needed, by shredding, erasing or otherwise modifying to make it unreadable or indecipherable. Organizations are considered compliant with the state’s disposal regulations if they contract with a data disposal vendor. Data disposal Vendors must have measures in place for the destruction of records containing personal information so the records are unreadable or undecipherable. Texas has regulations specific to the consent, disclosure, protection and retention of individuals’ biometric identifiers. Organization may not obtain, possess, transfer, or use personal identifying information of another person without the other person’s consent or effective consent. Organizations may not obtain, possess, transfer, or use personal identifying information of another person without the other person’s consent or effective consent. Organizations (acting as contracted vendors for a state agency) that provide cloud computing services, must be vetted and able to provide documentation showing their certification and compliance with a state risk and authorization management program.

BREACH REPORTING
If 250 or more residents are affected by a breach of security, organizations must also notify the Attorney General with specific details of the breach, including the number of affected residents. Such notification must be completed within 30 days of discovery of the breach. Breach reporting to each consumer reporting agency that maintains files on consumers on a nationwide basis is required if more than 10,000 consumer notifications are sent, without unreasonable delay. Effective 9/1/2021, the Attorney General can post on their website the names of the companies who report a data breaches within 30 days of the date they are notified. The Attorney General will remove the company name from the posted list on their website one year from the original notification date, if no further breaches are reported within that time period.
CONSUMER NOTIFICATION

If your breach affects residents in other jurisdictions, those individuals must be notified based on the breach notification laws of the jurisdiction where they reside. Organizations must notify any Texas resident whose sensitive personal information was acquired by an unauthorized person within 60 days of discovery of the breach.

VENDOR/THIRD PARTIES

Vendors must notify Organizations upon discovery of a breach or suspected breach. The Organization is responsible for submitting any required regulatory reporting and consumer notifications. Organizations (acting as contracted vendors for a state agency) that provide cloud computing services, must be vetted and able to provide documentation showing their certification and compliance with a state risk and authorization management program.

FINES & PENALTIES

A violation of an Organization’s disposal of personal information is subject to a fine of up to $500 for each business record. Texas law has heavy penalties for violations of the regulations involving the protection of personal information and breach notification, including civil penalties from $2,000 to $50,000 per violation and $100 for each individual that failed to receive a notification (up to $250,000). The unauthorized use or possession of a consumer’s personal information is considered a deceptive trade practice. Organizations may be fined or penalized for Vendor violations.

Texas Statutes and Laws

TX BUSINESS AND COMMERCE CODE §§ 72.001 – 72.004

Disposal of Certain Business Records

TX HEALTH AND SAFETY CODE 181

Medical records privacy

TX BUSINESS AND COMMERCE CODE § 503.001

Capture or use of biometric identifier

TX BUSINESS AND COMMERCE CODE § 521.051

Unauthorized use or possession of personal identifying information

TX BUSINESS AND COMMERCE CODE § 521.052
Business duty to protect sensitive personal information
TX BUSINESS AND COMMERCE CODE § 521.053

Notification required following breach of security of computerized data

TX BUSINESS AND COMMERCE CODE § 521.151

Civil penalty; injunction

TX BUSINESS AND COMMERCE CODE §§ 521.001 – 521.002

Identity Theft Enforcement and Protection Act

TX Government Code – Chapter 2054 Information Resources § 2054.0593

Cloud Computing State Risk and Authorization Management Program

DISCLAIMER

The information provided is not legal guidance or recommendations and are for informational purposes only.