The Letter About Your Information
Bus. & Com. 521.053 — notice by the 60th day, and the attorney general at 250 residents
In Texas, a person the section requires to give notice of a breach of system security discloses it to each affected individual without unreasonable delay, and in each case not later than the 60th day after determining that the breach occurred, except for a delay law enforcement asks for or the time needed to determine the scope of the breach and restore the data system.
| Who is told | When, as the section puts it |
|---|---|
| Who is toldEach affected individual | When, as the section puts itWithout unreasonable delay, and not later than the 60th day after the breach is determined |
| Who is toldThe attorney general, if the breach involves at least 250 residents of this state | When, as the section puts itAs soon as practicable and not later than the 30th day, on the attorney general's online form |
| Who is toldEach consumer reporting agency, if more than 10,000 persons are notified at one time | When, as the section puts itWithout unreasonable delay |
- The attorney general posts a public listing of the notifications received, without sensitive personal information, and updates it within 30 days of a new one.
What counts as personal information, the forms notice may take, and the exceptions for encrypted data are in the section and are not reproduced in full here. Whether a notice was required or on time is a question for the attorney general, a court, and a licensed Texas attorney.
Sources for this section (1)
- Bus. & Com. 521.053 — Notification required following breach of security of computerized data
Legal information, not legal advice. Verified as of September 2026. Applying it to a particular situation is the work of a licensed Texas attorney.