Texas Breach Law Will Change In 2020, To Require Attorney General Notification

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
New requirements to the Texas data breach statute, including a requirement to notify the Texas attorney general of a breach, are set to go into effect January 1, 2020.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

New requirements to the Texas data breach statute, including a requirement to notify the Texas attorney general of a breach, are set to go into effect January 1, 2020. The legislation, signed by Texas Governor, Greg Abbot, on June 14, 2019, requires that the Texas attorney general be notified of a breach within 60 days. The AG notification is required only if 250 or more Texas residents are affected. The notification to the attorney general must include a description of the breach, number of residents affected, measures taken in response to the breach, measures planned to be taken after notification and whether law enforcement has been engaged with the investigation. The legislation also adds a 60 day timing requirement for notice, from the current "as quickly as possible" standard.

In an unusual step for breach notice laws, the legislation also creates a "Texas Privacy Protection Advisory Council." This Council is tasked with studying both Texas and other privacy laws, both domestic and foreign. Members of the Council will be in-state residents, and are to include someone from a nonprofit organization that looks at privacy from the consumer perspective, as well as a law school professor. The Council is tasked with making recommendations to the legislature in Texas on privacy law changes that "appear necessary from the results of the council's study." This development is interesting in light of the two Texas privacy bills that were recently introduced, the Texas Consumer Privacy Act and the Texas Privacy Protection Act. The Council's findings and recommendations are due September 1, 2020.

Putting it Into Practice: Companies with nationwide breach notice plans should work in the new requirement to notify the Texas attorney general prior to the January 1, 2020 effective date. We will continue to monitor the developments that result from this new Council, in the meantime.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More