Skip to content

Cyber Liability by state

Texas data breach notification law and cyber insurance

Direct answer

What is Texas's data breach notification law?

Texas's breach notification law (Tex. Bus. & Com. Code sect. 521.053) requires businesses to notify affected residents without unreasonable delay and not later than 60 days after determining that a breach occurred after a breach of personal information. Texas requires businesses to notify affected residents within 60 days of determining a breach, with Attorney General notice within 30 days when 250 or more residents are affected.

Reviewed by Cornerstone Staff28 years of financial services state licensing experienceLast verified July 29, 2026

What the statute requires

Texas requires businesses to notify affected residents within 60 days of determining a breach, with Attorney General notice within 30 days when 250 or more residents are affected. Cyber liability insurance typically covers the forensics, notification, and legal review this statute drives.

Consumer notification deadline
Without unreasonable delay and not later than 60 days after determining that a breach occurred
Regulator notice
Notify the Texas Attorney General not later than 30 days after determining a breach occurred when it affects 250 or more Texas residents.
Credit bureau notice
Notify consumer reporting agencies when a breach requires notice to more than 10,000 residents.
Safe harbor
Notification is not required if the compromised data was encrypted and the encryption key was not acquired.
Enforcement
Violations are enforceable by the Attorney General, who may seek civil penalties for each breach subject to a statutory cap.

Statutes and sources

  • Texas Identity Theft Enforcement and Protection Act

    Tex. Bus. & Com. Code sect. 521.053

Regulator: Texas Attorney General . Last verified 2026-07-29 from the official source .

Get Texas coverage handled

Share a few details and an agent will respond within one business day.