Tag Archives: Texas

Texas

Who Is Covered?

A person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. Tex. Bus. & Com. Code § 521.053(b).

 

What Information Is Protected?

“Personal identifying information” means information that alone or in conjunction with other information identifies an individual, including an individual’s:

 

  1. Name, social security number, date of birth, or government-issued identification number;
  2. Mother’s maiden name;
  3. Unique biometric data, including the individual’s fingerprint, voice print, and retina or iris image;
  4. Unique electronic identification number, address, or routing code; and
  5. Telecommunication access device as defined by Section 32.51, Penal Code. Tex. Bus. & Com. Code § 521.002(a)(1).

“Sensitive personal information” means:

 

  1. An individual’s first name or first initial and last name in combination with any one or more of the following items, if the name and the items are not encrypted: (i) social security number; (ii) driver’s license number or government-issued identification number; or (iii) account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to an individual’s financial account; or
  2. Information that identifies an individual and relates to: (i) the physical or mental health or condition of the individual; (ii) the provision of health care to the individual; or (iii) payment for the provision of health care to the individual. Tex. Bus. & Com. Code § 521.002(a)(2).

 

What Is A “Breach”?

“Breach of system security” means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data. Good faith acquisition of sensitive personal information by an employee or agent of the person for the purposes of the person is not a breach of system security unless the person uses or discloses the sensitive personal information in an unauthorized manner. Tex. Bus. & Com. Code § 521.053(a).

 

What Triggers Notification?

Discovering or receiving notification of the breach where any individual’s sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Tex. Bus. & Com. Code § 521.053(b).

 

How Is Notice Provided To Individuals?

Non-Residents: If the individual whose sensitive personal information was or is reasonably believed to have been acquired by an unauthorized person is a resident of a state that requires a person [under Texas law] to provide notice of a breach of system security, the notice of the breach of system security may be provided under that state’s law or under Texas law. Tex. Bus. & Com. Code § 521.053(b-1).

Timing: The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as necessary for the needs of law enforcement or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Tex. Bus. & Com. Code § 521.053(b), (d).

Delivery: Notice may be provided by:

 

  1. Written notice at the last known address of the individual;
  2. Electronic notice, if the notice is provided in accordance with 15 U.S.C. Section 7001; or
  3. Substitute notice if it is demonstrated that the cost of providing notice would exceed $250,000, the number of affected persons exceeds 500,000, or the person does not have sufficient contact information, in which case the notice may be given by: a) electronic mail, if the person has electronic mail addresses for the affected persons; b) conspicuous posting of the notice on the person’s website; or c) notice published in or broadcast on major statewide media. Tex. Bus. & Com. Code § 521.053(e), (f).

Content: None specified.

 

Is Notice To The Government Required?

Yes. A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state. The notification under this subsection must be submitted electronically using a form accessed through the attorney general’s Internet website and must include:

 

  1. A detailed description of the nature and circumstances of the breach or the use of sensitive personal information acquired as a result of the breach;
  2. The number of residents of this state affected by the breach at the time of notification;
  3. the number of affected residents that have been sent a disclosure of the breach by mail or other direct method of communication at the time of notification;
  4. The measures taken by the person regarding the breach;
  5. Any measures the person intends to take regarding the breach after the notification under this subsection; and
  6. Information regarding whether law enforcement is engaged in investigating the breach. Tex. Bus. & Com. Code § 521.053(i).

 

Is Notice To Credit Reporting Agencies Required?

Yes. If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency of the timing, distribution, and content of the notices. The person shall provide the notice required by this subsection without unreasonable delay. Tex. Bus. & Com. Code § 521.053(h).

 

Are There Security Measure Standards?

Yes. A business shall implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information collected or maintained by the business in the regular course of business. Tex. Bus. & Com. Code § 521.052(a).

Additionally, a business shall destroy or arrange for the destruction of customer records containing sensitive personal information within the business’s custody or control that are not to be retained by the business by:(1) shredding; (2) erasing; or (3) otherwise modifying the sensitive personal information in the records to make the information unreadable or indecipherable through any means. Tex. Bus. & Com. Code § 521.052(b).

 

What Are The Possible Consequences Of A Violation?

A person who violates this chapter is liable to this state for a civil penalty of at least $2,000 but not more than $50,000 for each violation. The attorney general may bring an action to recover the civil penalty imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a).

In addition to penalties assessed under Subsection (a), a person who fails to take reasonable action to comply with Section 521.053(b) is liable to this state for a civil penalty of not more than $100 for each individual to whom notification is due under that subsection for each consecutive day that the person fails to take reasonable action to comply with that subsection. Civil penalties under this section may not exceed $250,000 for all individuals to whom notification is due after a single breach. The attorney general may bring an action to recover the civil penalties imposed under this subsection. Tex. Bus. & Com. Code § 521.151(a-1).

 

Are There Any Exemptions/Exceptions?

A person who maintains the person’s own notification procedures as part of an information security policy for the treatment of sensitive personal information that complies with the timing requirements for notice under this section complies with this section if the person notifies affected persons in accordance with that policy. Tex. Bus. & Com. Code § 521.053(g).