September 16, 2019

September 13, 2019

Subscribe to Latest Legal News and Analysis

Texas Breach Law Will Change in 2020, To Require Attorney General Notification

New requirements to the Texas data breach statute, including a requirement to notify the Texas attorney general of a breach, are set to go into effect January 1, 2020. The legislation, signed by Texas Governor, Greg Abbot, on June 14, 2019, requires that the Texas attorney general be notified of a breach within 60 days. The AG notification is required only if 250 or more Texas residents are affected. The notification to the attorney general must include a description of the breach, number of residents affected, measures taken in response to the breach, measures planned to be taken after notification and whether law enforcement has been engaged with the investigation.  The legislation also adds a 60 day timing requirement for notice, from the current “as quickly as possible” standard.

In an unusual step for breach notice laws, the legislation also creates a “Texas Privacy Protection Advisory Council.” This Council is tasked with studying both Texas and other privacy laws, both domestic and foreign. Members of the Council will be in-state residents, and are to include someone from a nonprofit organization that looks at privacy from the consumer perspective, as well as a law school professor. The Council is tasked with making recommendations to the legislature in Texas on privacy law changes that “appear necessary from the results of the council’s study.” This development is interesting in light of the two Texas privacy bills that were recently introduced, the Texas Consumer Privacy Act and the Texas Privacy Protection Act.  The Council’s findings and recommendations are due September 1, 2020.

Putting it Into Practice: Companies with nationwide breach notice plans should work in the new requirement to notify the Texas attorney general prior to the January 1, 2020 effective date. We will continue to monitor the developments that result from this new Council, in the meantime.

Copyright © 2019, Sheppard Mullin Richter & Hampton LLP.

TRENDING LEGAL ANALYSIS


About this Author

Liisa Thomas, Sheppard Mullin Law Firm, Chicago, Cybersecurity Law Attorney
Partner

Liisa Thomas, a partner based in the firm’s Chicago and London offices, is Co-Chair of the Privacy and Cybersecurity Practice. Her clients rely on her ability to create clarity in a sea of confusing legal requirements and describe her as “extremely responsive, while providing thoughtful legal analysis combined with real world practical advice.” Liisa is the author of the definitive treatise on data breach, Thomas on Data Breach: A Practical Guide to Handling Worldwide Data Breach Notification, which has been described as “a no-nonsense roadmap for in-house and...

312-499-6335
Elfin Noce Business Trial Attorney
Associate

Elfin L. Noce is an Associate in the Business Trial Practice Group in the firm's Washington, D.C. office.

Practices

  • Litigation

Industries

  • Communications

Education

  • J.D., University of Missouri, Columbia, 2005

  • B.A., Truman State University, 2000

Admissions

  • *Not admitted in District of Columbia; supervised by partners of the firm

  • Missouri

202.747.2196