Recent news from the legislative department of Texas indicates a significant amendment in its data breach notification law. The updated law will be effective starting from September 1, 2023. According to the legal professionals of Sheppard Mullin Richter & Hampton LLP, there are two notable changes to the requirements for notifying the Texas Attorney General about a data breach.
Under the current law, any data breach affecting 250 or more residents of Texas must be reported to the Attorney General by the entity suffering the breach. However, post-amendment, the requirements for such notification has been refreshed significantly.
The two key changes that will go into effect from September 1st are expected to have major implications for corporations and law firms alike, particularly those dealing with large volumes of sensitive and personal data from Texas residents.
- The first change is related to the content of the notification to be provided to the Texas Attorney General. Additional data, such as the nature and circumstances of the breach, the number of residents affected, and measures taken in response to the breach, will be obligatory, enhancing the depth of reporting and potentially improving data breach identification and control measures.
- The second change concerns with the timeline within which the Texas Attorney General should be notified about a breach. As per the amendment, if more than 250 Texas residents are affected, the Attorney General must be notified no later than the 60th day after the date the breach was determined, tightening the notification window and imposing stricter control over rapid response and communication.
These changes are part of Texas’s broader initiative to refine its data protection and privacy laws. All corporations and law firms dealing with Texan clientele, directly or indirectly, are urged to follow these changes closely and ensure their data breach response plans are updated accordingly.