Texas 2017 - 85th Regular

Texas Senate Bill SB1409

Voted on by Senate
 
Out of House Committee
 
Voted on by House
 
Governor Action
 
Bill Becomes Law
 

Caption

Relating to a breach of system security of a business that exposes consumer credit card or debit card information; providing a civil penalty.

Impact

One of the notable components of SB1409 is the creation of the Data Security Breach Victim Compensation Fund, which is intended to provide financial restitution to consumers who suffer losses due to a security breach. Additionally, the bill imposes civil penalties on businesses that fail to secure their systems adequately. Specifically, businesses could be liable for a civil penalty of $50 for each credit or debit card affected by the breach, which would be collected and deposited into the compensation fund. This penalty acts as both a deterrent against inadequate security measures and a means of recovering some costs associated with breaches.

Summary

Senate Bill 1409 aims to address security breaches involving the unauthorized acquisition of sensitive personal information, particularly focusing on consumer credit and debit card data. The bill establishes necessary amendments to the Business & Commerce Code to enhance the requirements for businesses in the event of a security breach. It compels businesses that accept card payments to implement security measures to protect retained data and to notify the Attorney General and affected financial institutions within 24 hours of discovering a breach. This swift notification is crucial for preventing further financial harm to consumers and assisting in containment efforts.

Contention

Despite its protective intentions, SB1409 has the potential for contention among stakeholders. Proponents argue that the bill will enhance consumer protections and improve accountability among businesses regarding their cybersecurity practices. Conversely, some opponents may feel that the civil penalties could be excessively burdensome for smaller businesses, particularly those already struggling with compliance costs. Discussions may also arise regarding the effectiveness of the proposed fund in supporting impacted consumers and whether it adequately addresses the long-term implications of data breaches on consumer trust.

Companion Bills

TX HB2333

Identical Relating to a breach of system security of a business that exposes consumer credit card or debit card information; providing a civil penalty.

Previously Filed As

TX HB4

Relating to the regulation of the collection, use, processing, and treatment of consumers' personal data by certain business entities; imposing a civil penalty.

TX SB2377

Relating to homeland security, including the creation of the Texas Homeland Security Division in the Department of Public Safety, the operations of the Homeland Security Council, the creation of a homeland security fusion center, and the duties of state agencies and local governments in preparing for, reporting, and responding to cybersecurity breaches; providing administrative penalties; creating criminal offenses.

TX HB1844

Relating to the regulation of the collection, use, processing, and treatment of consumers' personal data by certain business entities; imposing a civil penalty.

TX SB2105

Relating to the registration of and certain other requirements relating to data brokers; providing a civil penalty and authorizing a fee.

TX SB768

Relating to the process for notifying the attorney general of a breach of security of computerized data by persons doing business in this state.

TX HB1660

Relating to the process for notifying the attorney general of a breach of security of computerized data by persons doing business in this state.

TX SB895

Relating to the regulation of money services businesses; creating a criminal offense; creating administrative penalties; authorizing the imposition of a fee.

TX HB4917

Relating to the regulation of third-party data collection entities; providing a civil penalty and authorizing a fee.

TX SB1204

Relating to state and local government information technology and information security.

TX HB4761

Relating to the notification required following a breach of security of computerized data.

Similar Bills

No similar bills found.