Texas 2019 - 86th Regular

Texas House Bill HB4390 Compare Versions

OldNewDifferences
1-H.B. No. 4390
1+By: Capriglione, et al. (Senate Sponsor - Nelson) H.B. No. 4390
2+ (In the Senate - Received from the House May 8, 2019;
3+ May 10, 2019, read first time and referred to Committee on Business &
4+ Commerce; May 20, 2019, reported adversely, with favorable
5+ Committee Substitute by the following vote: Yeas 9, Nays 0;
6+ May 20, 2019, sent to printer.)
7+Click here to see the committee vote
8+ COMMITTEE SUBSTITUTE FOR H.B. No. 4390 By: Nichols
29
310
11+ A BILL TO BE ENTITLED
412 AN ACT
513 relating to the privacy of personal identifying information and the
614 creation of the Texas Privacy Protection Advisory Council.
715 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
816 SECTION 1. Section 521.053, Business & Commerce Code, is
917 amended by amending Subsection (b) and adding Subsection (i) to
1018 read as follows:
1119 (b) A person who conducts business in this state and owns or
1220 licenses computerized data that includes sensitive personal
1321 information shall disclose any breach of system security, after
1422 discovering or receiving notification of the breach, to any
1523 individual whose sensitive personal information was, or is
1624 reasonably believed to have been, acquired by an unauthorized
1725 person. The disclosure shall be made without unreasonable delay and
1826 in each case not later than the 60th day after the date on which the
1927 person determines that the breach occurred [as quickly as
2028 possible], except as provided by Subsection (d) or as necessary to
2129 determine the scope of the breach and restore the reasonable
2230 integrity of the data system.
2331 (i) A person who is required to disclose or provide
2432 notification of a breach of system security under this section
2533 shall notify the attorney general of that breach not later than the
2634 60th day after the date on which the person determines that the
2735 breach occurred if the breach involves at least 250 residents of
2836 this state. The notification under this subsection must include:
2937 (1) a detailed description of the nature and
3038 circumstances of the breach or the use of sensitive personal
3139 information acquired as a result of the breach;
3240 (2) the number of residents of this state affected by
3341 the breach at the time of notification;
3442 (3) the measures taken by the person regarding the
3543 breach;
3644 (4) any measures the person intends to take regarding
3745 the breach after the notification under this subsection; and
3846 (5) information regarding whether law enforcement is
3947 engaged in investigating the breach.
4048 SECTION 2. (a) In this section, "council" means the Texas
4149 Privacy Protection Advisory Council created under this section.
4250 (b) The Texas Privacy Protection Advisory Council is
4351 created to study data privacy laws in this state, other states, and
4452 relevant foreign jurisdictions.
4553 (c) The council is composed of members who are residents of
4654 this state and appointed as follows:
4755 (1) five members appointed by the speaker of the house
4856 of representatives, two of whom must be representatives of an
4957 industry listed under Subsection (d) of this section and three of
5058 whom must be members of the house of representatives;
5159 (2) five members appointed by the lieutenant governor,
5260 two of whom must be representatives of an industry listed under
5361 Subsection (d) of this section and three of whom must be senators;
5462 and
5563 (3) five members appointed by the governor, three of
5664 whom must be representatives of an industry listed under Subsection
5765 (d) of this section and two of whom must be either:
5866 (A) a representative of a nonprofit organization
5967 that studies or evaluates data privacy laws from the perspective of
6068 individuals whose information is collected or processed by
6169 businesses; or
6270 (B) a professor who teaches at a law school in
6371 this state or other institution of higher education, as defined by
6472 Section 61.003, Education Code, and whose books or scholarly
6573 articles on the topic of data privacy have been published.
6674 (d) For purposes of making appointments of members who
6775 represent industries under Subsection (c) of this section, the
6876 speaker of the house of representatives, lieutenant governor, and
6977 governor shall appoint members from among the following industries
7078 and must coordinate their appointments to avoid overlap in
7179 representation of the industries:
7280 (1) medical profession;
7381 (2) technology;
7482 (3) Internet;
7583 (4) retail and electronic transactions;
7684 (5) consumer banking;
7785 (6) telecommunications;
7886 (7) consumer data analytics;
7987 (8) advertising;
8088 (9) Internet service providers;
8189 (10) social media platforms;
8290 (11) cloud data storage;
8391 (12) virtual private networks; or
8492 (13) retail electric.
8593 (e) The speaker of the house of representatives and the
8694 lieutenant governor shall each designate a co-chair from among
8795 their respective appointments to the council who are members of the
8896 legislature.
8997 (f) The council shall convene on a regular basis at the
9098 joint call of the co-chairs.
9199 (g) The council shall:
92100 (1) study and evaluate the laws in this state, other
93101 states, and relevant foreign jurisdictions that govern the privacy
94102 and protection of information that alone or in conjunction with
95103 other information identifies or is linked or reasonably linkable to
96104 a specific individual, technological device, or household; and
97105 (2) make recommendations to the members of the
98106 legislature on specific statutory changes regarding the privacy and
99107 protection of that information, including changes to Chapter 521,
100108 Business & Commerce Code, as amended by this Act, or to the Penal
101109 Code, that appear necessary from the results of the council's study
102110 under this section.
103111 (h) Not later than September 1, 2020, the council shall
104112 report the council's findings and recommendations to the members of
105113 the legislature.
106114 (i) The Department of Information Resources shall provide
107115 administrative support to the council.
108116 (j) Not later than the 60th day after the effective date of
109117 this Act, the speaker of the house of representatives, the
110118 lieutenant governor, and the governor shall appoint the members of
111119 the council.
112120 (k) The council is abolished and this section expires
113121 December 31, 2020.
114122 SECTION 3. (a) Except as provided by Subsection (b) of this
115123 section, this Act takes effect September 1, 2019.
116124 (b) Section 521.053, Business & Commerce Code, as amended by
117125 this Act, takes effect January 1, 2020.
118- ______________________________ ______________________________
119- President of the Senate Speaker of the House
120- I certify that H.B. No. 4390 was passed by the House on May 7,
121- 2019, by the following vote: Yeas 140, Nays 0, 2 present, not
122- voting; and that the House concurred in Senate amendments to H.B.
123- No. 4390 on May 24, 2019, by the following vote: Yeas 138, Nays 3,
124- 2 present, not voting.
125- ______________________________
126- Chief Clerk of the House
127- I certify that H.B. No. 4390 was passed by the Senate, with
128- amendments, on May 22, 2019, by the following vote: Yeas 30, Nays
129- 1.
130- ______________________________
131- Secretary of the Senate
132- APPROVED: __________________
133- Date
134- __________________
135- Governor
126+ * * * * *