Texas 2021 - 87th 1st C.S.

Texas House Bill HB307 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 87S10701 MWC-F
22 By: Shaheen H.B. No. 307
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to state agency and local government security incident
88 procedures.
99 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1010 SECTION 1. Section 2054.1125, Government Code, is
1111 transferred to Subchapter R, Chapter 2054, Government Code,
1212 redesignated as Section 2054.603, Government Code, and amended to
1313 read as follows:
1414 Sec. 2054.603 [2054.1125]. SECURITY INCIDENT [BREACH]
1515 NOTIFICATION BY STATE AGENCY OR LOCAL GOVERNMENT. (a) In this
1616 section:
1717 (1) "Security incident" means the unauthorized
1818 access, disclosure, exposure, modification, or destruction of
1919 sensitive personal information, confidential information, or other
2020 information the disclosure of which is regulated by law, including:
2121 (A) a breach ["Breach] of system security as
2222 defined [security" has the meaning assigned] by Section 521.053,
2323 Business & Commerce Code; and
2424 (B) ransomware as defined by Section 33.023,
2525 Penal Code.
2626 (2) "Sensitive personal information" has the meaning
2727 assigned by Section 521.002, Business & Commerce Code.
2828 (b) A state agency or local government that owns, licenses,
2929 or maintains computerized data that includes sensitive personal
3030 information, confidential information, or information the
3131 disclosure of which is regulated by law shall, in the event of a
3232 security incident [breach or suspected breach of system security or
3333 an unauthorized exposure of that information]:
3434 (1) comply with the notification requirements of
3535 Section 521.053, Business & Commerce Code, to the same extent as a
3636 person who conducts business in this state; [and]
3737 (2) not later than 72 [48] hours after the discovery of
3838 the security incident [breach, suspected breach, or unauthorized
3939 exposure], notify:
4040 (A) the department, including the chief
4141 information security officer, and the Texas Division of Emergency
4242 Management; or
4343 (B) if the security incident [breach, suspected
4444 breach, or unauthorized exposure] involves election data, the
4545 secretary of state; and
4646 (3) comply with all department rules relating to
4747 security incidents.
4848 (c) Not later than the 10th business day after the date of
4949 the eradication, closure, and recovery from a security incident
5050 [breach, suspected breach, or unauthorized exposure], a state
5151 agency or local government shall notify the department, including
5252 the chief information security officer, and the Texas Division of
5353 Emergency Management of the details of the security incident
5454 [event] and include in the notification an analysis of the cause of
5555 the security incident [event].
5656 (d) The department shall make available to state agencies
5757 and local governments a secure method for submitting the security
5858 incident information required by this section. All information
5959 provided under this section is confidential and is not subject to
6060 disclosure under Chapter 552.
6161 SECTION 2. This Act takes effect December 1, 2021.