Texas 2023 - 88th Regular

Texas House Bill HB1660 Compare Versions

OldNewDifferences
11 88R3500 MLH-F
22 By: Capriglione H.B. No. 1660
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to the process for notifying the attorney general of a
88 breach of security of computerized data by persons doing business
99 in this state.
1010 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1111 SECTION 1. Sections 521.053(i) and (j), Business & Commerce
1212 Code, are amended to read as follows:
1313 (i) A person who is required to disclose or provide
1414 notification of a breach of system security under this section
1515 shall notify the attorney general of that breach as soon as
1616 practicable and not later than the 30th [60th] day after the date on
1717 which the person determines that the breach occurred if the breach
1818 involves at least 250 residents of this state. The notification
1919 under this subsection must be submitted electronically using a form
2020 accessed through the attorney general's Internet website and must
2121 include:
2222 (1) a detailed description of the nature and
2323 circumstances of the breach or the use of sensitive personal
2424 information acquired as a result of the breach;
2525 (2) the number of residents of this state affected by
2626 the breach at the time of notification;
2727 (3) the number of affected residents that have been
2828 sent a disclosure of the breach by mail or other direct method of
2929 communication at the time of notification;
3030 (4) the measures taken by the person regarding the
3131 breach;
3232 (5) any measures the person intends to take regarding
3333 the breach after the notification under this subsection; and
3434 (6) information regarding whether law enforcement is
3535 engaged in investigating the breach.
3636 (j) The attorney general shall post on the attorney
3737 general's publicly accessible Internet website:
3838 (1) an electronic form for submitting a notification
3939 under Subsection (i); and
4040 (2) a listing of the notifications received by the
4141 attorney general under Subsection (i), excluding any sensitive
4242 personal information that may have been reported to the attorney
4343 general under that subsection, any information that may compromise
4444 a data system's security, and any other information reported to the
4545 attorney general that is made confidential by law. The attorney
4646 general shall:
4747 (A) [(1)] update the listing not later than the
4848 30th day after the date the attorney general receives notification
4949 of a new breach of system security;
5050 (B) [(2)] remove a notification from the listing
5151 not later than the first anniversary of the date the attorney
5252 general added the notification to the listing if the person who
5353 provided the notification has not notified the attorney general of
5454 any additional breaches under Subsection (i) during that period;
5555 and
5656 (C) [(3)] maintain only the most recently
5757 updated listing on the attorney general's website.
5858 SECTION 2. This Act takes effect September 1, 2023.