1 | 1 | | 88R14400 SHH-D |
---|
2 | 2 | | By: Lalani H.B. No. 4761 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | A BILL TO BE ENTITLED |
---|
6 | 6 | | AN ACT |
---|
7 | 7 | | relating to the notification required following a breach of |
---|
8 | 8 | | security of computerized data. |
---|
9 | 9 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
10 | 10 | | SECTION 1. Sections 521.053(b) and (i), Business & Commerce |
---|
11 | 11 | | Code, are amended to read as follows: |
---|
12 | 12 | | (b) A person who conducts business in this state and owns or |
---|
13 | 13 | | licenses computerized data that includes sensitive personal |
---|
14 | 14 | | information shall disclose any breach of system security, after |
---|
15 | 15 | | discovering or receiving notification of the breach, to any |
---|
16 | 16 | | individual whose sensitive personal information was, or is |
---|
17 | 17 | | reasonably believed to have been, acquired by an unauthorized |
---|
18 | 18 | | person. The disclosure shall be made without unreasonable delay |
---|
19 | 19 | | and in each case not later than the 30th [60th] day after the date on |
---|
20 | 20 | | which the person determines that the breach occurred, except as |
---|
21 | 21 | | provided by Subsection (d) or as necessary to determine the scope of |
---|
22 | 22 | | the breach and restore the reasonable integrity of the data system. |
---|
23 | 23 | | (i) A person who is required to disclose or provide |
---|
24 | 24 | | notification of a breach of system security under this section |
---|
25 | 25 | | shall notify the attorney general of that breach not later than the |
---|
26 | 26 | | 30th [60th] day after the date on which the person determines that |
---|
27 | 27 | | the breach occurred if the breach involves at least 250 residents of |
---|
28 | 28 | | this state. The notification under this subsection must include: |
---|
29 | 29 | | (1) a detailed description of the nature and |
---|
30 | 30 | | circumstances of the breach or the use of sensitive personal |
---|
31 | 31 | | information acquired as a result of the breach; |
---|
32 | 32 | | (2) the number of residents of this state affected by |
---|
33 | 33 | | the breach at the time of notification; |
---|
34 | 34 | | (3) the number of affected residents that have been |
---|
35 | 35 | | sent a disclosure of the breach by mail or other direct method of |
---|
36 | 36 | | communication at the time of notification; |
---|
37 | 37 | | (4) the measures taken by the person regarding the |
---|
38 | 38 | | breach; |
---|
39 | 39 | | (5) any measures the person intends to take regarding |
---|
40 | 40 | | the breach after the notification under this subsection; and |
---|
41 | 41 | | (6) information regarding whether law enforcement is |
---|
42 | 42 | | engaged in investigating the breach. |
---|
43 | 43 | | SECTION 2. This Act takes effect September 1, 2023. |
---|