Texas 2023 - 88th Regular

Texas House Bill HB4761 Compare Versions

OldNewDifferences
11 88R14400 SHH-D
22 By: Lalani H.B. No. 4761
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to the notification required following a breach of
88 security of computerized data.
99 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1010 SECTION 1. Sections 521.053(b) and (i), Business & Commerce
1111 Code, are amended to read as follows:
1212 (b) A person who conducts business in this state and owns or
1313 licenses computerized data that includes sensitive personal
1414 information shall disclose any breach of system security, after
1515 discovering or receiving notification of the breach, to any
1616 individual whose sensitive personal information was, or is
1717 reasonably believed to have been, acquired by an unauthorized
1818 person. The disclosure shall be made without unreasonable delay
1919 and in each case not later than the 30th [60th] day after the date on
2020 which the person determines that the breach occurred, except as
2121 provided by Subsection (d) or as necessary to determine the scope of
2222 the breach and restore the reasonable integrity of the data system.
2323 (i) A person who is required to disclose or provide
2424 notification of a breach of system security under this section
2525 shall notify the attorney general of that breach not later than the
2626 30th [60th] day after the date on which the person determines that
2727 the breach occurred if the breach involves at least 250 residents of
2828 this state. The notification under this subsection must include:
2929 (1) a detailed description of the nature and
3030 circumstances of the breach or the use of sensitive personal
3131 information acquired as a result of the breach;
3232 (2) the number of residents of this state affected by
3333 the breach at the time of notification;
3434 (3) the number of affected residents that have been
3535 sent a disclosure of the breach by mail or other direct method of
3636 communication at the time of notification;
3737 (4) the measures taken by the person regarding the
3838 breach;
3939 (5) any measures the person intends to take regarding
4040 the breach after the notification under this subsection; and
4141 (6) information regarding whether law enforcement is
4242 engaged in investigating the breach.
4343 SECTION 2. This Act takes effect September 1, 2023.