
Small Business Data Breach Notification Checklist for Texas
Use this Texas data breach notification checklist to meet the 60-day deadline, avoid penalties, and protect your small business after a data incident.
By Jeffrey Connors
A single stolen laptop, a phishing email that tricks one employee, or a payment terminal skimmer can trigger a legal clock that most Texas small business owners have never heard of. Under the Texas Business and Commerce Code, if your business owns or licenses computerized data containing personal information, you may be required to notify affected individuals, the Texas Attorney General, and sometimes consumer reporting agencies, all within a compressed timeline. Miss those deadlines and you can face penalties that dwarf the cost of the breach itself. This checklist walks you through what to do, step by step, so you can respond fast, document your decisions, and protect your business from avoidable liability.
What Counts as a Breach Under Texas Law
Texas defines a breach as unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of personal information. Personal information generally means a person's first name or initial plus last name combined with a data element such as a Social Security number, driver's license number, government-issued ID number, account or credit card number, or information that would let someone access a financial account. The law also covers usernames or email addresses combined with passwords or security questions that permit account access.
Two words in that definition matter enormously in practice: "computerized" and "unauthorized acquisition." If paper files are stolen from a locked office, the Texas statute may not apply, though other obligations or contractual duties might. If an encrypted laptop is lost and the encryption key was not compromised, the acquisition is generally not considered a reportable breach. That is why encryption, both at rest and in transit, is one of the cheapest risk management tools a small business can deploy.
There is also a good-faith exception. If an employee accidentally accesses data but does not retain, use, or disclose it, and the business reasonably determines no harm is likely, notification may not be required. Document that determination in writing. A regulator reviewing your response will want to see how you reached it, who was involved, and what evidence supported the conclusion.
Your Texas Data Breach Notification Checklist
Work through these steps in order. The sequence matters because the 60-day notification clock starts when you determine a breach occurred, not when you finish investigating every detail. Waiting for a perfect picture of what happened can cost you the ability to comply on time.
- Contain the breach immediately. Disconnect affected systems, reset compromised credentials, revoke access tokens, and preserve logs before anything is wiped. Notify your IT provider or managed service provider and instruct them to keep forensic images intact.
- Assemble your response team. Identify who will lead the investigation, who will handle legal questions, who will communicate with customers, and who will manage the insurance claim. For a small business, that may be three people wearing several hats.
- Determine whether notification is required. Confirm what data was involved, whether it was computerized, whether encryption protected it, and whether a good-faith exception applies. Write down your reasoning.
- Notify affected Texas residents within 60 days. The notice must be clear, describe the incident in general terms, list the categories of information involved, and give contact information for the business and the major credit reporting agencies.
- Notify the Texas Attorney General. If the breach involves 250 or more Texas residents, you must submit notice to the Attorney General no later than 30 days after you notify individuals.
- Notify consumer reporting agencies if the threshold is met. If more than 10,000 people are notified at one time, you must also alert nationwide consumer reporting agencies without unreasonable delay.
- Document everything. Keep a written record of the timeline, decisions, notifications sent, and remediation steps. This record is your best defense if the Attorney General or a plaintiff's attorney comes asking questions.
For a deeper look at the timing rules and how they interact with federal and industry-specific requirements, see this explanation of the Texas data breach notification law. The 60-day and 30-day windows are not suggestions. They are statutory deadlines that regulators track carefully.
What the 60-Day Clock Actually Requires
The 60-day deadline is measured from the moment you determine that a breach occurred, not from the moment you first suspect one. That distinction trips up many small businesses. An incident that looks like a breach on Monday may turn out to be a false alarm by Friday, but if you conclude on Friday that it is real, the clock starts Friday, not Monday. Conversely, if you determine on Monday that a breach occurred and spend six weeks investigating before notifying anyone, you may already be out of compliance.
The notice itself has content requirements. It must be written in plain language, be titled clearly, describe the incident in general terms, identify the categories of personal information involved, provide a toll-free number and address for questions, and list the contact information for the three major credit reporting agencies. If you do not have a toll-free number, you can designate a telephone number, an email address, or a website where affected individuals can get information. The goal is to make it easy for a worried customer to reach a real person.
Texas allows substitute notice in limited situations, such as when the cost of providing notice would exceed $250,000, when more than 500,000 people are affected, or when you do not have sufficient contact information. In those cases, you can post a conspicuous notice on your website, notify major statewide media, and use email if you have addresses. Substitute notice is a fallback, not a shortcut. Document why you chose it.
Attorney General Notice and Reporting Thresholds
The 250-resident threshold for Attorney General notice is lower than many business owners expect. A breach affecting a few hundred customers can trigger a state-level filing. The filing is separate from individual notice, and the deadline is 30 days after you send individual notices. If you notify individuals on day 45, the Attorney General filing is due by day 75.
When you file with the Attorney General, include the number of Texas residents notified, a detailed description of the incident, the measures taken or planned in response, and information about whether law enforcement is investigating. The Attorney General's office publishes information about reported breaches, so accuracy matters. Do not guess at numbers. If your count changes as the investigation continues, update your filing.
If more than 10,000 people are notified at one time, you also need to notify nationwide consumer reporting agencies. Those agencies include Equifax, Experian, and TransUnion. They maintain fraud alert systems and can help affected individuals protect themselves. Coordinate the timing so the agencies are not blindsided by a wave of calls from consumers who learned about the breach before the agencies did.
Cyber Liability Insurance: Your Financial Backstop
Notification costs add up quickly. Printing and mailing letters, setting up a call center, offering credit monitoring, paying forensics experts, and covering legal review can easily run into tens of thousands of dollars for a small business. Cyber liability insurance is designed to cover many of those costs, and it often includes breach response services that can take over the notification process for you.
A typical cyber liability policy can cover forensic investigation, legal counsel, notification and credit monitoring, public relations, business interruption, and even ransom payments in some cases. The key is to review your policy before an incident happens so you know who to call, what the deductible is, and what sublimits apply. Many carriers have preferred vendors for forensics and notification, and using those vendors can speed up reimbursement.
If you do not currently carry cyber coverage, this is the moment to price it. Texas businesses that handle customer data, process payments, or store employee records are all exposed. If you are comparing coverage options and looking for proven ways to cut Texas small business insurance costs, bundling cyber liability with your general liability or business owners policy is often the most efficient path. A licensed independent agency can compare multiple carriers and find a package that fits your risk profile and budget.
Building a Breach Response Plan Before You Need One
The best time to build a breach response plan is before you have a breach. A written plan does not need to be long. It needs to identify who does what, who to call, and how to document decisions. Keep a printed copy somewhere accessible because your systems may be locked down during an incident.
Your plan should include contact information for your IT provider, your attorney, your insurance broker, and your carrier's claims line. It should include templates for customer notification letters and Attorney General filings. It should include a communication protocol so that only authorized people speak to the media or to customers. And it should include a schedule for testing and updating the plan at least once a year.
Train your employees on phishing, password hygiene, and how to report a suspected incident. Most small business breaches start with a single click on a malicious link or a reused password. A short quarterly training session and a clear reporting channel can prevent the incident that would otherwise trigger the entire notification process. Pair that training with technical controls such as multi-factor authentication, endpoint protection, and regular backups that are tested for restoration.
Finally, review your vendor contracts. If a third-party vendor holds your data and suffers a breach, you need to know who is responsible for notification and who pays for it. Push for clear language that requires the vendor to notify you promptly, cooperate with your investigation, and carry its own cyber liability coverage. Your customers will look to you, not your vendor, when their data is exposed, so protect your ability to respond.
Texas small businesses face real exposure when data is compromised, but the path through a breach is manageable when you have a checklist, the right insurance, and a team that knows what to do. Start with the steps above, confirm your coverage, and keep your response plan current. If you need help finding cyber liability or other commercial coverage that fits your Texas business, request a free quote from a licensed independent agency and get guidance tailored to your trade and contracts.