State Data Breach Notification Letter
Texas Data-Breach Notification Preparation Packet
1. Incident and Role Record
- Organization: [________________________________]
- Incident identifier: [________________________________]
- Incident discovery date and time: [__/__/____] [____:____]
- Date and time the organization determined a qualifying breach occurred: [__/__/____] [____:____]
- Decision maker and supporting investigation record: [________________________________]
- Data owner / license holder: [________________________________]
- Data custodian or service provider: [________________________________]
- Texas residents affected or reasonably believed affected: [________________________________]
- Total persons to be notified at one time: [________________________________]
- Texas counsel reviewer: [________________________________]
- Incident-response lead: [________________________________]
Select the organization's role for each affected dataset:
- ☐ Owns or licenses the computerized data and conducts business in Texas.
- ☐ Maintains computerized data owned or licensed by another person.
- ☐ Has different roles for different datasets; complete a separate row for each.
| Dataset | Owner / license holder | Maintainer | Contract-notice recipient | Confirmed role |
|---|---|---|---|---|
| [____________] | [____________] | [____________] | [____________] | [____________] |
2. Texas Trigger Analysis
A. Computerized Data and Sensitive Personal Information
- ☐ The incident involved computerized data.
- ☐ The affected data includes a first name or first initial plus last name combined with an unencrypted Social Security number.
- ☐ The affected data includes a first name or first initial plus last name combined with an unencrypted driver's-license or government-ID number.
- ☐ The affected data includes a first name or first initial plus last name combined with an unencrypted financial-account or card number plus the access credential needed to reach the account.
- ☐ The affected data identifies an individual and relates to physical or mental health, health care, or payment for health care.
- ☐ The information is not excluded publicly available government information.
- ☐ Another data type is involved; Texas counsel has identified the exact current authority: [________________________________].
B. Acquisition and Compromise
- ☐ There was unauthorized acquisition, not merely an unconfirmed attempt or exposure.
- ☐ The acquisition compromised the security, confidentiality, or integrity of covered sensitive personal information.
- ☐ If affected data was encrypted, the unauthorized person had the key required to decrypt it.
- ☐ Any employee or agent acquisition was outside good-faith purposes, or the employee or agent used or disclosed the information without authorization.
- ☐ The organization documented facts supporting each checked conclusion.
Decision:
- ☐ Texas Chapter 521 resident notice is required.
- ☐ Texas Chapter 521 resident notice is not required; counsel-approved basis: [________________________________].
- ☐ The facts remain incomplete; investigation owner and next decision date: [________________________________].
3. Deadline and Delay Calendar
A. Owner / License Holder Notice by a Maintainer
If § 521.053(c) applies:
- Discovery date and time: [__/__/____] [____:____]
- Immediate notice sent to owner or license holder: [__/__/____] [____:____]
- Recipient and delivery evidence: [________________________________]
B. Affected-Individual Notice by an Owner or License Holder
If § 521.053(b) applies:
- Breach determination date: [__/__/____]
- Day 60 after determination: [__/__/____]
- Planned individual-notice date: [__/__/____]
- Basis that notice will be made without unreasonable delay: [________________________________]
- Additional time used to determine scope or restore reasonable system integrity: [________________________________]
C. Law-Enforcement Delay
- ☐ No law-enforcement delay is being used.
- ☐ A law-enforcement agency requested delay and determined notice would impede a criminal investigation.
- Agency, official, date, and written record: [________________________________]
- Date agency determined notice would no longer compromise the investigation: [__/__/____]
- Rescheduled notice date: [__/__/____]
4. Notice-Channel Screen
Select and document the authorized route:
- ☐ Written notice to the individual's last known address.
- ☐ Electronic notice meeting 15 U.S.C. § 7001.
- ☐ Existing information-security-policy notice procedure that satisfies the Texas timing requirements.
- ☐ Substitute notice after counsel confirmed at least one statutory gate:
- ☐ estimated notice cost exceeds $250,000;
- ☐ affected-person count exceeds 500,000; or
- ☐ contact information is insufficient.
For substitute notice, counsel-approved channels:
- ☐ electronic mail where addresses are available;
- ☐ conspicuous website posting; and/or
- ☐ publication or broadcast through major statewide media.
Evidence supporting the channel decision: [________________________________]
5. Texas Attorney General Reporting Screen
A. Threshold and Deadline
- ☐ The breach involves fewer than 250 Texas residents; no § 521.053(i) report is triggered on that count.
- ☐ The breach involves at least 250 Texas residents; report electronically as soon as practicable and no later than day 30 after the breach determination.
- Determination date: [__/__/____]
- Day 30: [__/__/____]
- Planned submission date: [__/__/____]
- Authorized submitting representative: [________________________________]
B. Webform Preparation
Prepare all required information before opening the form because the OAG page states that the system cannot save progress.
| Required item | Verified response | Evidence owner |
|---|---|---|
| Detailed nature and circumstances of the breach or use of acquired SPI | [____________] | [____________] |
| Texas residents affected at submission | [____________] | [____________] |
| Affected Texas residents sent direct notice at submission | [____________] | [____________] |
| Measures already taken | [____________] | [____________] |
| Measures intended after submission | [____________] | [____________] |
| Whether law enforcement is investigating | [____________] | [____________] |
Operational checks:
- ☐ Submission is by an authorized agent.
- ☐ A separate webform is prepared for each separate breach.
- ☐ Potential open-record disclosure has been reviewed; no privileged or unnecessary sensitive material is included.
- ☐ The confirmation email and record number will be retained.
- ☐ A supplemental filing, if needed, will state total affected and notified consumers to date and all affected information types.
Current OAG reporting page: https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting
6. Nationwide Consumer-Reporting-Agency Screen
- ☐ Notification is required at one time to 10,000 or fewer persons; § 521.053(h) is not triggered by count.
- ☐ Notification is required at one time to more than 10,000 persons; notify each nationwide consumer reporting agency without unreasonable delay.
- Timing, distribution, and content summary supplied to CRAs: [________________________________]
- CRA recipients, dates, and delivery evidence: [________________________________]
7. Other-Law and Contract Overlay
- ☐ Every affected person's state of residence has been identified.
- ☐ Other-state notice, content, timing, regulator, and CRA duties have been reviewed.
- ☐ Federal or sector-specific duties have been reviewed, including any applicable health, financial, education, communications, government-contractor, or critical-infrastructure rule.
- ☐ Contractual customer, insurer, cyber-policy, vendor, and law-enforcement notice duties have been reviewed.
- ☐ The organization has not assumed that Texas compliance completes every other notification duty.
Draft Affected-Individual Notice
[DATE]
[RECIPIENT NAME]
[ADDRESS]
[CITY, STATE ZIP]
Re: Notice of Data Security Incident
Dear [RECIPIENT NAME]:
What Happened
On [DETERMINATION DATE], [ORGANIZATION] determined that [concise, verified description of unauthorized acquisition and relevant dates]. The incident occurred or may have occurred between [START DATE] and [END DATE]. We discovered the incident on [DISCOVERY DATE].
What Information Was Involved
Our investigation determined that the affected information relating to you included [list only verified data elements]. [State whether each listed element was encrypted and whether any decryption key was acquired, if verified and useful.]
What We Are Doing
We [describe verified containment, investigation, restoration, security, vendor, and law-enforcement measures]. We are also [describe any credit monitoring, identity protection, or other assistance accurately, including provider, term, activation deadline, exclusions, and enrollment method].
What You Can Do
You may review account statements and credit reports for activity you do not recognize and follow the account provider's reporting instructions. Additional incident-specific steps include:
- [________________________________]
- [________________________________]
- [________________________________]
If offering fraud-alert, credit-freeze, identity-theft, medical-identity, or tax-identity resources, attach a counsel-reviewed resource sheet containing current contact information and instructions appropriate to the affected data.
For More Information
Contact [ORGANIZATION OR RESPONSE CENTER] at [PHONE], [EMAIL OR WEB ADDRESS], during [HOURS AND TIME ZONE]. Reference incident [IDENTIFIER].
Sincerely,
[AUTHORIZED NAME]
[TITLE]
[ORGANIZATION]
Final Release Checklist
- ☐ Every factual statement was checked against the current investigation record.
- ☐ No unsupported assurance states that information was not accessed, acquired, used, or misused.
- ☐ The recipient population and address list were quality-checked.
- ☐ The notice method and send date satisfy the approved legal calendar.
- ☐ Assistance terms, activation deadlines, and vendor instructions are accurate.
- ☐ Texas AG reporting and nationwide CRA reporting were separately completed or documented as not triggered.
- ☐ Other-state, federal, sector, contractual, and insurance overlays were completed.
- ☐ Legal, privacy, security, communications, and executive approvals were recorded.
- ☐ Copies, delivery evidence, OAG confirmation, and the decision record will be retained under the approved retention schedule.
Current Official References
- Texas Legislature, Business and Commerce Code Chapter 521: https://tcss.legis.texas.gov/resources/BC/htm/BC.521.htm
- Texas Office of the Attorney General, Data Breach Reporting: https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting
Verified August 29, 2026. Sections 521.002 and 521.053 were checked against the current official Legislature text. The mandatory bill-index screen surfaced enacted 2025 H.B. 150, but the official enrolled bill only cross-references §§ 521.002 and 521.053 and does not amend them; the current § 521.053 history ends with 2023 S.B. 768. No case citations appear in this file.
About this template
- Last updated
- August 29, 2026
- Citations checked
- August 29, 2026
- Jurisdiction
- Texas
- Category
- Legal Letters & Correspondence
Legal authority
- Tex. Bus. & Com. Code § 521.002(2), (b) (sensitive personal information)
- Tex. Bus. & Com. Code § 521.053(a)-(d) (breach trigger, roles, timing, and law-enforcement delay)
- Tex. Bus. & Com. Code § 521.053(e)-(h) (notice methods, substitute notice, policy notice, and nationwide CRA notice)
- Tex. Bus. & Com. Code § 521.053(i) (Texas Attorney General electronic reporting)
Formal legal letters create a written record, trigger response deadlines, and often preserve rights under a statute or contract. Cease-and-desist letters, notice letters, and formal responses all have their own expected format, and the language used can mean the difference between a quick resolution and a courtroom fight. Well-drafted correspondence also documents that you tried to resolve things reasonably, which matters if the dispute escalates later.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on August 29, 2026.
Tex. Bus. & Com. Code § 521.002(2), (b) (sensitive personal information) (checked August 29, 2026): ""Sensitive personal information" means, subject to Subsection (b): (A) an individual's first name or first initial and last name in combination with any one or more of the following items, if the name and the items are not encrypted: (i) social security number; (ii) driver's license number or government-issued identification number; or (iii) account number or credit or debit card number in combination with any required security code, access code, or password that would permit access to an individual's financial account; or (B) information that identifies an individual and relates to: (i) the physical or mental health or condition of the individual; (ii) the provision of health care to the individual; or (iii) payment for the provision of health care to the individual. For purposes of this chapter, the term "sensitive personal information" does not include publicly available information that is lawfully made available to the public from the federal government or a state or local government."
Tex. Bus. & Com. Code § 521.053(a)-(d) (breach trigger, roles, timing, and law-enforcement delay) (checked August 29, 2026): ""Breach of system security" means unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person, including data that is encrypted if the person accessing the data has the key required to decrypt the data. Good faith acquisition of sensitive personal information by an employee or agent of the person for the purposes of the person is not a breach of system security unless the person uses or discloses the sensitive personal information in an unauthorized manner. A person who conducts business in this state and owns or licenses computerized data that includes sensitive personal information shall disclose any breach of system security, after discovering or receiving notification of the breach, to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. The disclosure shall be made without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred, except as provided by Subsection (d) or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Any person who maintains computerized data that includes sensitive personal information not owned by the person shall notify the owner or license holder of the information of any breach of system security immediately after discovering the breach, if the sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person. A person may delay providing notice as required by Subsection (b) or (c) at the request of a law enforcement agency that determines that the notification will impede a criminal investigation. The notification shall be made as soon as the law enforcement agency determines that the notification will not compromise the investigation."
Tex. Bus. & Com. Code § 521.053(e)-(h) (notice methods, substitute notice, policy notice, and nationwide CRA notice) (checked August 29, 2026): "A person may give notice as required by Subsection (b) or (c) by providing: (1) written notice at the last known address of the individual; (2) electronic notice, if the notice is provided in accordance with 15 U.S.C. Section 7001; or (3) notice as provided by Subsection (f). If the person required to give notice under Subsection (b) or (c) demonstrates that the cost of providing notice would exceed $250,000, the number of affected persons exceeds 500,000, or the person does not have sufficient contact information, the notice may be given by: (1) electronic mail, if the person has electronic mail addresses for the affected persons; (2) conspicuous posting of the notice on the person's website; or (3) notice published in or broadcast on major statewide media. Notwithstanding Subsection (e), a person who maintains the person's own notification procedures as part of an information security policy for the treatment of sensitive personal information that complies with the timing requirements for notice under this section complies with this section if the person notifies affected persons in accordance with that policy. If a person is required by this section to notify at one time more than 10,000 persons of a breach of system security, the person shall also notify each consumer reporting agency, as defined by 15 U.S.C. Section 1681a, that maintains files on consumers on a nationwide basis, of the timing, distribution, and content of the notices. The person shall provide the notice required by this subsection without unreasonable delay."
Tex. Bus. & Com. Code § 521.053(i) (Texas Attorney General electronic reporting) (checked August 29, 2026): "A person who is required to disclose or provide notification of a breach of system security under this section shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred if the breach involves at least 250 residents of this state. The notification under this subsection must be submitted electronically using a form accessed through the attorney general's Internet website and must include: (1) a detailed description of the nature and circumstances of the breach or the use of sensitive personal information acquired as a result of the breach; (2) the number of residents of this state affected by the breach at the time of notification; (3) the number of affected residents that have been sent a disclosure of the breach by mail or other direct method of communication at the time of notification; (4) the measures taken by the person regarding the breach; (5) any measures the person intends to take regarding the breach after the notification under this subsection; and (6) information regarding whether law enforcement is engaged in investigating the breach."
Draft your State Data Breach Notification Letter in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.