
Texas Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Texas requires breach notification within 60 days to individuals and 30 days to the AG. Penalties reach $50,000 per violation under the DTPA.
Loading...
Browse our full library of legal guides, state law breakdowns, and practical legal information.
11269 articles
Browse by Category →
Texas requires breach notification within 60 days to individuals and 30 days to the AG. Penalties reach $50,000 per violation under the DTPA.

New Jersey biometric privacy law under the NJDPA requires consent before collecting fingerprints, facial geometry, or voiceprints. Learn the rules, penalties, and your rights.

DC requires breach notification without unreasonable delay and AG notice when 50+ residents are affected. Learn about the private right of action, 18-month identity theft protection, and penalties.

West Virginia has no biometric privacy law, and its breach notification statute excludes biometric data. Learn about proposed HB 5567 and current protections.

New Jersey requires data breach notification within 30 days, with a unique 7-day rule for social media breaches. Learn about treble damages, AG and State Police reporting, and penalties up to $20K.

Alabama has no standalone biometric privacy law. Learn how the Data Breach Notification Act protects biometric data, penalties up to $500K, and employer obligations.

Maine requires data breach notification within 30 days. Learn who must comply, what triggers notification, encryption safe harbors, and penalties under state law.

New Mexico requires data breach notification within 45 days of discovery under N.M. Stat. 57-12C. Learn about biometric data coverage, AG reporting, HIPAA/GLBA exemptions, and enforcement.

Learn how Virginia's VCDPA protects biometric data like fingerprints and iris scans. Opt-in consent required, AG enforcement, up to $7,500 per violation.

Florida biometric privacy law covers fingerprints, voiceprints, and iris scans under the FDBR. Learn opt-out rights, penalties, and the $1B threshold.

Connecticut requires 60-day breach notification, 24-month credit monitoring for SSN breaches, and AG reporting. Learn the rules under Conn. Gen. Stat. 36a-701b.

Learn Massachusetts data breach notification rules under Chapter 93H and 201 CMR 17.00, including WISP requirements, penalties, and credit monitoring obligations.