Law / United States / Texas

Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information

Tex. Bus. & Com. Code sec. 521.052

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 April 2009.

A security baseline statutes rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds any business that collects or maintains sensitive personal information (an individual's name combined with a Social Security number, driver's license or government-issued identification number, or a financial account, credit, or debit card number together with any required access code; or information that identifies an individual and relates to the individual's physical or mental health, health care, or payment for health care) in the regular course of business; a financial institution as defined by 15 U.S.C. § 6809 is exempt.
  • Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect that sensitive personal information from unlawful use or disclosure. The statute states no further content for what 'reasonable' requires beyond this general standard.
  • Destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or indecipherable through any means.
  • There is no private right of action for a violation of this duty; only the attorney general may enforce it, seeking a civil penalty of $2,000 to $50,000 per violation and injunctive relief under Section 521.151.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Civil penalty under Section 521.151(a) for a violation of this chapter generally, recoverable only by the attorney general; the statute names no aggregate cap for this per-violation penalty. Section 521.151(a-1)'s separate penalty of up to $100 per individual, capped at $250,000 per breach, punishes a failure to comply with the breach-notification duty at Section 521.053(b), which is this jurisdiction's privacy row, not this one.

Rule
Per violation only
As of
12 September 2026
Minimum
2,000
Currency
USD
Per violation unit
Violation
Per violation amount
50,000

Who enforces it

Enforcement body

The attorney general may bring an action to recover the civil penalty and to enjoin a violation of this chapter under Section 521.151. Section 521.152's deceptive-trade-practice private action reaches only a violation of Section 521.051, a different duty, not this section.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A business must implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information it collects or maintains in the regular course of business. A business must also destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise rendering it unreadable or indecipherable.

A financial institution as defined by 15 U.S.C. § 6809 is exempt from the destruction duty, and the section states no further content for what 'reasonable' requires beyond the general standard.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Texas Business and Commerce Code, Identity Theft Enforcement and Protection Act

Back to the example  ·  Lint your app