Law / United States / Texas
Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information
Tex. Bus. & Com. Code sec. 521.052
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 April 2009.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds any business that collects or maintains sensitive personal information (an individual's name combined with a Social Security number, driver's license or government-issued identification number, or a financial account, credit, or debit card number together with any required access code; or information that identifies an individual and relates to the individual's physical or mental health, health care, or payment for health care) in the regular course of business; a financial institution as defined by 15 U.S.C. § 6809 is exempt.
- Implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect that sensitive personal information from unlawful use or disclosure. The statute states no further content for what 'reasonable' requires beyond this general standard.
- Destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise modifying the information to make it unreadable or indecipherable through any means.
- There is no private right of action for a violation of this duty; only the attorney general may enforce it, seeking a civil penalty of $2,000 to $50,000 per violation and injunctive relief under Section 521.151.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Civil penalty under Section 521.151(a) for a violation of this chapter generally, recoverable only by the attorney general; the statute names no aggregate cap for this per-violation penalty. Section 521.151(a-1)'s separate penalty of up to $100 per individual, capped at $250,000 per breach, punishes a failure to comply with the breach-notification duty at Section 521.053(b), which is this jurisdiction's privacy row, not this one.
- Rule
- Per violation only
- As of
- 12 September 2026
- Minimum
- 2,000
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 50,000
Who enforces it
Enforcement body
The attorney general may bring an action to recover the civil penalty and to enjoin a violation of this chapter under Section 521.151. Section 521.152's deceptive-trade-practice private action reaches only a violation of Section 521.051, a different duty, not this section.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A business must implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information it collects or maintains in the regular course of business. A business must also destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise rendering it unreadable or indecipherable.
A financial institution as defined by 15 U.S.C. § 6809 is exempt from the destruction duty, and the section states no further content for what 'reasonable' requires beyond the general standard.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product