Data Breach Response for Texas Startups: Notification Laws, SEC Disclosure Rules, and Your Incident Response Plan

Texas breach notification law, SEC cybersecurity disclosure rules, FTC enforcement for inadequate data security, a step-by-step incident response plan, and cyber insurance coverage gaps every Texas startup founder must close before raising capital.

Abstract fresco on deep navy: an oval teal crystal with one diagonal fracture across its face rebonded in copper and glowing cream, small motes of light drifting away from the break.
Loading AudioNative Player...

Every Texas startup collects personal data — names, email addresses, payment information, and increasingly biometric or health data. When that data is compromised, a cascade of legal obligations kicks in: state breach notification statutes, federal enforcement authority, and for public companies, SEC cybersecurity disclosure rules. Most founders do not have an incident response plan, have never mapped their notification obligations, and carry insurance that explicitly excludes the losses a breach generates. This guide walks through the overlapping legal frameworks — Texas breach notification law, TDPSA security obligations, SEC Form 8-K Item 1.05, FTC enforcement, and cyber insurance — and gives you a practical incident response plan you can operationalize before a breach forces the issue.

If you are already navigating Texas privacy compliance, our TDPSA compliance guide covers the broader data privacy obligations that intersect with breach response, and our Texas CUBI biometric privacy compliance guide addresses the heightened obligations that apply when biometric data is involved.

What Triggers a "Breach of System Security" Under Texas Law

Texas breach notification law is codified at Tex. Bus. & Com. Code § 521.053. The statute defines a "breach of system security" as "unauthorized acquisition of computerized data that compromises the security, confidentiality, or integrity of sensitive personal information maintained by a person." Critically, this includes encrypted data if the person accessing it has the decryption key.

"Sensitive personal information" under the statute includes an individual's first name or first initial and last name in combination with one of the following: Social Security number, government-issued identification number, or financial account information with access credentials. A good-faith acquisition of sensitive personal information by an employee or agent for company purposes is not a breach unless the information is used or disclosed in an unauthorized manner.

Two practical points matter for founders. First, the trigger is unauthorized acquisition, not merely unauthorized access. If an attacker breaches your systems but you can demonstrate that no sensitive personal information was actually acquired — for example, because the data was properly encrypted and the attacker did not obtain the key — the breach notification obligation may not be triggered. But the burden of proving that no acquisition occurred falls on your company, and it is a high bar. Second, the definition of sensitive personal information is not limited to the categories listed above. If your startup collects biometric identifiers — face geometry, voiceprints, fingerprints — the Texas CUBI statute adds additional security and destruction obligations that compound your exposure.

The 60-Day Consumer Notification Clock and the 30-Day AG Deadline

Once your company determines that a breach has occurred, § 521.053 imposes two overlapping notification deadlines:

  • Consumer notification (60 days): You must disclose the breach to any individual whose sensitive personal information was — or is reasonably believed to have been — acquired by an unauthorized person. The disclosure must be made "without unreasonable delay" and in no case later than the 60th day after the date you determine the breach occurred. You may delay notification only if a law enforcement agency determines that notification would impede a criminal investigation.
  • Attorney General notification (30 days): If the breach involves at least 250 Texas residents, you must also notify the Texas Attorney General "as soon as practicable and not later than the 30th day" after you determine the breach occurred. This notification must be submitted electronically through a form on the AG's website and must include: a description of the breach, the number of Texas residents affected, the number who have been sent direct notification, measures taken, measures intended, and whether law enforcement is engaged.

There is also a third notification tier: if you are required to notify more than 10,000 individuals at one time, you must also notify each nationwide consumer reporting agency (Equifax, Experian, TransUnion) of the timing, distribution, and content of the notices.

The practical challenge for founders is the intersection of these timelines with the investigation timeline. You may not know the full scope of the breach within 30 days. The statute allows the notification timeline to account for the time "necessary to determine the scope of the breach and restore the reasonable integrity of the data system" — but this exception is not a blank check. Document your investigation progress meticulously, because the AG and plaintiffs' counsel will scrutinize whether your delay was reasonable.

TDPSA Security Obligations: Why Every Texas Startup Is a Regulated Entity

The Texas Data Privacy and Security Act (TDPSA), enacted as House Bill 4 and effective July 1, 2024, imposes separate but related obligations that compound breach exposure. Under the TDPSA, controllers must "establish, implement, and maintain reasonable data security practices" to protect the confidentiality, integrity, and accessibility of personal data. The Texas AG has exclusive enforcement authority, with penalties of up to $7,500 per violation after a 30-day cure period.

The TDPSA's significance for breach response is twofold. First, there is no revenue threshold — virtually every startup processing Texas consumers' personal data is subject to the TDPSA. Second, a data breach is not just a notification trigger; it is also evidence that your security practices may have been unreasonable. A breach can simultaneously trigger § 521.053 notification obligations and a TDPSA enforcement action for inadequate security. The AG has already demonstrated willingness to enforce the TDPSA aggressively, filing its first enforcement action against Allstate in January 2025 over alleged unlawful collection and sale of geolocation data.

If your breach involves sensitive data — precise geolocation, health data, racial or ethnic origin, or biometric identifiers — the TDPSA requires that you obtained consumer consent before processing. A breach of data you collected without proper consent compounds your exposure: you face not only the breach notification obligations but also a TDPSA claim for processing without consent. For a comprehensive framework for TDPSA compliance, see our TDPSA compliance guide.

SEC Form 8-K Item 1.05: Cybersecurity Disclosure for Public Companies

If your startup is public — or planning an IPO — the SEC's cybersecurity disclosure rules add a federal disclosure layer on top of state notification obligations. Under Release No. 33-11216, effective September 5, 2023, public companies must disclose material cybersecurity incidents on Form 8-K, Item 1.05. Compliance began December 18, 2023, for all registrants other than smaller reporting companies (which began June 15, 2024).

The key requirements:

  • Four-business-day clock: Once the company determines that a cybersecurity incident is material, it must file a Form 8-K within four business days. The clock starts when materiality is determined — not when the incident is first discovered. However, the SEC expects companies to make materiality determinations "without unreasonable delay" after becoming aware of the incident.
  • Materiality standard: The SEC adopted the existing materiality standard from Basic Inc. v. Levinson and TSC Industries v. Northway: information is material if there is a "substantial likelihood that a reasonable shareholder would consider it important" or if it would have "significantly altered the 'total mix' of information made available."
  • Content requirements: The 8-K must describe the material aspects of the nature, scope, and timing of the incident, as well as the material impact or reasonably likely material impact on the company.
  • Delayed disclosure for national security: The SEC permits delayed disclosure if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety.

The SEC has already brought enforcement actions under these rules. In October 2024, the SEC charged four companies — Unisys, Avaya, Check Point, and Mimecast — with making materially misleading disclosures about cybersecurity incidents arising from the SolarWinds compromise, after staff had already cautioned registrants that materiality determinations must be made without unreasonable delay (see Director Gerding's May 2024 statement). For pre-IPO startups, the lesson is that your incident response plan must include a materiality determination process that involves legal counsel, not just your engineering team.

FTC Enforcement: When Inadequate Security Becomes an Unfair Practice

Beyond state and SEC obligations, the Federal Trade Commission enforces data security standards under Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices." The FTC's position is that inadequate data security is an unfair practice — and the agency has pursued enforcement actions against companies of all sizes, including startups.

Two cases illustrate the enforcement landscape:

Drizly: Personal Liability for the CEO

In October 2022, the FTC finalized a consent order against Drizly, LLC after a 2020 data breach exposed the personal information of approximately 2.5 million consumers. The FTC found that Drizly failed to implement reasonable security measures despite warnings about security vulnerabilities. Critically, the FTC named Drizly's CEO individually in the order, holding him personally accountable for the company's data security failures — an unusual step that signaled the agency's willingness to reach executives directly. The order required the CEO to implement a comprehensive information security program at any company he leads in the future.

CafePress: A Cautionary Tale for E-Commerce

In June 2022, the FTC finalized an action against CafePress after a 2019 breach exposed the personal information of approximately 22 million consumers, including names, email addresses, physical addresses, phone numbers, and partially truncated Social Security numbers. The FTC found that CafePress failed to implement basic security measures — including inadequate password requirements, insufficient encryption, and poor patch management — and then attempted to cover up the breach by requiring affected consumers to provide additional personal information to "verify" their identities before offering assistance. The consent order required CafePress to implement a comprehensive security program and submit to independent audits for 20 years.

The practical takeaway for founders: the FTC does not need a breach-specific statute to pursue enforcement. If your security practices are deemed unreasonable under Section 5, the FTC can impose consent orders, require multi-year security programs, and — as Drizly showed — hold individual executives personally accountable. The cost of a consent order extends far beyond monetary penalties: it creates ongoing compliance obligations that burden your company for years and surface during M&A diligence.

Your Incident Response Plan: A Step-by-Step Framework

The NIST SP 800-61 Rev. 2 incident response framework — long the gold standard for incident handling, and superseded in April 2025 by Rev. 3, which realigns incident response to the CSF 2.0 functions — organizes response into four phases. Here is how we apply each phase for Texas startups:

Phase 1: Preparation (Before an Incident Occurs)

  • Build an incident response team. Designate a team lead (typically your CTO or VP of Engineering), a legal liaison (internal or outside counsel), a communications lead, and an executive sponsor. Document contact information for each team member and their backups.
  • Develop an incident response plan. Write it down. The plan should include: severity classification criteria (what counts as a P0 vs. P1 incident), escalation procedures, notification decision trees (who decides whether to notify consumers, the AG, the SEC), and contact information for your cyber insurance broker, outside counsel, and forensic firm.
  • Implement logging and monitoring. You cannot respond to a breach you cannot detect. Ensure you have centralized logging, alerting on suspicious access patterns, and retention policies that preserve logs long enough to support a forensic investigation.
  • Tabletop exercises. Run a simulated breach scenario at least annually. The exercise should surface gaps in your plan — missing contacts, unclear decision-making authority, or technical blind spots — before a real incident does.

Phase 2: Detection and Analysis (When Something Looks Wrong)

  • Triage the alert. Not every alert is a breach. Your team should have a defined process for escalating from "suspicious activity" to "confirmed incident" to "confirmed breach involving sensitive personal information."
  • Engage forensic support early. If you suspect a breach involving sensitive personal information, engage a digital forensics firm immediately. The forensic investigation will determine what data was accessed, when the breach began, and whether the attacker is still in your systems — all of which are necessary for your notification analysis.
  • Preserve evidence. Preserve system images, logs, and affected data in a forensically sound manner. Do not attempt to remediate before evidence is preserved — you may destroy the very information you need to prove what happened.
  • Engage legal counsel. Counsel should be engaged at the detection stage, not after the investigation is complete. Attorney-client privilege over the investigation depends on counsel directing the forensic work — if your engineering team runs the investigation without legal involvement, the results may not be privileged.

Phase 3: Containment, Eradication, and Recovery

  • Contain the breach. Isolate affected systems, revoke compromised credentials, and block attacker access paths. The goal is to stop the bleeding without destroying evidence.
  • Eradicate the threat. Remove malware, close vulnerabilities, and verify that the attacker no longer has access. This may require rebuilding systems from known-good images rather than patching compromised ones.
  • Recover systems. Restore from clean backups, verify system integrity, and bring systems back online in a prioritized order. Monitor for signs of attacker return during the recovery phase.
  • Assess notification obligations. Based on the forensic findings, determine: What sensitive personal information was acquired? How many Texas residents are affected? Is the breach material for SEC purposes? Do you need to notify the AG within 30 days? Do you need to notify consumer reporting agencies?

Phase 4: Post-Incident Activity

  • Conduct a post-incident review. What went well? What failed? What controls need to be added or improved? Document the lessons learned and update your incident response plan accordingly.
  • Track notification compliance. Confirm that all required notifications were sent within the applicable deadlines. Document the date and method of each notification — this is your evidence of compliance if the AG or a regulator comes asking.
  • Update your security posture. The breach is a learning opportunity. Implement the technical and organizational controls that would have prevented it. If the FTC or AG investigates, evidence of post-incident remediation is a mitigating factor.

Cyber Insurance: Why Your CGL and E&O Policies Won't Cover a Breach

Most founders carry Commercial General Liability (CGL) and Errors & Omissions (E&O) insurance and assume they are covered for a data breach. They are not. Standard CGL policies cover bodily injury and property damage — not data breaches. Traditional E&O policies cover professional negligence claims — not the costs of investigating and notifying a breach, defending against regulatory enforcement, or paying ransomware demands.

A dedicated cyber liability insurance policy covers the costs that CGL and E&O exclude:

  • Forensic investigation costs: The cost of engaging a digital forensics firm to determine what happened, what data was compromised, and how the attacker gained access.
  • Notification costs: The cost of notifying affected individuals, the Texas AG, and consumer reporting agencies — including the cost of credit monitoring services, which can be the single largest expense in a breach response.
  • Legal defense and regulatory response: The cost of defending against consumer class actions, AG enforcement actions, and FTC investigations arising from the breach.
  • Business interruption: Lost revenue from system downtime during the breach response, particularly relevant for SaaS startups whose entire business depends on system availability.
  • Ransomware payments: Some policies cover ransom payments, though this coverage is increasingly subject to exclusions and sub-limits.

What investors require before a Series A: Most institutional investors require portfolio companies to carry cyber liability insurance as part of their pre-investment diligence. A typical Series A investor will require at least $1–5 million in cyber coverage, with higher limits for startups in regulated industries (healthcare, fintech) or those handling large volumes of sensitive data. If you show up to diligence without cyber insurance, the investor will either require you to obtain it as a condition to closing or will flag it as a material risk in their investment committee memo — which can affect valuation or deal terms.

When purchasing cyber insurance, watch for these common coverage gaps:

  • Prior acts exclusions: If your policy only covers breaches discovered during the policy period, a breach that began before your coverage started may be excluded. Ask for retroactive coverage that predates your policy effective date.
  • Unencrypted data exclusions: Some policies exclude coverage for breaches involving unencrypted data. If your startup stores sensitive personal information in plaintext, you may be uninsurable — or your premiums may be prohibitively expensive.
  • Ransomware sub-limits: Many policies cap ransomware payments at a fraction of the total policy limit. If ransomware is a primary risk vector for your business, negotiate higher sub-limits.
  • Regulatory investigation costs: Confirm that your policy covers the cost of responding to AG and FTC investigations, not just consumer lawsuits. These costs can exceed the cost of the breach itself.

For a broader discussion of how insurance gaps affect startup risk management — including AI-specific coverage issues — see our AI product liability and insurance guide.

A data breach is a when, not an if. We help Texas startups build incident response plans, map notification obligations, assess cyber insurance coverage, and prepare for the regulatory scrutiny that follows. Get ahead of it before a breach forces the issue.

Get in touch

Actionable Next Steps

  1. Write your incident response plan this quarter. It does not need to be elaborate — a five-page document covering team roles, severity classification, escalation procedures, and notification decision trees is sufficient for an early-stage startup. The value is in the exercise of creating it, not the length of the document.
  2. Map your notification obligations now. Identify what sensitive personal information you collect, where it is stored, who has access to it, and which laws apply (§ 521.053, TDPSA, and if you are public, SEC Form 8-K Item 1.05). Build a notification decision tree that accounts for the 60-day consumer clock, the 30-day AG deadline, and the 10,000-person consumer reporting agency threshold.
  3. Purchase cyber liability insurance before your next funding round. Start with $1–2 million in coverage and work with a broker who understands startup risk profiles. Review the policy for prior acts exclusions, unencrypted data exclusions, and regulatory investigation coverage. If you are heading into a Series A, assume investors will ask about your cyber coverage — and have a specific answer ready.
  4. Run a tabletop exercise. Gather your team for two hours and simulate a breach scenario. Walk through detection, escalation, forensic engagement, notification decisions, and communications. The gaps you identify will be your to-do list for the next quarter.
  5. Implement basic security controls. Encrypt sensitive personal data at rest and in transit. Implement multi-factor authentication. Maintain centralized logging with sufficient retention. These are the controls the FTC evaluates in enforcement actions, and they are the controls your cyber insurer will require before binding coverage.
  6. Engage outside counsel for a breach readiness review. The cost of a pre-incident compliance assessment is a fraction of the cost of responding to a breach without a plan — and a fraction of the cost of an AG enforcement action or FTC investigation. We help founders build incident response plans, map their notification obligations, and assess their insurance coverage before a breach forces the conversation.

A data breach is inevitable for most companies that handle personal data. What separates companies that survive a breach from those that do not is preparation: an incident response plan that has been tested, notification obligations that have been mapped in advance, and insurance that actually covers the losses a breach generates. The founders who build this infrastructure before a breach occurs will face regulators, plaintiffs, and investors with confidence. The founders who do not will be building it under the pressure of an active incident — when every hour of delay compounds the legal, financial, and reputational damage.