| |

Data Breach Notification Requirements for CPA Firms in Texas

Compliance Guide · Dallas–Fort Worth

Data Breach Notification Requirements for CPA Firms in Texas

A breach triggers three separate reporting obligations at once — state, IRS, and often the FTC.

Quick Answer
Under Texas Business & Commerce Code Chapter 521, a CPA firm that experiences a data breach must notify affected individuals within 60 days of determining a breach occurred, and notify the Texas Attorney General within 30 days if 250 or more Texas residents are affected. Penalties run $2,000–$50,000 per violation, plus up to $100 per individual per day (capped at $250,000 per breach). But state law is only one obligation — a CPA firm handling taxpayer data must also report the incident to the IRS and typically the Federation of Tax Administrators (FTA), separately from any state-level notice. These three obligations run in parallel, not in sequence, and missing any one of them is its own violation.

Why a CPA Firm Breach Triggers 3 Separate Reporting Duties

Most breach-notification content is written for general businesses and covers only state law. A CPA or tax firm sits at the intersection of three different frameworks simultaneously, because taxpayer data is regulated differently than ordinary customer data:

1

Texas State Law (Chapter 521)

Applies to any business that owns or licenses computerized data on Texas residents — no revenue or size threshold. This is the baseline obligation every firm faces, regardless of what kind of data was involved.

2

IRS Reporting

Because the firm handles taxpayer data specifically, a breach also requires notifying the IRS through the tax professional data theft reporting process, and contacting the Federation of Tax Administrators (FTA) so affected states’ tax agencies can flag returns for potential fraud. This is separate from, and in addition to, the state consumer notification above.

3

FTC Safeguards Rule Notification

Since the 2023 amendment, firms covered by the Safeguards Rule must notify the FTC directly for breaches affecting 500 or more consumers, regardless of what state notifications are also required. This is a distinct filing from both the state and IRS processes.

Texas Deadlines and Penalties

Requirement Deadline / Threshold
Notify affected individuals Without unreasonable delay, no later than 60 days
Notify Texas Attorney General 30 days, if 250+ Texas residents affected
Penalty per violation $2,000 – $50,000
Additional daily penalty Up to $100/individual/day, capped at $250,000/breach

One detail worth knowing: the 60-day clock starts when the business determines a breach occurred, not when it first suspects one — but the “without unreasonable delay” language means a firm can’t deliberately slow-walk its own investigation to buy more time. Notification may only be delayed if law enforcement determines it would interfere with an active criminal investigation, and even then only for the duration of that investigation.

What Counts as “Sensitive Personal Information” Under Texas Law

The law defines this as a first name or initial plus last name, combined with at least one of: Social Security number, driver’s license number, or financial account/card number. For a CPA firm, this describes nearly every client file by default — there’s effectively no category of tax client data that falls outside this definition.

If a Breach Happens: The Order of Operations

Engage a security expert to determine the cause and scope, contain the breach, and prevent further exposure
Contact your insurance carrier to report the incident and confirm what breach mitigation expenses are covered
Report to the IRS and FTA through the tax professional data theft reporting process, and determine which state tax agencies also need notification for affected clients
Notify affected clients directly, coordinating timing with law enforcement if a criminal investigation is underway
Notify the Texas Attorney General electronically if 250+ Texas residents are affected, and the FTC if 500+ consumers are affected under the Safeguards Rule
Document everything — the investigation, every notification sent, and every remediation step, retained for a minimum of 5 years
The best time to plan this sequence is before a breach happens. A firm’s Written Information Security Plan should already include template notification letters, pre-identified state obligations, and current contact information for every regulatory body involved — not something assembled for the first time under pressure.

Why CPA Firms Choose Silver Storm Solutions

Cybersecurity-first approach Incident response planning
FTC Safeguards Rule / WISP expertise Proactive managed IT services

We help firms build a documented incident response plan before a breach happens, mapping out every notification obligation in advance so a bad day doesn’t turn into a missed deadline.

Frequently Asked Questions

Does Texas law require notifying the Attorney General for every breach?

No. AG notification is only required when a breach affects 250 or more Texas residents. Individual notification to affected people is required regardless of how many people are affected.

If our firm serves clients in multiple states, does Texas law cover all of them?

No. Texas law applies to Texas residents specifically. Clients in other states are covered by that state’s own breach notification law, which may have different deadlines — some states require notification in as little as 30 days.

Do we need to report a breach to the IRS even if we already notified clients under Texas law?

Yes. IRS and FTA reporting for taxpayer data is a separate obligation from state consumer notification law. Satisfying one does not satisfy the other — both need to happen.

How long should we keep records of a data breach response?

A minimum of five years, covering the investigation, every notification sent, and every remediation action taken — this documentation is exactly what regulators and insurers will ask to see afterward.

Is Your Firm Ready to Respond to a Breach?

Silver Storm Solutions can help you build a documented incident response plan covering every notification obligation your firm faces.

Schedule a Technology Assessment

Related resources:
FTC Safeguards Rule & WISP Compliance: What CPA Firms Must Have in Place ·
Ransomware Risk During Tax Season: What CPA Firms Need to Know

Similar Posts