2.4 Texas Business Data Security and Payment-Card Rules

Key Takeaways

  • Business & Commerce Code Chapter 521 requires reasonable procedures to protect sensitive personal information and secure destruction when records are no longer retained.
  • A person conducting business in Texas must give breach notice as quickly as possible and no later than 60 days after determining that a breach occurred, subject to statutory exceptions.
  • A breach affecting at least 250 Texas residents also triggers notice to the Texas attorney general.
  • An auction company should minimize stored bidder data, restrict access, secure online accounts, and use verifiable destruction methods.
  • The exam reference also includes the Texas statutory prohibition on merchant credit-card surcharges; a payment term should not be mislabeled to evade it.
Last updated: September 2026

2.4 Texas Business Data Security and Payment-Card Rules

Why this is tested: Registration records can contain names, addresses, government identifiers, financial-account data, and payment credentials. Business & Commerce Code Chapter 521 treats protection of that information as an operating duty, not merely an information-technology preference.

Sensitive Personal Information

Chapter 521 defines protected information by combinations of identifying data. Examples include an individual's name with a Social Security number, government-issued identification number, or financial-account information that permits access. The statutory definition also addresses certain health information.

Not every bidder number or public business address is automatically sensitive personal information. The exam approach is to identify whether the record contains the statutory identifiers and whether an unauthorized person could use the information to identify or access an individual's account.

An auction firm may encounter protected data in bidder applications, copies of identification, wire instructions, card-processing records, employment files, and settlement documents. The company remains responsible for its procedures even when it uses online auction software or another service provider.

Reasonable Protection and Secure Destruction

Section 521.052 requires a business to implement and maintain reasonable procedures, including taking appropriate corrective action, to protect sensitive personal information from unlawful use or disclosure.

“Reasonable” is risk-based. Useful controls include:

  • collect only information needed for a legitimate purpose;
  • restrict employee access by job function;
  • use unique accounts and multifactor authentication;
  • avoid transmitting bank instructions through unsecured channels;
  • verify change requests using a trusted contact method;
  • keep devices and auction platforms updated;
  • establish retention and destruction schedules; and
  • document response duties with vendors.

When business records containing sensitive personal information are disposed of, Chapter 521 requires destruction by shredding, erasing, or otherwise modifying the information so that it is unreadable or undecipherable. Placing intact bidder forms in an ordinary trash bin is not secure destruction.

Record retention and data minimization work together. If another law requires a record for two or four years, retain it securely for that period. When the lawful business need ends, destroy the protected data securely rather than keeping it indefinitely.

Security Breach Notice

A breach problem begins when sensitive personal information is, or is reasonably believed to have been, acquired by an unauthorized person. A person who conducts business in Texas and owns or licenses computerized data must notify affected individuals as quickly as possible and no later than 60 days after determining that the breach occurred, unless a statutory law-enforcement delay or other exception applies.

A business that maintains another person's data must notify the owner or license holder immediately after discovering the breach so the responsible party can carry out the notice duties.

If the breach involves at least 250 Texas residents, notice to the Texas attorney general is also required. Do not confuse that threshold with the duty to notify affected individuals; the individual-notice obligation is not limited to breaches of 250 people.

A practical incident sequence is: contain the event, preserve evidence, determine the affected information and residents, coordinate required notices, correct the weakness, and document decisions. Concealing the incident or delaying analysis creates additional risk.

Auction Examples

A clerk emails a spreadsheet containing bidder names and bank-account access information to the wrong outside address. The company should treat the event as a potential breach, attempt containment, and promptly investigate the Chapter 521 notice duties.

By contrast, an employee sends public lot numbers and bidder aliases with no identifying information or account access data. That mistake may violate company policy but does not automatically satisfy the statutory definition of a breach of sensitive personal information. Classification comes before the notice conclusion.

Credit-Card Surcharges

The official auctioneer study material also directs candidates to Business & Commerce Code Chapter 604A. Section 604A.002 states that a seller may not impose a surcharge on a buyer who uses a credit card instead of cash, check, debit card, or a similar means.

For exam purposes, distinguish a stated credit-card surcharge from a properly structured and truthfully advertised price arrangement. Calling an added charge a “convenience fee” does not control if it functions as a prohibited surcharge. Payment pricing must also be consistent across the advertisement, registration terms, invoice, and opening announcement.

Separate card-network rules and federal requirements may apply in actual operations. The licensing exam asks whether the auctioneer recognizes the Texas reference and avoids surprising the bidder.

Exam Checklist

For a data question, ask: What information? Who acquired it? Who owns the data? How many Texas residents? When was the breach determined? For disposal, choose a method that makes the information unreadable or undecipherable.

Test Your Knowledge

Which disposal method best satisfies Chapter 521 for paper bidder records containing sensitive personal information?

A
B
C
D
Test Your Knowledge

After determining that a qualifying breach occurred, what is the outside Chapter 521 deadline for notice to affected individuals, absent an applicable exception?

A
B
C
D
Test Your Knowledge

A breach affects 300 Texas residents. What additional threshold-based notice is implicated?

A
B
C
D