Policies and Procedures

Effective Date: June 2, 2026
Website: https://www.kuboshdpsrecords.com
Compliance Contact: support@kuboshdpsrecords.com
Purpose of this document. This document sets out the operational policies and procedures that govern the day-to-day operation of kuboshdpsrecords.com (the "Service"). It is designed to ensure compliance with the federal Driver’s Privacy Protection Act (18 U.S.C. §§ 2721–2725), the Texas Motor Vehicle Records Disclosure Act (Tex. Transp. Code Ch. 730), the Texas Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code Ch. 521), the Texas Identity Theft by Electronic Device statute (Tex. Bus. & Com. Code Ch. 522), and other applicable law. All employees, contractors, agents, and service providers of the Company are required to read, understand, and comply with this document.
1. Company Overview and Government Affiliation Disclaimer
Kuboshdpsrecords.com is a privately owned, for-profit Texas business operated by Paul A. Kubosh (the “Company”). The Company provides a record-procurement service through which an individual Texas driver may authorize the Company to obtain that individual’s own Texas driver record from the Texas Department of Public Safety (“Texas DPS”), or through which an Authorized Recipient under Tex. Transp. Code Ch. 730 may obtain a driver record for a Permissible Purpose.
The Company is not affiliated with, authorized by, endorsed by, or sponsored by Texas DPS, the State of Texas, or any other government agency. Every page of the Site and every customer-facing document includes a clear and conspicuous disclaimer of government affiliation, and every employee is trained never to imply, in any customer communication, that the Company is a government agency or an authorized arm of Texas DPS.
2. Scope
These policies and procedures apply to the Company, its principal, its employees, its contractors, and its service providers (collectively, “Personnel”) with respect to the processing of any Personal Information obtained from or in connection with a motor vehicle record maintained by Texas DPS, including any Personal Information collected from the individual to whom the record pertains. They also apply to any Sensitive Personal Information collected by the Company in the regular course of business as defined in Tex. Bus. & Com. Code § 521.002(a)(2).
3. Records Offered and Processing
3.1 Record Types
Subject to Texas DPS eligibility rules and the Company’s contractual arrangements, the Company processes requests for the following record types:
- Type 1 – Status Record;
- Type 2 – Three-Year Driver History;
- Type 2A – Certified Three-Year Driver History;
- Type 3 – List of All Crashes and Violations on Record (CDL/CLP holders only);
- Type 3A – Certified List of All Crashes and Violations on Record (CDL/CLP holders only); and
- Certified Abstract / Type AR – Certified Copy of the Entire Driving Record (CDL/CLP holders only).
The Company does not offer Type 4 (School Bus Driver Record), which is restricted to Independent School Districts. Pricing and availability of each record type are posted on the Site.
3.2 Order Intake
Orders are accepted only through the secure Site. Personnel may not accept orders for the procurement of another individual’s driver record by telephone, e-mail, fax, or other channel unless (a) the requestor identifies a Permissible Purpose under 18 U.S.C. § 2721(b) and Tex. Transp. Code § 730.007 and the Company has appropriately documented that purpose, and (b) where applicable, the requestor has provided the written consent of the subject of the record as required by Tex. Transp. Code § 730.006.
3.3 Identity Verification
At checkout the Company collects, at a minimum, the customer’s full legal name, Texas driver license number, audit number, last four digits of Social Security Number, exact date of birth, driver license expiration date, mailing address, and e-mail address. Personnel verify that all required fields are populated before submitting the request to Texas DPS. Personnel do not alter, infer, or guess any portion of the customer-supplied information; an incomplete or apparently inaccurate order is held for customer correction.
3.4 Permissible Purpose Documentation
Each order generates a record of the Permissible Purpose certified by the customer at checkout, along with the timestamp and IP address from which the certification was made. These records are retained for at least five (5) years from the date of the order, consistent with Tex. Transp. Code § 730.013(c) and 18 U.S.C. § 2721(c), and are made available to Texas DPS, the Texas Attorney General, or other appropriate authority upon lawful request.
3.5 Processing Times
Standard non-certified orders submitted during business hours are typically processed within one to eight hours; certified records require physical mailing by Texas DPS and are not within the Company’s control. Processing-time estimates posted on the Site are estimates only and are not warranted.
4. Delivery
Driving Records are delivered by the method selected by the customer at checkout: secure electronic delivery (e-mail, typically as a password-protected PDF); USPS mail; next-business-day courier (Texas addresses only); or next-business-day A.M. courier (Texas addresses only). Personnel follow the operational steps in Section 10 below for each delivery mode and document each step in the order record.
5. Payments and Refunds
5.1 Payment Acceptance
Payments are accepted only through the Company’s PCI-DSS-compliant payment processor. Personnel never write down, store, photograph, or transmit a customer’s full payment card number, card verification value, or banking credentials. All payment authorization and capture occurs through the processor.
5.2 Refund Procedure
Refunds are processed in accordance with Section 9 of the Terms and Conditions. Refund requests are reviewed by the Refund Coordinator (or, in the absence of a designated coordinator, by the principal) and processed each Tuesday and Friday except on federal holidays. Each refund decision is documented in the order record, including the reason for grant or denial.
5.3 Chargeback Response
Upon receipt of a chargeback, Personnel preserve the complete order record, including the customer’s identity-verification fields, the timestamp of the Permissible Purpose certification, the IP address from which the order was placed, the delivery confirmation, and any customer correspondence, and prepare a response to the card issuer within the deadlines set by the processor.
6. Information Security
Consistent with the Company’s duty under Tex. Bus. & Com. Code § 521.052(a) to implement and maintain reasonable procedures to protect Sensitive Personal Information from unlawful use or disclosure, and with reference to the framework of the Texas Administrative Code Title 1, Part 10, Chapter 202 (NIST SP 800-53 based controls) as guidance, the Company maintains the following information-security controls:
- All Sensitive Personal Information in transit between the customer’s browser and the Site is encrypted using current-generation Transport Layer Security (TLS).
- Sensitive Personal Information at rest is stored on systems protected by access controls, system-level authentication, and, where commercially reasonable, encryption.
- Access to systems containing Sensitive Personal Information is restricted on a least-privilege, need-to-know basis using individual user accounts; shared accounts are prohibited.
- Strong, unique passwords are required for all administrative accounts, and multi-factor authentication is enabled for all systems that support it.
- Administrative-access logs are maintained and reviewed periodically for anomalies.
- Software, operating systems, and web-application components are kept current with security patches.
- Antivirus, anti-malware, and endpoint-protection tools are deployed on all systems used to process Sensitive Personal Information.
- Backups of Company data are encrypted, stored separately from production systems, and tested periodically for restorability.
- Web-application security is reviewed periodically, including testing for input validation, authentication, session management, access control, and known web-application vulnerabilities.
- Vendors and service providers that have access to Sensitive Personal Information are contractually obligated to maintain commercially reasonable safeguards and to comply with applicable law, and their security practices are reviewed at onboarding and periodically thereafter.
7. Data Retention and Destruction
Personal Information is retained only for as long as is reasonably necessary to (a) provide the Service, (b) comply with the recordkeeping requirements of Tex. Transp. Code § 730.013(c), 18 U.S.C. § 2721(c), and the Company’s contractual obligations to Texas DPS, (c) meet tax and accounting obligations, (d) defend or pursue legal claims, and (e) detect and prevent fraud and abuse.
When records containing Sensitive Personal Information are no longer required for these purposes, the Company destroys or arranges for the destruction of those records in accordance with Tex. Bus. & Com. Code § 521.052(b), by:
- Cross-cut shredding of paper records;
- Secure erasure or cryptographic wiping of electronic media in accordance with NIST SP 800-88 Guidelines for Media Sanitization (or successor); and
- Physical destruction of storage media that cannot be reliably wiped.
8. Permissible Purpose, Redisclosure, and Anti-Sale Controls
8.1 Customer Certification at Checkout
At checkout each customer is required to certify, under penalty of law, that the customer (a) is the individual who is the subject of the Driving Record or has lawful authority and the subject’s written consent under Tex. Transp. Code § 730.006, and (b) will use the Driving Record only for a Permissible Purpose under 18 U.S.C. § 2721(b) and Tex. Transp. Code § 730.007. The Site retains the text of the certification, the time it was made, and the customer’s IP address.
8.2 No Redisclosure in Identical or Substantially Identical Format
The Company does not redisclose a Driving Record in the identical or substantially identical format in which it was received from Texas DPS, except to deliver the record to the customer who placed the order. Personnel are trained on this restriction (Tex. Transp. Code § 730.013(a)).
8.3 No Sale to Non-Authorized Recipients
The Company does not sell Personal Information obtained from a motor vehicle record to any person who is not an Authorized Recipient, as prohibited by Tex. Transp. Code § 730.0122. Personnel are trained that such sale is a misdemeanor punishable by a fine of up to $100,000 and gives rise to civil liability under § 730.0123 (actual damages, minimum $2,500, plus court costs).
8.4 Anti-Marketing Restrictions
The Company does not use Personal Information from any Driving Record for telephone marketing of extended vehicle warranties, for bulk marketing campaigns, or for behavioral advertising.
8.5 Deletion if Not an Authorized Recipient
If the Company becomes aware that it is not an Authorized Recipient of any Personal Information it has received from Texas DPS, the Company will promptly delete that Personal Information from its records, in accordance with Tex. Transp. Code § 730.0121.
9. Breach Response Plan
9.1 Detection and Containment
Personnel who discover or suspect a security incident (including unauthorized access to systems, lost or stolen devices, or improper disclosure) report it immediately to the principal. The principal, with assistance from technical service providers, isolates affected systems, preserves logs and forensic evidence, and assesses whether an unauthorized acquisition of Sensitive Personal Information has occurred.
9.2 Investigation
The Company conducts a prompt and reasonable investigation to determine whether a “breach of system security” within the meaning of Tex. Bus. & Com. Code § 521.053(a) has occurred, the nature and scope of the breach, the categories of Sensitive Personal Information involved, the number of individuals affected, and the corrective measures required. The investigation is documented in writing.
9.3 Individual Notice
If the investigation confirms a breach of system security with respect to Sensitive Personal Information owned or licensed by the Company, the Company provides notice to each affected individual whose Sensitive Personal Information was, or is reasonably believed to have been, acquired by an unauthorized person. Notice is provided without unreasonable delay and not later than the sixtieth (60th) day after the date on which the Company determines that the breach occurred, except as permitted by § 521.053(b) or (d). Notice is given by (a) written notice at the individual’s last known address; (b) electronic notice in accordance with 15 U.S.C. § 7001; or (c) substitute notice as permitted by § 521.053(f) where the cost of notice would exceed $250,000, the number of affected persons exceeds 500,000, or the Company lacks sufficient contact information.
9.4 Texas Attorney General Notice
If the breach involves the Sensitive Personal Information of at least 250 Texas residents, the Company provides notice to the Texas Attorney General electronically through the form on the Attorney General’s website not later than the thirtieth (30th) day after the date on which the Company determines that the breach occurred, in accordance with Tex. Bus. & Com. Code § 521.053(i). The notice includes a detailed description of the breach, the number of affected Texas residents at the time of notification, the number that have been sent disclosure of the breach, the measures taken and to be taken by the Company, and information regarding whether law enforcement is investigating.
9.5 Consumer Reporting Agency Notice
If the Company is required to notify more than 10,000 individuals of a breach at one time, the Company will also notify each nationwide consumer reporting agency, as defined by 15 U.S.C. § 1681a, of the timing, distribution, and content of the notices, without unreasonable delay, in accordance with § 521.053(h).
9.6 Texas DPS Contract Notice (If Applicable)
If a breach involves data obtained pursuant to a contract under Tex. Transp. Code § 730.007, the Company will notify the contracting agency not later than 48 hours after discovery of the breach, as required by § 730.014(c)(4).
9.7 Law Enforcement
Notice may be delayed at the request of a law enforcement agency that determines that notification would impede a criminal investigation, in which case notice is given as soon as the agency determines that notification will not compromise the investigation, consistent with § 521.053(d).
9.8 Recordkeeping
Records of each security incident, including the investigation, classification, notifications, and remediation, are retained for at least five years.
10. Standard Operating Procedures
10.1 Order Fulfillment SOP
- Order received through the Site and entered into the queue with a unique order identifier and timestamp.
- Personnel confirm that all required identity fields are populated and that the customer has affirmatively certified the Permissible Purpose at checkout.
- Personnel submit the request to Texas DPS via the authorized channel (online portal or DR-1 mail form, as applicable).
- Upon receipt of the record from Texas DPS, Personnel verify that the record matches the customer’s submission and prepare it for delivery.
- Personnel deliver the record by the method selected at checkout and log the delivery in the order record.
- If a record cannot be processed (e.g., Texas DPS rejection due to incorrect data), Personnel attempt to contact the customer to correct the information within 14 days, consistent with the Terms and Conditions.
10.2 Customer Inquiry SOP
- All inquiries are received at support@kuboshdpsrecords.com and assigned a unique ticket number.
- Personnel verify the requestor’s identity by reference to the order record before disclosing any account-specific or order-specific information.
- Personnel respond to routine inquiries within two business days; complex inquiries are escalated to the principal.
- All inquiries and responses are logged.
10.3 Vendor Onboarding SOP
- Each new vendor that will process Sensitive Personal Information on behalf of the Company is vetted for reputation, security posture (e.g., SOC 2 or equivalent attestation where available), insurance coverage, and compliance with applicable law.
- A written services agreement is executed before any Sensitive Personal Information is shared with the vendor; the agreement requires confidentiality, security safeguards consistent with this document, breach-notification cooperation, and limitations on use of the data.
- Vendor access is provisioned on a least-privilege basis and reviewed periodically.
10.4 Employee Onboarding and Training SOP
- Before being granted access to any Sensitive Personal Information, each new employee or contractor signs a written confidentiality and acceptable-use agreement and acknowledges receipt of these policies and procedures.
- Each new employee or contractor completes training covering: the DPPA and Tex. Transp. Code Ch. 730; permissible and prohibited uses; redisclosure and anti-sale restrictions; identity-theft and information-security obligations under Tex. Bus. & Com. Code Ch. 521; breach-response procedures; customer-service standards; and the Company’s disciplinary policy.
- Refresher training is provided at least annually and after any material change to law or to these policies and procedures.
10.5 Termination SOP
- Upon termination of employment or contract, all credentials, badges, keys, and devices are returned or revoked immediately.
- Access to all Company systems and to all vendor systems is disabled the same day.
- The departing person is reminded in writing of continuing confidentiality and non-disclosure obligations.
11. Compliance, Audit, and Review
The Company conducts a documented compliance review at least annually. The review covers, at a minimum: (a) the accuracy and currency of these policies and procedures; (b) employee training records; (c) vendor security and contractual compliance; (d) information-security controls; (e) order-record sampling for Permissible Purpose certification, identity verification, and delivery confirmation; (f) breach-incident records; and (g) customer complaint logs. The findings of each review are documented and any required remediation is tracked to completion.
These policies and procedures are reviewed and updated at least annually and whenever there is a material change in applicable law, the Company’s operations, or the Company’s contractual relationship with Texas DPS.
12. Enforcement; Disciplinary Action
Violations of these policies and procedures are taken seriously. Depending on the severity of the violation, the principal may impose discipline up to and including immediate termination of employment or contract, and may report apparent violations of law to law enforcement, the Texas Attorney General, Texas DPS, or other appropriate authorities. The Company cooperates with law enforcement and regulatory authorities in the investigation of any apparent violation. Civil and criminal liability under federal and Texas law (including but not limited to 18 U.S.C. §§ 2722–2724, Tex. Transp. Code §§ 730.0122, 730.0123, 730.013, 730.015, 730.016, and Tex. Bus. & Com. Code § 521.151) may also apply to violators.
13. Customer Complaints and Disputes
Customer complaints are received at support@kuboshdpsrecords.com and acknowledged within two business days. The principal (or designee) investigates each complaint and responds with a written resolution as soon as practicable. Complaints involving allegations of privacy violations, identity theft, or unauthorized access are escalated immediately. The complaint log is reviewed during the annual compliance review for patterns or systemic issues.
14. Records Maintained
The Company maintains the following categories of records, with the indicated minimum retention periods (longer if required by law or contract):
- Customer order records (including Permissible Purpose certifications) — five (5) years (Tex. Transp. Code § 730.013(c); 18 U.S.C. § 2721(c));
- Payment-transaction summaries (excluding full card data) — seven (7) years for tax and accounting purposes;
- Security-incident investigation files — five (5) years from incident closure;
- Employee and contractor training records — duration of employment or contract plus three (3) years;
- Vendor contracts and security attestations — duration of relationship plus five (5) years; and
- Customer complaint and dispute records — three (3) years from resolution.
15. Roles and Responsibilities
Principal (Paul A. Kubosh) is responsible for the overall compliance program, approval of policies and procedures, vendor selection, signing of confidentiality and security agreements, and final decisions regarding breach response and law-enforcement cooperation.
Operations Personnel are responsible for order intake, identity verification, processing requests to Texas DPS, delivery of records, customer support, and prompt escalation of any security incident or apparent violation of law.
Technology Service Providers are responsible for hosting, payment processing, e-mail and communications, and information-security tooling, in each case subject to written agreement with the Company.
16. Updates to These Policies and Procedures
These policies and procedures are reviewed annually and may be revised at any time. Material changes are communicated to Personnel, who must acknowledge the updated document before continuing to access Company systems.
17. Contact
Questions about these policies and procedures should be directed to:
Paul A. Kubosh
Kuboshdpsrecords.com
E-mail: support@kuboshdpsrecords.com
Website: https://www.kuboshdpsrecords.com
