Texas
TDPSA Consumer Rights: Your Texas Data Privacy Rights
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 6 primary sources cited on this page. How we verify our legal content

If a Texas company holds data about you, the Texas Data Privacy and Security Act gives you five enforceable rights over that data, plus a separate right to appeal a denial. Here is exactly how to use each one, what timelines apply, and what to do when a company refuses.
The TDPSA (Tex. Bus. & Com. Code ch. 541) took effect July 1, 2024, enacted as H.B. 4 during the 88th Texas Legislature. Under Section 541.002(a), it applies to any person that conducts business in Texas or targets Texas residents, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration. Even a small business remains subject to the narrower rule in Section 541.107, which requires consent before selling sensitive data. For a broader overview of how the law works, see the Texas Data Privacy Laws hub. For a plain-language explanation of the law's scope and who it covers, see What Is the TDPSA.
Your TDPSA Rights at a Glance
Texas Business and Commerce Code Chapter 541 grants you five consumer rights over personal data held by covered controllers, plus a separate right to appeal a denial. Under § 541.051(b), the five rights are:
- Access and confirm. You can ask whether a company is processing your personal data and request a copy of it.
- Correct. You can require a company to fix inaccuracies in your personal data, taking into account the nature of the data and the purpose of processing.
- Delete. You can require a company to delete personal data it obtained from you or about you.
- Portability. You can request your data in a portable, machine-readable format that allows you to transfer it to another controller.
- Opt out. You can stop a company from using your data for targeted advertising, selling your data to third parties, or running automated profiling that produces significant decisions about you.
Section 541.053 adds a separate guarantee alongside these five rights: you can appeal any denial, and if the appeal is denied, you can escalate to the Texas Attorney General.
These rights apply to personal data you provided directly and to data the company obtained about you from other sources. The law was enacted as Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), with core provisions effective July 1, 2024 and the universal opt-out mandate effective January 1, 2025.
How to Submit a TDPSA Rights Request
Under § 541.055(b), a company cannot require you to create a new account as a condition for submitting a request. You may use an existing account if you have one. Under § 541.055(a), a controller must establish two or more secure and reliable methods for consumers to submit a request, so if a covered company gives you only a single channel, that is itself a compliance gap worth documenting. Most companies link to their privacy rights portal in the footer of their website or inside their privacy policy.
Step-by-step process:
- Go to the company's website and look in the footer or privacy policy for a link labeled "Texas Privacy Rights," "Your Privacy Rights," "Consumer Privacy Request," or "Do Not Sell My Personal Information."
- Select the right you want to exercise (access, correction, deletion, portability, or opt-out).
- Provide identifying information so the company can authenticate you. This typically means your name, the email address associated with your account, and possibly account details or answers to security questions.
- Submit the request and save a copy: a screenshot or confirmation email is enough.
- The 45-day response clock starts on the date the company receives your request under § 541.052(b).
Under § 541.052, companies must provide responses free of charge at least twice annually per consumer. If your requests become manifestly unfounded, excessive, or repetitive, the company may charge a reasonable fee or decline to act, but the burden of proving that standard is met falls on the company, not on you.
Timelines: 45 Days, One Extension, Then an Answer
Section 541.052 sets the response clock. A company must respond without undue delay, and no later than the 45th day after the date it receives your request. If a company needs more time, it may extend the window by a single additional 45 days, but it must notify you of the extension before the initial period closes and explain why the extension is reasonably necessary.
That means in the worst case you should hear something within 90 days total. If the company decides to decline your request rather than simply needing extra processing time, it must tell you its reasons and explain how to appeal. A company that goes silent past 45 days without notifying you of an extension has violated § 541.052, which gives you grounds to proceed directly to an appeal or a complaint.
Keep records of when you submitted your request. The statute runs the deadline from the date of receipt of the request, and nothing in § 541.052 restarts that clock if the company later comes back asking for more information. Section 541.052(e) says only that a controller that cannot authenticate a request using commercially reasonable efforts is not required to comply with it, and may ask you for additional information reasonably necessary to authenticate you and your request. Answer any verification request promptly, and confirm the company's receipt date in writing where you can, because the deadline is still measured from that original receipt.
Your Right to Access and Correct Your Data
Access (§ 541.051(b)(1)): You can ask any covered company to confirm whether it is processing personal data about you and to give you a copy of that data. The right has two parts: confirmation (does the company hold your data?) and access (show me what you have). This is the natural starting point before you exercise any other right.
How to exercise it: Submit an access request through the company's designated privacy channel. You may need to specify the categories of data you are interested in or ask for all personal data the company holds. The company must respond within 45 days with confirmation and, if it is processing your data, a readable copy.
Correction (§ 541.051(b)(2)): Once you have seen your data, you can require correction of any inaccuracies "taking into account the nature of the personal data and the purposes of the processing." This matters most for data used to make decisions about you: credit profiles, health-related information, contact records, or behavioral classifications.
How to exercise it: Submit a correction request identifying the specific inaccuracy and, where possible, providing documentation of the correct information. The company has 45 days to respond and must tell you what it changed or why it declined. A refusal triggers your appeal right.

Your Right to Delete Personal Data
Under § 541.051(b)(3), you can request deletion of personal data "provided by or obtained about" you. The right covers both data you supplied directly (account information, purchase history, form submissions) and data the company acquired about you from other sources (behavioral profiles, data-broker records, inferred attributes).
How to exercise it: Submit a deletion request through the company's privacy portal or designated contact method. Be specific about what you want deleted: categories of data, specific records, or all personal data the company holds about you. The 45-day clock applies.
Deletion has statutory limits. A company may keep data that is necessary to complete a transaction, to detect security incidents, to exercise or defend legal claims, to comply with a legal obligation, or to carry out certain research or public-interest functions. When a company declines to delete, it must explain which exception applies. Vague or unsupported refusals are not sufficient under § 541.052.
Your Right to Data Portability
Section 541.051(b)(4) lets you obtain a copy of personal data you previously provided to the company in a portable format. The statute requires the format to be "readily usable" and to allow you to "transmit the data to another controller without hindrance" to the extent technically feasible.
How to exercise it: Request a data export through the company's privacy rights channel. Common formats include CSV, JSON, or structured spreadsheets. The "technically feasible" qualifier means the company can use standard formats rather than building a custom export; it does not allow the company to provide an unusable dump or refuse entirely on grounds of complexity.
Portability applies to data you provided to the controller. It does not necessarily require the company to export data it derived or inferred internally from your activity. Like access requests, portability responses are free up to twice per year and must arrive within 45 days.
The Opt-Out Rights: Targeted Ads, Data Sales, and Profiling
Section 541.051(b)(5) gives you the right to opt out of three distinct uses of your personal data:
- Targeted advertising. Ads selected for you based on your behavior across different websites, apps, or services that are not under common ownership or control. If a company is sharing your browsing history or purchase data with an ad network to serve you behavioral ads, you can stop that.
- Sale of personal data. Transferring your personal data to a third party in exchange for monetary or other valuable consideration. Under the TDPSA, this includes exchanges for non-monetary value, which is broader than Virginia's definition but narrower than California's CPRA on the "sharing" side.
- Profiling in furtherance of significant decisions. Automated processing that produces decisions with legal or similarly significant effects on you, covering decisions about credit, insurance, employment, housing, education, or access to essential goods and services.
How to exercise it: Look in the company's footer or privacy policy for a link labeled "Do Not Sell My Personal Data," "Opt Out of Targeted Advertising," or "Privacy Choices." Submit the request through the designated channel. Under § 541.052, the company must honor your opt-out within the standard 45-day response window.
Note the distinction between the opt-out rights (targeted ads, sale, profiling) and the opt-IN requirement for sensitive data addressed below. Ordinary personal data defaults to opt-out. Sensitive data requires consent before processing begins.
For a comparison of how these opt-out rules compare to other state laws, see the TDPSA compliance checklist for businesses, which covers the controller-side obligations in detail.
Global Privacy Control: The Browser-Level Opt-Out
Texas is one of the first states to mandate recognition of universal opt-out signals. Section 541.055(e), effective January 1, 2025, lets you designate an authorized agent, including a browser signal such as the Global Privacy Control (GPC), to submit an opt-out from the sale of personal data and targeted advertising on your behalf. The duty it creates is real but conditional: a controller must comply with an opt-out request received from an authorized agent if the controller is able to verify, with commercially reasonable effort, your identity and the agent's authority to act on your behalf.
The same subsection names four situations in which a controller is not required to comply: the authorized agent does not communicate the request in a clear and unambiguous manner; the controller is unable to verify with commercially reasonable effort that you are a Texas resident; the controller does not possess the ability to process the request; or the controller does not process similar requests under comparable state or federal law. In practice that means a browser signal is a genuine legal opt-out in Texas, but it is not an absolute one.
What GPC is: The Global Privacy Control is a browser-level signal you enable once. Sites subject to a participating state's privacy law then treat that signal as a formal opt-out, subject to the conditions above. In the ordinary case you do not have to hunt down each company's privacy portal or fill out a separate form site by site.
How to enable GPC:
- Firefox: Settings > Privacy and Security > Enable "Tell websites not to sell or share my data."
- Brave: Settings > Privacy and Security > "Send a 'Do Not Sell My Personal Information' signal."
- Chrome or Edge (via extension): Install the Global Privacy Control extension from the Chrome Web Store or Edge Add-ons.
A Texas-specific caution about default-on signals. Section 541.055(f)(2) provides that the technology used to send a universal opt-out signal "may not make use of a default setting, but must require the consumer to make an affirmative, freely given, and unambiguous choice to indicate the consumer's intent to opt out." A browser that ships with GPC switched on for everyone, as the DuckDuckGo browser does, does not by itself demonstrate that affirmative choice, so a Texas controller has a statutory basis to disregard the signal. If your browser has GPC enabled out of the box, the safer route in Texas is to enable the signal yourself in a browser where it is off by default, or to also submit the company's own opt-out request so your choice is on the record.
Once you have enabled it yourself, a Texas-covered business must honor that signal as an opt-out from data sales and targeted advertising under § 541.055(e), provided the verification conditions in that subsection are met and none of its four exceptions applies. This is still the most efficient way to exercise your Texas opt-out rights at scale, across dozens or hundreds of sites at once. Where you want certainty with a particular company, filing its own opt-out form as well costs you very little.

Sensitive Data: Companies Need Your Permission First
For certain categories of personal data, the TDPSA flips the default entirely. Under § 541.101(b)(4), a controller cannot process your sensitive data at all without first obtaining your consent. This is an opt-IN requirement: the company must ask permission before processing begins, not after.
Under § 541.001(29), sensitive data includes:
- Racial or ethnic origin
- Religious beliefs
- Health diagnoses or mental health conditions
- Sexuality
- Citizenship or immigration status
- Genetic data
- Biometric data processed to uniquely identify you (fingerprints, facial geometry, retina scans)
- Precise geolocation data (typically within a radius defined by GPS or similar technology)
- Personal data of known children
The January 2025 enforcement action illustrates how seriously Texas takes this category. The Texas AG sued Allstate and its subsidiary Arity on January 13, 2025, for allegedly collecting precise geolocation and driving data from more than 45 million people without notice or consent, in violation of § 541.101(b)(4). The case signals that sensitive-data violations are a top enforcement priority.
If a company is processing any of these categories about you without having obtained your consent, that is a violation of § 541.101(b)(4) and a strong basis for a Texas AG complaint.
Non-Discrimination: Companies Cannot Punish You for Exercising Your Rights
Section 541.101(b)(3) prohibits controllers from discriminating against you for exercising any TDPSA right, including by denying goods or services, charging different prices or rates, or providing a different level of quality. A company cannot:
- Deny you goods or services because you submitted a privacy request
- Charge you a different price or rate because you exercised a TDPSA right
- Provide you a lower quality of service because you asked for your data or requested deletion
- Retaliate against you in any other way for using these rights
There is an express exception, and it covers the scenario most readers of this page will actually meet. Section 541.101(c) provides that subsection (b)(3) may not be construed to prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services, including offering goods or services for no fee, if you have exercised your right to opt out under § 541.051, or if the offer is related to your voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program. The same subsection also makes clear that a controller is not required to provide a product or service that requires personal data it does not collect or maintain.
So a site that withdraws a free ad-supported tier after you opt out of data sales, or a store that drops you from a rewards discount, is not automatically violating the statute. The non-discrimination rule has its real force against a company that penalizes you for an access, correction, deletion, or portability request, which § 541.101(c) does not carve out.
Section 541.054 goes further: any contract provision that tries to waive or limit your rights under §§ 541.051 through 541.053 is "contrary to public policy and is void and unenforceable." You cannot sign away your TDPSA rights, and no company can make doing so a condition of service.
If you believe a company has penalized you for exercising your rights, document the treatment carefully: the denial of service, the price difference, or the quality gap. Include that documentation when you file a complaint with the Texas AG.
How to Appeal a Denied Request
If a company refuses your request to access, correct, delete, port, or opt out, it must tell you why and explain how to appeal. Under § 541.053(a)-(c), every covered controller must establish an appeal process that is conspicuously available and functions similarly to the original request process.
Step 1: Internal appeal to the controller. Submit your appeal through whatever channel the company designates, typically the same privacy portal used for initial requests or a separate appeal email. There is no prescribed form. Clearly state that you are appealing the denial, identify the original request by date and type, and explain why you believe the denial was improper. Save a copy of your appeal submission and the date you sent it.
The company must respond to your appeal within 60 days of receiving it and must provide a written explanation of its decision. Note the different timelines: 45 days for initial requests, 60 days for appeals. If the company approves your appeal, it must take the corrective action promptly.
Step 2: Escalation to the Texas Attorney General. Under § 541.053(d), if the company denies your appeal, it must provide you with the Texas AG's online complaint mechanism described in § 541.152. The company is legally required to hand you that link; you should not need to search for it independently.
If the company simply ignores your request for 45 days without notifying you of an extension, you do not need to go through a formal appeal. A non-response is itself a violation, and you can file a complaint with the AG directly.
How to File a Complaint with the Texas Attorney General
Under § 541.152, the Texas Attorney General is required by law to maintain on its official website: (1) information about consumer rights under TDPSA Subchapter B, and (2) an online mechanism through which consumers can file TDPSA complaints. After an appeal denial, the company must point you directly to that mechanism.
Where to file:
- Texas AG TDPSA complaint page: https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-privacy-rights/texas-data-privacy-and-security-act
- AG Consumer Complaint Portal: https://consumerprotection.texasattorneygeneral.gov/consumercomplaintportal/s/
What to include in your complaint:
- The name of the company and its website
- The date you submitted your original request
- The type of request (access, deletion, opt-out, etc.)
- The date and content of the company's denial
- The date you submitted your appeal
- The date and content of the appeal denial
- Copies of all written correspondence
The more documentation you provide, the stronger your complaint. The AG's enforcement office looks for documented patterns of non-compliance as triggers for investigations, but individual complaints that are well-documented can also lead to action against specific violators.
Under § 541.154, the AG must provide a controller with 30 days' written notice identifying the alleged violation before filing suit, during which the controller may cure. If the violation is not cured, the AG can seek civil penalties of up to $7,500 per violation under § 541.155. The AG has exclusive enforcement authority under § 541.151; there is no private right of action. You cannot sue the company yourself. But filing a complaint creates a formal record and can contribute to AG enforcement priority decisions.
Related guides
- What Is the TDPSA? Texas Data Privacy and Security Act
- TDPSA Compliance Checklist for Businesses (2026)
- Texas Data Privacy Laws: TDPSA & Consumer Rights Guide (2026)
- Texas Biometric Privacy Laws: Collection, Consent & Penalties (2026)
- US State Privacy Laws Comparison Chart (2026)
More Texas Laws
Frequently Asked Questions
How do I find where to submit a TDPSA rights request?
Look in the company's website footer or privacy policy for a link labeled Texas Privacy Rights, Your Privacy Choices, Do Not Sell My Personal Information, or Consumer Privacy Request. Under § 541.055(b), the company cannot require you to create a new account to submit a request, and under § 541.055(a) it must establish two or more secure and reliable methods for consumers to submit one. If you cannot find the link, contact the company's customer service team and ask specifically for the TDPSA consumer rights submission method.
How long does a company have to respond to my TDPSA request?
Under § 541.052, the company must respond within 45 days of the date it receives your request. One 45-day extension is allowed, but the company must notify you within the first 45-day window that it is taking the extension and explain why. Asking you for more information to authenticate the request does not restart the clock. Responses must be free at least twice per year. After two requests in a calendar year, the company may charge a reasonable fee only if your requests are manifestly unfounded, excessive, or repetitive, and the burden of proving that is on the company.
What is the TDPSA appeal process and how long does it take?
If a company denies your request, it must offer a conspicuous appeal process under § 541.053. Submit your appeal through the company's designated channel, clearly identifying the original request and why you believe the denial was wrong. The company has 60 days to respond with a written explanation. If the appeal is denied, the company must provide you with the Texas AG's online complaint portal link under § 541.053(d) and § 541.152.
Does Global Privacy Control (GPC) work for Texas residents?
Yes, within limits. Under § 541.055(e), effective January 1, 2025, a company subject to the TDPSA must honor an opt-out request submitted by your authorized agent, including a GPC browser signal, if it can verify your identity and the agent's authority with commercially reasonable effort. That subsection also excuses compliance in four situations, including where the company cannot verify that you are a Texas resident and where it does not possess the ability to process the request. Under § 541.055(f)(2) the signal may not come from a default setting; it must reflect your own affirmative, freely given, and unambiguous choice, so a browser that enables GPC out of the box does not satisfy the statute. Enable it yourself in Firefox or Brave under Privacy and Security, or in Chrome or Edge with a GPC extension.
What counts as sensitive data under the TDPSA?
Under § 541.001(29), sensitive data includes: racial or ethnic origin; religious beliefs; health diagnoses or mental health conditions; sexuality; citizenship or immigration status; genetic data; biometric data processed to uniquely identify you; precise geolocation data; and personal data of known children. Under § 541.101(b)(4) a company must obtain your consent before processing any of these categories and cannot simply let you opt out after the fact.
Can a company charge me more after I opt out of data sales?
Sometimes, yes. Section 541.101(b)(3) bars a controller from discriminating against you for exercising a TDPSA right, but § 541.101(c) says that rule may not be construed to prohibit a controller from offering a different price, rate, level, quality, or selection of goods or services, including offering them for no fee, where you have exercised your right to opt out under § 541.051 or where the offer relates to your voluntary participation in a bona fide loyalty, rewards, premium features, discounts, or club card program. Losing a free ad-supported tier or a rewards discount after an opt-out is therefore not automatically a violation. A penalty imposed because you asked for access, correction, deletion, or portability is a different matter and is not carved out.
Can I sue a company that violates my TDPSA rights?
No. The TDPSA grants exclusive enforcement authority to the Texas Attorney General under § 541.151; there is no private right of action. You can file a complaint with the AG at the Texas AG TDPSA complaint page, and the AG can seek civil penalties of up to $7,500 per violation under § 541.155 after giving the company a 30-day opportunity to cure under § 541.154. The AG sued Allstate and its subsidiary Arity under the TDPSA in January 2025, demonstrating that the office actively uses this authority.
Does the TDPSA apply to every company that holds my data?
No. It covers any person that conducts business in Texas or targets Texas residents, processes or sells personal data, and is not a small business under U.S. Small Business Administration size standards, which vary by industry rather than a single revenue figure. There is no consumer-volume or revenue-share threshold. A small business must still get consent before selling sensitive data under Section 541.107. Nonprofits, government agencies, HIPAA-covered entities for healthcare data, Gramm-Leach-Bliley financial institutions for covered data, and certain other regulated entities are exempt.
Can a company charge me to handle my privacy request?
Not for your first two requests per year. Under § 541.052, responses must be free at least twice annually. After that, a company may charge a reasonable fee only if your request is manifestly unfounded, excessive, or repetitive, and the company bears the burden of demonstrating that your request meets that standard. If the company wants to charge you and you believe your request is legitimate, challenge the fee in writing and include the dispute in any subsequent AG complaint.
Updates
Corrected this guide against the official text of Tex. Bus. & Com. Code ch. 541: Texas requires companies to offer two or more request-submission methods, the universal opt-out duty carries verification conditions and four exceptions and cannot rest on a browser default under § 541.055(f)(2), § 541.101(c) expressly permits a different price or service level after you opt out of data sales, the 45-day clock runs from receipt with no restart, and the overstated description of the Allstate suit as a first-in-the-nation enforcement action was removed.
Corrected the article's description of who the TDPSA covers: the law's actual gate is U.S. Small Business Administration size status, not the revenue and resident-count thresholds this page had previously stated in its intro and one FAQ answer. Also corrected a miscount of consumer rights (the statute lists five, plus a separate right to appeal) and restored the statute's own term 'sexuality' in the sensitive-data list.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Texas Business & Commerce Code
§ 541.051CONSUMER'S PERSONAL DATA RIGHTS; REQUEST TO EXERCISE RIGHTSIn forcecited in 3 of our articles
(a) A consumer is entitled to exercise the consumer rights authorized by this section at any time by submitting a request to a controller specifying the consumer rights the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise the consumer rights on behalf of the child. (b) A controller shall comply with an authenticated consumer request to exercise the right to: (1) confirm whether a controller is processing the consumer's personal data and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 1 court opinionsMost recently applied by a court: 2025
Leading cases:
- State of Texas v. Arity 875, LLC (Texas Court of Appeals, 15th District 2025)“…10 Tex. Bus. & Com. Code § 541.051(b)(5) .................................…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: What Is the TDPSA? Texas Data Privacy and Security Act, Texas Data Privacy Laws: TDPSA & Consumer Rights Guide (2026)
§ 541.052CONTROLLER RESPONSE TO CONSUMER REQUESTIn force
(a) Except as otherwise provided by this chapter, a controller shall comply with a request submitted by a consumer to exercise the consumer's rights pursuant to Section 541.051 as provided by this section. (b) A controller shall respond to the consumer request without undue delay, which may not be later than the 45th day after the date of receipt of the request. The controller may extend the response period once by an additional 45 days when reasonably necessary, taking into account the complexity and number of the consumer's requests, so long as the controller informs the consumer of the extension within the initial 45-day response period, together with the reason for the extension. (c) If a controller declines to take action regarding the consumer's request, the controller shall inform the consumer without undue delay, which may not be later than the 45th day after the date of receipt of the request, of the justification for declining to take action and provide instructions on how to appeal the decision in accordance with Section 541.053. (d) A controller shall provide information in response to a consumer request free of charge, at least twice annually per consumer.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.053APPEALIn force
(a) A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision under Section 541.052(c). (b) The appeal process must be conspicuously available and similar to the process for initiating action to exercise consumer rights by submitting a request under Section 541.051. (c) A controller shall inform the consumer in writing of any action taken or not taken in response to an appeal under this section not later than the 60th day after the date of receipt of the appeal, including a written explanation of the reason or reasons for the decision. (d) If the controller denies an appeal, the controller shall provide the consumer with the online mechanism described by Section 541.152 through which the consumer may contact the attorney general to submit a complaint.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.055METHODS FOR SUBMITTING CONSUMER REQUESTSIn forcecited in 2 of our articles
(a) A controller shall establish two or more secure and reliable methods to enable consumers to submit a request to exercise their consumer rights under this chapter. The methods must take into account: (1) the ways in which consumers normally interact with the controller; (2) the necessity for secure and reliable communications of those requests; and (3) the ability of the controller to authenticate the identity of the consumer making the request. (b) A controller may not require a consumer to create a new account to exercise the consumer's rights under this subchapter but may require a consumer to use an existing account. (c) Except as provided by Subsection (d), if the controller maintains an Internet website, the controller must provide a mechanism on the website for consumers to submit requests for information required to be disclosed under this chapter. (d) A controller that operates exclusively online and has a direct relationship with a consumer from whom the controller collects personal information is only required to provide an e-mail address for the submission of requests described by Subsection (c).
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.054WAIVER OR LIMITATION OF CONSUMER RIGHTS PROHIBITEDIn force
Any provision of a contract or agreement that waives or limits in any way a consumer right described by Sections 541.051, 541.052, and 541.053 is contrary to public policy and is void and unenforceable.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.152INTERNET WEBSITE AND COMPLAINT MECHANISMIn force
The attorney general shall post on the attorney general's Internet website: (1) information relating to: (A) the responsibilities of a controller under Subchapters B and C; (B) the responsibilities of a processor under Subchapter C; and (C) a consumer's rights under Subchapter B; and (2) an online mechanism through which a consumer may submit a complaint under this chapter to the attorney general.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Tex. Bus. & Com. Code ch. 541 -- Texas Data Privacy and Security Act (full text)(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.051 -- Consumer rights(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.052 -- Consumer request procedures and response timelines(texas.public.law)
- Tex. Bus. & Com. Code § 541.053 -- Appeal of denied consumer requests(texas.public.law)
- Tex. Bus. & Com. Code § 541.054 -- Waiver of consumer rights void and unenforceable(texas.public.law)
- Tex. Bus. & Com. Code § 541.055 -- Controller duties; universal opt-out signals (eff. Jan. 1, 2025)(texas.public.law)
- Tex. Bus. & Com. Code § 541.101 -- Sensitive data; consent; non-discrimination(texas.public.law)
- Tex. Bus. & Com. Code § 541.152 -- Texas AG consumer rights information and complaint mechanism(texas.public.law)
- Texas Attorney General -- File a TDPSA Consumer Privacy Complaint(texasattorneygeneral.gov).gov
- Texas AG Consumer Complaint Portal(consumerprotection.texasattorneygeneral.gov).gov
- Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4) -- TDPSA enactment(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code §§ 541.151, 541.154-541.155 -- AG exclusive enforcement authority, cure notice, civil penalty(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code §§ 541.052, 541.055, 541.101 -- official chapter text (Texas Legislature)(tcss.legis.texas.gov)