Texas
What Is the TDPSA? Texas Data Privacy and Security Act
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 13 primary sources cited on this page. How we verify our legal content

The Texas Data Privacy and Security Act (TDPSA), codified at Tex. Bus. & Com. Code ch. 541, took effect July 1, 2024. Signed by Governor Greg Abbott on June 18, 2023, it gives Texas residents rights over their personal data and sets a coverage threshold found nowhere else in U.S. state privacy law: instead of a revenue floor or data-volume minimum, it simply covers every business that is not a U.S. Small Business Administration small business.
As of 2026, the Texas Attorney General holds exclusive enforcement authority over the TDPSA and may seek civil penalties up to $7,500 per violation. Businesses that receive a written violation notice have 30 days to cure before any action can proceed.
What the TDPSA is: statute, enactment, and effective dates
The Texas Data Privacy and Security Act is Texas's first comprehensive consumer data privacy law. It is codified at Texas Business and Commerce Code Chapter 541, Sections 541.001 through 541.204, and was enacted as House Bill 4 during the 88th Legislative Session. Governor Greg Abbott signed HB 4 on June 18, 2023. The main body of the law took effect July 1, 2024, giving businesses roughly a year to prepare after enactment.
One specific provision took effect on a later date. Section 541.055(e), which requires controllers to honor universal opt-out signals submitted by a consumer's authorized agent through qualifying technology, became effective January 1, 2025. The enrolled bill text expressly states: "The Act takes effect July 1, 2024, except for Section 541.055(e), Business & Commerce Code...takes effect January 1, 2025." That staggered structure gave businesses additional time to implement the technical mechanisms needed to detect and honor browser-level opt-out preferences before the requirement kicked in.
Texas joins more than 20 states that have enacted comprehensive data privacy legislation as of mid-2026. What makes the TDPSA stand apart from that group is not its effective date or its consumer rights (those are largely in line with the national pattern) but how it defines which businesses it covers. The SBA small-business threshold is a design choice no other state legislature has replicated, and it has significant practical consequences for mid-size companies that would not be covered by the CCPA.
For the full compliance framework covering controller and processor obligations, data protection assessment requirements, and privacy notice content requirements, see the Texas data privacy laws parent page.
Who the TDPSA covers: the SBA small-business threshold
The TDPSA's applicability test is unique among U.S. state privacy laws. Under Section 541.002(a), the law applies to any person that: (1) conducts business in Texas or produces a product or service consumed by residents of Texas; AND (2) processes or engages in the sale of personal data; AND (3) is not a small business as defined by the U.S. Small Business Administration.
The statute's own language is direct: "This chapter applies only to a person that: (1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision."
That third prong is the differentiator. Compare it with California's approach under the CCPA, which requires that a for-profit business meet at least one of three quantitative thresholds: more than $25 million in annual gross revenue, processing the personal information of 100,000 or more California consumers or households, or deriving 50% or more of annual revenue from selling or sharing personal information. A company that earns $10 million per year and handles data for 40,000 Californians is not subject to the CCPA. The same company, if it processes personal data of any Texas residents and does not qualify as an SBA small business, is subject to the TDPSA.
The U.S. Small Business Administration publishes size standards by NAICS industry code. The thresholds vary widely: a company in a professional services sector may be "small" at fewer than 150 employees, while a manufacturing firm may qualify up to 1,500 employees or $47 million in receipts. Because the TDPSA outsources the size determination to federal SBA standards, a company's TDPSA coverage status can turn on its specific industry classification, not just its headcount or revenue in the abstract. Businesses operating across multiple NAICS codes should identify which standard governs their primary activities.
The practical upshot: many mid-size data brokers, software-as-a-service companies, and analytics firms that do not meet the CCPA's revenue floor are nonetheless covered by the TDPSA as soon as they process data relating to even a small number of Texas residents.
Categorical exemptions under Section 541.002(b)
In addition to the SBA small-business exclusion, Section 541.002(b) lists categorical entity exemptions that remove certain types of organizations from the TDPSA's reach regardless of size or data volume. The following entity types are exempt:
- State agencies and political subdivisions of Texas
- Financial institutions, or data, subject to Title V of the Gramm-Leach-Bliley Act (GLBA). The exemption runs to the institution or to the data itself; the TDPSA contains no exemption for a financial institution's affiliates.
- HIPAA-covered entities and business associates
- Nonprofit organizations
- Institutions of higher education
- Electric utilities, power generation companies, and retail electric providers regulated under Texas Utilities Code
These exemptions mean that hospitals, banks, credit unions, universities, charities, and state government bodies all operate outside the TDPSA even if they handle large volumes of Texas resident data. A HIPAA-covered health system, for example, is exempt from TDPSA obligations on the same patient data it holds, though it remains subject to HIPAA's own data rights and security obligations.
Controllers that are partially exempt (for example, a company that operates both a HIPAA-regulated health division and a non-regulated consumer division) should apply the TDPSA only to the data that falls outside the exempt category. The statute does not grant a whole-organization exemption based on partial regulatory overlap.

The small-business exception and the sensitive-data carve-out
Businesses that qualify as SBA small businesses are exempt from most TDPSA requirements. They do not need to respond to consumer access, correction, deletion, or portability requests. They do not need to provide a privacy notice that conforms to Section 541.102's content requirements. They do not need to honor universal opt-out signals.
But the exemption is not total. Section 541.107(a) creates a targeted obligation that applies specifically to small businesses: "A person described by Section 541.002(a)(3) may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer."
In plain terms, if a small business wants to sell sensitive personal data, it must first get the consumer's opt-in consent. There is no size-based pass on this requirement. The legislature drew a line between operational obligations (which only apply to non-SBA businesses) and protective rights over the most sensitive categories of data (which apply even to the smallest covered entity that sells data).
Sensitive data under Section 541.001 of the statute includes: data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; genetic or biometric data processed for the purpose of uniquely identifying an individual; personal data collected from a known child under 13; and precise geolocation data within a radius of 1,750 feet. A small business that collects and sells, for example, location data from users near a medical facility, or that monetizes health-related survey responses, cannot simply claim the SBA exemption and proceed without consent.
The five consumer rights under the TDPSA
Texas residents covered by the TDPSA hold five rights against covered controllers under Section 541.051(b)(1) through (5). Subsection (a) is a separate provision: it lets a consumer submit a request at any time and lets a parent or legal guardian exercise these rights on behalf of a known child. The rights themselves are enumerated in subsection (b):
- Right of access. A consumer may confirm whether a controller is processing their personal data and receive a copy of that data in a portable and readily usable format.
- Right of correction. A consumer may require a controller to correct inaccurate personal data about them, taking into account the nature and purpose of the processing.
- Right of deletion. A consumer may request deletion of personal data provided by or collected about them, subject to limited exceptions where the controller can demonstrate a lawful basis for continued retention.
- Right of portability. A consumer may obtain a copy of their personal data in a readily usable digital format that permits transfer to another controller without hindrance, to the extent technically feasible.
- Right to opt out. A consumer may opt out of three categories of processing: targeted advertising directed at that consumer; the sale of the consumer's personal data to third parties; and profiling that produces a legal or similarly significant effect, such as decisions affecting access to credit, employment, education, insurance, or housing.
Controllers must respond to an authenticated consumer rights request within 45 days of receipt. If the controller needs additional time, it may extend the response period by one additional 45 days (90 days total) when reasonably necessary, provided it notifies the consumer of the extension within the initial 45-day window. If the controller denies a request, it must notify the consumer and explain the basis for the denial. The consumer then has the right to appeal the denial, and the controller must respond to the appeal within 60 days with a written explanation if the appeal is again denied.
For the full compliance framework covering controller and processor obligations, data protection assessment requirements, and consumer rights response procedures, see the Texas data privacy laws parent page.
Universal opt-out signals: what the TDPSA requires as of January 1, 2025
Section 541.055(e), effective January 1, 2025, requires controllers to honor opt-out preferences expressed through an authorized agent using qualifying technology. The statute describes this technology as including "a link to an Internet website, an Internet browser setting or extension, or a global setting on an electronic device, that allows the consumer to indicate the consumer's intent to opt out of the processing" of their personal data for targeted advertising or sale.
This statutory language covers opt-out technologies that operate at the browser or device level rather than requiring the consumer to visit each website individually to click an opt-out button. The Global Privacy Control (GPC), a browser-based signal developed by privacy advocates and supported by a growing number of browsers and extensions, fits within this description. The statute does not name GPC by brand, but the technical description encompasses GPC-type signals: a global browser or device setting through which a consumer has indicated an intent to opt out.
One requirement limits which signals qualify. Section 541.055(f)(2) states that the technology "may not make use of a default setting, but must require the consumer to make an affirmative, freely given, and unambiguous choice to indicate the consumer's intent to opt out of any processing of a consumer's personal data." A browser configured out of the box to send a do-not-process signal, without any deliberate action by the user, does not meet this standard. The signal must reflect something the consumer actively chose to enable.
Section 541.055(e) sets out four grounds on which a controller is not required to comply with an opt-out request received from an authorized agent: (1) the agent does not communicate the request to the controller in a clear and unambiguous manner; (2) the controller cannot verify, with commercially reasonable effort, that the consumer is a resident of Texas; (3) the controller does not possess the ability to process the request; or (4) the controller does not process similar or identical requests it receives from consumers for the purpose of complying with similar or identical laws or regulations of another state. Grounds (3) and (4) are broad. The fourth in particular measures the Texas duty against what a controller already does elsewhere, so a controller that honors no universal opt-out signals under any other state's law has a statutory argument for declining in Texas as well.
Texas's universal opt-out requirement is comparable in effect to California's mandate that covered businesses honor GPC signals, but the Texas rule is grounded in a statutory provision rather than a regulatory interpretation. Virginia's VCDPA, by contrast, does not require controllers to honor universal opt-out signals even as of mid-2026, making Texas's statutory mandate broader on this point than Virginia's framework.

Sensitive and biometric data: opt-in consent and mandatory sale notices
The TDPSA imposes two distinct layers of protection for sensitive personal data, and both layers apply to any covered controller, not just those that handle large volumes of data.
The first layer is the consent requirement. Section 541.101(b)(4) prohibits any covered controller from processing sensitive data about a consumer "without obtaining the consumer's consent, or, in the case of processing the sensitive data of a known child, without processing that data in accordance with the Children's Online Privacy Protection Act." This is an opt-in standard: before any sensitive data may be processed, the controller must affirmatively obtain the consumer's agreement. There is no default-on processing with an opt-out path for sensitive categories.
Sensitive data under Section 541.001 includes: (1) data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; (2) genetic or biometric data processed for the purpose of uniquely identifying an individual; (3) personal data collected from a known child under 13; and (4) precise geolocation data within a radius of 1,750 feet. The biometric category specifically covers facial recognition templates, fingerprints, voice prints, iris scans, and similar identifiers: any data processed to uniquely identify a person by biological characteristics.
The second layer is the notice requirement. When a controller sells sensitive personal data, Section 541.102(b) requires it to post a specific statutory notice in the same location and manner as its privacy notice: "NOTICE: We may sell your sensitive personal data." The statute does not give controllers discretion to phrase this differently or embed it in boilerplate language. When a controller sells biometric personal data specifically, Section 541.102(c) requires a separate additional notice: "NOTICE: We may sell your biometric personal data." Both notices must appear in the same location as the privacy notice, not buried in a terms-of-service footnote, but displayed alongside the primary disclosure document.
These two requirements interact: a controller that sells sensitive data must both obtain opt-in consent before the processing and post the statutory notice. The consent and the notice serve different functions. Consent authorizes the processing; the notice informs consumers that a sale may occur. Both must be in place before the sale begins.
TDPSA enforcement: AG-exclusive, 30-day cure, up to $7,500 per violation
Enforcement of the TDPSA belongs exclusively to the Texas Attorney General. Section 541.156 states that the chapter "may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law." No consumer may sue a covered business directly under Chapter 541, no matter how clear or willful the violation. All enforcement runs through the AG's office.
Before the AG may file any enforcement action, Section 541.154 requires the office to provide written notice to the alleged violator identifying the specific provision(s) of Chapter 541 at issue and giving the business 30 days to cure the violation. The statute's language is precise: before bringing an action under Section 541.155, "the attorney general shall notify a person in writing, not later than the 30th day before bringing the action, identifying the specific provisions of this chapter the attorney general alleges have been or are being violated." If the business cures the violation and provides written documentation within that 30-day window, no enforcement action may proceed for that violation.
The cure period under the TDPSA is permanent, with no sunset date. This is a meaningful distinction from some other state privacy laws that began with cure provisions and later eliminated them. Colorado's privacy law, for example, started with a cure period that expired January 1, 2025; Connecticut's cure period also expired. The Texas legislature embedded no expiration into the cure mechanism, making it a durable feature of the enforcement landscape. A business that discovers a TDPSA compliance gap and corrects it before the AG files suit can avoid penalties for that specific violation.
If the violation is not cured within 30 days, or if the business subsequently violates a written cure statement it previously provided to the AG, Section 541.155(a) authorizes civil penalties of up to $7,500 for each violation. The AG may also recover reasonable expenses, court costs, and attorney fees. The $7,500 cap applies per violation. For a business that systematically denied consumer deletion requests across thousands of accounts, the per-violation accumulation can become significant.
Data protection assessments are also an enforcement target. Section 541.105(a) requires controllers to document assessments for high-risk processing activities including targeted advertising, selling personal data, certain profiling, and sensitive data processing. These assessments apply only to processing activities that began after the July 1, 2024 effective date and are not retroactive. The AG may request documentation of assessments during an investigation, making them both a compliance requirement and a potential enforcement exhibit.
For the controller and processor obligations, privacy notice content requirements, vendor contract mandates, and data protection assessment documentation rules, see the Texas data privacy laws parent page.
TDPSA vs. CCPA: the key differences
The TDPSA and California's CCPA are the two most-compared U.S. state privacy laws for companies operating nationally. Our state data privacy law comparison page covers the full multistate picture, but three distinctions between the TDPSA and California's CCPA matter most in practice.
Coverage threshold. The CCPA applies to for-profit businesses meeting at least one of three quantitative thresholds: more than $25 million in annual gross revenue, data on 100,000 or more California consumers or households, or 50% or more of annual revenue from selling or sharing personal information. The TDPSA sets no revenue floor and no data-volume floor. Its only size filter is SBA small-business status. A company that earns $18 million per year and processes data for 30,000 Texas residents is not covered by the CCPA but is covered by the TDPSA, provided it is not an SBA small business in its industry. Conversely, a very large SBA-ineligible company that handles minimal Texas data may be covered by the TDPSA while a smaller high-volume California company is covered by the CCPA. The two laws cast different nets.
Universal opt-out. Both the TDPSA and the CCPA/CPRA now require covered businesses to honor browser and device-level opt-out signals submitted by consumers. California's obligation was established through regulatory guidance by the California Privacy Protection Agency interpreting the CPRA. Texas's obligation is written directly into the statute at Section 541.055(e), effective January 1, 2025. The legal basis differs: Texas's universal opt-out requirement rests on a statutory command; California's rests on agency interpretation of a broader opt-out mandate. The Texas command is also qualified on the face of the statute, because Section 541.055(e)(1) through (4) list four grounds on which a controller is not required to comply with an agent-submitted opt-out.
Private right of action. The CCPA retains a limited private right of action for consumers whose unencrypted and nonredacted personal information is exposed in a data breach caused by a business's failure to implement reasonable security procedures. Consumers may seek statutory damages of $100 to $750 per consumer per incident, or actual damages if higher. The TDPSA has no private right of action of any kind. A Texas resident whose data is sold without consent, whose deletion request is ignored, or whose sensitive data is processed without consent cannot sue the covered business directly under Chapter 541. All enforcement runs exclusively through the AG.
Related guides
- TDPSA Consumer Rights: Your Texas Data Privacy Rights
- TDPSA Compliance Checklist for Businesses (2026)
- Texas Data Privacy Laws: TDPSA & Consumer Rights Guide (2026)
- Texas Biometric Privacy Laws: Collection, Consent & Penalties (2026)
- US State Privacy Laws Comparison Chart (2026)
More Texas Laws
Frequently Asked Questions
What is the TDPSA?
The TDPSA, or Texas Data Privacy and Security Act, is Texas's comprehensive consumer data privacy law codified at Texas Business and Commerce Code Chapter 541 (Sections 541.001 through 541.204). Governor Greg Abbott signed HB 4 into law on June 18, 2023, and the statute took effect July 1, 2024. It gives Texas residents five data rights and requires covered businesses to be transparent about how they collect, use, and sell personal data. One provision governing universal opt-out signals became effective January 1, 2025.
Who does the TDPSA apply to?
The TDPSA applies to any person or business that (1) conducts business in Texas or produces products or services consumed by Texas residents, (2) processes or sells personal data, and (3) is not a small business as defined by the U.S. Small Business Administration. There is no minimum revenue threshold and no consumer data-volume floor. SBA size standards vary by industry code, so whether a company qualifies as an SBA small business depends on its primary NAICS classification and either its employee count or annual receipts.
Does the TDPSA apply to small businesses?
Mostly no. SBA-defined small businesses are exempt from most TDPSA obligations, including privacy notice requirements, consumer rights response duties, and universal opt-out honoring. However, even small businesses may not sell sensitive personal data (including health data, biometric identifiers, children's data, precise geolocation data, or data revealing race or immigration status) without first obtaining opt-in consent from the affected consumer. That restriction applies to small businesses regardless of their exemption from other TDPSA requirements.
What rights do Texas consumers have under the TDPSA?
Texas residents have five rights under Section 541.051(b): (1) access: confirm whether their data is being processed and get a copy; (2) correct: require a controller to fix inaccurate data; (3) delete: request removal of personal data the consumer provided or that was collected about them; (4) portability: receive a machine-readable copy for transfer to another controller; and (5) opt out: of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects. Controllers must respond within 45 days, with one allowable 45-day extension.
What is the penalty for violating the TDPSA?
Up to $7,500 in civil penalties per violation, plus reasonable expenses, court costs, and attorney fees recoverable by the AG. Before filing suit, the Texas AG must serve written notice identifying the specific statutory provision(s) allegedly violated and allow 30 days to cure. If the business remedies the violation and submits written documentation of compliance within that window, no enforcement action may proceed for that violation. The cure period is permanent; the TDPSA contains no sunset date for the cure provision.
Does the TDPSA have a private right of action?
No. Section 541.156 expressly states the TDPSA 'may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law.' Enforcement is exclusively the Texas Attorney General's authority. Individual consumers cannot sue covered businesses directly under Chapter 541 for any violation, including unauthorized data sales, ignored deletion requests, or processing of sensitive data without consent.
Does the TDPSA require honoring Global Privacy Control (GPC) signals?
Yes, in effect. Section 541.055(e), effective January 1, 2025, requires controllers to honor opt-out signals submitted by a consumer's authorized agent through qualifying technology, including browser settings, browser extensions, and global device-level settings. The statutory description encompasses GPC-type signals, though the statute does not name GPC by brand. The technology must represent an affirmative, unambiguous consumer choice and not a browser default setting. Section 541.055(e) also lists four grounds on which a controller is not required to comply with an agent-submitted request, including that the controller cannot verify Texas residency, does not possess the ability to process the request, or does not process similar requests in order to comply with another state's similar law.
What notice must a controller post if it sells sensitive personal data?
Controllers that sell sensitive personal data must post the exact statutory text: 'NOTICE: We may sell your sensitive personal data.' This notice must appear in the same location and manner as the privacy notice. Controllers that sell biometric personal data specifically must also post a separate notice: 'NOTICE: We may sell your biometric personal data.' Both notices are required in addition to, not instead of, obtaining opt-in consent before processing sensitive data.
How is the TDPSA different from the CCPA?
Three key differences: (1) Coverage threshold: the CCPA uses revenue and data-volume minimums ($25M/100K consumers); the TDPSA uses SBA small-business status as its only size filter, meaning many mid-size companies covered by the TDPSA are not covered by the CCPA, and vice versa. (2) Universal opt-out: both now require honoring browser opt-out signals, but Texas's requirement is a direct statutory command in Section 541.055(e) while California's is grounded in regulatory interpretation. (3) Private right of action: the CCPA includes a limited private right of action for data breach victims; the TDPSA has none.
Updates
Corrected the statutory subsection cited for the five consumer rights, restored the enacted wording of three statutory quotations, added the four grounds on which a controller may decline an agent-submitted opt-out signal, and narrowed the Gramm-Leach-Bliley exemption description to match the enacted text.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Texas Business & Commerce Code
§ 541.051CONSUMER'S PERSONAL DATA RIGHTS; REQUEST TO EXERCISE RIGHTSIn forcecited in 3 of our articles
(a) A consumer is entitled to exercise the consumer rights authorized by this section at any time by submitting a request to a controller specifying the consumer rights the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise the consumer rights on behalf of the child. (b) A controller shall comply with an authenticated consumer request to exercise the right to: (1) confirm whether a controller is processing the consumer's personal data and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 1 court opinionsMost recently applied by a court: 2025
Leading cases:
- State of Texas v. Arity 875, LLC (Texas Court of Appeals, 15th District 2025)“…10 Tex. Bus. & Com. Code § 541.051(b)(5) .................................…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: TDPSA Consumer Rights: Your Texas Data Privacy Rights, Texas Data Privacy Laws: TDPSA & Consumer Rights Guide (2026)
§ 541.002APPLICABILITY OF CHAPTERIn force
(a) This chapter applies only to a person that: (1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision. (b) This chapter does not apply to: (1) a state agency or a political subdivision of this state; (2) a financial institution or data subject to Title V, Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.); (3) a covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. Parts 160 and 164, established under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.), and the Health Information Technology for Economic and Clinical Health Act (Division A, Title XIII, and Division B, Title IV, Pub. L. No.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.107REQUIREMENTS FOR SMALL BUSINESSESIn force
(a) A person described by Section 541.002(a)(3) may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. (b) A person who violates this section is subject to the penalty under Section 541.155.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.101CONTROLLER DUTIES; TRANSPARENCYIn forcecited in 2 of our articles
(a) A controller: (1) shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which that personal data is processed, as disclosed to the consumer; and (2) for purposes of protecting the confidentiality, integrity, and accessibility of personal data, shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices that are appropriate to the volume and nature of the personal data at issue.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 3 court opinionsMost recently applied by a court: 2025
Leading cases:
- State of Texas v. Arity 875, LLC (Texas Court of Appeals, 15th District 2025)“…13 Tex. Bus. & Com. Code § 541.101(b)(3) .................................…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: TDPSA Compliance Checklist for Businesses (2026)
§ 541.102PRIVACY NOTICEIn force
(a) A controller shall provide consumers with a reasonably accessible and clear privacy notice that includes: (1) the categories of personal data processed by the controller, including, if applicable, any sensitive data processed by the controller; (2) the purpose for processing personal data; (3) how consumers may exercise their consumer rights under Subchapter B, including the process by which a consumer may appeal a controller's decision with regard to the consumer's request; (4) if applicable, the categories of personal data that the controller shares with third parties; (5) if applicable, the categories of third parties with whom the controller shares personal data; and (6) a description of the methods required under Section 541.055 through which consumers can submit requests to exercise their consumer rights under this chapter. (b) If a controller engages in the sale of personal data that is sensitive data, the controller shall include the following notice: "NOTICE: We may sell your sensitive personal data." The notice must be posted in the same location and in the same manner as the privacy notice described by Subsection (a).
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Cited in 3 court opinionsMost recently applied by a court: 2025
Leading cases:
- State of Texas v. Arity 875, LLC (Texas Court of Appeals, 15th District 2025)“…9, 43 Tex. Bus. & Com. Code § 541.102(a) ....................................…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 541.055METHODS FOR SUBMITTING CONSUMER REQUESTSIn forcecited in 2 of our articles
(a) A controller shall establish two or more secure and reliable methods to enable consumers to submit a request to exercise their consumer rights under this chapter. The methods must take into account: (1) the ways in which consumers normally interact with the controller; (2) the necessity for secure and reliable communications of those requests; and (3) the ability of the controller to authenticate the identity of the consumer making the request. (b) A controller may not require a consumer to create a new account to exercise the consumer's rights under this subchapter but may require a consumer to use an existing account. (c) Except as provided by Subsection (d), if the controller maintains an Internet website, the controller must provide a mechanism on the website for consumers to submit requests for information required to be disclosed under this chapter. (d) A controller that operates exclusively online and has a direct relationship with a consumer from whom the controller collects personal information is only required to provide an e-mail address for the submission of requests described by Subsection (c).
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.154NOTICE OF VIOLATION OF CHAPTER; OPPORTUNITY TO CUREIn force
Before bringing an action under Section 541.155, the attorney general shall notify a person in writing, not later than the 30th day before bringing the action, identifying the specific provisions of this chapter the attorney general alleges have been or are being violated. The attorney general may not bring an action against the person if: (1) within the 30-day period, the person cures the identified violation; and (2) the person provides the attorney general a written statement that the person: (A) cured the alleged violation; (B) notified the consumer that the consumer's privacy violation was addressed, if the consumer's contact information has been made available to the person; (C) provided supportive documentation to show how the privacy violation was cured; and (D) made changes to internal policies, if necessary, to ensure that no such further violations will occur.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.155CIVIL PENALTY; INJUNCTIONIn force
(a) A person who violates this chapter following the cure period described by Section 541.154 or who breaches a written statement provided to the attorney general under that section is liable for a civil penalty in an amount not to exceed $7,500 for each violation. (b) The attorney general may bring an action in the name of this state to: (1) recover a civil penalty under this section; (2) restrain or enjoin the person from violating this chapter; or (3) recover the civil penalty and seek injunctive relief. (c) The attorney general may recover reasonable attorney's fees and other reasonable expenses incurred in investigating and bringing an action under this section. (d) The attorney general shall deposit a civil penalty collected under this section in accordance with Section 402.007, Government Code.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.156NO PRIVATE RIGHT OF ACTIONIn force
This chapter may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
§ 541.105DATA PROTECTION ASSESSMENTSIn force
(a) A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data: (1) the processing of personal data for purposes of targeted advertising; (2) the sale of personal data; (3) the processing of personal data for purposes of profiling, if the profiling presents a reasonably foreseeable risk of: (A) unfair or deceptive treatment of or unlawful disparate impact on consumers; (B) financial, physical, or reputational injury to consumers; (C) a physical or other intrusion on the solitude or seclusion, or the private affairs or concerns, of consumers, if the intrusion would be offensive to a reasonable person; or (D) other substantial injury to consumers; (4) the processing of sensitive data; and (5) any processing activities involving personal data that present a heightened risk of harm to consumers.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Tex. Bus. & Com. Code ch. 541:Texas Data Privacy and Security Act (Full Text)(statutes.capitol.texas.gov).gov
- Texas HB 4, 88th Legislature (2023):Enrolled Bill Text(capitol.texas.gov).gov
- Texas HB 4:Legislative History (88th Regular Session)(capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.002:Applicability(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.051:Consumer Rights(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.055:Consumer Opt-Out Rights and Universal Opt-Out Signals(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.101:Controller Responsibilities(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.102:Privacy Notice and Sensitive Data Sale Notices(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.105:Data Protection Assessments(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.107:Small Business Sensitive Data Restriction(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.154:30-Day Cure Period(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.155:Civil Penalty; Injunction(statutes.capitol.texas.gov).gov
- Tex. Bus. & Com. Code § 541.156:No Private Right of Action(statutes.capitol.texas.gov).gov