Texas — Comprehensive Law

Texas Privacy Law

Texas enforces one of the broadest comprehensive privacy laws in the country. The Texas Data Privacy and Security Act took effect on July 1, 2024 and is unusual in having no revenue or consumer-count threshold: House Bill 4 of the 88th Legislature applies it to any person who conducts business in Texas or produces a product or service consumed by Texans, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration. Texas also publishes a running public list of the breaches reported to the Attorney General, and its office has pursued privacy claims in bankruptcy court and in state court against platforms in the last two years.

The Texas Data Privacy and Security Act (TDPSA)

Enacted as House Bill 4 in the 88th Regular Session, the TDPSA added subtitle C to title 11 of the Business & Commerce Code. Section 541.002(a) states the applicability test in three parts and, unlike the comprehensive laws of most other states, states no numeric threshold at all. Section 541.002(b) then removes state agencies and political subdivisions, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, and covered entities and business associates governed by the HHS privacy, security and breach-notification rules. Section 541.107 keeps a duty on the small businesses the applicability test otherwise excludes: they may not engage in the sale of sensitive data without prior consumer consent, and a violation carries the same penalty as any other.

Effective dateJuly 1, 2024
CitationTex. Bus. & Com. Code ch. 541
Enforced byTexas Attorney General
Maximum penaltyUp to $7,500 per violation under Tex. Bus. & Com. Code § 541.155
Private right of actionNo, enforcement by the state only
Right to cure30 days (permanent right to cure)

Who Must Comply

The TDPSA reaches a business that conducts business in Texas or produces products or services consumed by Texas residents, and processes or engages in the sale of personal data, and is not a small business as defined by the U.S. Small Business Administration (no revenue or consumer-count minimum).

The absence of any numeric threshold makes the TDPSA one of the widest-reaching state privacy laws — small and mid-sized companies that fall below the thresholds in California or Virginia are inside the Texas statute unless they meet the Small Business Administration definition, and even then section 541.107 still bars them from selling sensitive data without consent

Consumer Rights Under the TDPSA

Residents of Texas can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.

Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.

Sector-Specific Privacy Laws in Texas

Capture or Use of Biometric Identifier Act (CUBI)

Chapter 503 of the Business & Commerce Code has prohibited capturing a biometric identifier — a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry — for a commercial purpose without informed consent since 2009. It is enforced by the Attorney General and provides no private right of action, which distinguishes it from the Illinois biometric statute that generates most private biometric litigation.

Data broker registration (Tex. Bus. & Com. Code ch. 509)

Senate Bill 2105 of the 88th Legislature requires data brokers that process the personal data of Texas residents to register annually with the Texas Secretary of State and to maintain reasonable administrative, technical and physical safeguards. The registration duty is separate from the TDPSA and attaches by the character of the business rather than by the applicability test in section 541.002.

Public breach listing — Tex. Bus. & Com. Code § 521.053(j)

House Bill 3746 of the 87th Legislature added subsection (j) to section 521.053, requiring the Attorney General to post on a publicly accessible website a listing of the breach notifications received under subsection (i), excluding sensitive personal information, information that may compromise a data system’s security, and anything made confidential by law. The same subsection requires the listing to be updated not later than the 30th day after the office receives notification of a new breach.

Data Breach Notification in Texas

The Identity Theft Enforcement and Protection Act, chapter 521 of the Business & Commerce Code, governs breach notice in Texas. Section 521.053(i), as amended by House Bill 3746 in 2021, requires a person disclosing a breach to notify the Attorney General not later than the 60th day after determining the breach occurred where it involves at least 250 Texas residents, and prescribes what that notification must contain: a detailed description of the nature and circumstances of the breach or of the use of sensitive personal information acquired through it, the number of Texas residents affected at the time of notification, the number of affected residents who have been sent a disclosure by mail or another direct method at that point, the measures the person has taken, any measures it intends to take afterwards, and whether law enforcement is investigating. The same bill added subsection (j), which turns those filings into a public record: the Attorney General must publish a listing of the notifications received and update it within 30 days of each new one.

Residents must be notified without unreasonable delay and no later than 60 days after discovery. Notify the Texas Attorney General not later than the 60th day after determining a breach occurred, where the breach involves at least 250 Texas residents. Complaints are taken by the Texas Attorney General, which enforces the statute.

Recent Enforcement in Texas

23andMe — $150 million in state claims, $1,266,860 to Texas. The Attorney General announced a settlement of bankruptcy claims against 23andMe resolving issues from the 2023 breach that compromised the genetic data of 6.9 million customers worldwide. The settlement includes $150 million in allowed claims for a multistate coalition of 42 states; because the estate is finite, recovery is limited to $18 million paid immediately, of which Texas receives $1,266,860. The office states the multistate investigation found 23andMe engaged in unreasonable data-security practices and failed to implement adequate safeguards against hacking, that the company learned of the breach months after the information had become publicly available, and that it first denied a breach and then blamed consumers for how their accounts were configured. The settlement carries forward requirements the office describes as equivalent to those a traditional enforcement action would have imposed: enhanced data-security standards, comprehensive risk assessments, an independent advisory board, enforcement of applicable state privacy laws without exception, and continued consumer deletion rights. 23andMe separately agreed to a $46.75 million class-action settlement in the bankruptcy for consumers who submitted claims by February 17, 2026.

Discord — agreed temporary injunction on age assurance, 2026. Texas filed suit against Discord on May 22, 2026 and secured a temporary restraining order, then an Agreed Temporary Injunction seven weeks later. The Attorney General states the order requires Discord to extend to Texas users the age-assurance and default safety settings it already runs in the United Kingdom, within 90 days: routing messages from strangers into a separate request inbox, blocking sensitive content for Texas teens and locking that setting unless the user is confirmed to be an adult, and closing adult-only spaces to anyone not age-assured. Discord must report progress to the office every 30 days, and the order binds the company until final judgment and is enforceable by contempt. The office states that in 2025 Discord submitted 489,782 reports of suspected child sexual exploitation to the National Center for Missing & Exploited Children. The release notes that New Jersey, Nevada, Indiana and Arkansas have also sued Discord, and that the case proceeds to trial where Texas will seek civil penalties under the Deceptive Trade Practices Act.

Pending Privacy Legislation

The TDPSA has been in force since July 1, 2024 and the data-broker registration duty since September 1, 2023. The Attorney General’s current privacy docket runs through litigation rather than new legislation: the Discord case is set for trial, and the office has separately announced an investigation into LinkedIn over advertising of job opportunities.

Federal Privacy Laws That Apply in Texas

Federal privacy law applies in Texas by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The TDPSA sits alongside those rules rather than displacing them: the Texas Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.

Texas Privacy Law FAQ

Does the TDPSA apply to small businesses in Texas?
Section 541.002(a)(3) excludes a person that is a small business as defined by the United States Small Business Administration — but only “except to the extent that Section 541.107 applies.” Section 541.107(a) provides that such a person may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer, and subsection (b) makes a violation subject to the same civil penalty as any other TDPSA violation.
Can I sue a company directly for a TDPSA violation?
No. Section 541.156 provides that the chapter “may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law.” Under section 541.155 the Attorney General may bring an action to recover a civil penalty not to exceed $7,500 per violation, to enjoin the conduct, or both, and may recover reasonable attorney’s fees and investigative expenses.
How long does a Texas company have to notify the Attorney General of a breach?
Section 521.053(i) sets the deadline at not later than the 60th day after the date the person determines the breach occurred, and applies it where the breach involves at least 250 Texas residents. The subsection also lists six items the notification must include, among them the number of residents affected at the time of notification and the number who have already been sent a direct disclosure.
Are Texas breach notifications public?
The listing is. Section 521.053(j), added by House Bill 3746 in 2021, requires the Attorney General to post a listing of the notifications received under subsection (i) on a publicly accessible website, and to update it not later than the 30th day after receiving notification of a new breach. The subsection excludes from the listing any sensitive personal information reported, any information that may compromise a data system’s security, and any other reported information made confidential by law.
What is the difference between CUBI and the TDPSA?
CUBI is chapter 503 of the Business & Commerce Code and governs a narrow category — biometric identifiers captured for a commercial purpose — while the TDPSA is chapter 541 and governs personal data generally, with consumer rights of access, correction, deletion, portability and opt-out. A business handling biometric data in Texas is within the scope of both, and neither provides a private right of action.
Does the TDPSA give a company a chance to fix a violation before penalties?
Section 541.155(a) makes a person liable for a civil penalty only where it violates the chapter “following the cure period described by Section 541.154” or breaches a written statement given to the Attorney General under that section. Section 541.154 describes what that written statement must say: that the person cured the alleged violation, notified the consumer that the violation was addressed where contact information was available, provided supporting documentation showing how it was cured, and made any necessary changes to internal policies.
Which organisations are outside the TDPSA entirely?
Section 541.002(b) lists them. They include state agencies and political subdivisions of Texas, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, and covered entities and business associates governed by the privacy, security and breach-notification rules issued by the U.S. Department of Health and Human Services under 45 C.F.R.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.