Texas Privacy Law
Texas enforces one of the broadest comprehensive privacy laws in the country. The Texas Data Privacy and Security Act took effect on July 1, 2024 and is unusual in having no revenue or consumer-count threshold: House Bill 4 of the 88th Legislature applies it to any person who conducts business in Texas or produces a product or service consumed by Texans, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration. Texas also publishes a running public list of the breaches reported to the Attorney General, and its office has pursued privacy claims in bankruptcy court and in state court against platforms in the last two years.
The Texas Data Privacy and Security Act (TDPSA)
Enacted as House Bill 4 in the 88th Regular Session, the TDPSA added subtitle C to title 11 of the Business & Commerce Code. Section 541.002(a) states the applicability test in three parts and, unlike the comprehensive laws of most other states, states no numeric threshold at all. Section 541.002(b) then removes state agencies and political subdivisions, financial institutions and data subject to Title V of the Gramm-Leach-Bliley Act, and covered entities and business associates governed by the HHS privacy, security and breach-notification rules. Section 541.107 keeps a duty on the small businesses the applicability test otherwise excludes: they may not engage in the sale of sensitive data without prior consumer consent, and a violation carries the same penalty as any other.
| Effective date | July 1, 2024 |
|---|---|
| Citation | Tex. Bus. & Com. Code ch. 541 |
| Enforced by | Texas Attorney General |
| Maximum penalty | Up to $7,500 per violation under Tex. Bus. & Com. Code § 541.155 |
| Private right of action | No, enforcement by the state only |
| Right to cure | 30 days (permanent right to cure) |
Who Must Comply
The TDPSA reaches a business that conducts business in Texas or produces products or services consumed by Texas residents, and processes or engages in the sale of personal data, and is not a small business as defined by the U.S. Small Business Administration (no revenue or consumer-count minimum).
The absence of any numeric threshold makes the TDPSA one of the widest-reaching state privacy laws — small and mid-sized companies that fall below the thresholds in California or Virginia are inside the Texas statute unless they meet the Small Business Administration definition, and even then section 541.107 still bars them from selling sensitive data without consent
Consumer Rights Under the TDPSA
Residents of Texas can confirm whether a business is processing their data and obtain a copy of it, require correction of inaccurate personal data, require deletion of personal data the business holds about them, obtain their data in a portable, readily usable format, opt out of targeted advertising, opt out of the sale of their personal data and opt out of profiling used for decisions producing legal or similarly significant effects.
Sensitive data is treated separately. Health, biometric, precise geolocation and demographic data may not be processed without opt-in consent, which means the default is no processing until the consumer agrees.
Sector-Specific Privacy Laws in Texas
Capture or Use of Biometric Identifier Act (CUBI)
Chapter 503 of the Business & Commerce Code has prohibited capturing a biometric identifier — a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry — for a commercial purpose without informed consent since 2009. It is enforced by the Attorney General and provides no private right of action, which distinguishes it from the Illinois biometric statute that generates most private biometric litigation.
Data broker registration (Tex. Bus. & Com. Code ch. 509)
Senate Bill 2105 of the 88th Legislature requires data brokers that process the personal data of Texas residents to register annually with the Texas Secretary of State and to maintain reasonable administrative, technical and physical safeguards. The registration duty is separate from the TDPSA and attaches by the character of the business rather than by the applicability test in section 541.002.
Public breach listing — Tex. Bus. & Com. Code § 521.053(j)
House Bill 3746 of the 87th Legislature added subsection (j) to section 521.053, requiring the Attorney General to post on a publicly accessible website a listing of the breach notifications received under subsection (i), excluding sensitive personal information, information that may compromise a data system’s security, and anything made confidential by law. The same subsection requires the listing to be updated not later than the 30th day after the office receives notification of a new breach.
Data Breach Notification in Texas
The Identity Theft Enforcement and Protection Act, chapter 521 of the Business & Commerce Code, governs breach notice in Texas. Section 521.053(i), as amended by House Bill 3746 in 2021, requires a person disclosing a breach to notify the Attorney General not later than the 60th day after determining the breach occurred where it involves at least 250 Texas residents, and prescribes what that notification must contain: a detailed description of the nature and circumstances of the breach or of the use of sensitive personal information acquired through it, the number of Texas residents affected at the time of notification, the number of affected residents who have been sent a disclosure by mail or another direct method at that point, the measures the person has taken, any measures it intends to take afterwards, and whether law enforcement is investigating. The same bill added subsection (j), which turns those filings into a public record: the Attorney General must publish a listing of the notifications received and update it within 30 days of each new one.
Residents must be notified without unreasonable delay and no later than 60 days after discovery. Notify the Texas Attorney General not later than the 60th day after determining a breach occurred, where the breach involves at least 250 Texas residents. Complaints are taken by the Texas Attorney General, which enforces the statute.
Recent Enforcement in Texas
23andMe — $150 million in state claims, $1,266,860 to Texas. The Attorney General announced a settlement of bankruptcy claims against 23andMe resolving issues from the 2023 breach that compromised the genetic data of 6.9 million customers worldwide. The settlement includes $150 million in allowed claims for a multistate coalition of 42 states; because the estate is finite, recovery is limited to $18 million paid immediately, of which Texas receives $1,266,860. The office states the multistate investigation found 23andMe engaged in unreasonable data-security practices and failed to implement adequate safeguards against hacking, that the company learned of the breach months after the information had become publicly available, and that it first denied a breach and then blamed consumers for how their accounts were configured. The settlement carries forward requirements the office describes as equivalent to those a traditional enforcement action would have imposed: enhanced data-security standards, comprehensive risk assessments, an independent advisory board, enforcement of applicable state privacy laws without exception, and continued consumer deletion rights. 23andMe separately agreed to a $46.75 million class-action settlement in the bankruptcy for consumers who submitted claims by February 17, 2026.
Discord — agreed temporary injunction on age assurance, 2026. Texas filed suit against Discord on May 22, 2026 and secured a temporary restraining order, then an Agreed Temporary Injunction seven weeks later. The Attorney General states the order requires Discord to extend to Texas users the age-assurance and default safety settings it already runs in the United Kingdom, within 90 days: routing messages from strangers into a separate request inbox, blocking sensitive content for Texas teens and locking that setting unless the user is confirmed to be an adult, and closing adult-only spaces to anyone not age-assured. Discord must report progress to the office every 30 days, and the order binds the company until final judgment and is enforceable by contempt. The office states that in 2025 Discord submitted 489,782 reports of suspected child sexual exploitation to the National Center for Missing & Exploited Children. The release notes that New Jersey, Nevada, Indiana and Arkansas have also sued Discord, and that the case proceeds to trial where Texas will seek civil penalties under the Deceptive Trade Practices Act.
Pending Privacy Legislation
The TDPSA has been in force since July 1, 2024 and the data-broker registration duty since September 1, 2023. The Attorney General’s current privacy docket runs through litigation rather than new legislation: the Discord case is set for trial, and the office has separately announced an investigation into LinkedIn over advertising of job opportunities.
Federal Privacy Laws That Apply in Texas
Federal privacy law applies in Texas by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The TDPSA sits alongside those rules rather than displacing them: the Texas Attorney General enforces the state law, while the federal regulators continue to reach the sectors and activities they cover.
Texas Privacy Law FAQ
Does the TDPSA apply to small businesses in Texas?
Can I sue a company directly for a TDPSA violation?
How long does a Texas company have to notify the Attorney General of a breach?
Are Texas breach notifications public?
What is the difference between CUBI and the TDPSA?
Does the TDPSA give a company a chance to fix a violation before penalties?
Which organisations are outside the TDPSA entirely?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- House Bill 4 (88th Legislature, 2023) — Texas Data Privacy and Security Act, enrolled text statute
- House Bill 3746 (87th Legislature, 2021) — amending Tex. Bus. & Com. Code § 521.053 statute
- Texas Attorney General — $150 million settlement against 23andMe over the genetic data breach agency
- Texas Attorney General — Agreed temporary injunction requiring Discord to extend age-assurance protections to Texas agency
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.