EnglishEspañol
Texas flag

Texas

Texas Data Privacy Laws: TDPSA & Consumer Rights Guide (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 20 primary sources cited on this page. How we verify our legal content

Texas Data Privacy Laws: TDPSA & Consumer Rights Guide (2026)

Frequently Asked Questions

Does the Texas Data Privacy and Security Act apply to small businesses?

Small businesses as defined by the federal Small Business Administration are generally exempt from the TDPSA. There is one firm exception: if a small business sells sensitive consumer data (including health information, biometric data, precise geolocation, or data about children under 13), it must obtain the consumer's consent before doing so. Size does not eliminate that obligation.

What rights do Texas consumers have under the TDPSA?

Texas consumers have the right to confirm whether a business processes their personal data, access that data, correct inaccuracies, request deletion, obtain a portable copy, and opt out of targeted advertising, data sales, and profiling that produces legal or similarly significant effects. Businesses must respond to verified requests within 45 days. If a business denies a request, the consumer may appeal within a reasonable period of time, and the business then has 60 days to decide the appeal.

How quickly must a business notify Texas residents of a data breach?

Under the Texas Identity Theft Enforcement and Protection Act, businesses must notify affected individuals no later than 60 days after determining a breach occurred. If the breach affects 250 or more Texas residents, the business must also notify the Texas Attorney General within 30 days of discovering the breach.

Can I sue a company directly for violating the TDPSA?

No. The TDPSA does not include a private right of action. Only the Texas Attorney General can bring enforcement actions. If you believe a company has violated your data privacy rights, file a complaint with the Texas AG's Consumer Protection Division at texasattorneygeneral.gov.

What is the penalty for collecting biometric data without consent in Texas?

Under the Texas Capture or Use of Biometric Identifier Act (CUBI), collecting biometric identifiers such as fingerprints, facial geometry, retina scans, or voiceprints without informed consent carries a civil penalty of up to USD 25,000 per violation. The Texas AG enforces CUBI and has already secured the two largest biometric privacy settlements in U.S. history: USD 1.4 billion from Meta (July 2024) and USD 1.375 billion from Google (October 2025).

Does Texas require businesses to recognize Global Privacy Control?

Yes. Texas is one of a growing number of states that require covered data controllers to honor universal opt-out mechanisms, including Global Privacy Control. If your business processes personal data for targeted advertising or sells personal data to third parties, you must recognize valid universal opt-out signals and provide a clear means for consumers to opt out.

What is the Texas SCOPE Act and who does it cover?

The Securing Children Online Through Parental Empowerment (SCOPE) Act, effective September 1, 2024, applies to digital service providers that operate online platforms for social interaction used by minors under 18. Covered platforms cannot collect minors' geolocation data, display targeted advertising to minors, permit financial transactions by minors, or sell minors' personal data. Violations are treated as deceptive trade practices with penalties up to USD 10,000 per violation. Not every SCOPE Act duty is enforceable: on July 24, 2026 the Fifth Circuit held that the separate duty to monitor and filter harmful material for known minors (Section 509.053) is preempted by Section 230 of the Communications Decency Act, and it left the injunction against that provision in place.

What changed with Texas data broker law in 2025?

Two bills signed June 20, 2025 (SB 2121 and SB 1343), both effective September 1, 2025, significantly expanded Texas's data broker registration requirement. The prior definition required that data brokering be a company's principal revenue source; the new definition covers any business entity that collects, processes, or transfers personal data it did not collect directly from the individual. Qualifying businesses must register with the Texas Secretary of State and pay a USD 300 annual fee.

What does the Texas Responsible AI Governance Act (TRAIGA) require?

TRAIGA, effective January 1, 2026, prohibits AI systems from being used for behavioral manipulation, discrimination, unlawful deepfakes, or infringement of constitutional rights. Government entities must disclose when consumers are interacting with an AI system. The AG enforces TRAIGA with a 60-day cure period. The law also amended the TDPSA to clarify that processors must help controllers meet security obligations when processing data through AI systems.

Updates

Corrected the CUBI consent and disclosure rules (Texas requires notice and consent, not a signed writing, and biometric disclosure is limited to four narrow statutory exceptions), fixed the FAQ description of the 60-day TDPSA appeal deadline, and added the SCOPE Act litigation status following the Fifth Circuit's July 24, 2026 decision leaving the monitoring-and-filtering duty enjoined.

Corrected the TDPSA exempt-entities list to include the electric utility, power generation company, and retail electric provider exemption (Tex. Bus. & Com. Code Section 541.002(b)(6)), and corrected the CUBI 'publicly available image' consent rule to attribute it to the Texas Responsible AI Governance Act (H.B. 149, effective January 1, 2026) rather than a 2023 amendment, adding the two new CUBI exemptions TRAIGA created for AI model training and for AI-based security/fraud-detection use.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

May 2026 refresh: added Google USD 1.375 billion settlement (October 2025), Texas v. Allstate/Arity first TDPSA enforcement action (January 2025), 2025 data broker law amendments (SB 2121 and SB 1343, effective September 1, 2025), Texas Responsible AI Governance Act (TRAIGA, effective January 1, 2026), TAKE IT DOWN Act federal overlay (signed May 19, 2025, platform obligations effective May 19, 2026), expanded consumer rights and compliance guidance, updated penalty table, and 9 FAQ entries. Word count increased from approximately 2,847 to approximately 5,500.

Reviewed and approved by an editor

Sources and References

  1. Texas Business and Commerce Code Chapter 541 - Consumer Data Protection (TDPSA)(statutes.capitol.texas.gov).gov
  2. Texas Attorney General - TDPSA Overview(texasattorneygeneral.gov).gov
  3. Texas Business and Commerce Code Chapter 503 - Biometric Identifiers(statutes.capitol.texas.gov).gov
  4. Texas Attorney General - Biometric Identifier Act(texasattorneygeneral.gov).gov
  5. Texas Business and Commerce Code Chapter 521 - Identity Theft Enforcement and Protection Act(statutes.capitol.texas.gov).gov
  6. Texas Attorney General - Data Breach Reporting(texasattorneygeneral.gov).gov
  7. Texas Attorney General - Identity Theft Enforcement and Protection Act(texasattorneygeneral.gov).gov
  8. Texas Department of Information Resources - TDPSA(dir.texas.gov).gov
  9. DIR Report on the TDPSA (December 2024)(dir.texas.gov).gov
  10. Texas Business and Commerce Code Chapter 510 - Data Brokers(statutes.capitol.texas.gov).gov
  11. Texas Attorney General - SCOPE Act(texasattorneygeneral.gov).gov
  12. Texas Attorney General - Allstate and Arity Enforcement(texasattorneygeneral.gov).gov
  13. Texas Attorney General - Consumer Privacy Rights(texasattorneygeneral.gov).gov
  14. H.B. 4 Enrolled Bill Text (88th Legislature)(capitol.texas.gov).gov
  15. Texas DIR - Know Your Rights Under the TDPSA(dir.texas.gov).gov
  16. Texas Business and Commerce Code Chapter 509: Securing Children Online Through Parental Empowerment (SCOPE) Act(statutes.capitol.texas.gov).gov
  17. Texas AG press release: USD 1.4 billion Meta biometric settlement (July 2024)(texasattorneygeneral.gov).gov
  18. Texas AG press release: USD 1.375 billion Google settlement finalized (October 2025)(texasattorneygeneral.gov).gov
  19. Congress.gov: TAKE IT DOWN Act, S.146, 119th Congress (signed May 19, 2025)(congress.gov).gov
  20. WilmerHale: Texas AG brings first-ever lawsuit under a state comprehensive privacy law (January 2025)(wilmerhale.com)
  21. Holland and Knight - Privacy Legislation in Texas: What Happened in 2025 and What's Next (February 2026)(hklaw.com)
  22. Troutman Pepper: Changes to Texas Data Broker Law Effective September 1, 2025(troutmanprivacy.com)
  23. Baker Botts - Texas Enacts Responsible AI Governance Act: What Companies Need to Know (July 2025)(bakerbotts.com)
  24. Computer & Communications Industry Association v. Paxton, consolidated with Students Engaged in Advancing Texas v. Paxton, No. 24-50721 c/w No. 25-50096 (5th Cir. July 24, 2026) (SCOPE Act monitoring-and-filtering duty preempted by CDA Section 230)(ca5.uscourts.gov).gov
Share: