TX

Texas Privacy Law

Texas Data Privacy and Security Act

Effective: July 1, 2024ActiveReviewed by PrivacyLawMap editorial teamLast verified: June 18, 2026

Overview

The Texas Data Privacy and Security Act (TDPSA) was signed into law on June 18, 2023, and became effective on July 1, 2024. Texas is unique among state privacy laws for having no revenue or consumer count threshold, instead applying to all entities conducting business in Texas that process personal data, unless they qualify as a "small business" under the SBA definition. This makes the TDPSA one of the broadest state privacy laws in terms of applicability. Unlike California (CCPA) which requires $25M revenue or 50K+ consumers, or Virginia (VCDPA) which requires 100K+ consumers, the TDPSA covers businesses of all sizes that are not SBA-defined small businesses.

The TDPSA provides Texas consumers with comprehensive privacy rights, including access, correction, deletion, portability, and opt-out rights for data sales, targeted advertising, and profiling. Texas requires businesses to honor universal opt-out mechanisms such as Global Privacy Control (GPC), and the law includes an appeals process for denied consumer requests. The TDPSA exempts HIPAA-covered entities and data, GLBA-covered financial institutions and data, entities complying with FERPA, and data processed for certain employment and B2B contexts — similar to most other state privacy laws.

The Texas Attorney General has been among the most aggressive enforcers of privacy laws nationally. Since launching the Data Privacy and Security Initiative in June 2024, the AG has investigated over 200 companies including data brokers, car manufacturers, social media companies, and entities with ties to foreign adversaries. The AG secured the two largest single-state privacy settlements in US history — $1.4 billion from Meta (2024) over biometric data violations and $1.375 billion from Google (2025) over location tracking. Combined with the $11.4 million Pieces Technologies AI settlement and data broker registration enforcement sweeps, Texas has established itself as a leading privacy enforcement state.

The TDPSA includes a 30-day cure period and penalties of up to $7,500 per violation. Additionally, the Texas Responsible AI Governance Act (TRAIGA, HB 149), effective January 1, 2026, amends the TDPSA to add AI-specific obligations, including processor duties to protect personal data used by AI systems. With TRAIGA, Texas became one of the first states to link comprehensive privacy law compliance to AI governance.

Texas Data Privacy Law: 2026 TDPSA Compliance Focus

For the keyword "Texas data privacy law," the practical 2026 answer is that the TDPSA is already active and unusually broad: it does not use a fixed revenue or consumer-count threshold, and the main threshold question is whether the organization qualifies as an SBA-defined small business.

As of June 18, 2026, a Texas privacy program usually has to track four connected regimes rather than one statute: TDPSA Chapter 541 controller duties, universal opt-out signal recognition, the separate Chapter 510 data broker registration law, and TRAIGA AI-system obligations that became effective January 1, 2026.

Source check: Last verified June 18, 2026 against Texas Business & Commerce Code Chapter 541, the Texas Attorney General TDPSA consumer-rights page, the Texas Attorney General Data Broker Act page, the Texas Secretary of State data broker registry instructions, the Texas Attorney General July 21, 2025 privacy-enforcement roundup, and enrolled HB 149 / TRAIGA text (date_retrieved: 2026-06-18).

  • Applicability: no fixed revenue threshold and no fixed consumer-count threshold; covered businesses generally fall in unless they are SBA-defined small businesses or another exemption applies.
  • Small-business caveat: the Texas AG says small businesses are generally exempt, but a small business must still obtain consent before selling sensitive data.
  • Operational priority: GPC and similar universal opt-out signals have been required since January 1, 2025, so ad-tech and sale/targeted-advertising opt-out flows should be tested before relying on notice language alone.
  • Data broker layer: Chapter 510 registration is separate from TDPSA compliance. The Secretary of State registry requires annual registration and a $300 registration or renewal fee, while the AG enforces the substantive data broker law.
  • AI layer: enrolled HB 149 / TRAIGA added AI-system governance and amended TDPSA processor-security language for data collected, stored, and processed by artificial intelligence systems.
  • Enforcement signal: the Texas AG reported investigations into more than 200 companies and privacy settlements including Meta ($1.4B) and Google ($1.375B), making Texas a high-enforcement-risk state even before a public TDPSA-specific penalty lands.

Applicability Thresholds

Conditions are joined by OR meeting ANY one triggers applicability.

No revenue or consumer count threshold. Applies to all entities that are not small businesses as defined by the SBA.

Consumer Rights

Right to Access
Right to Delete
Right to Correct
Data Portability
Opt-Out of Sale
Opt-Out of Targeted Ads
Opt-Out of Profiling
Limit Sensitive Data Use
Right to Appeal
Private Right of Action

Key Changes in 2025-2026

  • Texas Responsible AI Governance Act (TRAIGA, HB 149) effective January 1, 2026 — imposes obligations on AI developers and deployers, amends TDPSA to require processors to help protect personal data processed by AI systems, and requires government entities to disclose AI interactions
  • TRAIGA enforcement: AG has 60-day cure period for TRAIGA-specific violations; developers must provide risk documentation and deployers must conduct impact assessments for high-risk AI systems
  • Universal opt-out mechanism (GPC) recognition fully in effect since January 1, 2025 — AG enforcement of GPC compliance is an active priority
  • Texas AG Data Privacy & Security Initiative (since June 2024): investigated 200+ companies across sectors including data brokers, automakers, social media, and foreign-connected entities
  • Enforcement totals: $1.4B Meta settlement (biometric CUBI violations), $1.375B Google settlement (location tracking, TX-led multistate with $391M to Texas), $11.4M Pieces Technologies (AI healthcare misrepresentation)
  • Data broker registration enforcement ongoing — HB 4460 requires Secretary of State registration; AG has fined non-compliant brokers at $100/day penalty rate
  • Utah HB 357 (signed March 19, 2026, effective May 6, 2026) extends similar motor vehicle privacy protections — Texas companies selling to Utah may have additional obligations

Enforcement Details

Enforced By
Texas Attorney General
Penalty Per Violation
$7,500
Cure Period
30 days
Private Right of Action
No — AG enforcement only

Notable Enforcement Actions

Source check: date_retrieved 2026-06-18. This table is generated from the canonical penalties tracker, so new AG and CalPrivacy actions appear here without duplicating state-page copy. Public monetary penalties shown below total $2,775,000,000.

Google

Texas DTPA · Unauthorized Data Collection

$1,375,000,000

Texas Attorney General Ken Paxton secured a $1.375 billion settlement with Google related to data privacy rights of Texans. The settlement addressed unauthorized collection and use of personal data, marking the second billion-dollar privacy settlement for Texas.

May 9, 2025Source

Allstate / Arity

TDPSA · Unauthorized Collection and Sale of Sensitive Geolocation Data

Non-monetary

Texas Attorney General Ken Paxton filed the first-ever enforcement action under a state comprehensive data privacy law, suing Allstate and its subsidiary Arity for collecting and selling the driving behavior data of over 45 million Americans. Arity paid app developers (GasBuddy, Fuel Rewards, Routely) to embed tracking SDKs that collected precise geolocation data without consumer notice or consent. The data was used to build a "driving behavior database" sold to insurance companies to justify premium increases. The AG is seeking over $1 million in penalties ($7,500 per TDPSA violation, $10,000 per Data Broker Law violation). Case is ongoing.

January 13, 2025Source

Meta (Facebook)

Texas CUBI / DTPA · Unauthorized Biometric Data Collection

$1,400,000,000

Texas Attorney General Ken Paxton secured a record $1.4 billion settlement with Meta for running facial recognition on photos uploaded to Facebook without user consent, violating the Texas Capture or Use of Biometric Identifier Act (CUBI). This is the largest privacy settlement ever obtained by a single state.

July 30, 2024Source

Sensitive Data Categories

Consent model: opt-in

Racial or ethnic originReligious beliefsMental or physical health diagnosisSexual orientationCitizenship or immigration statusBiometric data for identification

Universal Opt-Out / GPC Requirements

GPC / Universal Opt-Out Required

Businesses must recognize and honor universal opt-out mechanisms such as Global Privacy Control (GPC). The Texas AG has indicated that compliance with this requirement is a priority.

Effective: January 1, 2025

Minor / Child Protections

The TDPSA requires opt-in consent for processing personal data of known children under 13. The law prohibits the sale of personal data of children under 13 and requires opt-in consent for targeted advertising directed at minors.

Compliance Checklist

  1. 1Determine applicability: check if your organization qualifies as a "small business" under the SBA definition for your specific NAICS code. For most tech/software companies, the threshold is $41.5M in average annual receipts or 500-1,500 employees. Also verify HIPAA, GLBA, and FERPA exemptions — these apply at the entity level for covered entities and at the data level for covered data types
  2. 2Conduct a comprehensive data inventory: map all personal data you collect, process, and share about Texas consumers. Identify sensitive data categories (racial/ethnic origin, religious beliefs, health data, sexual orientation, citizenship status, biometrics) that require opt-in consent. Document data flows to processors and third parties
  3. 3Implement universal opt-out signal recognition (GPC and similar mechanisms) — this is an active AG enforcement priority. Ensure GPC signals are detected server-side and propagated to all downstream processors and advertising partners. Test across browsers and devices
  4. 4Conduct data protection assessments for all high-risk processing activities: targeted advertising, data sales, profiling that produces legal or similarly significant effects, processing sensitive data, and any processing creating foreseeable risk of substantial injury
  5. 5If developing or deploying AI systems: assess TRAIGA (HB 149) obligations. Developers must provide risk documentation; deployers must conduct impact assessments for high-risk AI. Ensure AI systems do not process personal data in ways that enable unlawful discrimination
  6. 6If a data processor: update agreements to include TDPSA-mandated provisions and TRAIGA AI-related data protection duties. Processors must assist controllers with consumer rights requests and data protection assessments
  7. 7Update privacy notices with all TDPSA-required disclosures: categories of data collected, purposes of processing, categories of third parties receiving data, consumer rights and how to exercise them, sale/sharing disclosures, and contact information for the controller
  8. 8Implement consumer rights request mechanisms with 45-day response period (extendable by 45 additional days with notice). Include identity verification procedures and maintain records of requests and responses
  9. 9Obtain opt-in consent before processing sensitive personal data — consent must be freely given, specific, informed, and unambiguous. Implement age verification where feasible to avoid processing children's data without parental consent
  10. 10Establish a documented appeals process for denied consumer requests — you must inform consumers of the appeal process and respond within 60 days. If the appeal is denied, provide a mechanism for the consumer to contact the AG
  11. 11If operating as a data broker: register with the Texas Secretary of State as required by HB 4460 and pay annual fees. Post conspicuous data collection notices. Non-registration carries $100/day penalties that accrue from the effective date
  12. 12Implement data minimization practices: collect only personal data that is adequate, relevant, and reasonably necessary for the disclosed purpose. Review and purge data that is no longer needed
  13. 13Establish an ongoing compliance monitoring program: conduct regular GPC signal testing, update data protection assessments when processing activities change, train employees on consumer rights procedures, and document all compliance activities in preparation for potential AG inquiries
Put TDPSA Into Practice on Your SiteSponsored

Termly builds and maintains a Texas-ready privacy policy, a consent banner that recognizes universal opt-out signals like GPC, opt-in consent capture for sensitive data, and a workflow for the access, deletion and correction requests TDPSA grants.

Start Free with Termly

Texas Privacy Law FAQ

Official Resources