Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Tex. Bus. & Com. Code sec. 503.001, as amended by Tex. HB 149, 89th Legislature (2025)
stage In effect
since 2009-04-01
source official Texas statute text, Business and Commerce Code chapter 503, Texas Constitution and Statutes System
CUBI is Texas's dedicated biometric-identifier statute. It defines 'biometric identifier' as a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry, with no exclusion for an identifier derived from a photograph, video, or audio recording.
A person may not capture an individual's biometric identifier for a commercial purpose without first informing the individual and obtaining consent, may not sell, lease, or disclose a captured identifier outside narrow statutory exceptions, must store and transmit it with reasonable care equal to or better than its other confidential information, and must destroy it within a reasonable time, no later than the first anniversary of when the collection purpose expires.
HB 149 (89th Legislature, 2025), effective January 1, 2026, added that an individual's biometric identifiers appearing in publicly available online media do not by themselves establish consent to capture unless that individual made the media publicly available, and added exemptions for biometric identifiers used only to train, process, or store data for developing or evaluating an AI model, and for AI systems used to prevent fraud, harassment, or other illegal activity.
What it asks of an app →
Breach notification
cite Tex. Bus. & Com. Code sec. 521.053, as amended by Tex. SB 768, 88th Legislature (2023)
stage In effect
since 2009-04-01
source official Texas statute text, Business and Commerce Code chapter 521, Texas Constitution and Statutes System
A person conducting business in Texas that owns or licenses computerized data including sensitive personal information (a Social Security, driver's license, or government identification number, or a financial account number with an access code, each combined with a name, or certain health information) must notify affected Texas residents without unreasonable delay and no later than 60 days after determining a breach of system security occurred.
If 250 or more Texas residents are affected, the person must also notify the Texas Attorney General as soon as practicable and no later than 30 days after that determination, and a person notifying more than 10,000 persons at one time must also notify each nationwide consumer reporting agency.
Biometric data such as a fingerprint, voiceprint, or retina or iris image sits in the chapter's separate, broader personal identifying information definition and does not itself trigger this notification duty.
Enforcement of this notification duty is exclusive to the Attorney General, with a civil penalty of $2,000 to $50,000 per violation, and this section creates no private right of action, though a separate provision of the same chapter (sec. 521.152) ties a violation of the identity theft prohibition in sec. 521.051 to a private action under the Deceptive Trade Practices Act.
What it asks of an app →
Comprehensive regime
cite Tex. Bus. & Com. Code ch. 541, secs. 541.001-541.002
stage In effect
since 2024-07-01
source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System
TDPSA governs private-sector processing of Texas residents' personal data. It applies to a person who conducts business in Texas, or produces a product or service consumed by Texas residents, and who processes or sells personal data, unless the person is a small business under SBA size standards (a limited exception for selling sensitive data under sec. 541.107 applies regardless of size).
The Act excludes state agencies, political subdivisions, GLBA-regulated financial institutions, HIPAA covered entities, nonprofits, higher-education institutions, and electric utilities, and 'personal data' excludes deidentified data and publicly available information.
What it asks of an app →
Data subject rights
cite Tex. Bus. & Com. Code secs. 541.051-541.053, 541.105
stage In effect
since 2024-07-01
source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System
TDPSA gives a Texas consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect, exercisable against the controller.
A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available, must answer an appeal of a refusal within 60 days, and must conduct and document a data protection assessment before targeted advertising, sale, certain profiling, sensitive-data processing, or other heightened-risk processing.
What it asks of an app →
Enforcement supervision
cite Tex. Bus. & Com. Code secs. 541.151, 541.154-541.156
stage In effect
since 2024-07-01
source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System
The Texas Attorney General has exclusive authority to enforce TDPSA. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated; curing the violation within that period and confirming the cure in writing bars the action. An uncured violation is subject to a civil penalty of up to $7,500 per violation, and the chapter expressly bars any private right of action.
The Attorney General filed the state's first TDPSA enforcement action against Allstate Corp. and Arity LLC on January 13, 2025, over the sale of geolocation and driving-behavior data collected through SDKs embedded in third-party apps, and that case remains pending.
What it asks of an app →
Sensitive categories
cite Tex. Bus. & Com. Code secs. 541.001, 541.101(b)(4)
stage In effect
since 2024-07-01
source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System
TDPSA classifies genetic or biometric data processed to uniquely identify a person, along with racial or ethnic origin, religious belief, a mental or physical health diagnosis, sexuality, citizenship or immigration status, precise geolocation, and a known child's data, as sensitive data requiring the consumer's prior consent before a controller may process it.
'Biometric data' means data from automatic measurement of an individual's biological characteristics used to identify them, including a fingerprint, voiceprint, or eye retina or iris, but the definition expressly excludes data generated from a photograph, or from a video or audio recording, so an identifier derived solely from such a recording falls outside this consent duty.
What it asks of an app →