Law / Texas

Texas

privacy

Texas has no single omnibus privacy authority but layers three private-sector duty streams. The Texas Data Privacy and Security Act (TDPSA, Tex. Bus. & Com. Code ch. 541) is the general comprehensive regime, effective July 1, 2024, requiring opt-in consent for sensitive data and giving consumers access, correction, deletion, portability, and opt-out rights.

The Capture or Use of Biometric Identifier Act (CUBI, Tex. Bus. & Com. Code sec. 503.001), in force since April 1, 2009 and amended effective January 1, 2026 by HB 149, is a dedicated biometric statute covering voiceprints and hand or face geometry with its own consent, retention, and destruction duties, and its biometric identifier definition carries no exclusion for a recording-derived identifier, unlike TDPSA's narrower biometric data definition.

A separate section of the Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code sec. 521.053) governs breach notification, triggered by Social Security, driver's license, or financial account data rather than by biometric data alone.

All three tracks vest primary enforcement in the Texas Attorney General; neither TDPSA nor CUBI creates a private right of action, though a violation of the breach chapter's safeguard duty (Sec. 521.052, via Sec. 521.152) is actionable as a deceptive trade practice under the DTPA.

11 instruments named 6 researched in detail As of 2026-08-23

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Biometric privacy

Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149

cite Tex. Bus. & Com. Code sec. 503.001, as amended by Tex. HB 149, 89th Legislature (2025) stage In effect since 2009-04-01 source official Texas statute text, Business and Commerce Code chapter 503, Texas Constitution and Statutes System

CUBI is Texas's dedicated biometric-identifier statute. It defines 'biometric identifier' as a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry, with no exclusion for an identifier derived from a photograph, video, or audio recording.

A person may not capture an individual's biometric identifier for a commercial purpose without first informing the individual and obtaining consent, may not sell, lease, or disclose a captured identifier outside narrow statutory exceptions, must store and transmit it with reasonable care equal to or better than its other confidential information, and must destroy it within a reasonable time, no later than the first anniversary of when the collection purpose expires.

HB 149 (89th Legislature, 2025), effective January 1, 2026, added that an individual's biometric identifiers appearing in publicly available online media do not by themselves establish consent to capture unless that individual made the media publicly available, and added exemptions for biometric identifiers used only to train, process, or store data for developing or evaluating an AI model, and for AI systems used to prevent fraud, harassment, or other illegal activity.

What it asks of an app

Breach notification

Identity Theft Enforcement and Protection Act, breach notification

cite Tex. Bus. & Com. Code sec. 521.053, as amended by Tex. SB 768, 88th Legislature (2023) stage In effect since 2009-04-01 source official Texas statute text, Business and Commerce Code chapter 521, Texas Constitution and Statutes System

A person conducting business in Texas that owns or licenses computerized data including sensitive personal information (a Social Security, driver's license, or government identification number, or a financial account number with an access code, each combined with a name, or certain health information) must notify affected Texas residents without unreasonable delay and no later than 60 days after determining a breach of system security occurred.

If 250 or more Texas residents are affected, the person must also notify the Texas Attorney General as soon as practicable and no later than 30 days after that determination, and a person notifying more than 10,000 persons at one time must also notify each nationwide consumer reporting agency.

Biometric data such as a fingerprint, voiceprint, or retina or iris image sits in the chapter's separate, broader personal identifying information definition and does not itself trigger this notification duty.

Enforcement of this notification duty is exclusive to the Attorney General, with a civil penalty of $2,000 to $50,000 per violation, and this section creates no private right of action, though a separate provision of the same chapter (sec. 521.152) ties a violation of the identity theft prohibition in sec. 521.051 to a private action under the Deceptive Trade Practices Act.

What it asks of an app

Comprehensive regime

Texas Data Privacy and Security Act (HB 4), general applicability and scope

cite Tex. Bus. & Com. Code ch. 541, secs. 541.001-541.002 stage In effect since 2024-07-01 source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

TDPSA governs private-sector processing of Texas residents' personal data. It applies to a person who conducts business in Texas, or produces a product or service consumed by Texas residents, and who processes or sells personal data, unless the person is a small business under SBA size standards (a limited exception for selling sensitive data under sec. 541.107 applies regardless of size).

The Act excludes state agencies, political subdivisions, GLBA-regulated financial institutions, HIPAA covered entities, nonprofits, higher-education institutions, and electric utilities, and 'personal data' excludes deidentified data and publicly available information.

What it asks of an app

Data subject rights

Texas Data Privacy and Security Act, consumer rights and assessments

cite Tex. Bus. & Com. Code secs. 541.051-541.053, 541.105 stage In effect since 2024-07-01 source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

TDPSA gives a Texas consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect, exercisable against the controller.

A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available, must answer an appeal of a refusal within 60 days, and must conduct and document a data protection assessment before targeted advertising, sale, certain profiling, sensitive-data processing, or other heightened-risk processing.

What it asks of an app

Enforcement supervision

Texas Data Privacy and Security Act, Attorney General enforcement

cite Tex. Bus. & Com. Code secs. 541.151, 541.154-541.156 stage In effect since 2024-07-01 source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

The Texas Attorney General has exclusive authority to enforce TDPSA. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated; curing the violation within that period and confirming the cure in writing bars the action. An uncured violation is subject to a civil penalty of up to $7,500 per violation, and the chapter expressly bars any private right of action.

The Attorney General filed the state's first TDPSA enforcement action against Allstate Corp. and Arity LLC on January 13, 2025, over the sale of geolocation and driving-behavior data collected through SDKs embedded in third-party apps, and that case remains pending.

What it asks of an app

Sensitive categories

Texas Data Privacy and Security Act, sensitive data and biometric consent

cite Tex. Bus. & Com. Code secs. 541.001, 541.101(b)(4) stage In effect since 2024-07-01 source official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

TDPSA classifies genetic or biometric data processed to uniquely identify a person, along with racial or ethnic origin, religious belief, a mental or physical health diagnosis, sexuality, citizenship or immigration status, precise geolocation, and a known child's data, as sensitive data requiring the consumer's prior consent before a controller may process it.

'Biometric data' means data from automatic measurement of an individual's biological characteristics used to identify them, including a fingerprint, voiceprint, or eye retina or iris, but the definition expressly excludes data generated from a photograph, or from a video or audio recording, so an identifier derived solely from such a recording falls outside this consent duty.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.