close
close
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Texas Privacy Law

TX

Texas (TDPSA)

Last updated

TDPSA Enacted, in effect

Who this affects: This page tracks Texas’s TDPSA, which governs controllers and processors.

Who it applies to: Entities that do business in Texas or serve its residents, process or sell personal data, and are not small businesses as the SBA defines them; some provisions apply under a separate test (see below).

Content on this page is not legal advice This page aggregates publicly cited regulatory facts for informational purposes only. It is not legal advice, and DataGrail is not responsible for decisions made in reliance on it. Consult qualified counsel for your specific compliance obligations.
July 1, 2024
Effective ↗
Attorney General
Enforced by ↗
$7,500
Maximum penalty per violation ↗
None
Private right of action ↗

The law, in plain English

Must · Can’t · Should

TDPSA, distilled to what actually changes your week. Read one column to know your floor, your hard limits, and the further obligations and good practices worth planning for.

Must

  • Respond to authenticated access, correction, deletion, portability and opt-out requests without undue delay, within 45 days. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.051 “A controller shall comply with an authenticated consumer request to exercise the right to:” Read the statute TX-541.052 “A controller shall respond to the consumer request without undue delay, which may not be later than the 45th day after the date of receipt of the request” Read the statute TX-541.051 “confirm whether a controller is processing the consumer's personal data and to access the personal data” Read the statute TX-541.051 “correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data” Read the statute TX-541.051 “delete personal data provided by or obtained about the consumer” Read the statute TX-541.051 “if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance” Read the statute TX-541.051 “opt out of the processing of the personal data for purposes of: (A) targeted advertising; (B) the sale of personal data” Read the statute
  • Run an appeal process, answer appeals in writing within 60 days, and if denied, give the attorney general complaint mechanism. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.053 “A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision under Section 541.052(c)” Read the statute TX-541.053 “A controller shall inform the consumer in writing of any action taken or not taken in response to an appeal under this section not later than the 60th day after the date of receipt of the appeal, including a written explanation of the reason or reasons for the decision” Read the statute TX-541.053 “If the controller denies an appeal, the controller shall provide the consumer with the online mechanism described by Section 541.152 through which the consumer may contact the attorney general to submit a complaint” Read the statute
  • Honor authorized-agent opt-outs sent by browser setting, extension or device setting when you can verify identity and authority. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.055 “A consumer may designate an authorized agent using a technology, including a link to an Internet website, an Internet browser setting or extension, or a global setting on an electronic device, that allows the consumer to indicate the consumer's intent to opt out of the processing. A controller shall comply with an opt-out request received from an authorized agent under this subsection if the controller is able to verify, with commercially reasonable effort, the identity of the consumer and the authorized agent's authority to act on the consumer's behalf.” Read the statute TX-541.055 “A controller shall comply with an opt-out request received from an authorized agent under this subsection if the controller is able to verify, with commercially reasonable effort, the identity of the consumer and the authorized agent's authority to act on the consumer's behalf” Read the statute

Can't

  • Process a consumer's sensitive data without consent, or a known child's sensitive data other than in accordance with COPPA. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.101 “process the sensitive data of a consumer without obtaining the consumer's consent, or, in the case of processing the sensitive data of a known child, without processing that data in accordance with the Children's Online Privacy Protection Act of 1998 (15 U.S.C. Section 6501 et seq.)” Read the statute
  • Require a consumer to create a new account to exercise privacy rights, though you may require use of an existing account. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.055 “A controller may not require a consumer to create a new account to exercise the consumer's rights under this subchapter but may require a consumer to use an existing account” Read the statute
  • Process personal data for a purpose not reasonably necessary to or compatible with the disclosed purpose, unless you get consent. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.101 “process personal data for a purpose that is neither reasonably necessary to nor compatible with the disclosed purpose for which the personal data is processed, as disclosed to the consumer, unless the controller obtains the consumer's consent” Read the statute

Should

  • Bind processors by contract covering instructions, nature and purpose, data type, duration, and both parties' rights and duties. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.104 “The contract must include: (1) clear instructions for processing data; (2) the nature and purpose of processing; (3) the type of data subject to processing; (4) the duration of processing; (5) the rights and obligations of both parties; and (6) a requirement that the processor shall: (A) ensure that each person processing personal data is subject to a duty of confidentiality” Read the statute
  • Publish a clear, accessible privacy notice and clearly disclose any sale or targeted advertising and how to opt out of it. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.102 “A controller shall provide consumers with a reasonably accessible and clear privacy notice that includes” Read the statute TX-541.103 “the controller shall clearly and conspicuously disclose that process and the manner in which a consumer may exercise the right to opt out of that process” Read the statute TX-541.051 “opt out of the processing of the personal data for purposes of: (A) targeted advertising; (B) the sale of personal data” Read the statute
  • Conduct and document data protection assessments for covered processing and keep them ready for attorney general demands. DataGrail editorial summary: our plain-English wording, written from the sources below, not statutory text. TX-541.105 “A controller shall conduct and document a data protection assessment of each of the following processing activities involving personal data” Read the statute TX-541.105 “A controller shall make a data protection assessment requested under Section 541.153(b) available to the attorney general pursuant to a civil investigative demand under Section 541.153” Read the statute

These are the highlights we judge most important, not everything TDPSA requires. The comprehensive law section below covers the full detail, fact by fact, with the statutory text behind every one.

The comprehensive law

Texas Data Privacy and Security Act

TDPSA (HB 4) is Texas’s comprehensive privacy law. Every fact was extracted from the primary statute by the DataGrail regulation engine and is grounded to the cited source. Scan the facts; the exact statutory text sits one click away on each source link.

Status
Enacted, in effect
Archived excerpt — the text we read …ic value, actual or potential, from not being generally known to, and not being readily ascertainable through proper means by, another person who can obtain economic value from the disclosure or use of the information. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 60431260 Verify at the source

Corroborated by Privacy-law tracker

Effective
July 1, 2024
The authorized-agent opt-out technology rule in 541.055(e) took effect January 1, 2025 (H.B. 4 SECTION 7(b)). Archived excerpt — the text we read …ic value, actual or potential, from not being generally known to, and not being readily ascertainable through proper means by, another person who can obtain economic value from the disclosure or use of the information. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 60431260 Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Signed
June 18, 2023
“Signed by the Governor 06/18/2023” View the source
Enforced by
Attorney General
Archived excerpt — the text we read Sec. 541.151. ENFORCEMENT AUTHORITY EXCLUSIVE. The attorney general has exclusive authority to enforce this chapter. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 8288c2cf Verify at the source
Maximum penalty per violation
$7,500
Only for violations not cured within 30 days or a breached cure statement. The AG may also recover fees and costs. “is liable for a civil penalty in an amount not to exceed $7,500 for each violation” View the statute
Right to cure
30 days
Mandatory, no sunset. The cure needs a written statement to the AG, consumer notice and supporting documents. Archived excerpt — the text we read …ttorney general shall notify a person in writing, not later than the 30th day before bringing the action, identifying the specific provisions of this chapter the attorney general alleges have been or are being violated. The attorney general may not bring an action against the person if: (1) within the 30-day period, the person cures the identified violation; and (2) the person provides the attorney general a written statement that the person: (A) cured the alleged violation; (B) notified the consumer that the consumer's privacy violation was addressed, if the consumer's contact information has been made available to the person; (C) provided supportive documentation to show how the privacy violation was cured; and (D) made changes to internal policies, if necessary, to ensure that no such further violations will occur. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 5907c8e8 Verify at the source
Private right of action
No private right of action.
Archived excerpt — the text we read Sec. 541.156. NO PRIVATE RIGHT OF ACTION. This chapter may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot deba6b8f Verify at the source

Corroborated by Privacy-law tracker Regulator guidance

Universal opt-out signal
Required
Archived excerpt — the text we read … A consumer may designate another person to serve as the consumer's authorized agent and act on the consumer's behalf to opt out of the processing of the consumer's personal data under Sections 541.051(b)(5)(A) and (B). A consumer may designate an authorized agent using a technology, including a link to an Internet website, an Internet browser setting or extension, or a global setting on an electronic device, that allows the consumer to indicate the consumer's intent to opt out of the processing. A controller shall comply with an opt-out request received from an authorized agent under this subsection if the controller is able to verify, with commercially reasonable effort, the identity of the consumer and the authorized agent's authority to act on the consumer's behalf. A controller is not required to comply with an opt-out request received from an authorized agent under this subsection if: (1) the authorized agent does not communicate the request to the controller in a clear and unam… Archived from source — captured 2026-07-21 · snapshot 81c5192a Verify at the source

Who it applies to

Entities that do business in Texas or serve its residents, process or sell personal data, and are not small businesses as the SBA defines them; some provisions apply under a separate test (see full text)

What the law gives consumers

  • Right to access Archived excerpt — the text we read …ing to a known child, a parent or legal guardian of the child may exercise the consumer rights on behalf of the child. (b) A controller shall comply with an authenticated consumer request to exercise the right to: (1) confirm whether a controller is processing the consumer's personal data and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by o… Archived from source — captured 2026-07-21 · snapshot 4154bd93 Verify at the source
  • Right to correct Archived excerpt — the text we read …e child. (b) A controller shall comply with an authenticated consumer request to exercise the right to: (1) confirm whether a controller is processing the consumer's personal data and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the contro… Archived from source — captured 2026-07-21 · snapshot 4154bd93 Verify at the source
  • Right to delete For data obtained from another source, the controller may keep a record of the request and the minimum data needed to keep it deleted, or opt the consumer out of non-exempt processing (541.052(f)). Archived excerpt — the text we read …ta and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily us… Archived from source — captured 2026-07-21 · snapshot 4154bd93 Verify at the source
  • Right to data portability Archived excerpt — the text we read …onsumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of a decision that produces a legal or similarly signi… Archived from source — captured 2026-07-21 · snapshot 4154bd93 Verify at the source
  • Right to opt out of sale Archived excerpt — the text we read … consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 4154bd93 Verify at the source
  • Right to opt out of targeted advertising Archived excerpt — the text we read … consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 4154bd93 Verify at the source
  • Right to opt out of profiling for significant decisions Archived excerpt — the text we read …llows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal data for purposes of: (A) targeted advertising; (B) the sale of personal data; or (C) profiling in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 4154bd93 Verify at the source
  • Sensitive data: opt-in consent required Archived excerpt — the text we read …rights contained in this chapter, including by denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; or (4) process the sensitive data of a consumer without obtaining the consumer's consent, or, in the case of processing the sensitive data of a known child, without processing that data in accordance with the Children's Online Privacy Protection Act of 1998 (15 U.S.C. Section 6501 et seq.). (c) Subsection … Archived from source — captured 2026-07-21 · snapshot 75eb760b Verify at the source
  • Right to appeal Archived excerpt — the text we read Sec. 541.053. APPEAL. (a) A controller shall establish a process for a consumer to appeal the controller's refusal to take action on a request within a reasonable period of time after the consumer's receipt of the decision under Section 541.052(c). (b) The appeal process must be conspicuously available and similar to the process for initiating action to exercise consumer rights by submitting a… Archived from source — captured 2026-07-21 · snapshot 512d1803 Verify at the source
  • Right against discrimination Archived excerpt — the text we read …cessed, as disclosed to the consumer, unless the controller obtains the consumer's consent; (2) process personal data in violation of state and federal laws that prohibit unlawful discrimination against consumers; (3) discriminate against a consumer for exercising any of the consumer rights contained in this chapter, including by denying goods or services, charging different prices or rates for goods or services, or providing a different level of quality of goods or services to the consumer; or (4) process the sensitive data of a consumer without obtaining the consumer'… Archived from source — captured 2026-07-21 · snapshot 75eb760b Verify at the source
  • Not granted: Private right of action Archived excerpt — the text we read Sec. 541.156. NO PRIVATE RIGHT OF ACTION. This chapter may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot deba6b8f Verify at the source

Who the law governs

  • Controllers Archived excerpt — the text we read …patterns. (7) "Consumer" means an individual who is a resident of this state acting only in an individual or household context. The term does not include an individual acting in a commercial or employment context. (8) "Controller" means an individual or other person that, alone or jointly with others, determines the purpose and means of processing personal data. (9) "Covered entity" has the meaning assigned to the term by the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.). (10) "Dark pattern" means a user interface designed or ma… Archived from source — captured 2026-07-21 · snapshot 60431260 Verify at the source
  • Processors Archived excerpt — the text we read … of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data. (23) "Processor" means a person that processes personal data on behalf of a controller. (24) "Profiling" means any form of solely automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual's economic situation, heal… Archived from source — captured 2026-07-21 · snapshot 60431260 Verify at the source

Exemptions

  • Small businesses (sensitive-data sale ban still applies) Small businesses (as defined by the U.S. SBA), except that the 541.107 ban on selling sensitive data without prior consumer consent still applies. Archived excerpt — the text we read …(a) This chapter applies only to a person that: (1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision. (b) This chapter does not apply to: (1) a state agency or a political subdivision of this state; (2) a financial institution or data subject to Title V, Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.); (3) … Archived from source — captured 2026-07-21 · snapshot 9d73185e Verify at the source
  • State agencies and political subdivisions Archived excerpt — the text we read … not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision. (b) This chapter does not apply to: (1) a state agency or a political subdivision of this state; (2) a financial institution or data subject to Title V, Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.); (3) a covered entity or business associate governed by the privacy, security, and breach notification r… Archived from source — captured 2026-07-21 · snapshot 9d73185e Verify at the source
  • GLBA: financial institutions and data subject to Title V Entity- and data-level Archived excerpt — the text we read …siness Administration, except to the extent that Section 541.107 applies to a person described by this subdivision. (b) This chapter does not apply to: (1) a state agency or a political subdivision of this state; (2) a financial institution or data subject to Title V, Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.); (3) a covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. Parts 160 and 164, established… Archived from source — captured 2026-07-21 · snapshot 9d73185e Verify at the source
  • HIPAA covered entities and business associates Archived excerpt — the text we read …. (b) This chapter does not apply to: (1) a state agency or a political subdivision of this state; (2) a financial institution or data subject to Title V, Gramm-Leach-Bliley Act (15 U.S.C. Section 6801 et seq.); (3) a covered entity or business associate governed by the privacy, security, and breach notification rules issued by the United States Department of Health and Human Services, 45 C.F.R. Parts 160 and 164, established under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.), and the Health Information Technology for Economic and Clinical Health Act (Division A, Title XIII, a… Archived from source — captured 2026-07-21 · snapshot 9d73185e Verify at the source
  • Nonprofit organizations as defined in 541.001 Texas nonprofit corporations; 501(c)(3), (6), (12) and (19) organizations; certain 501(c)(4) organizations; and political organizations. Archived excerpt — the text we read …ty and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.), and the Health Information Technology for Economic and Clinical Health Act (Division A, Title XIII, and Division B, Title IV, Pub. L. No. 111-5); (4) a nonprofit organization; (5) an institution of higher education; or (6) an electric utility, a power generation company, or a retail electric provider, as those terms are defined by Section 31.002, Utilities Code. Added by Acts 2023, 88th L… Archived from source — captured 2026-07-21 · snapshot 9d73185e Verify at the source
  • Institutions of higher education Archived excerpt — the text we read …96 (42 U.S.C. Section 1320d et seq.), and the Health Information Technology for Economic and Clinical Health Act (Division A, Title XIII, and Division B, Title IV, Pub. L. No. 111-5); (4) a nonprofit organization; (5) an institution of higher education; or (6) an electric utility, a power generation company, or a retail electric provider, as those terms are defined by Section 31.002, Utilities Code. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff.… Archived from source — captured 2026-07-21 · snapshot 9d73185e Verify at the source
  • Electric utilities, power generation companies, and retail electric providers As defined by Utilities Code 31.002. Archived excerpt — the text we read …e Health Information Technology for Economic and Clinical Health Act (Division A, Title XIII, and Division B, Title IV, Pub. L. No. 111-5); (4) a nonprofit organization; (5) an institution of higher education; or (6) an electric utility, a power generation company, or a retail electric provider, as those terms are defined by Section 31.002, Utilities Code. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 9d73185e Verify at the source
  • Protected health information under HIPAA Archived excerpt — the text we read Sec. 541.003. CERTAIN INFORMATION EXEMPT FROM CHAPTER. The following information is exempt from this chapter: (1) protected health information under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (2) health records; (3) patient identifying information for purposes of 42 U.S.C. Section 290dd-2; (4) identifiable private information: (A) for purposes of the federal policy for the protection of human subjects u… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Health records Archived excerpt — the text we read …EXEMPT FROM CHAPTER. The following information is exempt from this chapter: (1) protected health information under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (2) health records; (3) patient identifying information for purposes of 42 U.S.C. Section 290dd-2; (4) identifiable private information: (A) for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 4… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Patient identifying information under 42 U.S.C. Section 290dd-2 Archived excerpt — the text we read …The following information is exempt from this chapter: (1) protected health information under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (2) health records; (3) patient identifying information for purposes of 42 U.S.C. Section 290dd-2; (4) identifiable private information: (A) for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 46; (B) collected as part of human subjects research under the good clinical pra… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Human subjects research information under federal policy for protection of human subjects Archived excerpt — the text we read …ormation under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (2) health records; (3) patient identifying information for purposes of 42 U.S.C. Section 290dd-2; (4) identifiable private information: (A) for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 46; (B) collected as part of human subjects research under the good clinical practice guidelines issued by The International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH) or o… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Human subjects research data Human subjects research under ICH good clinical practice guidelines or 21 C.F.R. Parts 50 and 56. Archived excerpt — the text we read …atient identifying information for purposes of 42 U.S.C. Section 290dd-2; (4) identifiable private information: (A) for purposes of the federal policy for the protection of human subjects under 45 C.F.R. Part 46; (B) collected as part of human subjects research under the good clinical practice guidelines issued by The International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH) or of the protection of human subjects under 21 C.F.R. Parts 50 and 56; or (C) that is personal data used or shared in research conducted in accordance with the requirements set forth in this chapter or other research conducted in accordance with applicable law; (5) information and docum… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Personal data used or shared in research conducted in accordance with applicable law Archived excerpt — the text we read …practice guidelines issued by The International Council for Harmonisation of Technical Requirements for Pharmaceuticals for Human Use (ICH) or of the protection of human subjects under 21 C.F.R. Parts 50 and 56; or (C) that is personal data used or shared in research conducted in accordance with the requirements set forth in this chapter or other research conducted in accordance with applicable law; (5) information and documents created for purposes of the Health Care Quality Improvement Act of 1986 (42 U.S.C. Section 11101 et seq.); (6) patient safety work product for purposes of the Patient Safety and Quality … Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Information under Health Care Quality Improvement Act of 1986 Archived excerpt — the text we read ….F.R. Parts 50 and 56; or (C) that is personal data used or shared in research conducted in accordance with the requirements set forth in this chapter or other research conducted in accordance with applicable law; (5) information and documents created for purposes of the Health Care Quality Improvement Act of 1986 (42 U.S.C. Section 11101 et seq.); (6) patient safety work product for purposes of the Patient Safety and Quality Improvement Act of 2005 (42 U.S.C. Section 299b-21 et seq.); (7) information derived from any of the health care-related information list… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Patient safety work product under Patient Safety and Quality Improvement Act of 2005 Archived excerpt — the text we read … this chapter or other research conducted in accordance with applicable law; (5) information and documents created for purposes of the Health Care Quality Improvement Act of 1986 (42 U.S.C. Section 11101 et seq.); (6) patient safety work product for purposes of the Patient Safety and Quality Improvement Act of 2005 (42 U.S.C. Section 299b-21 et seq.); (7) information derived from any of the health care-related information listed in this section that is deidentified in accordance with the requirements for deidentification under the Health Insurance Portability and A… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Deidentified health-related information under HIPAA deidentification standards Archived excerpt — the text we read …h Care Quality Improvement Act of 1986 (42 U.S.C. Section 11101 et seq.); (6) patient safety work product for purposes of the Patient Safety and Quality Improvement Act of 2005 (42 U.S.C. Section 299b-21 et seq.); (7) information derived from any of the health care-related information listed in this section that is deidentified in accordance with the requirements for deidentification under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (8) information originating from, and intermingled to be indistinguishable with, or information treated in the same manner as, information exempt under this section that is maintained… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Information intermingled with exempt health information When maintained by a HIPAA covered entity/business associate or a 42 U.S.C. 290dd-2 program/qualified service organization. Archived excerpt — the text we read …ormation listed in this section that is deidentified in accordance with the requirements for deidentification under the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (8) information originating from, and intermingled to be indistinguishable with, or information treated in the same manner as, information exempt under this section that is maintained by a covered entity or business associate as defined by the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.) or by a program or a qualified service organization as defined by 42 U.S.C. Section 290dd-2; (9) information that is included in a limited data set as described by 45 C.F.R. Section 164.514(e), to the extent that the information is used, disclosed, and maintained in the manner specified by 45 C.F.R. Section 1… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • HIPAA limited data set information Archived excerpt — the text we read …associate as defined by the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.) or by a program or a qualified service organization as defined by 42 U.S.C. Section 290dd-2; (9) information that is included in a limited data set as described by 45 C.F.R. Section 164.514(e), to the extent that the information is used, disclosed, and maintained in the manner specified by 45 C.F.R. Section 164.514(e); (10) information collected or used only for public health activities and purposes as authorized by the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (11) the collectio… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Public health activities information under HIPAA Archived excerpt — the text we read …n that is included in a limited data set as described by 45 C.F.R. Section 164.514(e), to the extent that the information is used, disclosed, and maintained in the manner specified by 45 C.F.R. Section 164.514(e); (10) information collected or used only for public health activities and purposes as authorized by the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (11) the collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's creditworthiness, credit standing, credit capacity, chara… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • FCRA-regulated data Archived excerpt — the text we read …on 164.514(e); (10) information collected or used only for public health activities and purposes as authorized by the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. Section 1320d et seq.); (11) the collection, maintenance, disclosure, sale, communication, or use of any personal information bearing on a consumer's creditworthiness, credit standing, credit capacity, character, general reputation, personal characteristics, or mode of living by a consumer reporting agency or furnisher that provides information for use in a consumer report, and by a user of a consumer report, but only to the extent that the activity is regulated by and authorized under the Fair Credit Reporting Act (15 U.S.C. Section 1681 et seq.); (12) personal data collected, processed, sold, or disclosed in compliance with the Driver's Privacy Protection Act of 1994 (18 U.S.C. Section 2721 et seq.); (13) personal data regulated by the Family Educational Righ… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Driver's Privacy Protection Act data Archived excerpt — the text we read …ation for use in a consumer report, and by a user of a consumer report, but only to the extent that the activity is regulated by and authorized under the Fair Credit Reporting Act (15 U.S.C. Section 1681 et seq.); (12) personal data collected, processed, sold, or disclosed in compliance with the Driver's Privacy Protection Act of 1994 (18 U.S.C. Section 2721 et seq.); (13) personal data regulated by the Family Educational Rights and Privacy Act of 1974 (20 U.S.C. Section 1232g); (14) personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act of 1… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • FERPA-regulated data Archived excerpt — the text we read … Credit Reporting Act (15 U.S.C. Section 1681 et seq.); (12) personal data collected, processed, sold, or disclosed in compliance with the Driver's Privacy Protection Act of 1994 (18 U.S.C. Section 2721 et seq.); (13) personal data regulated by the Family Educational Rights and Privacy Act of 1974 (20 U.S.C. Section 1232g); (14) personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act of 1971 (12 U.S.C. Section 2001 et seq.); (15) data processed or maintained in the course of an individual applying t… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Farm Credit Act data Archived excerpt — the text we read …ed in compliance with the Driver's Privacy Protection Act of 1994 (18 U.S.C. Section 2721 et seq.); (13) personal data regulated by the Family Educational Rights and Privacy Act of 1974 (20 U.S.C. Section 1232g); (14) personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act of 1971 (12 U.S.C. Section 2001 et seq.); (15) data processed or maintained in the course of an individual applying to, being employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data … Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Employment data Archived excerpt — the text we read …y Educational Rights and Privacy Act of 1974 (20 U.S.C. Section 1232g); (14) personal data collected, processed, sold, or disclosed in compliance with the Farm Credit Act of 1971 (12 U.S.C. Section 2001 et seq.); (15) data processed or maintained in the course of an individual applying to, being employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; (16) data processed or maintained as the emergency contact information of an individual under this chapter that is used for emergency contact purposes; or (17) data that is processed or maintained and is necessary to… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Emergency contact information Archived excerpt — the text we read …vidual applying to, being employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role; (16) data processed or maintained as the emergency contact information of an individual under this chapter that is used for emergency contact purposes; or (17) data that is processed or maintained and is necessary to retain to administer benefits for another individual that relates to an individual described by Subdivision (15) and used for the purposes of administer… Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Benefits administration data Archived excerpt — the text we read …ta is collected and used within the context of that role; (16) data processed or maintained as the emergency contact information of an individual under this chapter that is used for emergency contact purposes; or (17) data that is processed or maintained and is necessary to retain to administer benefits for another individual that relates to an individual described by Subdivision (15) and used for the purposes of administering those benefits. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 7c928666 Verify at the source
  • Purely personal or household activity Archived excerpt — the text we read Sec. 541.004. INAPPLICABILITY OF CHAPTER. This chapter does not apply to the processing of personal data by a person in the course of a purely personal or household activity. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot e92f49cf Verify at the source
  • Trade secrets (no obligation to disclose) Archived excerpt — the text we read …vileged communication. (c) This chapter may not be construed as imposing a requirement on controllers and processors that adversely affects the rights or freedoms of any person, including the right of free speech. (d) This chapter may not be construed as requiring a controller, processor, third party, or consumer to disclose a trade secret. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 996207c6 Verify at the source
  • Privileged communications to a person covered by an evidentiary privilege Archived excerpt — the text we read …itigate privacy risks associated with research, including any risks associated with reidentification; or (9) assist another controller, processor, or third party with any of the requirements under this subsection. (b) This chapter may not be construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this state as part of a privileged communication. (c) This chapter may not be construed as imposing a requirement on controllers and processors that adversely affects the rights or freedoms of any person, including the right of free speech. (d) This chapter may not b… Archived from source — captured 2026-07-21 · snapshot 996207c6 Verify at the source
  • Rights and freedoms of others, including free speech Archived excerpt — the text we read … construed to prevent a controller or processor from providing personal data concerning a consumer to a person covered by an evidentiary privilege under the laws of this state as part of a privileged communication. (c) This chapter may not be construed as imposing a requirement on controllers and processors that adversely affects the rights or freedoms of any person, including the right of free speech. (d) This chapter may not be construed as requiring a controller, processor, third party, or consumer to disclose a trade secret. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot 996207c6 Verify at the source
  • Evidentiary privilege (compliance would violate a Texas evidentiary privilege) Archived excerpt — the text we read … or (C) are otherwise compatible with processing data in furtherance of the provision of a product or service specifically requested by a consumer or the performance of a contract to which the consumer is a party. (b) A requirement imposed on a controller or processor under this chapter does not apply if compliance with the requirement by the controller or processor, as applicable, would violate an evidentiary privilege under the laws of this state. Added by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), Sec. 2, eff. July 1, 2024. Archived from source — captured 2026-07-21 · snapshot cd36617a Verify at the source

Published Sep 29, 2026 from the DataGrail regulation engine; each fact links to its primary source.

Timeline

TDPSA milestones

Drag the handle or use ← → to step through the milestones. The marker shows where today falls.

Done Upcoming Today
You are here
Completed January 1, 2025

Authorized-agent opt-out technology rule (541.055(e)) took effect

The authorized-agent opt-out technology rule in 541.055(e) took effect January 1, 2025 (H.B. 4 SECTION 7(b)).

Source: primary citation

Enforcement so far

The fines are already landing

Real regulatory actions and settlements under the Texas privacy laws we track. Every entry is a DataGrail summary linking to the primary source.

$1,375M Total penalties
1 Actions on record
View all

DataGrail’s wording, not statutory text. The figures are computed from the linked sources.

When staying on top of the law isn't enough, DataGrail automates the work.
DSR automation and regulatory tracking — handled by the platform behind this reference.
How DataGrail helps
Back to the Regulations Hub Reference only — not legal advice. Published Sep 29, 2026