#
A clearly identified enforcer (OAG) and a stack of in-force statutes with defined material and territorial scope.
Sub-modules (5)
Regulator And AuthorityGreen
TDPSA is enforced exclusively by the Texas AG; there is no independent Texas DPA.
Claims (1):
- The Texas Data Privacy and Security Act is enforced exclusively by the Texas Attorney General's Office, with no dedicated Texas data protection authority.
Act And InstrumentsGreen
TDPSA, CUBI, TITEPA (as amended), and TRAIGA form the operative instrument stack.
Claims (3):
- Texas enacted the Texas Data Privacy and Security Act (HB 4) on June 18, 2023, with compliance required from July 1, 2024.
- The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) entered into force on January 1, 2026, one month before the Colorado AI Act.
- Texas maintains a standalone biometric statute, the Capture or Use of Biometric Identifier Act (CUBI), codified at Tex. Bus. & Com. Code §503.001, effective since April 1, 2009.
Material ScopeGreen
Personal data is broadly defined to include pseudonymous data linked or linkable to an identifiable individual.
Claims (1):
- TDPSA personal data is defined as information linked or reasonably linkable to an identified or identifiable individual, including pseudonymous data.
Territorial ScopeGreen
TDPSA uses a unique three-factor applicability test rather than revenue/volume thresholds common to other state laws.
Claims (1):
- TDPSA applies to entities conducting business in Texas or producing products/services consumed by Texas residents that process or sell personal data and are not a small business under SBA guidelines — a unique three-factor threshold without revenue or volume stipulations.
Regulator Registration And FilingAmber
No general controller registration exists under TDPSA itself, but a mandatory data-broker registry operates under Ch. 509, tightened by SB 1343.
Claims (2):
- Texas maintains a mandatory data-broker registry under Business & Commerce Code Chapter 509, requiring registration with the Texas Secretary of State and authorizing civil penalties for noncompliance.
- SB 1343 expanded data-broker registration-statement requirements (purchaser credentialing, children's-data handling, security-breach statistics) and mandates a conspicuous website notice, applicable to statements submitted on or after September 1, 2025.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (8)
- ConfirmedDataGuidance (OneTrust) — The Texas Data Privacy and Security Act is enforced exclusively by the Texas Attorney General's Office, with no dedicated Texas data protection authority.observed
- ConfirmedDataGuidance (OneTrust) — Texas enacted the Texas Data Privacy and Security Act (HB 4) on June 18, 2023, with compliance required from July 1, 2024.observed
- ConfirmedInternational Association of Privacy Professionals — The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) entered into force on January 1, 2026, one month before the Colorado AI Act.observed
- ConfirmedU.S. Federal Trade Commission — Texas maintains a standalone biometric statute, the Capture or Use of Biometric Identifier Act (CUBI), codified at Tex. Bus. & Com. Code §503.001, effective since April 1, 2009.observed
- ConfirmedDataGuidance (OneTrust) — TDPSA personal data is defined as information linked or reasonably linkable to an identified or identifiable individual, including pseudonymous data.observed
- ConfirmedInternational Association of Privacy Professionals — TDPSA applies to entities conducting business in Texas or producing products/services consumed by Texas residents that process or sell personal data and are not a small business under SBA guidelines — a unique three-factor threshold without revenue or volume stipulations.observed
- ConfirmedTexas Legislature — Texas maintains a mandatory data-broker registry under Business & Commerce Code Chapter 509, requiring registration with the Texas Secretary of State and authorizing civil penalties for noncompliance.observed
- ConfirmedDataGuidance (OneTrust) — SB 1343 expanded data-broker registration-statement requirements (purchaser credentialing, children's-data handling, security-breach statistics) and mandates a conspicuous website notice, applicable to statements submitted on or after September 1, 2025.observed