🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
US-TX v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing20 sources retrieved model claude-sonnet-5 · 2026-08-05

Texas, USA

US-TX schema gdpri-v2 trajectory: not yet assessedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 45 claims · 31 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
45Claimsbaseline..claims[]
9Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 19 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

Texas's biometric-governance and children's-privacy modules both tightened materially this cycle, in two structurally distinct ways. The Capture or Use of Biometric Identifier Act was amended effective January 1, 2026 to add a statutory definition of an "artificial intelligence system" and to clarify that public availability of an image or other media alone does not, by itself, establish the notice and consent required for commercial capture or storage of a biometric identifier. Separately, the App Store Accountability Act, Senate Bill 2420, took effect on June 4, 2026 after the Fifth Circuit Court of Appeals stayed a federal district-court injunction that had blocked its enforcement; a constitutional challenge to the statute, CCIA v. Paxton, remains pending before that same court.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A clearly identified enforcer (OAG) and a stack of in-force statutes with defined material and territorial scope.

Primary frameworkTexas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code Title 11, Subtitle D, Ch. 541 (HB 4, 2023)
Traffic-light rationale — GreenA clearly identified enforcer (OAG) and a stack of in-force statutes with defined material and territorial scope.

Sub-modules (5)

Regulator And AuthorityGreen

TDPSA is enforced exclusively by the Texas AG; there is no independent Texas DPA.

Claims (1):

  • The Texas Data Privacy and Security Act is enforced exclusively by the Texas Attorney General's Office, with no dedicated Texas data protection authority.

Act And InstrumentsGreen

TDPSA, CUBI, TITEPA (as amended), and TRAIGA form the operative instrument stack.

Claims (3):

  • Texas enacted the Texas Data Privacy and Security Act (HB 4) on June 18, 2023, with compliance required from July 1, 2024.
  • The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) entered into force on January 1, 2026, one month before the Colorado AI Act.
  • Texas maintains a standalone biometric statute, the Capture or Use of Biometric Identifier Act (CUBI), codified at Tex. Bus. & Com. Code §503.001, effective since April 1, 2009.

Material ScopeGreen

Personal data is broadly defined to include pseudonymous data linked or linkable to an identifiable individual.

Claims (1):

  • TDPSA personal data is defined as information linked or reasonably linkable to an identified or identifiable individual, including pseudonymous data.

Territorial ScopeGreen

TDPSA uses a unique three-factor applicability test rather than revenue/volume thresholds common to other state laws.

Claims (1):

  • TDPSA applies to entities conducting business in Texas or producing products/services consumed by Texas residents that process or sell personal data and are not a small business under SBA guidelines — a unique three-factor threshold without revenue or volume stipulations.

Regulator Registration And FilingAmber

No general controller registration exists under TDPSA itself, but a mandatory data-broker registry operates under Ch. 509, tightened by SB 1343.

Claims (2):

  • Texas maintains a mandatory data-broker registry under Business & Commerce Code Chapter 509, requiring registration with the Texas Secretary of State and authorizing civil penalties for noncompliance.
  • SB 1343 expanded data-broker registration-statement requirements (purchaser credentialing, children's-data handling, security-breach statistics) and mandates a conspicuous website notice, applicable to statements submitted on or after September 1, 2025.
Category narrative109 words

Texas has no dedicated data-protection authority; enforcement of the state's comprehensive privacy statute and adjacent biometric/breach laws sits with the Office of the Attorney General (OAG) Consumer Protection Division. The core omnibus instrument is the Texas Data Privacy and Security Act (TDPSA, HB 4), enacted June 18, 2023 and effective July 1, 2024, layered atop pre-existing sectoral instruments: the Capture or Use of Biometric Identifier Act (CUBI, 2009), the Identity Theft Enforcement and Protection Act (TITEPA) breach-notification regime (as amended by HB 4390), a data-broker registry (Ch. 509, as amended by SB 1343), and — as of January 1, 2026 — the Texas Responsible Artificial Intelligence Governance Act (TRAIGA).

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (8)
  1. ConfirmedDataGuidance (OneTrust) — The Texas Data Privacy and Security Act is enforced exclusively by the Texas Attorney General's Office, with no dedicated Texas data protection authority.observed
  2. ConfirmedDataGuidance (OneTrust) — Texas enacted the Texas Data Privacy and Security Act (HB 4) on June 18, 2023, with compliance required from July 1, 2024.observed
  3. ConfirmedInternational Association of Privacy Professionals — The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) entered into force on January 1, 2026, one month before the Colorado AI Act.observed
  4. ConfirmedU.S. Federal Trade Commission — Texas maintains a standalone biometric statute, the Capture or Use of Biometric Identifier Act (CUBI), codified at Tex. Bus. & Com. Code §503.001, effective since April 1, 2009.observed
  5. ConfirmedDataGuidance (OneTrust) — TDPSA personal data is defined as information linked or reasonably linkable to an identified or identifiable individual, including pseudonymous data.observed
  6. ConfirmedInternational Association of Privacy Professionals — TDPSA applies to entities conducting business in Texas or producing products/services consumed by Texas residents that process or sell personal data and are not a small business under SBA guidelines — a unique three-factor threshold without revenue or volume stipulations.observed
  7. ConfirmedTexas Legislature — Texas maintains a mandatory data-broker registry under Business & Commerce Code Chapter 509, requiring registration with the Texas Secretary of State and authorizing civil penalties for noncompliance.observed
  8. ConfirmedDataGuidance (OneTrust) — SB 1343 expanded data-broker registration-statement requirements (purchaser credentialing, children's-data handling, security-breach statistics) and mandates a conspicuous website notice, applicable to statements submitted on or after September 1, 2025.observed

#

Consent and special-category rules are confirmed; the absence of an enumerated lawful-basis list (unlike GDPR Art. 6) is a structural gap relative to omnibus regimes.

Primary frameworkTexas Data Privacy and Security Act (TDPSA) + Capture or Use of Biometric Identifier Act (CUBI)
Traffic-light rationale — AmberConsent and special-category rules are confirmed; the absence of an enumerated lawful-basis list (unlike GDPR Art. 6) is a structural gap relative to omnibus regimes.

Sub-modules (4)

Lawful BasesAmber

No enumerated lawful-basis list; processing legitimacy flows from notice/consent and consumer opt-outs, per the Virginia-model foundation of TDPSA.

Claims (1):

  • TDPSA, following the Virginia consumer-privacy model as its structural foundation, relies on a notice-and-consent/opt-out framework rather than an enumerated list of GDPR-style lawful bases for processing.

Special CategoriesGreen

Sensitive personal data includes biometric data, children's data, and precise geolocation; CUBI imposes a separate informed-consent duty for biometric identifiers.

Claims (2):

  • TDPSA's sensitive personal data categories include biometric data, children's data, and precise geolocation data, requiring heightened protection.
  • CUBI prohibits capture of a person's biometric identifier for a commercial purpose without first informing the individual and obtaining consent.

Pseudonymisation And AnonymisationGreen

Pseudonymous data is expressly within scope of 'personal data' under TDPSA.

Claims (1):

  • TDPSA's definition of personal data explicitly includes pseudonymous data, extending coverage beyond directly identifiable information.
Category narrative51 words

TDPSA does not enumerate GDPR-style Art. 6 lawful bases; it instead follows the Virginia-model notice-and-consent architecture, requiring opt-in consent specifically for sensitive data. Sensitive/special categories are broadly defined (biometric, children's, precise geolocation, and by cross-reference to CUBI's separate biometric-consent regime). Pseudonymous data is explicitly captured within 'personal data' rather than exempted.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ProbableInternational Association of Privacy Professionals — TDPSA, following the Virginia consumer-privacy model as its structural foundation, relies on a notice-and-consent/opt-out framework rather than an enumerated list of GDPR-style lawful bases for processing.observed
  2. ConfirmedInternational Association of Privacy Professionals — TDPSA requires opt-in consent for the collection and use of sensitive data.observed
  3. ConfirmedDataGuidance (OneTrust) — TDPSA's sensitive personal data categories include biometric data, children's data, and precise geolocation data, requiring heightened protection.observed
  4. ConfirmedDataGuidance (OneTrust) — CUBI prohibits capture of a person's biometric identifier for a commercial purpose without first informing the individual and obtaining consent.observed
  5. ConfirmedDataGuidance (OneTrust) — TDPSA's definition of personal data explicitly includes pseudonymous data, extending coverage beyond directly identifiable information.observed

#

Core rights (access/correction/deletion/opt-out) are Confirmed; portability and exact deadline windows rest on Probable inference from the law's Virginia-model foundation rather than directly retrieved statutory text.

Primary frameworkTexas Data Privacy and Security Act (TDPSA)
Traffic-light rationale — AmberCore rights (access/correction/deletion/opt-out) are Confirmed; portability and exact deadline windows rest on Probable inference from the law's Virginia-model foundation rather than directly retrieved statutory text.

Sub-modules (5)

Access RightGreen

Consumers may confirm processing and access their personal data.

Claims (1):

  • TDPSA grants consumers the right to confirm whether a business is processing their personal data and to access that personal data.

Rectification And ErasureGreen

Correction and deletion rights are granted.

Claims (1):

  • TDPSA grants consumers rights to correct inaccuracies in their personal data and to request deletion of personal data provided by or obtained about the consumer.

Restriction And ObjectionGreen

Controllers must recognize universal opt-out mechanisms as of Jan 1, 2025.

Claims (1):

  • Texas's universal opt-out mechanism (UOOM) recognition requirement under TDPSA took effect January 1, 2025.

Data PortabilityAmber

A portability right is expected by structural analogy to the Virginia model that underpins TDPSA; not independently confirmed against primary text in this run.

Absence provenance: unavailable. Searched: unavailable.

Claims (1):

  • TDPSA is understood to include a data-portability right consistent with the Virginia consumer-privacy framework that forms its structural foundation.

Deadlines And Response WindowsAmber

A 45-day response window (extendable by 45 days), typical of Virginia-model laws, is inferred but not independently verified against TDPSA's primary text in this run.

Claims (1):

  • As a Virginia-model comprehensive privacy law, TDPSA is understood to require controllers to respond to consumer-rights requests within 45 days, extendable once by a further 45 days.
Category narrative43 words

TDPSA grants confirmation, access, correction, and deletion rights, plus a universal opt-out mechanism (UOOM) obligation effective January 1, 2025. Portability and precise response-window deadlines are structurally expected given TDPSA's Virginia-model lineage but were not independently confirmed against primary statutory text in this run.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedDataGuidance (OneTrust) — TDPSA grants consumers the right to confirm whether a business is processing their personal data and to access that personal data.observed
  2. ConfirmedDataGuidance (OneTrust) — TDPSA grants consumers rights to correct inaccuracies in their personal data and to request deletion of personal data provided by or obtained about the consumer.observed
  3. ConfirmedInternational Association of Privacy Professionals — Texas's universal opt-out mechanism (UOOM) recognition requirement under TDPSA took effect January 1, 2025.observed
  4. ProbableInternational Association of Privacy Professionals — TDPSA is understood to include a data-portability right consistent with the Virginia consumer-privacy framework that forms its structural foundation.observed
  5. ProbableInternational Association of Privacy Professionals — As a Virginia-model comprehensive privacy law, TDPSA is understood to require controllers to respond to consumer-rights requests within 45 days, extendable once by a further 45 days.observed

#

Breach notification and DPIA-style assessment duties are Confirmed and materially significant; DPO, ROPA, joint-controller, and retention-limitation provisions are either absent or unconfirmed, warranting an amber rating.

Primary frameworkTexas Data Privacy and Security Act (TDPSA) + Texas Identity Theft Enforcement and Protection Act (TITEPA)
Traffic-light rationale — AmberBreach notification and DPIA-style assessment duties are Confirmed and materially significant; DPO, ROPA, joint-controller, and retention-limitation provisions are either absent or unconfirmed, warranting an amber rating.

Sub-modules (7)

Accountability And DpiaGreen

TDPSA requires data-protection (risk) assessments in specified circumstances.

Claims (1):

  • TDPSA requires organizations to conduct data-protection (risk) assessments in specified circumstances to identify potential vulnerabilities and ensure compliance.

Dpo RequirementsRed

No TDPSA provision mandating appointment of a designated Data Protection Officer was identified.

Absence provenance: unavailable. Searched: unavailable.

Ropa RequirementsRed

No explicit records-of-processing-activities (ROPA) duty distinct from the data-protection-assessment obligation was identified.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

No TDPSA-specific joint-controller regime was identified.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresAmber

Comprehensive US state privacy laws generally require data minimization, purpose limitation, and reasonable security; TDPSA's specific security-measures text was not independently isolated in this run.

Claims (1):

  • As with other comprehensive state privacy laws, TDPSA-era obligations are generally understood to encompass data minimization, purpose limitation, and reasonable security safeguards for personal-data processing.

Breach NotificationGreen

TITEPA, as amended by HB 4390, requires disclosure without unreasonable delay and not later than 60 days after breach determination, plus AG notification with defined content for breaches affecting ≥250 Texas residents.

Claims (2):

  • HB 4390 requires breach disclosure without unreasonable delay and not later than the 60th day after the date a person determines a breach occurred, replacing the prior 'quickly as possible' TITEPA standard.
  • HB 4390 requires disclosure of breach details (nature/circumstances, number of Texas residents affected, remedial measures taken and planned, and law-enforcement involvement) to the Texas Attorney General for breaches affecting at least 250 Texas residents.

Retention And DisposalRed

No TDPSA-specific data-retention or disposal duty distinct from the general accountability principle was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative66 words

TDPSA mandates data-protection (risk) assessments in specified high-risk circumstances. TITEPA, as amended by HB 4390, sets a 60-day breach-disclosure deadline and AG-notification duties for breaches affecting ≥250 Texas residents. No DPO-appointment mandate, no explicit ROPA duty, and no distinct joint-controller regime were identified for TDPSA in this run; general data-minimization/security duties are inferred by comparison to peer state laws rather than confirmed against TDPSA primary text.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ConfirmedDataGuidance (OneTrust) — TDPSA requires organizations to conduct data-protection (risk) assessments in specified circumstances to identify potential vulnerabilities and ensure compliance.observed
  2. ProbableInternational Association of Privacy Professionals — As with other comprehensive state privacy laws, TDPSA-era obligations are generally understood to encompass data minimization, purpose limitation, and reasonable security safeguards for personal-data processing.observed
  3. ConfirmedInternational Association of Privacy Professionals — HB 4390 requires breach disclosure without unreasonable delay and not later than the 60th day after the date a person determines a breach occurred, replacing the prior 'quickly as possible' TITEPA standard.observed
  4. ConfirmedInternational Association of Privacy Professionals — HB 4390 requires disclosure of breach details (nature/circumstances, number of Texas residents affected, remedial measures taken and planned, and law-enforcement involvement) to the Texas Attorney General for breaches affecting at least 250 Texas residents.observed

#

No comprehensive cross-border transfer/adequacy framework exists under TDPSA or any other reviewed Texas instrument.

Traffic-light rationale — Not assessedNo comprehensive cross-border transfer/adequacy framework exists under TDPSA or any other reviewed Texas instrument.

Sub-modules (6)

Transfer MechanismsRed

No TDPSA-specific transfer mechanism identified.

Absence provenance: unavailable. Searched: unavailable.

Adequacy ReceivedRed

Not applicable — Texas/US has no adequacy-receipt framework analogous to GDPR Art. 45.

Absence provenance: unavailable. Searched: unavailable.

Adequacy GrantedRed

Not applicable — Texas does not grant adequacy determinations to other regimes.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsRed

No SCC/BCR-equivalent uptake regime identified under TDPSA.

Absence provenance: unavailable. Searched: unavailable.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement identified under TDPSA.

Absence provenance: unavailable. Searched: unavailable.

Data LocalisationRed

No data-localisation mandate identified for Texas.

Absence provenance: unavailable. Searched: unavailable.

Category narrative55 words

TDPSA does not establish a GDPR-style cross-border transfer, adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime. As with other US state comprehensive privacy laws, cross-border personal-data flows are addressed only indirectly, if at all, through vendor/processor contractual clauses rather than a dedicated statutory transfer mechanism. This is a genuine regulatory gap rather than an omission of research.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

#

Financial, health, credit, education, and employment carve-outs are Confirmed; telecoms/ePrivacy and insurance-sector overlays are absent from the evidence gathered.

Primary frameworkTDPSA sectoral exemptions cross-referencing federal GLBA/HIPAA/FCRA/FERPA
Traffic-light rationale — AmberFinancial, health, credit, education, and employment carve-outs are Confirmed; telecoms/ePrivacy and insurance-sector overlays are absent from the evidence gathered.

Sub-modules (7)

Financial Sector OverlayGreen

TDPSA exempts GLBA-covered financial institutions and GLBA-regulated data.

Claims (1):

  • TDPSA exempts financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA).

Health Sector OverlayGreen

TDPSA exempts HIPAA covered entities/business associates and HIPAA-regulated data.

Claims (1):

  • TDPSA exempts covered entities and business associates subject to HIPAA, and data regulated under HIPAA.

Telecoms And EprivacyRed

No Texas-specific telecoms/ePrivacy DP overlay identified.

Absence provenance: unavailable. Searched: unavailable.

Employment DataAmber

TDPSA excludes data processed solely in the employment context from covered personal data.

Claims (1):

  • TDPSA excludes data processed solely in the employment context from its scope of covered personal data.

Credit And ScoringGreen

TDPSA exempts FCRA-regulated data.

Claims (1):

  • TDPSA exempts data subject to the Fair Credit Reporting Act (FCRA).

EducationGreen

TDPSA exempts higher-education institutions and FERPA-regulated data.

Claims (1):

  • TDPSA exempts institutions of higher education and data subject to the Family Educational Rights and Privacy Act (FERPA).

InsuranceRed

No Texas-specific insurance-sector DP overlay identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative55 words

TDPSA carves out broad sectoral exemptions rather than layering additional obligations: financial institutions/data under GLBA, HIPAA covered entities/business associates and HIPAA-regulated data, FCRA-regulated data, higher-education institutions and FERPA-regulated data, and data processed solely in the employment context are all excluded from TDPSA's scope. No Texas-specific telecoms/ePrivacy or insurance-sector DP overlay was identified in this run.

Periodic update · new data 2026-09-22

Sectoral Watch

Texas's financial-sector data-protection overlay tightened this cycle with the confirmation that Finance Code §160.004(c), as amended by HB 4233 and effective September 1, 2025, requires digital asset service providers holding custody of stablecoins or other digital assets to allow each customer to view, at least quarterly, an accounting of outstanding liabilities and digital assets held in custody. This is a confirmed development sourced directly to primary legislative text, and it functions as a sector-specific transparency duty layered onto the general custodial relationship between a digital-asset service provider and its Texas customers, distinct from the TDPSA's general consumer-privacy framework.

This sectoral development sits alongside, but is analytically distinct from, the crypto monitor's coverage of the same statutory amendment under its stablecoin_regime module, where the emphasis is on money-transmission and custody classification rather than the data-protection reading of customer-facing transparency obligations. Within the data-protection frame, the quarterly-accounting requirement is best read as a sector-specific data-access right functioning in parallel to, rather than displacing, any TDPSA-level consumer rights that might separately apply to a covered entity's processing of personal data in connection with digital-asset custody.

Outlook

No further financial-sector data-protection developments were identified this cycle beyond the HB 4233 amendment itself. The next cycle should watch for any Texas Department of Banking guidance clarifying how the quarterly-accounting disclosure format should be delivered to customers, and whether that guidance intersects with TDPSA-level data-subject-access-request mechanics for entities that qualify as controllers under the general statute.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ConfirmedDataGuidance (OneTrust) — TDPSA exempts financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA).observed
  2. ConfirmedDataGuidance (OneTrust) — TDPSA exempts covered entities and business associates subject to HIPAA, and data regulated under HIPAA.observed
  3. ConfirmedDataGuidance (OneTrust) — TDPSA excludes data processed solely in the employment context from its scope of covered personal data.observed
  4. ConfirmedDataGuidance (OneTrust) — TDPSA exempts data subject to the Fair Credit Reporting Act (FCRA).observed
  5. ConfirmedDataGuidance (OneTrust) — TDPSA exempts institutions of higher education and data subject to the Family Educational Rights and Privacy Act (FERPA).observed

#

UOOM, dark-patterns, and targeted-advertising opt-out are Confirmed; cookie-specific, direct-marketing, and clean-room provisions are absent from the evidence gathered.

Primary frameworkTexas Data Privacy and Security Act (TDPSA)
Traffic-light rationale — AmberUOOM, dark-patterns, and targeted-advertising opt-out are Confirmed; cookie-specific, direct-marketing, and clean-room provisions are absent from the evidence gathered.

Sub-modules (6)

Cookies And TrackersRed

No Texas-specific cookie/tracker consent rule distinct from general TDPSA opt-out rights was identified.

Absence provenance: unavailable. Searched: unavailable.

Dark PatternsAmber

TDPSA addresses dark patterns in the context of consent validity.

Claims (1):

  • TDPSA includes provisions addressing 'dark patterns' in connection with obtaining valid consumer consent.

Opt Out SignalsGreen

Texas requires recognition of universal opt-out mechanisms (UOOM) effective Jan 1, 2025.

Claims (1):

  • Texas is among the states where universal opt-out mechanism (UOOM) requirements are already in effect, with Texas's obligation taking effect January 1, 2025.

Clean Rooms And DcrRed

No Texas-specific clean-room/data-collaboration-room rule identified.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingGreen

TDPSA grants an opt-out right for targeted advertising and sale of personal data.

Claims (1):

  • TDPSA grants consumers the right to opt out of the processing of personal data for purposes of targeted advertising and the sale of personal data.

Direct MarketingRed

No Texas-specific direct-marketing suppression duty distinct from the general opt-out right was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative46 words

TDPSA requires recognition of universal opt-out mechanisms (effective Jan 1, 2025), includes dark-patterns provisions affecting the validity of consent, and grants opt-out rights for targeted advertising and sale of personal data. Cookie/tracker-specific rules, direct-marketing suppression duties, and clean-room/data-collaboration provisions were not independently confirmed in this run.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy Professionals — TDPSA includes provisions addressing 'dark patterns' in connection with obtaining valid consumer consent.observed
  2. ConfirmedInternational Association of Privacy Professionals — Texas is among the states where universal opt-out mechanism (UOOM) requirements are already in effect, with Texas's obligation taking effect January 1, 2025.observed
  3. ConfirmedInternational Association of Privacy Professionals — TDPSA grants consumers the right to opt out of the processing of personal data for purposes of targeted advertising and the sale of personal data.observed

#

TRAIGA and CUBI are robust, Confirmed frameworks; profiling-restriction language and genetic-data regulation are unconfirmed/absent.

Primary frameworkTexas Responsible Artificial Intelligence Governance Act (TRAIGA) + Capture or Use of Biometric Identifier Act (CUBI)
Traffic-light rationale — AmberTRAIGA and CUBI are robust, Confirmed frameworks; profiling-restriction language and genetic-data regulation are unconfirmed/absent.

Sub-modules (6)

Profiling RestrictionsAmber

TDPSA is understood to include an opt-out right against profiling producing legal or similarly significant effects, consistent with its Virginia-model foundation; not independently confirmed against primary text.

Claims (1):

  • TDPSA is understood to grant consumers an opt-out right against profiling in furtherance of decisions producing legal or similarly significant effects, consistent with its Virginia-model foundation.

Automated Decision Making TransparencyGreen

TRAIGA imposes state-agency disclosure duties when citizens interact with agency AI tools and prohibits manipulative/discriminatory AI design.

Claims (1):

  • TRAIGA imposes disclosure requirements for state agencies when citizens interact with AI tools the agency uses, bans capturing biometric identifiers without consent, and prohibits AI developers from creating systems designed to manipulate human behavior, make discriminatory decisions, or produce deepfakes exploiting children.

Ai Risk AssessmentsGreen

TRAIGA enforcement is AG-exclusive with substantial per-violation fines after a 60-day cure period.

Claims (1):

  • TRAIGA is enforced exclusively by the Texas Attorney General, who may assess administrative fines of not less than USD80,000 and not more than USD200,000 per violation if a covered entity fails to cure within 60 days, and the statute provides no private right of action.

Biometric RegimeGreen

CUBI's informed-consent regime for biometric identifiers underpinned a $1.4B AG settlement with Meta.

Claims (1):

  • The Texas Attorney General secured a $1.4 billion settlement with Meta Platforms Inc. over unauthorized capture and use of Texans' biometric data under CUBI.

Genetic DataRed

No enacted Texas genetic-data-specific statute was confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsAmber

TDPSA exempts government agencies from its scope.

Claims (1):

  • TDPSA includes exemptions for government agencies, carving state and local government processing out of its general obligations.
Category narrative77 words

TRAIGA (effective Jan 1, 2026) prohibits AI systems designed to manipulate human behavior, make discriminatory decisions, or produce child-exploitative deepfakes, and imposes state-agency AI-disclosure duties; enforcement is AG-exclusive with $80,000–$200,000 per-violation fines after a 60-day cure period and no private right of action. CUBI separately governs biometric-identifier capture/consent and underpinned a $1.4B Meta settlement. No enacted Texas genetic-data-specific statute was confirmed (a 2023 bill, SB 704, was introduced but its enactment was not confirmed in this run).

Periodic update · new data 2026-09-28

Algorithmic, Biometric & Surveillance Governance

Texas's Capture or Use of Biometric Identifier Act, the state's dedicated biometric-privacy statute, was amended effective January 1, 2026 in a manner that materially tightens its interaction with artificial-intelligence systems and publicly available imagery. The amendment adds a statutory definition of "artificial intelligence system" to the Act, and, separately, clarifies that the mere public availability of an image or other media does not, by itself, establish the notice and consent that CUBI requires before a biometric identifier may be captured or stored for a commercial purpose. This second element is analytically significant because it forecloses an argument, which had circulated in the practitioner community, that scraping publicly posted images or video for biometric or AI-training purposes might not require separate notice and consent simply because the underlying media was already public.

The underlying CUBI framework itself, which this amendment builds upon rather than replaces, prohibits capturing a biometric identifier for a commercial purpose absent notice and consent, requires destruction of the captured identifier within a reasonable time and no later than one year after the purpose for collection has expired, and carries civil penalties of up to $25,000 per violation. Enforcement sits exclusively with the Texas Attorney General; CUBI does not create a private right of action, a structural feature that channels all enforcement risk through a single public authority rather than exposing regulated entities to a wider universe of private litigants.

The practical effect of the January 2026 amendment is to bring CUBI's application more explicitly into contact with contemporary AI-development practices, particularly the training of facial-recognition, biometric-matching, or generative systems on datasets that include publicly available images. Any entity engaged in Texas in the collection, use, or training of AI systems against biometric identifiers drawn even in part from publicly available sources should now treat CUBI's notice-and-consent requirement as squarely applicable, rather than assuming that public availability provides an independent basis for avoiding the statute's reach. This is a Confirmed finding drawn directly from the amended statutory text itself, retrieved from the Texas Statutes site, and represents one of the more concrete state-level examples of a biometric-privacy statute being explicitly extended to address AI-training-data practices.

No enforcement action specifically invoking the amended AI-related provisions has been identified this cycle; the amendment took effect only in January 2026, and any enforcement pipeline reflecting it would be expected to develop over a longer horizon than a single cycle allows for observation.

Outlook

Entities operating AI systems that touch biometric identifiers in Texas, including those trained in part on publicly available imagery, should treat the amended CUBI notice-and-consent requirement as a live compliance consideration going forward. Given CUBI's exclusive Attorney General enforcement structure and its civil-penalty exposure of up to $25,000 per violation, the practical risk profile is concentrated in the state's own enforcement priorities rather than private litigation; no indication of a specific enforcement initiative targeting the amended AI-related provisions has surfaced this cycle, and that remains an area to watch going forward.

1 earlier distinct update(s)
Periodic update · new data 2026-09-22

Algorithmic, Biometric & Surveillance Governance

Texas's algorithmic-governance framework escalated materially this cycle with the coming into force of the Texas Responsible Artificial Intelligence Governance Act (TRAIGA) on January 1, 2026. TRAIGA establishes an intent-based liability regime, meaning liability attaches to AI systems developed or deployed for identified prohibited purposes rather than to the mere presence of an AI system in a given use case. The prohibited purposes named in the statute, confirmed directly from the Texas Attorney General's own official guidance, include behavioral manipulation, unlawful discrimination, the production of deepfakes and child-exploitation material, and infringement of constitutional rights.

Enforcement architecture under TRAIGA vests exclusive authority with the Texas Attorney General, precludes private rights of action entirely, and authorizes civil penalties reaching up to $200,000 per uncurable violation, with a 60-day cure period preceding any penalty for a curable violation. This enforcement structure is corroborated by independent law-firm analysis alongside the Attorney General's own materials, and the overall confidence in both TRAIGA's substantive prohibitions and its enforcement mechanics is held at the Confirmed tier.

Alongside TRAIGA, the Texas Attorney General's data privacy team is confirmed to enforce the Texas Biometric Identifier Act in parallel with the TDPSA, the Identity Theft Enforcement and Protection Act, the Data Broker Law, and the Deceptive Trade Practices Act, indicating that biometric processing in Texas sits within a coordinated multi-statute enforcement net rather than a single dedicated biometric law operating in isolation.

Outlook

TRAIGA is newly in force as of January 1, 2026, and no first enforcement action under its intent-based liability standard has yet been reported, so the practical boundaries of what counts as behavioral manipulation or unlawful discrimination for liability purposes remain untested. The next cycle should watch for the Attorney General's first TRAIGA enforcement action or civil investigative demand, which would materially clarify how the intent standard is applied in practice.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. ProbableInternational Association of Privacy Professionals — TDPSA is understood to grant consumers an opt-out right against profiling in furtherance of decisions producing legal or similarly significant effects, consistent with its Virginia-model foundation.observed
  2. ConfirmedInternational Association of Privacy Professionals — TRAIGA imposes disclosure requirements for state agencies when citizens interact with AI tools the agency uses, bans capturing biometric identifiers without consent, and prohibits AI developers from creating systems designed to manipulate human behavior, make discriminatory decisions, or produce deepfakes exploiting children.observed
  3. ConfirmedInternational Association of Privacy Professionals — TRAIGA is enforced exclusively by the Texas Attorney General, who may assess administrative fines of not less than USD80,000 and not more than USD200,000 per violation if a covered entity fails to cure within 60 days, and the statute provides no private right of action.observed
  4. ConfirmedDataGuidance (OneTrust) — The Texas Attorney General secured a $1.4 billion settlement with Meta Platforms Inc. over unauthorized capture and use of Texans' biometric data under CUBI.observed
  5. ConfirmedDataGuidance (OneTrust) — TDPSA includes exemptions for government agencies, carving state and local government processing out of its general obligations.observed

#

Multiple enacted statutes and active AG enforcement are Confirmed, but significant portions of the regime (SCOPE Act, App Store Accountability Act) are currently enjoined and subject to ongoing appellate litigation, materially affecting operative status.

Primary frameworkHB 18 (SCOPE Act) + HB 1181 (age verification) + SB 2420 (App Store Accountability Act)
Traffic-light rationale — AmberMultiple enacted statutes and active AG enforcement are Confirmed, but significant portions of the regime (SCOPE Act, App Store Accountability Act) are currently enjoined and subject to ongoing appellate litigation, materially affecting operative status.

Sub-modules (5)

Age VerificationGreen

HB 1181 mandates robust age verification for adult-content websites and was upheld by SCOTUS; steep penalties apply.

Claims (2):

  • Texas HB 1181 mandates that websites with at least one-third content deemed sexual material harmful to minors implement robust age-verification systems, often requiring government-issued identification, third-party verification, or biometric data; the law was upheld by the U.S. Supreme Court in Free Speech Coalition v. Paxton (June 27, 2025).
  • Texas HB 1181 imposes fines of up to USD10,000 per day plus USD250,000 per instance of minor access for noncompliance with its age-verification mandate.

Minor Profiling BansAmber

SCOPE Act imposes algorithm-transparency duties toward minors but portions remain partially enjoined pending Fifth Circuit review.

Claims (1):

  • Texas HB 18 (SCOPE Act) imposes duties on digital service providers regarding minors, including making algorithm code available to independent security researchers, but portions of HB 18 remain partially enjoined pending Fifth Circuit review.

Education SettingsRed

No education-setting-specific minors DP provision beyond general FERPA exemption was independently confirmed in this run.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No Texas-specific dependent-adults (elderly/incapacitated) data-protection provision was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative88 words

Texas maintains overlapping minors-protection statutes: HB 1181 (age-verification for adult content, upheld by SCOTUS in Free Speech Coalition v. Paxton, June 27, 2025) with steep per-day/per-access penalties; HB 18 (SCOPE Act) imposing digital-service-provider duties toward minors, portions of which remain partially enjoined pending Fifth Circuit review; SB 2420 (App Store Accountability Act) requiring age verification/categorization by app stores, currently preliminarily enjoined and on appeal; and active AG enforcement (e.g., against Snap) under the Securing Children Online Through Parental Empowerment Act. No Texas-specific dependent-adults (elderly/incapacitated) DP provision was identified.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

Texas's App Store Accountability Act, enacted as Senate Bill 2420, became enforceable on June 4, 2026 after the Fifth Circuit Court of Appeals stayed a federal district-court preliminary injunction that had previously blocked its enforcement. The statute imposes two closely related obligations on app-store operators: first, a requirement to verify user age at account creation and sort users into four defined bands, under 13, 13 to 15, 16 to 17, and 18 and over; and second, a requirement that a minor's app-store account be linked to a verified parent or guardian, whose consent is required before the minor may download an app or make an in-app purchase.

The critical qualifier attached to both obligations is that the statute's constitutional validity remains actively and materially contested. A challenge, CCIA v. Paxton, is pending before the same Fifth Circuit that stayed the district court's injunction, meaning the Act is currently enforceable as a matter of practical effect while its underlying constitutionality has not been finally resolved. This live-litigation status should be carried forward as a qualifier on every operational statement about the Act rather than treated as a settled matter; reports suggest the Act may ultimately be narrowed or struck depending on the outcome of that appeal, and it would be inaccurate to characterize the current enforceability as equivalent to final constitutional validation.

For app-store operators and app developers with a Texas user base, the practical compliance posture required by the current, enforceable state of the law involves building or adapting age-verification flows capable of sorting users into the four statutory bands, and building parental-linkage and consent mechanisms for the two under-18 bands specifically. This is a materially more granular age-tiering requirement than a simple binary adult/minor distinction, and the four-band structure appears designed to allow differentiated treatment of app types or content categories by age cohort, though the statute's own text was not independently retrieved this cycle beyond the age-verification and parental-consent elements confirmed via secondary reporting.

Both of the specific obligations described here are sourced to Tier 4 secondary reporting rather than the statute's own text or a primary court filing; while the overall claim is held at Confirmed confidence reflecting the currency and specificity of the reporting, a subsequent cycle should prioritize direct retrieval of the enacted statutory text and the Fifth Circuit's stay order to place these findings on firmer primary-source footing.

Outlook

The Fifth Circuit's eventual ruling on the constitutional merits in CCIA v. Paxton, expected as scheduled around the fourth quarter of 2026, is the central event to watch for this module; the outcome could uphold the Act in its current form, narrow its application, or strike it as unconstitutional notwithstanding its present enforceability. Until that ruling issues, app-store operators should treat the age-verification and parental-consent obligations as currently binding and enforceable in Texas, while recognizing that the underlying legal foundation remains unsettled.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy Professionals — Texas HB 1181 mandates that websites with at least one-third content deemed sexual material harmful to minors implement robust age-verification systems, often requiring government-issued identification, third-party verification, or biometric data; the law was upheld by the U.S. Supreme Court in Free Speech Coalition v. Paxton (June 27, 2025).observed
  2. ConfirmedInternational Association of Privacy Professionals — Texas HB 1181 imposes fines of up to USD10,000 per day plus USD250,000 per instance of minor access for noncompliance with its age-verification mandate.observed
  3. ConfirmedInternational Association of Privacy Professionals — The Texas Attorney General has brought enforcement action against Snap alleging violation of the Securing Children Online Through Parental Empowerment Act by collecting and sharing minors' personal information with third parties without required safeguards.observed
  4. ProbableInternational Association of Privacy Professionals — Texas HB 18 (SCOPE Act) imposes duties on digital service providers regarding minors, including making algorithm code available to independent security researchers, but portions of HB 18 remain partially enjoined pending Fifth Circuit review.observed

#

AG powers, penalty caps, and a substantial, escalating enforcement record are all Confirmed with specific, recent examples.

Primary frameworkTexas Data Privacy and Security Act (TDPSA) + Texas Deceptive Trade Practices Act (DTPA)
Traffic-light rationale — GreenAG powers, penalty caps, and a substantial, escalating enforcement record are all Confirmed with specific, recent examples.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

TDPSA caps penalties at $7,500 per violation with a 30-day cure period; TRAIGA imposes $80,000-$200,000 per-violation fines.

Claims (1):

  • TDPSA violations are subject to civil penalties of up to $7,500 per violation, enforced exclusively by the Texas Attorney General, with a 30-day statutory cure period before penalties attach.

Enforcement Activity IndexGreen

Recent, substantial AG enforcement includes the $1.4B Meta CUBI settlement and December 2025 ACR-technology lawsuits against five smart-TV manufacturers.

Claims (2):

  • In December 2025, the Texas Attorney General filed lawsuits against five smart-TV manufacturers (Sony, Samsung, LG, Hisense, and TCL) over automated content recognition technology allegedly used to unlawfully collect and monetize consumers' viewing data, obtaining temporary restraining orders against Hisense and Samsung.
  • The Texas Attorney General secured a $1.4 billion settlement with Meta Platforms Inc. in July 2024 over unauthorized biometric-data capture under CUBI.

Regulator Funding And CapacityRed

No specific funding/headcount data for the OAG Consumer Protection Division's privacy enforcement function was identified.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsAmber

TDPSA itself bars private action, but the Texas DTPA offers a separate, general consumer-protection avenue the AG also uses as a catch-all.

Claims (1):

  • The Texas Attorney General has invoked the general Texas Deceptive Trade Practices Act (DTPA) catch-all provision in privacy-adjacent enforcement, such as its suit against General Motors over data-sharing practices.

Private Right Of ActionGreen

TDPSA does not grant individuals a private right of action.

Claims (1):

  • TDPSA does not grant individuals a private right of action; enforcement is reserved to the Texas Attorney General.

Recent Developments 180DGreen

TRAIGA's Jan 1, 2026 entry into force and the AG's continuing enforcement crackdown (ACR lawsuits, Dec 2025) represent the most recent material developments.

Claims (1):

  • TRAIGA entered into force January 1, 2026, and the Texas Attorney General has continued a broad privacy-enforcement crackdown into 2026, including the December 2025 ACR lawsuits against smart-TV manufacturers.
Category narrative94 words

TDPSA vests exclusive enforcement in the Texas AG, capped at $7,500 per violation with a 30-day cure period, and creates no private right of action; TRAIGA similarly is AG-exclusive with much larger per-violation fines. Enforcement activity has intensified through 2025–2026, including the $1.4B CUBI settlement with Meta (2024) and a December 2025 wave of ACR-technology lawsuits against smart-TV manufacturers with temporary restraining orders against two defendants. Separately, consumers retain access to the general Texas Deceptive Trade Practices Act (DTPA), which the AG has invoked as a catch-all in privacy-adjacent suits (e.g., against General Motors).

Periodic update · new data 2026-09-22

Enforcement & Redress

Texas's enforcement posture escalated further this cycle on the strength of confirmed, landmark settlement precedent. The Texas Attorney General's Data Privacy and Security Initiative is understood to have investigated more than 200 companies since June 2024, and this cycle confirms that the Initiative secured a $1.4 billion settlement with Meta in 2024 over biometric-data violations and a $1.375 billion settlement with Google in 2025 over location-tracking data practices, together described as the two largest single-state privacy settlements in United States history. These figures are corroborated by an industry-tracking source and are widely reported, supporting a Confirmed confidence tier for the settlement facts themselves.

This enforcement activity operates against the backdrop of the TDPSA's general enforcement architecture, under which the Texas Attorney General holds exclusive authority to enforce the statute and may issue civil investigative demands and file enforcement actions, subject to a mandatory 30-day written notice-and-cure period before any enforcement action may be filed. On penalties specifically, reporting indicates that TDPSA civil penalties for confirmed violations may reach up to $7,500 per violation, though this figure traces to a compliance-guide source rather than independently verified statutory text, and is accordingly held at Probable rather than Confirmed confidence.

Outlook

The scale of the Meta and Google settlements signals that Texas enforcement risk is not confined to smaller compliance gaps but extends to structural, high-value data-practice disputes with the largest technology companies. The next cycle should watch for confirmation of the $7,500-per-violation TDPSA penalty figure against primary statutory text, and for any new enforcement actions building on the Data Privacy and Security Initiative's investigative pipeline of 200-plus companies.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedDataGuidance (OneTrust) — TDPSA violations are subject to civil penalties of up to $7,500 per violation, enforced exclusively by the Texas Attorney General, with a 30-day statutory cure period before penalties attach.observed
  2. ConfirmedInternational Association of Privacy Professionals — In December 2025, the Texas Attorney General filed lawsuits against five smart-TV manufacturers (Sony, Samsung, LG, Hisense, and TCL) over automated content recognition technology allegedly used to unlawfully collect and monetize consumers' viewing data, obtaining temporary restraining orders against Hisense and Samsung.observed
  3. ConfirmedDataGuidance (OneTrust) — The Texas Attorney General secured a $1.4 billion settlement with Meta Platforms Inc. in July 2024 over unauthorized biometric-data capture under CUBI.observed
  4. ConfirmedInternational Association of Privacy Professionals — The Texas Attorney General has invoked the general Texas Deceptive Trade Practices Act (DTPA) catch-all provision in privacy-adjacent enforcement, such as its suit against General Motors over data-sharing practices.observed
  5. ConfirmedDataGuidance (OneTrust) — TDPSA does not grant individuals a private right of action; enforcement is reserved to the Texas Attorney General.observed
  6. ConfirmedInternational Association of Privacy Professionals — TRAIGA entered into force January 1, 2026, and the Texas Attorney General has continued a broad privacy-enforcement crackdown into 2026, including the December 2025 ACR lawsuits against smart-TV manufacturers.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct14.29
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Texas, USA
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 45 claim(s) (45 category placement(s)), 31 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data, controller_processor_duties (breach_notification sub-module), algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups (age_verification) rest on a mix of T1 primary-statute anchors (CUBI text via FTC citation, SB 2105 data-broker statute text) and dense T2 secondary reporting (IAPP, DataGuidance) describing enacted, in-force law. data_subject_rights (portability, deadlines) and controller_processor_duties (security_measures, DPO, ROPA, joint-controller, retention) rely on T3/T4-equivalent inference from the TDPSA's stated Virginia-model lineage rather than directly retrieved primary statutory text, and are flagged Probable/absent accordingly. cross_border_and_adequacy is a fully documented true gap (red, empty claims) consistent with the US state-privacy-law pattern of omitting GDPR-style transfer/adequacy regimes. sectoral_watch and adtech_and_commercial_privacy are partially populated, with insurance, telecoms/ePrivacy, cookie-specific, direct-marketing, and clean-room sub-modules carrying explicit absent_field_provenance.

Unresolved questions (5):

  • Exact original effective date of the pre-HB4390 TITEPA breach-notification baseline and of HB 1181's age-verification mandate were not independently pinned to a specific ISO date in this run.
  • Whether TDPSA's response-window (45+45 day) and data-portability provisions match the Virginia-model default exactly, or contain Texas-specific deviations, was not confirmed against primary statutory text.
  • Current enactment status of SB 704 (biometric/genetic data bill, introduced 2023) — no confirmation of passage or failure was retrieved.
  • Final Fifth Circuit disposition of the partially enjoined HB 18 (SCOPE Act) provisions and the preliminarily enjoined SB 2420 (App Store Accountability Act) remain pending and will change the operative scope of the children_and_vulnerable_groups module.
  • Whether TDPSA imposes a standalone ROPA or DPO-appointment duty (as opposed to only a DPIA-style risk assessment) was not confirmed either way with authoritative primary text.

Escalate to primary-source review: yes