Texas Data Privacy Act
Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Accountability
Per TDPSA: DPIA + Universal Opt-Out Mechanism + processor agreements.
- TDPSA evidence for TEXASTDPSA-5
- UOOM + sale notice + appeal partial
Assessments and Profiling
Profiling in furtherance of decisions that produce legal or similarly significant effects (e.g., financial, housing, employment, healthcare, insurance, education) triggers opt-out rights and mandatory DPIA.
- Inventory of automated decision systems
- DPIA per profiling use case
- Opt-out mechanism specifically for profiling
- Human review fallback procedure
- Profiling for credit/insurance without DPIA
- No separate profiling opt-out (bundled with sale)
Controllers must conduct and document data protection assessments for: targeted advertising, sale of personal data, profiling with foreseeable risk of unfair/deceptive treatment, processing sensitive data, and any processing presenting a heightened risk of harm. Assessments are confidential and subject to AG request.
- DPIA register listing all triggering processing activities
- DPIA template covering benefits/risks, mitigations, consumer expectations
- Approval sign-off by privacy officer or legal
- Refresh cadence (material change, periodic review)
- No DPIA for ad-tech or profiling activities
- Template misses consumer expectation analysis
- DPIAs not refreshed when processing changes
The Texas Responsible AI Governance Act (TRAIGA, effective Jan 2026) interacts with TDPSA profiling and sensitive data provisions. Controllers using AI for consequential decisions must align TDPSA DPIAs with TRAIGA impact assessments and disclosure requirements.
- AI inventory mapped to TDPSA profiling and TRAIGA consequential decisions
- Combined DPIA + AI impact assessment
- AI disclosure to consumers (TRAIGA § 552.054)
- Bias and disparate impact testing
- TDPSA DPIA does not address algorithmic decisioning detail required by TRAIGA
- No AI inventory linked to privacy records
Consumer Rights
Controllers must establish an internal appeal process if a consumer request is refused. Appeals must be decided within 60 days with a written explanation. If the appeal is denied, the controller must inform the consumer of the ability to contact the Texas AG.
- Documented appeal workflow
- Appeal decision letter template referencing Texas AG complaint route
- Appeal log with outcomes and rationale
- Annual appeals metrics review
- No appeal mechanism at all
- Appeal denial letter omits Texas AG contact information
- Appeals handled by the same person who denied the original request
Consumers have the right to confirm whether a controller is processing their personal data and to access that personal data.
- DSAR intake form (web, email, toll-free for sensitive data sellers)
- Identity verification procedure
- Access request fulfillment log
- Response templates and data export format (portable, machine-readable)
- No identity verification step
- Response delivered in non-portable format
- Missing log of requests received and outcomes
Consumers may correct inaccuracies in their personal data, taking into account the nature of the data and the purposes of processing.
- Correction request workflow and ticketing
- Source-of-truth documentation for corrected fields
- Downstream propagation evidence (processors, integrations notified)
- Reasonableness assessment for declined corrections
- Corrections not propagated to processors or third parties
- No documentation of why a correction was refused
Consumers may delete personal data provided by or obtained about the consumer.
- Deletion procedure covering primary, backup, archive, and processor systems
- Deletion confirmation log per request
- Documented exemptions used (legal hold, fraud prevention, etc.)
- Retention schedule referencing deletion triggers
- Backups not addressed in deletion procedure
- Processors not instructed to delete in parallel
- Exemptions claimed without documented basis
Controllers may not discriminate against a consumer for exercising any of the rights under TDPSA, including denying goods/services, charging different prices, or providing a different level of quality. Loyalty programs are not automatically discrimination.
- Loyalty program terms with bona fide value exchange documentation
- Internal policy prohibiting service degradation post-opt-out
- Audit of pricing/service tiers vs. opt-out status
- Loss of features after opt-out without disclosure that the feature relied on the processing
- No internal training on non-discrimination
Consumers may opt out of processing of personal data for purposes of targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
- Opt-out mechanism for targeted advertising (web form, link, GPC honored)
- Sale opt-out workflow with downstream signaling
- Profiling opt-out for legal/significant effects decisions
- Universal Opt-Out Mechanism (UOOM) acknowledgment plan (note: TDPSA does not yet mandate UOOM but Texas AG has signaled scrutiny)
- Single opt-out toggle that does not distinguish the three categories
- Opt-out not propagated to ad-tech partners
- GPC not honored where claimed in policy
Consumers may obtain a copy of personal data they previously provided, in a portable and, to the extent technically feasible, readily usable format that allows transmission to another controller.
- Portable export format specification (JSON, CSV)
- Sample export packet
- Technical feasibility documentation for non-supported formats
- Export provided only in PDF (not machine-readable)
- Trade-secret or proprietary inferences not separated
Controllers must respond to consumer requests without undue delay and within 45 days of receipt. The period may be extended once by an additional 45 days when reasonably necessary, with notice to the consumer of the extension and the reason.
- Ticketing system with SLA timers
- Extension notification templates and log
- Monthly SLA compliance report
- Process for free response (first two per year) and reasonable fee thereafter
- No automated SLA tracking
- Extensions taken silently without consumer notice
- Fees charged on first response without basis
Consumers may use an authorized agent (including by means of an internet link or browser setting) to opt out of targeted advertising or sale on the consumer's behalf. Controllers must comply where authority is reasonably verified.
- Authorized agent verification procedure
- Acceptance of browser-based opt-out signals (current commitment and roadmap)
- Logs of agent-submitted requests
- Consumer authorization forms
- No procedure to accept agent requests
- Verification burden placed solely on the agent without controller process
Controller Duties and Data Minimisation
If data is de-identified, the controller must take reasonable measures to ensure the data cannot be re-associated with an individual, publicly commit to processing it only in de-identified form, and contractually obligate recipients to comply with the same restrictions.
- De-identification methodology and threshold documentation
- Public commitment statement
- Contracts with downstream recipients requiring de-identification preservation
- Periodic re-identification risk assessment
- Claiming de-identification without re-identification risk testing
- No contractual flow-down to recipients
Controllers must limit collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes for which the data is processed. Processing beyond disclosed purposes requires consumer consent.
- Data inventory mapped to disclosed purposes
- Field-level necessity justification
- Secondary-use consent records where applicable
- Periodic minimization review
- Collection of fields not tied to a purpose
- Secondary use without re-consent
Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data, appropriate to the volume and nature of the personal data at issue.
- Written information security program (WISP)
- Risk assessments and remediation tracker
- Access control, encryption, logging evidence
- Vendor security reviews
- Mapping to a recognized framework (NIST CSF, ISO 27001, SOC 2)
- No documented WISP
- Encryption at rest missing for sensitive data stores
- No periodic risk assessment
Enforcement
The Texas Attorney General has exclusive enforcement authority. Before bringing an action, the AG must provide written notice of the alleged violation and a 30-day cure period. The cure period does not sunset. Civil penalties up to $7,500 per violation, plus injunctive relief and reasonable attorney's fees.
- AG notice intake and response playbook
- Cure tracking workflow with 30-day deadline
- Sworn written statement template (cured violation + no further violation)
- Penalty exposure register
- No playbook for receipt of AG notice
- Sworn statement not used to close the cure window
- No internal escalation path within 30 days
The Texas AG (through its Consumer Protection Division and Data Privacy and Security Initiative launched 2024) has issued enforcement sweeps targeting data brokers, ad-tech, biometric processors, and sensitive data sellers. High-profile settlements include Meta (biometric, $1.4B, 2024) and Google (biometric/location, $1.375B, 2025).
- Subscription to Texas AG press releases and enforcement bulletins
- Annual review of enforcement actions and lessons learned
- Gap analysis against settled matters (biometric, ad-tech, sensitive data sale notice)
- Data broker registration under Tex. Bus. & Com. Code Ch. 509 if applicable
- No monitoring of AG enforcement trends
- Data broker registration missed
- No gap remediation after high-profile settlements
Per TDPSA: Consumer Appeal Process + AG enforcement + 30-day cure + civil penalties.
- TDPSA evidence for TEXASTDPSA-6
- UOOM + sale notice + appeal partial
Notice
Per TDPSA: Privacy Notice Content Requirements.
- TDPSA evidence for TEXASTDPSA-4
- UOOM + sale notice + appeal partial
Privacy Notice and Disclosures
Controllers must provide a reasonably accessible and clear privacy notice that includes categories of personal data processed, purpose of processing, how consumers exercise rights and appeal, categories shared with third parties, categories of third parties, and a description of methods to submit requests.
- Public-facing privacy notice with all six required disclosure elements
- Versioning log of privacy notice changes
- Last-updated timestamp and effective date
- Accessibility review evidence (WCAG, plain language)
- Missing description of consumer appeal process
- No categories of third parties listed (only generic references)
- Outdated last-updated date
Controllers that sell sensitive personal data must post the exact notice: 'NOTICE: We may sell your sensitive personal data.' Controllers that sell biometric personal data must post: 'NOTICE: We may sell your biometric personal data.' Notices must be in the same location and manner as the privacy notice.
- Screenshot of website privacy notice showing exact statutory language
- Determination memo on whether entity sells sensitive or biometric data (broad definition of sale includes monetary or other valuable consideration)
- Placement evidence (same location and manner as privacy notice)
- Mobile and desktop rendering confirmation
- Paraphrased notice instead of exact statutory wording
- Notice buried in privacy policy rather than displayed in same location
- No determination of whether ad-tech disclosures constitute sale of sensitive data
Processors, Contracts and Downstream Disclosure
Controllers must have a contract with processors that governs the processing, including instructions, nature/purpose, type of data, duration, rights/obligations of both parties, confidentiality, deletion or return at end of provision, processor cooperation, audit rights, and subprocessor flow-down.
- Executed DPA with each processor including all eight required clauses
- Subprocessor list and flow-down evidence
- Audit reports or self-attestations from processors
- Deletion/return certificates at contract termination
- DPA lacks audit cooperation clause
- Subprocessors not flowed down
- No deletion certificate on contract end
Where personal data is sold or shared, the controller should bind recipients contractually to use limitations, security obligations, and downstream consumer rights honoring. This supports the TDPSA accountability and DPIA expectations.
- Standard sale/share contract addendum
- Recipient list with executed addendum status
- Use-limitation audit
- Opt-out propagation to recipients
- Sale partners onboarded without addendum
- Opt-out signals not forwarded to recipients
Entities that meet the Texas data broker definition (Tex. Bus. & Com. Code Ch. 509, effective Sept 2023) must register annually with the Texas Secretary of State, pay a fee, and post a website notice. Data broker status interacts with TDPSA sale-of-data and sensitive-data-sale notice obligations.
- Data broker determination memo
- Annual registration receipt with Texas SOS
- Website data broker notice
- Cross-reference to TDPSA § 541.054 sensitive/biometric notice
- Missed registration despite meeting threshold (50%+ revenue or 50%+ of personal data sold from non-customers)
- Website notice missing
Processors must adhere to controller instructions, assist controllers in meeting obligations (security, breach response, DSARs, DPIAs), ensure confidentiality, and engage subprocessors only with controller authorization and equivalent contracts.
- Processor self-attestation of TDPSA compliance
- Breach notification SLA in contract
- DSAR assistance procedure between controller and processor
- Subprocessor authorization workflow
- Processor signs DPA but has no internal procedures
- Subprocessor changes not notified
- No breach notification SLA
Programme Governance and Records
TDPSA does not introduce a separate breach notification regime. Notification obligations remain under Texas Bus. & Com. Code § 521.053 requiring notice without unreasonable delay (and within 30 days if 250+ Texas residents affected, including notice to Texas AG).
- Incident response plan referencing 30-day AG notification for 250+ residents
- Tabletop exercise records
- Notification templates (consumer, AG, credit bureaus if 10,000+)
- Breach register
- Plan references only HIPAA/GLBA without Texas § 521.053
- No 30-day AG notification trigger documented
While TDPSA does not mandate a named DPO, controllers must demonstrate accountability through written policies, training, recordkeeping of consumer requests and DPIAs, and a designated privacy contact accessible to consumers and the AG.
- Privacy program charter and ownership
- Annual training records
- Records of processing activities (RoPA)
- Designated privacy contact published
- Board or executive reporting cadence
- Policies exist but no training rollout
- Privacy contact buried or generic email
- No board visibility
Controllers should maintain records sufficient to demonstrate compliance, including DSAR receipts, response times, appeal outcomes, DPIAs, and consent records. Records must be producible upon Texas AG civil investigative demand.
- Centralized DSAR log with metadata (date, type, outcome, time-to-close)
- Annual DSAR metrics summary
- Document retention schedule for privacy records
- Texas AG CID response playbook
- Logs scattered across email and shared drives
- No retention schedule for privacy records
- DPIAs not centrally stored
Although not explicitly mandated, demonstrable workforce training is part of reasonable administrative safeguards and supports the accountability and DPIA obligations under TDPSA.
- Annual privacy training curriculum referencing TDPSA
- Completion rates by role
- Role-based training for engineering, marketing, support
- Phishing/handling drills
- Generic privacy training without Texas content
- Marketing and ad-ops teams not trained on opt-out and sensitive-data sale notice
Rights
Per TDPSA: consumer rights including access + correction + deletion + portability + opt-out.
- TDPSA evidence for TEXASTDPSA-2
- UOOM + sale notice + appeal partial
Scope
Per Texas TDPSA (Data Privacy and Security Act): scope. Requirements include (a) Applicability and Scope Determination + (b) Entity and Data Level Exemptions + (c) small business consent provisions.
- TDPSA evidence for TEXASTDPSA-1
- UOOM + sale notice + appeal partial
Scope, Applicability and Exemptions
TDPSA applies to any person that conducts business in Texas or produces products/services consumed by Texas residents AND processes or engages in the sale of personal data AND is not a small business as defined by the U.S. SBA. Unlike other state privacy laws, there is no consumer-count threshold.
- Applicability memo confirming Texas nexus and PI processing
- SBA size standard determination (NAICS code, employee count, average annual receipts)
- Documentation showing entity exceeds SBA small business thresholds OR sells sensitive personal data (which makes small businesses partially in scope)
- Inventory of Texas resident touchpoints (web traffic, customers, marketing)
- Assuming small business exemption without SBA size standard analysis
- Missing the sensitive-data sale carve-out that pulls small businesses partially in scope
- No documented Texas nexus assessment
TDPSA exempts state agencies, financial institutions subject to GLBA, covered entities and business associates under HIPAA, nonprofit organizations, higher education institutions, and electric utilities. Data-level exemptions cover GLBA-covered data, HIPAA PHI, FCRA, FERPA, DPPA, and certain research data.
- Exemption analysis memo per entity and per dataset
- Mapping of data flows to exempt vs. non-exempt categories
- Recordkeeping for FCRA/GLBA/HIPAA program reliance
- Entity-level exemption claimed where only data-level applies
- No analysis of mixed data flows
Sensitive Data
Per TDPSA: Sensitive Data including biometric + precise geolocation + Sale of Sensitive Personal Data Notice + children's data + consent requirements.
- TDPSA evidence for TEXASTDPSA-3
- UOOM + sale notice + appeal partial
Sensitive, Children and Biometric Data
Personal data of a known child (under 13) is sensitive personal data and must be processed in accordance with COPPA. For consumers known to be 13-17, controllers cannot process for targeted advertising, sale, or profiling without consent.
- Age gating and verifiable parental consent records for under-13
- Teen-specific opt-in for 13-17 advertising/sale/profiling
- COPPA compliance program documentation
- Data minimization for known minors
- No mechanism to identify the 13-17 cohort
- Targeted ads served to known teens without consent
A controller may not process sensitive personal data without obtaining the consumer's freely given, specific, informed, and unambiguous consent. Sensitive data includes racial/ethnic origin, religious beliefs, mental/physical health diagnosis, sexual orientation, citizenship/immigration status, genetic/biometric data, precise geolocation, and data of a known child.
- Sensitive data inventory and classification
- Consent capture UI screenshots (opt-in, granular, unbundled)
- Consent records with timestamp, version, scope
- Withdrawal mechanism as easy as granting
- Pre-checked boxes or bundled consent
- No record of consent version or text shown
- Withdrawal flow harder than the original opt-in
Biometric data is sensitive personal data under TDPSA, requiring opt-in consent. Texas Capture or Use of Biometric Identifier (CUBI) Act (§ 503.001) imposes additional pre-capture notice, written consent, retention limits, and prohibition on sale (with narrow exceptions).
- CUBI-compliant pre-capture notice and consent records
- Biometric retention schedule (destroy within reasonable time, no later than one year after purpose ends)
- TDPSA sale-of-biometric notice if applicable
- Sale restriction analysis (CUBI narrow exceptions)
- Treating biometric only under TDPSA, missing CUBI requirements
- No retention destruction evidence
- Sale of biometrics without CUBI exception analysis
Precise geolocation data (radius of 1,750 feet or less) is sensitive personal data requiring opt-in consent before processing.
- Inventory of geolocation collection points (SDKs, apps)
- Opt-in consent capture with purpose disclosure
- SDK and ad partner audit
- Truncation/coarsening procedures where consent not obtained
- Background location collection without opt-in
- Third-party SDKs harvesting geo without disclosure
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Texas Data Privacy Act framework page.