Skip to content

Evidence request lists

Texas Data Privacy Act

Evidence request list. 39 controls, 39 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability

TEXASTDPSA-5
DPIA, Universal Opt-Out, Processor Management

Per TDPSA: DPIA + Universal Opt-Out Mechanism + processor agreements.

Artefacts an auditor will ask for
  • TDPSA evidence for TEXASTDPSA-5
Where this commonly fails
  • UOOM + sale notice + appeal partial

Assessments and Profiling

TDPSA-541-101-PROFILING
Profiling Producing Legal or Significant Effects

Profiling in furtherance of decisions that produce legal or similarly significant effects (e.g., financial, housing, employment, healthcare, insurance, education) triggers opt-out rights and mandatory DPIA.

Artefacts an auditor will ask for
  • Inventory of automated decision systems
  • DPIA per profiling use case
  • Opt-out mechanism specifically for profiling
  • Human review fallback procedure
Where this commonly fails
  • Profiling for credit/insurance without DPIA
  • No separate profiling opt-out (bundled with sale)
TDPSA-541-105-DPIA
Data Protection Assessments (DPIAs)

Controllers must conduct and document data protection assessments for: targeted advertising, sale of personal data, profiling with foreseeable risk of unfair/deceptive treatment, processing sensitive data, and any processing presenting a heightened risk of harm. Assessments are confidential and subject to AG request.

Artefacts an auditor will ask for
  • DPIA register listing all triggering processing activities
  • DPIA template covering benefits/risks, mitigations, consumer expectations
  • Approval sign-off by privacy officer or legal
  • Refresh cadence (material change, periodic review)
Where this commonly fails
  • No DPIA for ad-tech or profiling activities
  • Template misses consumer expectation analysis
  • DPIAs not refreshed when processing changes
TDPSA-541-AI-CROSS
AI Cross-Reference (TRAIGA and Profiling)

The Texas Responsible AI Governance Act (TRAIGA, effective Jan 2026) interacts with TDPSA profiling and sensitive data provisions. Controllers using AI for consequential decisions must align TDPSA DPIAs with TRAIGA impact assessments and disclosure requirements.

Artefacts an auditor will ask for
  • AI inventory mapped to TDPSA profiling and TRAIGA consequential decisions
  • Combined DPIA + AI impact assessment
  • AI disclosure to consumers (TRAIGA § 552.054)
  • Bias and disparate impact testing
Where this commonly fails
  • TDPSA DPIA does not address algorithmic decisioning detail required by TRAIGA
  • No AI inventory linked to privacy records

Consumer Rights

TDPSA-541-052-APPEAL
Consumer Appeal Process

Controllers must establish an internal appeal process if a consumer request is refused. Appeals must be decided within 60 days with a written explanation. If the appeal is denied, the controller must inform the consumer of the ability to contact the Texas AG.

Artefacts an auditor will ask for
  • Documented appeal workflow
  • Appeal decision letter template referencing Texas AG complaint route
  • Appeal log with outcomes and rationale
  • Annual appeals metrics review
Where this commonly fails
  • No appeal mechanism at all
  • Appeal denial letter omits Texas AG contact information
  • Appeals handled by the same person who denied the original request
TDPSA-541-101-ACCESS
Consumer Right to Access

Consumers have the right to confirm whether a controller is processing their personal data and to access that personal data.

Artefacts an auditor will ask for
  • DSAR intake form (web, email, toll-free for sensitive data sellers)
  • Identity verification procedure
  • Access request fulfillment log
  • Response templates and data export format (portable, machine-readable)
Where this commonly fails
  • No identity verification step
  • Response delivered in non-portable format
  • Missing log of requests received and outcomes
TDPSA-541-101-CORRECT
Consumer Right to Correction

Consumers may correct inaccuracies in their personal data, taking into account the nature of the data and the purposes of processing.

Artefacts an auditor will ask for
  • Correction request workflow and ticketing
  • Source-of-truth documentation for corrected fields
  • Downstream propagation evidence (processors, integrations notified)
  • Reasonableness assessment for declined corrections
Where this commonly fails
  • Corrections not propagated to processors or third parties
  • No documentation of why a correction was refused
TDPSA-541-101-DELETE
Consumer Right to Deletion

Consumers may delete personal data provided by or obtained about the consumer.

Artefacts an auditor will ask for
  • Deletion procedure covering primary, backup, archive, and processor systems
  • Deletion confirmation log per request
  • Documented exemptions used (legal hold, fraud prevention, etc.)
  • Retention schedule referencing deletion triggers
Where this commonly fails
  • Backups not addressed in deletion procedure
  • Processors not instructed to delete in parallel
  • Exemptions claimed without documented basis
TDPSA-541-101-NONDISCRIM
Non-Discrimination for Exercising Rights

Controllers may not discriminate against a consumer for exercising any of the rights under TDPSA, including denying goods/services, charging different prices, or providing a different level of quality. Loyalty programs are not automatically discrimination.

Artefacts an auditor will ask for
  • Loyalty program terms with bona fide value exchange documentation
  • Internal policy prohibiting service degradation post-opt-out
  • Audit of pricing/service tiers vs. opt-out status
Where this commonly fails
  • Loss of features after opt-out without disclosure that the feature relied on the processing
  • No internal training on non-discrimination
TDPSA-541-101-OPTOUT
Consumer Right to Opt Out (Targeted Ads, Sale, Profiling)

Consumers may opt out of processing of personal data for purposes of targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.

Artefacts an auditor will ask for
  • Opt-out mechanism for targeted advertising (web form, link, GPC honored)
  • Sale opt-out workflow with downstream signaling
  • Profiling opt-out for legal/significant effects decisions
  • Universal Opt-Out Mechanism (UOOM) acknowledgment plan (note: TDPSA does not yet mandate UOOM but Texas AG has signaled scrutiny)
Where this commonly fails
  • Single opt-out toggle that does not distinguish the three categories
  • Opt-out not propagated to ad-tech partners
  • GPC not honored where claimed in policy
TDPSA-541-101-PORT
Consumer Right to Data Portability

Consumers may obtain a copy of personal data they previously provided, in a portable and, to the extent technically feasible, readily usable format that allows transmission to another controller.

Artefacts an auditor will ask for
  • Portable export format specification (JSON, CSV)
  • Sample export packet
  • Technical feasibility documentation for non-supported formats
Where this commonly fails
  • Export provided only in PDF (not machine-readable)
  • Trade-secret or proprietary inferences not separated
TDPSA-541-103-RESPONSE
Consumer Request Response Timelines

Controllers must respond to consumer requests without undue delay and within 45 days of receipt. The period may be extended once by an additional 45 days when reasonably necessary, with notice to the consumer of the extension and the reason.

Artefacts an auditor will ask for
  • Ticketing system with SLA timers
  • Extension notification templates and log
  • Monthly SLA compliance report
  • Process for free response (first two per year) and reasonable fee thereafter
Where this commonly fails
  • No automated SLA tracking
  • Extensions taken silently without consumer notice
  • Fees charged on first response without basis
TDPSA-541-AUTH-AGENT
Authorized Agent Requests

Consumers may use an authorized agent (including by means of an internet link or browser setting) to opt out of targeted advertising or sale on the consumer's behalf. Controllers must comply where authority is reasonably verified.

Artefacts an auditor will ask for
  • Authorized agent verification procedure
  • Acceptance of browser-based opt-out signals (current commitment and roadmap)
  • Logs of agent-submitted requests
  • Consumer authorization forms
Where this commonly fails
  • No procedure to accept agent requests
  • Verification burden placed solely on the agent without controller process

Controller Duties and Data Minimisation

TDPSA-541-101-DEID
De-identified and Pseudonymous Data

If data is de-identified, the controller must take reasonable measures to ensure the data cannot be re-associated with an individual, publicly commit to processing it only in de-identified form, and contractually obligate recipients to comply with the same restrictions.

Artefacts an auditor will ask for
  • De-identification methodology and threshold documentation
  • Public commitment statement
  • Contracts with downstream recipients requiring de-identification preservation
  • Periodic re-identification risk assessment
Where this commonly fails
  • Claiming de-identification without re-identification risk testing
  • No contractual flow-down to recipients
TDPSA-541-101-PURPOSE
Purpose Limitation and Data Minimization

Controllers must limit collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes for which the data is processed. Processing beyond disclosed purposes requires consumer consent.

Artefacts an auditor will ask for
  • Data inventory mapped to disclosed purposes
  • Field-level necessity justification
  • Secondary-use consent records where applicable
  • Periodic minimization review
Where this commonly fails
  • Collection of fields not tied to a purpose
  • Secondary use without re-consent
TDPSA-541-101-SECURITY
Reasonable Security Practices

Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of personal data, appropriate to the volume and nature of the personal data at issue.

Artefacts an auditor will ask for
  • Written information security program (WISP)
  • Risk assessments and remediation tracker
  • Access control, encryption, logging evidence
  • Vendor security reviews
  • Mapping to a recognized framework (NIST CSF, ISO 27001, SOC 2)
Where this commonly fails
  • No documented WISP
  • Encryption at rest missing for sensitive data stores
  • No periodic risk assessment

Enforcement

TDPSA-541-203-AG
Texas AG Enforcement and 30-Day Cure

The Texas Attorney General has exclusive enforcement authority. Before bringing an action, the AG must provide written notice of the alleged violation and a 30-day cure period. The cure period does not sunset. Civil penalties up to $7,500 per violation, plus injunctive relief and reasonable attorney's fees.

Artefacts an auditor will ask for
  • AG notice intake and response playbook
  • Cure tracking workflow with 30-day deadline
  • Sworn written statement template (cured violation + no further violation)
  • Penalty exposure register
Where this commonly fails
  • No playbook for receipt of AG notice
  • Sworn statement not used to close the cure window
  • No internal escalation path within 30 days
TDPSA-541-AG-SWEEP
Texas AG Enforcement Posture and Sweeps

The Texas AG (through its Consumer Protection Division and Data Privacy and Security Initiative launched 2024) has issued enforcement sweeps targeting data brokers, ad-tech, biometric processors, and sensitive data sellers. High-profile settlements include Meta (biometric, $1.4B, 2024) and Google (biometric/location, $1.375B, 2025).

Artefacts an auditor will ask for
  • Subscription to Texas AG press releases and enforcement bulletins
  • Annual review of enforcement actions and lessons learned
  • Gap analysis against settled matters (biometric, ad-tech, sensitive data sale notice)
  • Data broker registration under Tex. Bus. & Com. Code Ch. 509 if applicable
Where this commonly fails
  • No monitoring of AG enforcement trends
  • Data broker registration missed
  • No gap remediation after high-profile settlements
TEXASTDPSA-6
Consumer Appeal and Enforcement

Per TDPSA: Consumer Appeal Process + AG enforcement + 30-day cure + civil penalties.

Artefacts an auditor will ask for
  • TDPSA evidence for TEXASTDPSA-6
Where this commonly fails
  • UOOM + sale notice + appeal partial

Notice

TEXASTDPSA-4
Privacy Notice Content Requirements

Per TDPSA: Privacy Notice Content Requirements.

Artefacts an auditor will ask for
  • TDPSA evidence for TEXASTDPSA-4
Where this commonly fails
  • UOOM + sale notice + appeal partial

Privacy Notice and Disclosures

TDPSA-541-051-NOTICE
Privacy Notice Content Requirements

Controllers must provide a reasonably accessible and clear privacy notice that includes categories of personal data processed, purpose of processing, how consumers exercise rights and appeal, categories shared with third parties, categories of third parties, and a description of methods to submit requests.

Artefacts an auditor will ask for
  • Public-facing privacy notice with all six required disclosure elements
  • Versioning log of privacy notice changes
  • Last-updated timestamp and effective date
  • Accessibility review evidence (WCAG, plain language)
Where this commonly fails
  • Missing description of consumer appeal process
  • No categories of third parties listed (only generic references)
  • Outdated last-updated date
TDPSA-541-052
Sale of Sensitive Personal Data Notice

Controllers that sell sensitive personal data must post the exact notice: 'NOTICE: We may sell your sensitive personal data.' Controllers that sell biometric personal data must post: 'NOTICE: We may sell your biometric personal data.' Notices must be in the same location and manner as the privacy notice.

Artefacts an auditor will ask for
  • Screenshot of website privacy notice showing exact statutory language
  • Determination memo on whether entity sells sensitive or biometric data (broad definition of sale includes monetary or other valuable consideration)
  • Placement evidence (same location and manner as privacy notice)
  • Mobile and desktop rendering confirmation
Where this commonly fails
  • Paraphrased notice instead of exact statutory wording
  • Notice buried in privacy policy rather than displayed in same location
  • No determination of whether ad-tech disclosures constitute sale of sensitive data

Processors, Contracts and Downstream Disclosure

TDPSA-541-104-DPA
Controller-Processor Data Processing Agreement

Controllers must have a contract with processors that governs the processing, including instructions, nature/purpose, type of data, duration, rights/obligations of both parties, confidentiality, deletion or return at end of provision, processor cooperation, audit rights, and subprocessor flow-down.

Artefacts an auditor will ask for
  • Executed DPA with each processor including all eight required clauses
  • Subprocessor list and flow-down evidence
  • Audit reports or self-attestations from processors
  • Deletion/return certificates at contract termination
Where this commonly fails
  • DPA lacks audit cooperation clause
  • Subprocessors not flowed down
  • No deletion certificate on contract end
TDPSA-541-CONTRACTS-FLOW
Downstream Sale and Disclosure Contracts

Where personal data is sold or shared, the controller should bind recipients contractually to use limitations, security obligations, and downstream consumer rights honoring. This supports the TDPSA accountability and DPIA expectations.

Artefacts an auditor will ask for
  • Standard sale/share contract addendum
  • Recipient list with executed addendum status
  • Use-limitation audit
  • Opt-out propagation to recipients
Where this commonly fails
  • Sale partners onboarded without addendum
  • Opt-out signals not forwarded to recipients
TDPSA-541-DATABROKER
Data Broker Registration Cross-Reference

Entities that meet the Texas data broker definition (Tex. Bus. & Com. Code Ch. 509, effective Sept 2023) must register annually with the Texas Secretary of State, pay a fee, and post a website notice. Data broker status interacts with TDPSA sale-of-data and sensitive-data-sale notice obligations.

Artefacts an auditor will ask for
  • Data broker determination memo
  • Annual registration receipt with Texas SOS
  • Website data broker notice
  • Cross-reference to TDPSA § 541.054 sensitive/biometric notice
Where this commonly fails
  • Missed registration despite meeting threshold (50%+ revenue or 50%+ of personal data sold from non-customers)
  • Website notice missing
TDPSA-541-PROC-OBL
Processor Obligations and Cooperation

Processors must adhere to controller instructions, assist controllers in meeting obligations (security, breach response, DSARs, DPIAs), ensure confidentiality, and engage subprocessors only with controller authorization and equivalent contracts.

Artefacts an auditor will ask for
  • Processor self-attestation of TDPSA compliance
  • Breach notification SLA in contract
  • DSAR assistance procedure between controller and processor
  • Subprocessor authorization workflow
Where this commonly fails
  • Processor signs DPA but has no internal procedures
  • Subprocessor changes not notified
  • No breach notification SLA

Programme Governance and Records

TDPSA-541-BREACH
Breach Notification (Texas Identity Theft Act Cross-Reference)

TDPSA does not introduce a separate breach notification regime. Notification obligations remain under Texas Bus. & Com. Code § 521.053 requiring notice without unreasonable delay (and within 30 days if 250+ Texas residents affected, including notice to Texas AG).

Artefacts an auditor will ask for
  • Incident response plan referencing 30-day AG notification for 250+ residents
  • Tabletop exercise records
  • Notification templates (consumer, AG, credit bureaus if 10,000+)
  • Breach register
Where this commonly fails
  • Plan references only HIPAA/GLBA without Texas § 521.053
  • No 30-day AG notification trigger documented
TDPSA-541-GOVERN
Privacy Governance and Accountability

While TDPSA does not mandate a named DPO, controllers must demonstrate accountability through written policies, training, recordkeeping of consumer requests and DPIAs, and a designated privacy contact accessible to consumers and the AG.

Artefacts an auditor will ask for
  • Privacy program charter and ownership
  • Annual training records
  • Records of processing activities (RoPA)
  • Designated privacy contact published
  • Board or executive reporting cadence
Where this commonly fails
  • Policies exist but no training rollout
  • Privacy contact buried or generic email
  • No board visibility
TDPSA-541-RECORDS
Records of Consumer Requests and Decisions

Controllers should maintain records sufficient to demonstrate compliance, including DSAR receipts, response times, appeal outcomes, DPIAs, and consent records. Records must be producible upon Texas AG civil investigative demand.

Artefacts an auditor will ask for
  • Centralized DSAR log with metadata (date, type, outcome, time-to-close)
  • Annual DSAR metrics summary
  • Document retention schedule for privacy records
  • Texas AG CID response playbook
Where this commonly fails
  • Logs scattered across email and shared drives
  • No retention schedule for privacy records
  • DPIAs not centrally stored
TDPSA-541-TRAINING
Workforce Training and Awareness

Although not explicitly mandated, demonstrable workforce training is part of reasonable administrative safeguards and supports the accountability and DPIA obligations under TDPSA.

Artefacts an auditor will ask for
  • Annual privacy training curriculum referencing TDPSA
  • Completion rates by role
  • Role-based training for engineering, marketing, support
  • Phishing/handling drills
Where this commonly fails
  • Generic privacy training without Texas content
  • Marketing and ad-ops teams not trained on opt-out and sensitive-data sale notice

Rights

TEXASTDPSA-2
Consumer Rights

Per TDPSA: consumer rights including access + correction + deletion + portability + opt-out.

Artefacts an auditor will ask for
  • TDPSA evidence for TEXASTDPSA-2
Where this commonly fails
  • UOOM + sale notice + appeal partial

Scope

TEXASTDPSA-1
Scope, Applicability, Exemptions

Per Texas TDPSA (Data Privacy and Security Act): scope. Requirements include (a) Applicability and Scope Determination + (b) Entity and Data Level Exemptions + (c) small business consent provisions.

Artefacts an auditor will ask for
  • TDPSA evidence for TEXASTDPSA-1
Where this commonly fails
  • UOOM + sale notice + appeal partial

Scope, Applicability and Exemptions

TDPSA-541-001
Applicability and Scope Determination

TDPSA applies to any person that conducts business in Texas or produces products/services consumed by Texas residents AND processes or engages in the sale of personal data AND is not a small business as defined by the U.S. SBA. Unlike other state privacy laws, there is no consumer-count threshold.

Artefacts an auditor will ask for
  • Applicability memo confirming Texas nexus and PI processing
  • SBA size standard determination (NAICS code, employee count, average annual receipts)
  • Documentation showing entity exceeds SBA small business thresholds OR sells sensitive personal data (which makes small businesses partially in scope)
  • Inventory of Texas resident touchpoints (web traffic, customers, marketing)
Where this commonly fails
  • Assuming small business exemption without SBA size standard analysis
  • Missing the sensitive-data sale carve-out that pulls small businesses partially in scope
  • No documented Texas nexus assessment
TDPSA-541-001-EXEMPT
Entity and Data Level Exemptions

TDPSA exempts state agencies, financial institutions subject to GLBA, covered entities and business associates under HIPAA, nonprofit organizations, higher education institutions, and electric utilities. Data-level exemptions cover GLBA-covered data, HIPAA PHI, FCRA, FERPA, DPPA, and certain research data.

Artefacts an auditor will ask for
  • Exemption analysis memo per entity and per dataset
  • Mapping of data flows to exempt vs. non-exempt categories
  • Recordkeeping for FCRA/GLBA/HIPAA program reliance
Where this commonly fails
  • Entity-level exemption claimed where only data-level applies
  • No analysis of mixed data flows

Sensitive Data

TEXASTDPSA-3
Sensitive Data, Children, Sale Notice

Per TDPSA: Sensitive Data including biometric + precise geolocation + Sale of Sensitive Personal Data Notice + children's data + consent requirements.

Artefacts an auditor will ask for
  • TDPSA evidence for TEXASTDPSA-3
Where this commonly fails
  • UOOM + sale notice + appeal partial

Sensitive, Children and Biometric Data

TDPSA-541-053-CHILD
Children's Data and COPPA Alignment

Personal data of a known child (under 13) is sensitive personal data and must be processed in accordance with COPPA. For consumers known to be 13-17, controllers cannot process for targeted advertising, sale, or profiling without consent.

Artefacts an auditor will ask for
  • Age gating and verifiable parental consent records for under-13
  • Teen-specific opt-in for 13-17 advertising/sale/profiling
  • COPPA compliance program documentation
  • Data minimization for known minors
Where this commonly fails
  • No mechanism to identify the 13-17 cohort
  • Targeted ads served to known teens without consent
TDPSA-541-053-SENSITIVE
Sensitive Data Opt-In Consent

A controller may not process sensitive personal data without obtaining the consumer's freely given, specific, informed, and unambiguous consent. Sensitive data includes racial/ethnic origin, religious beliefs, mental/physical health diagnosis, sexual orientation, citizenship/immigration status, genetic/biometric data, precise geolocation, and data of a known child.

Artefacts an auditor will ask for
  • Sensitive data inventory and classification
  • Consent capture UI screenshots (opt-in, granular, unbundled)
  • Consent records with timestamp, version, scope
  • Withdrawal mechanism as easy as granting
Where this commonly fails
  • Pre-checked boxes or bundled consent
  • No record of consent version or text shown
  • Withdrawal flow harder than the original opt-in
TDPSA-541-101-BIOMETRIC
Biometric Data Handling (TDPSA and CUBI Overlap)

Biometric data is sensitive personal data under TDPSA, requiring opt-in consent. Texas Capture or Use of Biometric Identifier (CUBI) Act (§ 503.001) imposes additional pre-capture notice, written consent, retention limits, and prohibition on sale (with narrow exceptions).

Artefacts an auditor will ask for
  • CUBI-compliant pre-capture notice and consent records
  • Biometric retention schedule (destroy within reasonable time, no later than one year after purpose ends)
  • TDPSA sale-of-biometric notice if applicable
  • Sale restriction analysis (CUBI narrow exceptions)
Where this commonly fails
  • Treating biometric only under TDPSA, missing CUBI requirements
  • No retention destruction evidence
  • Sale of biometrics without CUBI exception analysis
TDPSA-541-101-GEO
Precise Geolocation Data

Precise geolocation data (radius of 1,750 feet or less) is sensitive personal data requiring opt-in consent before processing.

Artefacts an auditor will ask for
  • Inventory of geolocation collection points (SDKs, apps)
  • Opt-in consent capture with purpose disclosure
  • SDK and ad partner audit
  • Truncation/coarsening procedures where consent not obtained
Where this commonly fails
  • Background location collection without opt-in
  • Third-party SDKs harvesting geo without disclosure
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Texas Data Privacy Act framework page.