🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-TX · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 20 sources retrieved model claude-sonnet-5 ·

United States – Texas

US-TX schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 45 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
45Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

TRAIGA entered into force January 1, 2026. It imposes state-agency AI-disclosure duties, a ban on capturing biometric identifiers without consent, and bans AI systems designed to manipulate behavior, discriminate, or produce child-exploitative deepfakes. The Texas Attorney General enforces TRAIGA exclusively, with fines of $80,000 to $200,000 per violation for entities failing to cure within 60 days, and no private right of action. A widely used comparison, that TRAIGA preceded the Colorado AI Act by one month, is superseded: Colorado's SB 24-205 was delayed to June 30, 2026, judicially stayed on April 27, 2026, and repealed and replaced by SB 26-189, signed May 14, 2026, a narrower disclosure law effective January 1, 2027.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A clearly identified enforcer (OAG) and a stack of in-force statutes with defined material and territorial scope.

Primary frameworkTexas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code Title 11, Subtitle D, Ch. 541 (HB 4, 2023)
Traffic-light rationale — GreenA clearly identified enforcer (OAG) and a stack of in-force statutes with defined material and territorial scope.

Sub-modules (5)

Regulator And AuthorityGreen

TDPSA is enforced exclusively by the Texas AG; there is no independent Texas DPA.

Claims: CLM-USTX-a1b2c3d4

Act And InstrumentsGreen

TDPSA, CUBI, TITEPA (as amended), and TRAIGA form the operative instrument stack.

Claims: CLM-USTX-b2c3d4e5, CLM-USTX-c3d4e5f6, CLM-USTX-d4e5f6a7

Material ScopeGreen

Personal data is broadly defined to include pseudonymous data linked or linkable to an identifiable individual.

Claims: CLM-USTX-e5f6a7b8

Territorial ScopeGreen

TDPSA uses a unique three-factor applicability test rather than revenue/volume thresholds common to other state laws.

Claims: CLM-USTX-f6a7b8c9

Regulator Registration And FilingAmber

No general controller registration exists under TDPSA itself, but a mandatory data-broker registry operates under Ch. 509, tightened by SB 1343.

Claims: CLM-USTX-a7b8c9d0, CLM-USTX-b8c9d0e1

Category narrative109 words

Texas has no dedicated data-protection authority; enforcement of the state's comprehensive privacy statute and adjacent biometric/breach laws sits with the Office of the Attorney General (OAG) Consumer Protection Division. The core omnibus instrument is the Texas Data Privacy and Security Act (TDPSA, HB 4), enacted June 18, 2023 and effective July 1, 2024, layered atop pre-existing sectoral instruments: the Capture or Use of Biometric Identifier Act (CUBI, 2009), the Identity Theft Enforcement and Protection Act (TITEPA) breach-notification regime (as amended by HB 4390), a data-broker registry (Ch. 509, as amended by SB 1343), and — as of January 1, 2026 — the Texas Responsible Artificial Intelligence Governance Act (TRAIGA).

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedDataGuidance (OneTrust)The Texas Data Privacy and Security Act is enforced exclusively by the Texas Attorney General's Office, with no dedicated Texas data protection authority.
  2. ConfirmedDataGuidance (OneTrust)Texas enacted the Texas Data Privacy and Security Act (HB 4) on June 18, 2023, with compliance required from July 1, 2024.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe Texas Responsible Artificial Intelligence Governance Act (TRAIGA) entered into force on January 1, 2026, one month before the Colorado AI Act.
  4. ConfirmedU.S. Federal Trade CommissionTexas maintains a standalone biometric statute, the Capture or Use of Biometric Identifier Act (CUBI), codified at Tex. Bus. & Com. Code §503.001, effective since April 1, 2009.
  5. ConfirmedDataGuidance (OneTrust)TDPSA personal data is defined as information linked or reasonably linkable to an identified or identifiable individual, including pseudonymous data.
  6. ConfirmedInternational Association of Privacy ProfessionalsTDPSA applies to entities conducting business in Texas or producing products/services consumed by Texas residents that process or sell personal data and are not a small business under SBA guidelines — a unique three-factor threshold without revenue or volume stipulations.
  7. ConfirmedTexas LegislatureTexas maintains a mandatory data-broker registry under Business & Commerce Code Chapter 509, requiring registration with the Texas Secretary of State and authorizing civil penalties for noncompliance.
  8. ConfirmedDataGuidance (OneTrust)SB 1343 expanded data-broker registration-statement requirements (purchaser credentialing, children's-data handling, security-breach statistics) and mandates a conspicuous website notice, applicable to statements submitted on or after September 1, 2025.

#

Consent and special-category rules are confirmed; the absence of an enumerated lawful-basis list (unlike GDPR Art. 6) is a structural gap relative to omnibus regimes.

Primary frameworkTexas Data Privacy and Security Act (TDPSA) + Capture or Use of Biometric Identifier Act (CUBI)
Traffic-light rationale — AmberConsent and special-category rules are confirmed; the absence of an enumerated lawful-basis list (unlike GDPR Art. 6) is a structural gap relative to omnibus regimes.

Sub-modules (4)

Lawful BasesAmber

No enumerated lawful-basis list; processing legitimacy flows from notice/consent and consumer opt-outs, per the Virginia-model foundation of TDPSA.

Claims: CLM-USTX-c9d0e1f2

Special CategoriesGreen

Sensitive personal data includes biometric data, children's data, and precise geolocation; CUBI imposes a separate informed-consent duty for biometric identifiers.

Claims: CLM-USTX-e1f2a3b4, CLM-USTX-f2a3b4c5

Pseudonymisation And AnonymisationGreen

Pseudonymous data is expressly within scope of 'personal data' under TDPSA.

Claims: CLM-USTX-a3b4c5d6

Category narrative51 words

TDPSA does not enumerate GDPR-style Art. 6 lawful bases; it instead follows the Virginia-model notice-and-consent architecture, requiring opt-in consent specifically for sensitive data. Sensitive/special categories are broadly defined (biometric, children's, precise geolocation, and by cross-reference to CUBI's separate biometric-consent regime). Pseudonymous data is explicitly captured within 'personal data' rather than exempted.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ProbableInternational Association of Privacy ProfessionalsTDPSA, following the Virginia consumer-privacy model as its structural foundation, relies on a notice-and-consent/opt-out framework rather than an enumerated list of GDPR-style lawful bases for processing.
  2. ConfirmedInternational Association of Privacy ProfessionalsTDPSA requires opt-in consent for the collection and use of sensitive data.
  3. ConfirmedDataGuidance (OneTrust)TDPSA's sensitive personal data categories include biometric data, children's data, and precise geolocation data, requiring heightened protection.
  4. ConfirmedDataGuidance (OneTrust)CUBI prohibits capture of a person's biometric identifier for a commercial purpose without first informing the individual and obtaining consent.
  5. ConfirmedDataGuidance (OneTrust)TDPSA's definition of personal data explicitly includes pseudonymous data, extending coverage beyond directly identifiable information.

#

Core rights (access/correction/deletion/opt-out) are Confirmed; portability and exact deadline windows rest on Probable inference from the law's Virginia-model foundation rather than directly retrieved statutory text.

Primary frameworkTexas Data Privacy and Security Act (TDPSA)
Traffic-light rationale — AmberCore rights (access/correction/deletion/opt-out) are Confirmed; portability and exact deadline windows rest on Probable inference from the law's Virginia-model foundation rather than directly retrieved statutory text.

Sub-modules (5)

Access RightGreen

Consumers may confirm processing and access their personal data.

Claims: CLM-USTX-b4c5d6e7

Rectification And ErasureGreen

Correction and deletion rights are granted.

Claims: CLM-USTX-c5d6e7f8

Restriction And ObjectionGreen

Controllers must recognize universal opt-out mechanisms as of Jan 1, 2025.

Claims: CLM-USTX-d6e7f8a9

Data PortabilityAmber

A portability right is expected by structural analogy to the Virginia model that underpins TDPSA; not independently confirmed against primary text in this run.

Absence provenance: not recorded. Searched: not recorded.

Claims: CLM-USTX-e7f8a9b0

Deadlines And Response WindowsAmber

A 45-day response window (extendable by 45 days), typical of Virginia-model laws, is inferred but not independently verified against TDPSA's primary text in this run.

Claims: CLM-USTX-f8a9b0c1

Category narrative43 words

TDPSA grants confirmation, access, correction, and deletion rights, plus a universal opt-out mechanism (UOOM) obligation effective January 1, 2025. Portability and precise response-window deadlines are structurally expected given TDPSA's Virginia-model lineage but were not independently confirmed against primary statutory text in this run.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedDataGuidance (OneTrust)TDPSA grants consumers the right to confirm whether a business is processing their personal data and to access that personal data.
  2. ConfirmedDataGuidance (OneTrust)TDPSA grants consumers rights to correct inaccuracies in their personal data and to request deletion of personal data provided by or obtained about the consumer.
  3. ConfirmedInternational Association of Privacy ProfessionalsTexas's universal opt-out mechanism (UOOM) recognition requirement under TDPSA took effect January 1, 2025.
  4. ProbableInternational Association of Privacy ProfessionalsTDPSA is understood to include a data-portability right consistent with the Virginia consumer-privacy framework that forms its structural foundation.
  5. ProbableInternational Association of Privacy ProfessionalsAs a Virginia-model comprehensive privacy law, TDPSA is understood to require controllers to respond to consumer-rights requests within 45 days, extendable once by a further 45 days.

#

Breach notification and DPIA-style assessment duties are Confirmed and materially significant; DPO, ROPA, joint-controller, and retention-limitation provisions are either absent or unconfirmed, warranting an amber rating.

Primary frameworkTexas Data Privacy and Security Act (TDPSA) + Texas Identity Theft Enforcement and Protection Act (TITEPA)
Traffic-light rationale — AmberBreach notification and DPIA-style assessment duties are Confirmed and materially significant; DPO, ROPA, joint-controller, and retention-limitation provisions are either absent or unconfirmed, warranting an amber rating.

Sub-modules (7)

Accountability And DpiaGreen

TDPSA requires data-protection (risk) assessments in specified circumstances.

Claims: CLM-USTX-a9b0c1d2

Dpo RequirementsRed

No TDPSA provision mandating appointment of a designated Data Protection Officer was identified.

Absence provenance: not recorded. Searched: not recorded.

Ropa RequirementsRed

No explicit records-of-processing-activities (ROPA) duty distinct from the data-protection-assessment obligation was identified.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsRed

No TDPSA-specific joint-controller regime was identified.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresAmber

Comprehensive US state privacy laws generally require data minimization, purpose limitation, and reasonable security; TDPSA's specific security-measures text was not independently isolated in this run.

Claims: CLM-USTX-b0c1d2e3

Breach NotificationGreen

TITEPA, as amended by HB 4390, requires disclosure without unreasonable delay and not later than 60 days after breach determination, plus AG notification with defined content for breaches affecting ≥250 Texas residents.

Claims: CLM-USTX-c1d2e3f4, CLM-USTX-d2e3f4a5

Retention And DisposalRed

No TDPSA-specific data-retention or disposal duty distinct from the general accountability principle was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative66 words

TDPSA mandates data-protection (risk) assessments in specified high-risk circumstances. TITEPA, as amended by HB 4390, sets a 60-day breach-disclosure deadline and AG-notification duties for breaches affecting ≥250 Texas residents. No DPO-appointment mandate, no explicit ROPA duty, and no distinct joint-controller regime were identified for TDPSA in this run; general data-minimization/security duties are inferred by comparison to peer state laws rather than confirmed against TDPSA primary text.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedDataGuidance (OneTrust)TDPSA requires organizations to conduct data-protection (risk) assessments in specified circumstances to identify potential vulnerabilities and ensure compliance.
  2. ProbableInternational Association of Privacy ProfessionalsAs with other comprehensive state privacy laws, TDPSA-era obligations are generally understood to encompass data minimization, purpose limitation, and reasonable security safeguards for personal-data processing.
  3. ConfirmedInternational Association of Privacy ProfessionalsHB 4390 requires breach disclosure without unreasonable delay and not later than the 60th day after the date a person determines a breach occurred, replacing the prior 'quickly as possible' TITEPA standard.
  4. ConfirmedInternational Association of Privacy ProfessionalsHB 4390 requires disclosure of breach details (nature/circumstances, number of Texas residents affected, remedial measures taken and planned, and law-enforcement involvement) to the Texas Attorney General for breaches affecting at least 250 Texas residents.

#

No comprehensive cross-border transfer/adequacy framework exists under TDPSA or any other reviewed Texas instrument.

Traffic-light rationale — RedNo comprehensive cross-border transfer/adequacy framework exists under TDPSA or any other reviewed Texas instrument.

Sub-modules (6)

Transfer MechanismsRed

No TDPSA-specific transfer mechanism identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

Not applicable — Texas/US has no adequacy-receipt framework analogous to GDPR Art. 45.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

Not applicable — Texas does not grant adequacy determinations to other regimes.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No SCC/BCR-equivalent uptake regime identified under TDPSA.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement identified under TDPSA.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No data-localisation mandate identified for Texas.

Absence provenance: not recorded. Searched: not recorded.

Category narrative55 words

TDPSA does not establish a GDPR-style cross-border transfer, adequacy, SCC/BCR, transfer-impact-assessment, or data-localisation regime. As with other US state comprehensive privacy laws, cross-border personal-data flows are addressed only indirectly, if at all, through vendor/processor contractual clauses rather than a dedicated statutory transfer mechanism. This is a genuine regulatory gap rather than an omission of research.

#

Financial, health, credit, education, and employment carve-outs are Confirmed; telecoms/ePrivacy and insurance-sector overlays are absent from the evidence gathered.

Primary frameworkTDPSA sectoral exemptions cross-referencing federal GLBA/HIPAA/FCRA/FERPA
Traffic-light rationale — AmberFinancial, health, credit, education, and employment carve-outs are Confirmed; telecoms/ePrivacy and insurance-sector overlays are absent from the evidence gathered.

Sub-modules (7)

Financial Sector OverlayGreen

TDPSA exempts GLBA-covered financial institutions and GLBA-regulated data.

Claims: CLM-USTX-e3f4a5b6

Health Sector OverlayGreen

TDPSA exempts HIPAA covered entities/business associates and HIPAA-regulated data.

Claims: CLM-USTX-f4a5b6c7

Telecoms And EprivacyRed

No Texas-specific telecoms/ePrivacy DP overlay identified.

Absence provenance: not recorded. Searched: not recorded.

Employment DataAmber

TDPSA excludes data processed solely in the employment context from covered personal data.

Claims: CLM-USTX-a5b6c7d8

Credit And ScoringGreen

TDPSA exempts FCRA-regulated data.

Claims: CLM-USTX-b6c7d8e9

EducationGreen

TDPSA exempts higher-education institutions and FERPA-regulated data.

Claims: CLM-USTX-c7d8e9f0

InsuranceRed

No Texas-specific insurance-sector DP overlay identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative55 words

TDPSA carves out broad sectoral exemptions rather than layering additional obligations: financial institutions/data under GLBA, HIPAA covered entities/business associates and HIPAA-regulated data, FCRA-regulated data, higher-education institutions and FERPA-regulated data, and data processed solely in the employment context are all excluded from TDPSA's scope. No Texas-specific telecoms/ePrivacy or insurance-sector DP overlay was identified in this run.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedDataGuidance (OneTrust)TDPSA exempts financial institutions and data subject to the Gramm-Leach-Bliley Act (GLBA).
  2. ConfirmedDataGuidance (OneTrust)TDPSA exempts covered entities and business associates subject to HIPAA, and data regulated under HIPAA.
  3. ConfirmedDataGuidance (OneTrust)TDPSA excludes data processed solely in the employment context from its scope of covered personal data.
  4. ConfirmedDataGuidance (OneTrust)TDPSA exempts data subject to the Fair Credit Reporting Act (FCRA).
  5. ConfirmedDataGuidance (OneTrust)TDPSA exempts institutions of higher education and data subject to the Family Educational Rights and Privacy Act (FERPA).

#

UOOM, dark-patterns, and targeted-advertising opt-out are Confirmed; cookie-specific, direct-marketing, and clean-room provisions are absent from the evidence gathered.

Primary frameworkTexas Data Privacy and Security Act (TDPSA)
Traffic-light rationale — AmberUOOM, dark-patterns, and targeted-advertising opt-out are Confirmed; cookie-specific, direct-marketing, and clean-room provisions are absent from the evidence gathered.

Sub-modules (6)

Cookies And TrackersRed

No Texas-specific cookie/tracker consent rule distinct from general TDPSA opt-out rights was identified.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsAmber

TDPSA addresses dark patterns in the context of consent validity.

Claims: CLM-USTX-d8e9f0a1

Opt Out SignalsGreen

Texas requires recognition of universal opt-out mechanisms (UOOM) effective Jan 1, 2025.

Claims: CLM-USTX-e9f0a1b2

Clean Rooms And DcrRed

No Texas-specific clean-room/data-collaboration-room rule identified.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingGreen

TDPSA grants an opt-out right for targeted advertising and sale of personal data.

Claims: CLM-USTX-f0a1b2c3

Direct MarketingRed

No Texas-specific direct-marketing suppression duty distinct from the general opt-out right was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative46 words

TDPSA requires recognition of universal opt-out mechanisms (effective Jan 1, 2025), includes dark-patterns provisions affecting the validity of consent, and grants opt-out rights for targeted advertising and sale of personal data. Cookie/tracker-specific rules, direct-marketing suppression duties, and clean-room/data-collaboration provisions were not independently confirmed in this run.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsTDPSA includes provisions addressing 'dark patterns' in connection with obtaining valid consumer consent.
  2. ConfirmedInternational Association of Privacy ProfessionalsTexas is among the states where universal opt-out mechanism (UOOM) requirements are already in effect, with Texas's obligation taking effect January 1, 2025.
  3. ConfirmedInternational Association of Privacy ProfessionalsTDPSA grants consumers the right to opt out of the processing of personal data for purposes of targeted advertising and the sale of personal data.

#

TRAIGA and CUBI are robust, Confirmed frameworks; profiling-restriction language and genetic-data regulation are unconfirmed/absent.

Primary frameworkTexas Responsible Artificial Intelligence Governance Act (TRAIGA) + Capture or Use of Biometric Identifier Act (CUBI)
Traffic-light rationale — AmberTRAIGA and CUBI are robust, Confirmed frameworks; profiling-restriction language and genetic-data regulation are unconfirmed/absent.

Sub-modules (6)

Profiling RestrictionsAmber

TDPSA is understood to include an opt-out right against profiling producing legal or similarly significant effects, consistent with its Virginia-model foundation; not independently confirmed against primary text.

Claims: CLM-USTX-a1b2c3e4

Automated Decision Making TransparencyGreen

TRAIGA imposes state-agency disclosure duties when citizens interact with agency AI tools and prohibits manipulative/discriminatory AI design.

Claims: CLM-USTX-b2c3e4f5

Ai Risk AssessmentsGreen

TRAIGA enforcement is AG-exclusive with substantial per-violation fines after a 60-day cure period.

Claims: CLM-USTX-c3e4f5a6

Biometric RegimeGreen

CUBI's informed-consent regime for biometric identifiers underpinned a $1.4B AG settlement with Meta.

Claims: CLM-USTX-d4f5a6b7

Genetic DataRed

No enacted Texas genetic-data-specific statute was confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsAmber

TDPSA exempts government agencies from its scope.

Claims: CLM-USTX-e5a6b7c8

Category narrative77 words

TRAIGA (effective Jan 1, 2026) prohibits AI systems designed to manipulate human behavior, make discriminatory decisions, or produce child-exploitative deepfakes, and imposes state-agency AI-disclosure duties; enforcement is AG-exclusive with $80,000–$200,000 per-violation fines after a 60-day cure period and no private right of action. CUBI separately governs biometric-identifier capture/consent and underpinned a $1.4B Meta settlement. No enacted Texas genetic-data-specific statute was confirmed (a 2023 bill, SB 704, was introduced but its enactment was not confirmed in this run).

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ProbableInternational Association of Privacy ProfessionalsTDPSA is understood to grant consumers an opt-out right against profiling in furtherance of decisions producing legal or similarly significant effects, consistent with its Virginia-model foundation.
  2. ConfirmedInternational Association of Privacy ProfessionalsTRAIGA imposes disclosure requirements for state agencies when citizens interact with AI tools the agency uses, bans capturing biometric identifiers without consent, and prohibits AI developers from creating systems designed to manipulate human behavior, make discriminatory decisions, or produce deepfakes exploiting children.
  3. ConfirmedInternational Association of Privacy ProfessionalsTRAIGA is enforced exclusively by the Texas Attorney General, who may assess administrative fines of not less than USD80,000 and not more than USD200,000 per violation if a covered entity fails to cure within 60 days, and the statute provides no private right of action.
  4. ConfirmedDataGuidance (OneTrust)The Texas Attorney General secured a $1.4 billion settlement with Meta Platforms Inc. over unauthorized capture and use of Texans' biometric data under CUBI.
  5. ConfirmedDataGuidance (OneTrust)TDPSA includes exemptions for government agencies, carving state and local government processing out of its general obligations.

#

Multiple enacted statutes and active AG enforcement are Confirmed, but significant portions of the regime (SCOPE Act, App Store Accountability Act) are currently enjoined and subject to ongoing appellate litigation, materially affecting operative status.

Primary frameworkHB 18 (SCOPE Act) + HB 1181 (age verification) + SB 2420 (App Store Accountability Act)
Traffic-light rationale — AmberMultiple enacted statutes and active AG enforcement are Confirmed, but significant portions of the regime (SCOPE Act, App Store Accountability Act) are currently enjoined and subject to ongoing appellate litigation, materially affecting operative status.

Sub-modules (5)

Age VerificationGreen

HB 1181 mandates robust age verification for adult-content websites and was upheld by SCOTUS; steep penalties apply.

Claims: CLM-USTX-f6b7c8d9, CLM-USTX-a7c8d9e0

Minor Profiling BansAmber

SCOPE Act imposes algorithm-transparency duties toward minors but portions remain partially enjoined pending Fifth Circuit review.

Claims: CLM-USTX-c9e0f1a2

Education SettingsRed

No education-setting-specific minors DP provision beyond general FERPA exemption was independently confirmed in this run.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No Texas-specific dependent-adults (elderly/incapacitated) data-protection provision was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative88 words

Texas maintains overlapping minors-protection statutes: HB 1181 (age-verification for adult content, upheld by SCOTUS in Free Speech Coalition v. Paxton, June 27, 2025) with steep per-day/per-access penalties; HB 18 (SCOPE Act) imposing digital-service-provider duties toward minors, portions of which remain partially enjoined pending Fifth Circuit review; SB 2420 (App Store Accountability Act) requiring age verification/categorization by app stores, currently preliminarily enjoined and on appeal; and active AG enforcement (e.g., against Snap) under the Securing Children Online Through Parental Empowerment Act. No Texas-specific dependent-adults (elderly/incapacitated) DP provision was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsTexas HB 1181 mandates that websites with at least one-third content deemed sexual material harmful to minors implement robust age-verification systems, often requiring government-issued identification, third-party verification, or biometric data; the law was upheld by the U.S. Supreme Court in Free Speech Coalition v. Paxton (June 27, 2025).
  2. ConfirmedInternational Association of Privacy ProfessionalsTexas HB 1181 imposes fines of up to USD10,000 per day plus USD250,000 per instance of minor access for noncompliance with its age-verification mandate.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe Texas Attorney General has brought enforcement action against Snap alleging violation of the Securing Children Online Through Parental Empowerment Act by collecting and sharing minors' personal information with third parties without required safeguards.
  4. ProbableInternational Association of Privacy ProfessionalsTexas HB 18 (SCOPE Act) imposes duties on digital service providers regarding minors, including making algorithm code available to independent security researchers, but portions of HB 18 remain partially enjoined pending Fifth Circuit review.

#

AG powers, penalty caps, and a substantial, escalating enforcement record are all Confirmed with specific, recent examples.

Primary frameworkTexas Data Privacy and Security Act (TDPSA) + Texas Deceptive Trade Practices Act (DTPA)
Traffic-light rationale — GreenAG powers, penalty caps, and a substantial, escalating enforcement record are all Confirmed with specific, recent examples.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

TDPSA caps penalties at $7,500 per violation with a 30-day cure period; TRAIGA imposes $80,000-$200,000 per-violation fines.

Claims: CLM-USTX-d0e1f2b3

Enforcement Activity IndexGreen

Recent, substantial AG enforcement includes the $1.4B Meta CUBI settlement and December 2025 ACR-technology lawsuits against five smart-TV manufacturers.

Claims: CLM-USTX-e1f2b3c4, CLM-USTX-f2b3c4d5

Regulator Funding And CapacityRed

No specific funding/headcount data for the OAG Consumer Protection Division's privacy enforcement function was identified.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsAmber

TDPSA itself bars private action, but the Texas DTPA offers a separate, general consumer-protection avenue the AG also uses as a catch-all.

Claims: CLM-USTX-a3c4d5e6

Private Right Of ActionGreen

TDPSA does not grant individuals a private right of action.

Claims: CLM-USTX-b4d5e6f7

Recent Developments 180DGreen

TRAIGA's Jan 1, 2026 entry into force and the AG's continuing enforcement crackdown (ACR lawsuits, Dec 2025) represent the most recent material developments.

Claims: CLM-USTX-c5e6f7a8

Category narrative94 words

TDPSA vests exclusive enforcement in the Texas AG, capped at $7,500 per violation with a 30-day cure period, and creates no private right of action; TRAIGA similarly is AG-exclusive with much larger per-violation fines. Enforcement activity has intensified through 2025–2026, including the $1.4B CUBI settlement with Meta (2024) and a December 2025 wave of ACR-technology lawsuits against smart-TV manufacturers with temporary restraining orders against two defendants. Separately, consumers retain access to the general Texas Deceptive Trade Practices Act (DTPA), which the AG has invoked as a catch-all in privacy-adjacent suits (e.g., against General Motors).

No periodic updates recorded against this sub-brief.

Sources and claims (6)
  1. ConfirmedDataGuidance (OneTrust)TDPSA violations are subject to civil penalties of up to $7,500 per violation, enforced exclusively by the Texas Attorney General, with a 30-day statutory cure period before penalties attach.
  2. ConfirmedInternational Association of Privacy ProfessionalsIn December 2025, the Texas Attorney General filed lawsuits against five smart-TV manufacturers (Sony, Samsung, LG, Hisense, and TCL) over automated content recognition technology allegedly used to unlawfully collect and monetize consumers' viewing data, obtaining temporary restraining orders against Hisense and Samsung.
  3. ConfirmedDataGuidance (OneTrust)The Texas Attorney General secured a $1.4 billion settlement with Meta Platforms Inc. in July 2024 over unauthorized biometric-data capture under CUBI.
  4. ConfirmedInternational Association of Privacy ProfessionalsThe Texas Attorney General has invoked the general Texas Deceptive Trade Practices Act (DTPA) catch-all provision in privacy-adjacent enforcement, such as its suit against General Motors over data-sharing practices.
  5. ConfirmedDataGuidance (OneTrust)TDPSA does not grant individuals a private right of action; enforcement is reserved to the Texas Attorney General.
  6. ConfirmedInternational Association of Privacy ProfessionalsTRAIGA entered into force January 1, 2026, and the Texas Attorney General has continued a broad privacy-enforcement crackdown into 2026, including the December 2025 ACR lawsuits against smart-TV manufacturers.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Texas
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 45 claim(s), 20 source(s) in the cumulative register.