Templates Contracts Agreements DPA Short Form Transfer Addendum - Texas (Operational Compliance)

DPA Short Form Transfer Addendum - Texas (Operational Compliance)

Ready to Edit

DPA SHORT FORM TRANSFER ADDENDUM -- TEXAS

Operational Compliance Format -- Article Numbering

Addendum Effective Date: [__/__/____]

Reference Agreement: [________________________________] dated [__/__/____] (the "Agreement")

Transferor (Controller): [________________________________] ("Transferor")

Transferee (Processor): [________________________________] ("Transferee")

This Addendum establishes the operational compliance framework for transfers of Personal Data involving Texas consumers under the TDPSA (effective July 1, 2024) and the Texas Identity Theft Enforcement and Protection Act.


ARTICLE I: DEFINITIONS

1.1 "Personal Data" -- Tex. Bus. & Com. Code 541.001(23); information linked or reasonably linkable to an identified or identifiable individual.

1.2 "Sensitive Data" -- Tex. Bus. & Com. Code 541.001(29); racial/ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship/immigration status, genetic data, biometric data, children's data (under 13), precise geolocation.

1.3 "Controller" -- Tex. Bus. & Com. Code 541.001(7).

1.4 "Processor" -- Tex. Bus. & Com. Code 541.001(24).

1.5 "Sale" -- Tex. Bus. & Com. Code 541.001(28); exchange for monetary consideration.

1.6 "Targeted Advertising" -- Tex. Bus. & Com. Code 541.001(31).

1.7 "Profiling" -- Tex. Bus. & Com. Code 541.001(26).

1.8 "De-Identified Data" -- Tex. Bus. & Com. Code 541.001(10).

1.9 "Consent" -- Tex. Bus. & Com. Code 541.001(6); clear affirmative act.

1.10 "Data Breach" -- Unauthorized acquisition of sensitive personal information per Tex. Bus. & Com. Code 521.002.


ARTICLE II: OPERATIONAL SCOPE

2.1 Transfer Type: ☐ Controller-to-Processor ☐ Controller-to-Controller ☐ Processor-to-Sub-Processor

2.2 Pre-Transfer Compliance Checklist:

☐ Written contract executed (this Addendum; Tex. Bus. & Com. Code 541.054)
☐ Processing instructions documented
☐ Privacy notice published per 541.051
☐ Sensitive Data consent obtained (if applicable)
☐ Data protection assessment completed (where required; 541.058)
☐ Universal opt-out mechanism enabled (effective Jan. 1, 2025)
☐ Data inventory completed (Exhibit C)
☐ Technical measures verified (Exhibit B)
☐ Subprocessor list reviewed
☐ Consumer rights response workflow established
☐ Breach notification plan documented

2.3 Purpose: [________________________________]

2.4 Personal Data Categories Checklist:

☐ Names and identifiers ☐ Email addresses ☐ Phone numbers
☐ Physical addresses ☐ Online identifiers (IP, device IDs, cookies)
☐ Commercial records ☐ Financial data ☐ Employment data
☐ Geolocation ☐ Internet activity ☐ Biometric data
☐ Health information ☐ Education records ☐ Inferences/profiles
☐ Sensitive Data (complete Article IV checklist)

2.5 Consumer Categories: ☐ Customers ☐ Employees ☐ Applicants ☐ End Users ☐ Business Contacts ☐ Children under 13 ☐ Other: [________________________________]

2.6 Duration: Agreement term plus [____] day wind-down.


ARTICLE III: COMPLIANCE FRAMEWORK

3.1 TDPSA Statutory Contract Matrix (Tex. Bus. & Com. Code 541.054):

Requirement Reference Status
Clear Processing instructions Article VI, 6.1 ☐ Complete
Nature and purpose stated Article II, 2.3 ☐ Complete
Data types specified Article II, 2.4 ☐ Complete
Duration specified Article II, 2.6 ☐ Complete
Confidentiality duty Article VI, 6.3 ☐ Complete
Deletion/return provision Article XI ☐ Complete
Compliance information available Article XII, 12.1 ☐ Complete
Assessment cooperation Article XII, 12.2 ☐ Complete
Subprocessor contract requirement Article IX ☐ Complete

3.2 Legal Basis:

☐ Consent ☐ Contractual necessity ☐ Legal obligation ☐ Vital interests ☐ Legitimate interests

3.3 Sensitive Data Consent: ☐ Required and obtained ☐ Not applicable

3.4 International Transfer: ☐ DPF ☐ SCCs Module [____] ☐ UK Addendum ☐ N/A


ARTICLE IV: DATA CLASSIFICATION

4.1 Standard Data Inventory:

Data Element Included Purpose Retention
Full name ☐ Yes ☐ No [________________________________] [____]
Email ☐ Yes ☐ No [________________________________] [____]
Phone ☐ Yes ☐ No [________________________________] [____]
Address ☐ Yes ☐ No [________________________________] [____]
DOB ☐ Yes ☐ No [________________________________] [____]
IP address ☐ Yes ☐ No [________________________________] [____]
Device IDs ☐ Yes ☐ No [________________________________] [____]
Purchase history ☐ Yes ☐ No [________________________________] [____]
Employment data ☐ Yes ☐ No [________________________________] [____]

4.2 Sensitive Data Checklist (541.001(29)):

Category Included Consent Method Consent Date
Racial/ethnic origin ☐ Yes ☐ No [________________________________] [__/__/____]
Religious beliefs ☐ Yes ☐ No [________________________________] [__/__/____]
Health diagnosis ☐ Yes ☐ No [________________________________] [__/__/____]
Sexual orientation ☐ Yes ☐ No [________________________________] [__/__/____]
Citizenship/immigration ☐ Yes ☐ No [________________________________] [__/__/____]
Genetic data ☐ Yes ☐ No [________________________________] [__/__/____]
Biometric data ☐ Yes ☐ No [________________________________] [__/__/____]
Child data (under 13) ☐ Yes ☐ No [________________________________] [__/__/____]
Precise geolocation ☐ Yes ☐ No [________________________________] [__/__/____]

4.3 Identity Theft Act Data (521.002):

Category Included
SSN ☐ Yes ☐ No
Driver's license/govt ID ☐ Yes ☐ No
Financial account + credentials ☐ Yes ☐ No
Credit/debit card + security code ☐ Yes ☐ No
Health-related identifying info ☐ Yes ☐ No

ARTICLE V: TRANSFEROR OPERATIONAL OBLIGATIONS

5.1 Privacy Notice Checklist (541.051):

☐ Categories of Personal Data disclosed
☐ Processing purposes disclosed
☐ Consumer rights and exercise methods disclosed
☐ Categories of third-party recipients disclosed
☐ Sale and Targeted Advertising opt-out described
☐ Contact information provided

5.2 Data Minimization. Only data adequate, relevant, and reasonably necessary (541.052(a)).

5.3 Purpose Limitation. No Processing for incompatible purposes (541.052(b)).

5.4 Opt-Out Forwarding. Notify Transferee within [____] business days of any opt-out, deletion, or correction request.

5.5 DPA Tracking:

Assessment Type Required Completed Date
Targeted Advertising ☐ Yes ☐ No [__/__/____]
Sale of Personal Data ☐ Yes ☐ No [__/__/____]
Profiling (foreseeable risk) ☐ Yes ☐ No [__/__/____]
Sensitive Data Processing ☐ Yes ☐ No [__/__/____]
Other heightened risk ☐ Yes ☐ No [__/__/____]

5.6 Monitoring Schedule:

Activity Frequency Last Done Next Due
Privacy notice review Annually [__/__/____] [__/__/____]
Data inventory update Annually [__/__/____] [__/__/____]
DPA review Annually [__/__/____] [__/__/____]
Subprocessor review Quarterly [__/__/____] [__/__/____]
Consumer rights process test Annually [__/__/____] [__/__/____]
Breach drill Annually [__/__/____] [__/__/____]

ARTICLE VI: TRANSFEREE OPERATIONAL OBLIGATIONS

6.1 Required Actions Checklist:

☐ Process only per Transferor's documented instructions
☐ Maintain confidentiality of Personal Data
☐ Implement appropriate technical and organizational measures
☐ Assist with Consumer rights requests
☐ Cooperate with data protection assessments
☐ Comply with breach notification requirements
☐ Delete or return data upon termination
☐ Make compliance information available
☐ Allow and cooperate with assessments

6.2 Prohibited Actions Checklist:

☐ The Transferee shall NOT Sell Personal Data
☐ The Transferee shall NOT Process for Targeted Advertising without authorization
☐ The Transferee shall NOT Profile Consumers without authorization
☐ The Transferee shall NOT Process for unauthorized purposes
☐ The Transferee shall NOT combine data from other sources without direction

6.3 Confidentiality. All personnel with data access bound by confidentiality obligations (541.054(b)(1)).

6.4 De-Identification. Where de-identifying, Transferee shall: take reasonable measures to ensure data cannot be associated with an individual; publicly commit to maintaining de-identified form; not attempt re-identification.

6.5 Inability to Comply. Promptly notify Transferor. Transferor may suspend Transfer and/or terminate.


ARTICLE VII: TECHNICAL MEASURES

7.1 Security Controls Status:

Control Status Last Verified Next Review
TLS 1.2+ encryption ☐ Active ☐ Pending [__/__/____] [__/__/____]
AES-256 at-rest encryption ☐ Active ☐ Pending [__/__/____] [__/__/____]
MFA (admin/remote) ☐ Active ☐ Pending [__/__/____] [__/__/____]
RBAC ☐ Active ☐ Pending [__/__/____] [__/__/____]
Vulnerability scanning ☐ Active ☐ Pending [__/__/____] [__/__/____]
Penetration testing ☐ Active ☐ Pending [__/__/____] [__/__/____]
SIEM/monitoring ☐ Active ☐ Pending [__/__/____] [__/__/____]
Incident response plan ☐ Active ☐ Pending [__/__/____] [__/__/____]
Employee training ☐ Active ☐ Pending [__/__/____] [__/__/____]
BC/DR plan ☐ Active ☐ Pending [__/__/____] [__/__/____]

7.2 Enhanced Sensitive Data Measures. If Sensitive Data processed: field-level encryption; tokenization in non-prod; real-time alerts; segregated storage; annual PIA.

7.3 Data Disposal (521.052). Sensitive personal information disposed of using shredding, erasing, or other methods rendering data unreadable or undecipherable.


ARTICLE VIII: CONSUMER RIGHTS OPERATIONS

8.1 Rights Response Workflow:

Step Action Timeline
1 Consumer request received Day 0
2 Request forwarded to Transferee Within [____] days
3 Transferee searches/compiles data Within [____] days
4 Transferee provides results Within [____] days
5 Transferor responds to Consumer Within 45 days
6 Extension notice (if needed) Before Day 45
7 Final response (with extension) Within 90 days
8 Appeal response (if applicable) Within 60 days of appeal

8.2 Rights Coverage Matrix:

Right Citation Deadline Transferee Action
Confirm/Access 541.055(a)(1) 45 days (+45) Provide data
Correct 541.055(a)(2) 45 days (+45) Correct data
Delete 541.055(a)(3) 45 days (+45) Delete + notify subprocessors
Portability 541.055(a)(4) 45 days Machine-readable format
Opt out -- Targeted Ads 541.055(a)(5)(A) Promptly Cease targeting
Opt out -- Sale 541.055(a)(5)(B) Promptly Cease sale
Opt out -- Profiling 541.055(a)(5)(C) Promptly Cease profiling

8.3 Universal Opt-Out. GPC and equivalent signals honored (541.055(e), effective Jan. 1, 2025).

8.4 Non-Discrimination. No adverse treatment for exercising rights (541.056).


ARTICLE IX: SUBPROCESSOR MANAGEMENT

9.1 Authorization: ☐ Specific ☐ General (with [____] days' notice)

9.2 Subprocessor Tracker:

Subprocessor Location Activity Approved Date Review Due
[________________________________] [____] [________________________________] [__/__/____] [__/__/____]
[________________________________] [____] [________________________________] [__/__/____] [__/__/____]
[________________________________] [____] [________________________________] [__/__/____] [__/__/____]

9.3 Flow-Down Checklist:

☐ Processing limited to documented instructions
☐ Confidentiality obligations
☐ Technical/organizational measures
☐ Consumer rights cooperation
☐ Breach notification
☐ Audit rights
☐ Deletion/return on termination
☐ No Sale/Targeted Advertising without authorization

9.4 Liability. Transferee fully liable (541.054(d)).


ARTICLE X: DATA BREACH RESPONSE

10.1 Response Timeline:

Step Action Deadline
1 Breach detected/suspected Trigger
2 Transferee notifies Transferor Within [____] hours
3 Initial details provided With notification
4 Updates Every [____] hours
5 Individual notification Within 60 days of determination
6 AG notification (250+ TX residents) Within 30 days of determination

10.2 Breach Response Checklist:

☐ Breach contained
☐ Transferor notified within required timeframe
☐ Scope identified (number of Consumers, data categories)
☐ Sensitive personal information involvement assessed
☐ Law enforcement notification evaluated
☐ Consumer notification drafted (per 521.053)
☐ AG notification prepared (if 250+ TX residents, within 30 days)
☐ Credit monitoring arranged (if applicable)
☐ Root cause analysis initiated
☐ Remediation plan developed

10.3 Penalties. Late notification: up to $100/day/individual (521.151). TDPSA violations: up to $7,500/violation (541.155). AG 30-day cure opportunity before enforcement (541.154).

10.4 Indemnification. Transferee indemnifies for breach-related costs attributable to its security failures.


ARTICLE XI: DATA RETENTION AND DELETION

11.1 Retention Schedule:

Category Period Basis Method
[________________________________] [____] [________________________________] [________________________________]
[________________________________] [____] [________________________________] [________________________________]
[________________________________] [____] [________________________________] [________________________________]

11.2 Deletion Checklist:

☐ Return/deletion election received
☐ Primary data purged
☐ Backup deletion scheduled (within [____] months)
☐ Subprocessors notified
☐ Certification prepared and delivered (within [____] days)
☐ 521.052 disposal methods applied

11.3 Legal Hold. Permitted if required by law; Transferor notified; minimum data; protections continue.


ARTICLE XII: AUDIT AND MONITORING

12.1 Information Availability (541.054(b)(3)). All compliance information available upon request.

12.2 Assessment Cooperation (541.054(b)(4)). Reasonable assessments by Transferor or designated assessor.

12.3 Monitoring Schedule:

Activity Frequency Last Done Next Due
Compliance review Annually [__/__/____] [__/__/____]
Technical security assessment Annually [__/__/____] [__/__/____]
Subprocessor audit Annually [__/__/____] [__/__/____]
DPA support verification As needed [__/__/____] [__/__/____]

12.4 Evidence. SOC 2 Type II; ISO 27001; pen test summary; SIG/CAIQ; PIA docs; training records.

12.5 On-Site. [____] per year; [____] days' notice; NDA; Transferor bears cost unless non-compliance.

12.6 AG Cooperation. Transferee cooperates with Texas AG investigations.

12.7 Remediation. [____] days to remediate; evidence provided.


ARTICLE XIII: CROSS-BORDER PROVISIONS

13.1 Interstate. TDPSA applies to TX Consumer data regardless of Processing location.

13.2 International. Transfer mechanisms per Article III, Section 3.4.

13.3 Location: ☐ US only ☐ US + EEA/UK ☐ Specific: [________________________________] ☐ No restriction

13.4 Relocation Notice. [____] days prior.


ARTICLE XIV: LIABILITY

14.1 Mutual indemnification for Addendum breaches.

14.2 Transferee Indemnification: AG fines (up to $7,500/violation); notification penalties ($100/day/individual); breach costs; investigation costs.

14.3 Enforcement. AG only; no private right of action under TDPSA. DTPA may provide indirect claims. AG 30-day cure period (541.154).

14.4 Cap. Agreement cap applies except for unauthorized Sale, willful misconduct, notification failures.


ARTICLE XV: TERM AND TERMINATION

15.1 Term. Coterminous with Agreement.
15.2 Cure Period. [____] days.
15.3 Survival. Articles I, VI, VII, VIII, X, XI, XII, XIV survive.


ARTICLE XVI: EXECUTION

TRANSFEROR (CONTROLLER):

Signature: [________________________________]
Printed Name: [________________________________]
Title: [________________________________]
Organization: [________________________________]
Date: [__/__/____]

TRANSFEREE (PROCESSOR):

Signature: [________________________________]
Printed Name: [________________________________]
Title: [________________________________]
Organization: [________________________________]
Date: [__/__/____]


EXHIBIT A: RISK ASSESSMENT

Factor Rating Notes
Security ☐ Low ☐ Med ☐ High [________________________________]
Consumer rights ☐ Low ☐ Med ☐ High [________________________________]
Subprocessor risk ☐ Low ☐ Med ☐ High [________________________________]
AG enforcement ☐ Low ☐ Med ☐ High [________________________________]
Breach readiness ☐ Low ☐ Med ☐ High [________________________________]

Overall: ☐ Proceed ☐ Proceed with measures ☐ Do not proceed


EXHIBIT B: TECHNICAL MEASURES

Control Implemented Verified Date
TLS 1.2+ ☐ Yes ☐ No [________________________________] [__/__/____]
AES-256 ☐ Yes ☐ No [________________________________] [__/__/____]
RBAC ☐ Yes ☐ No [________________________________] [__/__/____]
MFA ☐ Yes ☐ No [________________________________] [__/__/____]
SIEM ☐ Yes ☐ No [________________________________] [__/__/____]
SOC 2 ☐ Yes ☐ No Expiry: [__/__/____]
ISO 27001 ☐ Yes ☐ No Expiry: [__/__/____]

EXHIBIT C: DATA INVENTORY AND SUBPROCESSORS

# Data Element Sensitive Source Purpose Retention Disposal
1 [________________________________] [________] [________________________________] [____] [________________________________]
2 [________________________________] [________] [________________________________] [____] [________________________________]
3 [________________________________] [________] [________________________________] [____] [________________________________]

SOURCES AND REFERENCES

Ezel AI
Hi! Need help customizing this document? I can tailor every section to your specific case in minutes.
AI Legal Assistant
Ezel AI
Hi! Need help customizing this document? I can tailor every section to your specific case in minutes.

Insert Image

Insert Table

Watch Ezel in action (sample case)

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
dpa_short_form_transfer_addendum_tx.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Customize this document with Ezel

  • Deep Legal Knowledge
    Understands case law, statutes, and legal doctrine specific to Texas.
  • Court-Ready Formatting
    Proper captions, certificates of service, and local rule compliance.
  • AI-Powered Editing on Your Timeline
    Edit as many times as you need. Tailor every section to your specific case.
  • Export as PDF & Word
    Download your finished document in professional PDF or DOCX format, ready to file or send.
Secure checkout via Stripe
Need to customize this document?

About This Template

A contract is a written record of what two or more parties agreed to and what happens if someone does not follow through. Clear language, defined terms, and clean signature blocks keep disputes small and enforceable. The most common mistakes in contracts come from vague promises, missing details about timing or payment, and skipping standard protective clauses like governing law and dispute resolution.

Important Notice

This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Last updated: March 2026