Texas TDPSA Privacy Notice

Texas Compliance & Regulatory Updated August 30, 2026 Free Word and PDF

TEXAS DATA PRIVACY AND SECURITY ACT PRIVACY NOTICE

Effective date: [__/__/____]

Last updated: [__/__/____]

Important Use Gate

This template is a Texas consumer-notice and compliance-control packet. It is not a determination that the Texas Data Privacy and Security Act (TDPSA) applies.

Before publication, counsel must classify the organization and each processing activity under current Tex. Bus. & Com. Code Chapter 541. Do not describe an activity as exempt merely because some data is regulated by another law; document whether an entity-level, data-level, role-specific, or use-specific provision applies.

The TDPSA generally took effect July 1, 2024. The technology-based authorized-agent provision in § 541.055(e) took effect January 1, 2025. The processor security-assistance amendment concerning applicable data handled by an artificial intelligence system took effect January 1, 2026.

1. Publisher and Notice Scope

Controller legal name: [________________________________]

Trade names covered: [________________________________]

Covered websites, applications, products, services, and offline interactions: [________________________________]

Controller address: [________________________________]

Privacy email: [________________________________]

Rights-request page: [________________________________]

Appeal method: [________________________________]

Texas Attorney General complaint mechanism to provide after a denied appeal: [________________________________]

This Notice describes how [CONTROLLER NAME] ("we," "us," or "our") processes personal data relating to Texas consumers through the covered services identified above.

A "consumer" under Tex. Bus. & Com. Code § 541.001(7) is a Texas resident acting only in an individual or household context. The definition excludes an individual acting in a commercial or employment context.

2. Coverage and Exemption Record

Section 541.002 applies Chapter 541 only when all three applicability elements are satisfied. Section 541.107 separately imposes a prior-consent rule on a covered small business that sells sensitive personal data.

Question Answer and evidence Counsel conclusion
Do we conduct business in Texas or produce a product or service consumed by Texas residents? [________________________________] [YES / NO / UNCERTAIN]
Do we process or engage in the sale of personal data? [________________________________] [YES / NO / UNCERTAIN]
Are we a small business under the current U.S. Small Business Administration definition applicable to us? [________________________________] [YES / NO / UNCERTAIN]
If small, do we sell personal data that is sensitive data? [________________________________] [YES / NO / UNCERTAIN]
Does an entity-level exclusion in § 541.002(b) apply? [CITE EXACT SUBSECTION AND FACTS] [YES / NO / PARTIAL]
Does a data- or use-specific exemption in Subchapter E apply? [CITE EXACT SECTION AND FACTS] [YES / NO / PARTIAL]
Are we acting as controller, processor, third party, or in multiple roles? [ACTIVITY-BY-ACTIVITY ANALYSIS] [________________________________]
Final coverage classification [IN SCOPE / SMALL-BUSINESS § 541.107 DUTY ONLY / OUT OF SCOPE / MIXED] Approved by: [________]

Do not publish an exemption conclusion in this Notice unless consumers need it and counsel has approved the wording.

3. Categories of Personal Data We Process

Personal data means information, including sensitive data, linked or reasonably linkable to an identified or identifiable individual. It does not include deidentified data or publicly available information as those terms are defined in § 541.001.

Category Examples actually processed Sources Purposes Retention period or criteria
Identifiers and contact information [Specify] [Specify] [Specify] [Specify]
Account and authentication data [Specify] [Specify] [Specify] [Specify]
Transaction and commercial data [Specify] [Specify] [Specify] [Specify]
Device, network, and online activity [Specify] [Specify] [Specify] [Specify]
Location data [Specify] [Specify] [Specify] [Specify]
Communications and user content [Specify] [Specify] [Specify] [Specify]
Preferences and inferences [Specify] [Specify] [Specify] [Specify]
Sensitive data [Specify or state none] [Specify] [Specify] [Specify]
Known-child data [Specify or state none] [Specify] [Specify] [Specify]
Other personal data [Specify] [Specify] [Specify] [Specify]

For this Notice, sensitive data includes the categories stated in § 541.001(29): specified protected-characteristic and health data, genetic or biometric data processed to uniquely identify an individual, personal data collected from a known child, and precise geolocation data.

4. Purposes for Processing

We process the categories identified above for the following disclosed purposes:

  • [Provide, operate, maintain, and improve specified products or services.]
  • [Create and administer accounts and transactions.]
  • [Communicate about support, service, security, and requested information.]
  • [Authenticate users and detect fraud, abuse, and security incidents.]
  • [Conduct analytics, research, advertising, or campaign measurement.]
  • [Comply with law and protect rights, safety, and systems.]
  • [Evaluate or complete a corporate transaction.]
  • [Other purpose stated with enough detail for the affected consumer.]

Section 541.101 limits collection to what is adequate, relevant, and reasonably necessary for disclosed purposes. We obtain consent before processing for a purpose that is neither reasonably necessary to nor compatible with the disclosed purpose unless Chapter 541 otherwise permits the processing.

5. How We Share Personal Data

Third-party category Personal-data categories shared Purpose
Hosting, cloud, security, and IT providers [Specify] [Specify]
Payment and transaction providers [Specify] [Specify]
Analytics providers [Specify] [Specify]
Advertising and social-media partners [Specify] [Specify]
Customer-support and fulfillment providers [Specify] [Specify]
Professional advisers [Specify] [Specify]
Affiliates [Specify] [Specify]
Government authorities and litigants [Specify] [Specify]
Corporate-transaction recipients [Specify] [Specify]
Other recipients [Specify] [Specify]

Section 541.102 requires the applicable categories of personal data shared with third parties and the applicable categories of third parties. Confirm that this table covers both.

6. Sale, Targeted Advertising, Profiling, and Sensitive Data

Sale of Personal Data

☐ We do not sell personal data as defined by § 541.001(28).

☐ We sell these categories of personal data: [________________________________].

Categories of third-party purchasers or recipients: [________________________________]

Sale opt-out method: [________________________________]

Targeted Advertising

☐ We do not process personal data for targeted advertising as defined by § 541.001(31).

☐ We process these categories for targeted advertising: [________________________________].

Targeted-advertising opt-out method: [________________________________]

Profiling

☐ We do not use solely automated profiling in furtherance of a decision producing a legal or similarly significant effect concerning a consumer.

☐ We conduct the following covered profiling: [________________________________].

Profiling opt-out method: [________________________________]

Sensitive Data and Required Sale Notices

We obtain consent before processing sensitive data when § 541.101(b)(4) applies. We process sensitive data of a known child in accordance with that subsection's Children's Online Privacy Protection Act requirement.

☐ We do not sell sensitive personal data.

☐ We sell sensitive personal data and post the following notice in the same location and manner as this Notice:

NOTICE: We may sell your sensitive personal data.

☐ We do not sell biometric personal data.

☐ We sell biometric personal data and post the following notice in the same location and manner as this Notice:

NOTICE: We may sell your biometric personal data.

If we sell personal data or process it for targeted advertising, § 541.103 requires a clear and conspicuous disclosure of the activity and the opt-out method.

7. Texas Consumer Rights

Subject to authentication and applicable statutory provisions, a Texas consumer may request to:

  • confirm whether we process the consumer's personal data and access that data;
  • correct inaccuracies, considering the data's nature and processing purposes;
  • delete personal data provided by or obtained about the consumer;
  • when available digitally, obtain a portable and readily usable copy of personal data the consumer previously provided to us; and
  • opt out of targeted advertising, sale of personal data, or profiling in furtherance of a decision producing a legal or similarly significant effect.

A parent or legal guardian may exercise § 541.051 rights regarding personal data belonging to a known child.

We do not discriminate against a consumer for exercising a Chapter 541 right, subject to the qualifications in § 541.101(c).

8. Submitting and Authenticating Requests

Request methods:

  • Web form: [________________________________]
  • Email: [________________________________]
  • Telephone: [________________________________]
  • Postal address: [________________________________]
  • Other secure method: [________________________________]

Section 541.055 generally requires at least two secure and reliable request methods. A controller operating exclusively online with a direct relationship to the consumer from whom it collects personal information may qualify for the email-only rule in § 541.055(d).

We do not require a consumer to create a new account to exercise a right. We may require use of an existing account and may request information reasonably necessary to authenticate a consumer and the request.

Authorized Agents and Technology-Based Opt-Out Requests

A consumer may designate an authorized agent to opt out of sale or targeted advertising. The designation may use qualifying technology described by § 541.055(e)-(f).

Technology or signal evaluated: [________________________________]

Clear, affirmative, freely given, and unambiguous choice confirmed: ☐ Yes ☐ No

Texas residency, consumer identity, and agent authority verification: [________________________________]

Technical capability and comparable-request handling: [________________________________]

Do not state that every browser signal is automatically honored. Document the statutory verification requirements and exceptions, then describe the controller's actual implementation accurately.

9. Response Timing, Fees, and Appeals

We respond without undue delay and no later than 45 days after receiving a request. When reasonably necessary because of complexity or request volume, we may extend once for an additional 45 days if we notify the consumer within the initial period and explain the reason.

We provide request information free at least twice annually per consumer. If a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to act, and we bear the burden specified in § 541.052(d).

If we decline a request, we provide the justification and appeal instructions without undue delay and no later than 45 days after receipt.

Appeal method: [________________________________]

Our appeal process is conspicuously available and similar to the request process. We respond in writing no later than 60 days after receiving an appeal and explain the decision. If we deny the appeal, we provide the Texas Attorney General's current online complaint mechanism.

10. Security, Minimization, and Deidentified Data

We maintain reasonable administrative, technical, and physical data-security practices appropriate to the volume and nature of the personal data. No security measure guarantees absolute security.

We limit collection as described in Section 4. For deidentified data, complete the § 541.106 control record before making any public commitment:

Deidentified-data control Implementation
Reasonable measures against association with an individual [________________________________]
Public commitment not to attempt reidentification [________________________________]
Contractual obligations imposed on recipients [________________________________]
Oversight of contractual commitments [________________________________]

11. Retention and Processing Locations

We retain each category of personal data for [STATE PERIOD OR CRITERIA], considering the disclosed purpose and applicable legal, accounting, security, fraud-prevention, and dispute needs.

Personal data may be processed in [COUNTRIES OR REGIONS] by [CONTROLLER / PROCESSOR CATEGORIES]. Describe any applicable transfer safeguards here: [________________________________].

12. Changes and Contact Information

The "Last updated" date identifies this Notice's current version. We will provide additional notice or obtain consent before a changed or incompatible processing purpose when Chapter 541 or another applicable law requires it.

Questions, requests, or complaints may be directed to:

[CONTROLLER LEGAL NAME]

Attn: [PRIVACY TEAM OR OFFICER]

[ADDRESS]

[EMAIL]

[PHONE]

13. Internal Controller Compliance Record

Required-Notice Cross-Check

§ 541.102 or § 541.103 item Notice section Verified against data inventory
Categories processed, including sensitive data if applicable Section 3 ☐
Processing purposes Section 4 ☐
Rights and appeal process Sections 7-9 ☐
Categories shared with third parties Section 5 ☐
Categories of third parties Section 5 ☐
Request methods Section 8 ☐
Sensitive-data sale notice, if applicable Section 6 ☐
Biometric-data sale notice, if applicable Section 6 ☐
Sale and targeted-advertising disclosure and opt-out Section 6 ☐

Processor Contract and Assistance Check

Section 541.104 governs processor duties and controller-processor contracts. As amended effective January 1, 2026, processor security assistance includes applicable personal data collected, stored, and processed by an artificial intelligence system.

Control Evidence
Processing instructions, nature, purpose, data type, and duration [________________________________]
Rights and obligations of both parties [________________________________]
Confidentiality duty [________________________________]
Consumer-request assistance [________________________________]
Security and breach assistance, including applicable AI-system data [________________________________]
Return or deletion after service, subject to law [________________________________]
Compliance information and assessment cooperation [________________________________]
Written subcontractor flow-down [________________________________]

Data Protection Assessment Check

Section 541.105 requires a documented assessment for each listed activity. Complete a separate assessment; this Notice does not satisfy that duty.

Activity Present? Assessment reference and date
Targeted advertising ☐ Yes ☐ No [________________________________]
Sale of personal data ☐ Yes ☐ No [________________________________]
Profiling with a listed reasonably foreseeable risk ☐ Yes ☐ No [________________________________]
Sensitive-data processing ☐ Yes ☐ No [________________________________]
Other processing presenting heightened risk of harm ☐ Yes ☐ No [________________________________]

Enforcement Awareness

The Texas Attorney General has exclusive authority to enforce Chapter 541. Section 541.154 provides a 30-day notice-and-cure process before an enforcement action. Section 541.155 authorizes a civil penalty not exceeding $7,500 per violation after the cure period or for breach of a cure statement. Section 541.156 creates no private right of action.

Do not present the cure process as permission to delay compliance.

14. Approval and Version Control

Role Name Approval / date
Privacy owner [________________________________] [________________________________]
Security owner [________________________________] [________________________________]
Data owner [________________________________] [________________________________]
Marketing / advertising owner [________________________________] [________________________________]
Qualified legal reviewer [________________________________] [________________________________]
Version Effective date Summary of change Approved by
[____] [__/__/____] [________________________________] [________________________________]

Sources and References


Conform every statement to the controller's actual data inventory, technology, contracts, request operations, and current law before publication.

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
tdpsa_privacy_notice_tx.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the Texas version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
August 30, 2026
Citations checked
August 30, 2026
Jurisdiction
Texas
Category
Compliance & Regulatory

Legal authority

  • Tex. Bus. & Com. Code § 541.001(7), (19), (24), (28)-(31) (core definitions)
  • Tex. Bus. & Com. Code § 541.002 (applicability)
  • Tex. Bus. & Com. Code § 541.051(b) (consumer rights)
  • Tex. Bus. & Com. Code § 541.052(b)-(e) (responses, fees, and authentication)
  • Tex. Bus. & Com. Code § 541.053 (appeals)
  • Tex. Bus. & Com. Code § 541.054 (waiver prohibition)
  • Tex. Bus. & Com. Code § 541.055 (request methods and authorized-agent opt-outs)
  • Tex. Bus. & Com. Code § 541.101 (controller duties)
  • Tex. Bus. & Com. Code § 541.102 (privacy notice)
  • Tex. Bus. & Com. Code § 541.103 (sale and targeted-advertising disclosure)
  • Tex. Bus. & Com. Code § 541.104 (processor duties and contracts)
  • Tex. Bus. & Com. Code § 541.105 (data protection assessments)
  • Tex. Bus. & Com. Code § 541.106(a), (d) (deidentified-data controls)
  • Tex. Bus. & Com. Code § 541.107 (small-business sensitive-data sale rule)
  • Tex. Bus. & Com. Code §§ 541.151, 541.154-.156 (exclusive public enforcement, cure, penalty, and no private action)
  • 2023 Tex. H.B. 4, § 7 (effective dates)
  • 2025 Tex. H.B. 149, §§ 3, 10 (processor AI-system amendment effective January 1, 2026)

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

A reviewer verified this template's legal citations against the official source on August 30, 2026.

Tex. Bus. & Com. Code § 541.001(7), (19), (24), (28)-(31) (checked August 30, 2026): ""Consumer" means an individual who is a resident of this state acting only in an individual or household context. The term does not include an individual acting in a commercial or employment context. "Personal data" means any information, including sensitive data, that is linked or reasonably linkable to an identified or identifiable individual. The term does not include deidentified data or publicly available information. "Profiling" means any form of solely automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. "Sale of personal data" means the sharing, disclosing, or transferring of personal data for monetary or other valuable consideration by the controller to a third party. "Sensitive data" means a category of personal data. The term includes personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; genetic or biometric data that is processed for the purpose of uniquely identifying an individual; personal data collected from a known child; or precise geolocation data. "Targeted advertising" means displaying to a consumer an advertisement that is selected based on personal data obtained from that consumer's activities over time and across nonaffiliated websites or online applications to predict the consumer's preferences or interests."

Tex. Bus. & Com. Code § 541.002 (checked August 30, 2026): "This chapter applies only to a person that: (1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision."

Tex. Bus. & Com. Code § 541.051(b) (checked August 30, 2026): "A controller shall comply with an authenticated consumer request to exercise the right to: (1) confirm whether a controller is processing the consumer's personal data and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer."

Tex. Bus. & Com. Code § 541.052(b)-(e) (checked August 30, 2026): "A controller shall respond to the consumer request without undue delay, which may not be later than the 45th day after the date of receipt of the request. The controller may extend the response period once by an additional 45 days when reasonably necessary, taking into account the complexity and number of the consumer's requests, so long as the controller informs the consumer of the extension within the initial 45-day response period, together with the reason for the extension. A controller shall provide information in response to a consumer request free of charge, at least twice annually per consumer."

Draft your Texas TDPSA Privacy Notice in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.