Texas TDPSA Privacy Notice
TEXAS DATA PRIVACY AND SECURITY ACT PRIVACY NOTICE
Effective date: [__/__/____]
Last updated: [__/__/____]
Important Use Gate
This template is a Texas consumer-notice and compliance-control packet. It is not a determination that the Texas Data Privacy and Security Act (TDPSA) applies.
Before publication, counsel must classify the organization and each processing activity under current Tex. Bus. & Com. Code Chapter 541. Do not describe an activity as exempt merely because some data is regulated by another law; document whether an entity-level, data-level, role-specific, or use-specific provision applies.
The TDPSA generally took effect July 1, 2024. The technology-based authorized-agent provision in § 541.055(e) took effect January 1, 2025. The processor security-assistance amendment concerning applicable data handled by an artificial intelligence system took effect January 1, 2026.
1. Publisher and Notice Scope
Controller legal name: [________________________________]
Trade names covered: [________________________________]
Covered websites, applications, products, services, and offline interactions: [________________________________]
Controller address: [________________________________]
Privacy email: [________________________________]
Rights-request page: [________________________________]
Appeal method: [________________________________]
Texas Attorney General complaint mechanism to provide after a denied appeal: [________________________________]
This Notice describes how [CONTROLLER NAME] ("we," "us," or "our") processes personal data relating to Texas consumers through the covered services identified above.
A "consumer" under Tex. Bus. & Com. Code § 541.001(7) is a Texas resident acting only in an individual or household context. The definition excludes an individual acting in a commercial or employment context.
2. Coverage and Exemption Record
Section 541.002 applies Chapter 541 only when all three applicability elements are satisfied. Section 541.107 separately imposes a prior-consent rule on a covered small business that sells sensitive personal data.
| Question | Answer and evidence | Counsel conclusion |
|---|---|---|
| Do we conduct business in Texas or produce a product or service consumed by Texas residents? | [________________________________] | [YES / NO / UNCERTAIN] |
| Do we process or engage in the sale of personal data? | [________________________________] | [YES / NO / UNCERTAIN] |
| Are we a small business under the current U.S. Small Business Administration definition applicable to us? | [________________________________] | [YES / NO / UNCERTAIN] |
| If small, do we sell personal data that is sensitive data? | [________________________________] | [YES / NO / UNCERTAIN] |
| Does an entity-level exclusion in § 541.002(b) apply? | [CITE EXACT SUBSECTION AND FACTS] | [YES / NO / PARTIAL] |
| Does a data- or use-specific exemption in Subchapter E apply? | [CITE EXACT SECTION AND FACTS] | [YES / NO / PARTIAL] |
| Are we acting as controller, processor, third party, or in multiple roles? | [ACTIVITY-BY-ACTIVITY ANALYSIS] | [________________________________] |
| Final coverage classification | [IN SCOPE / SMALL-BUSINESS § 541.107 DUTY ONLY / OUT OF SCOPE / MIXED] | Approved by: [________] |
Do not publish an exemption conclusion in this Notice unless consumers need it and counsel has approved the wording.
3. Categories of Personal Data We Process
Personal data means information, including sensitive data, linked or reasonably linkable to an identified or identifiable individual. It does not include deidentified data or publicly available information as those terms are defined in § 541.001.
| Category | Examples actually processed | Sources | Purposes | Retention period or criteria |
|---|---|---|---|---|
| Identifiers and contact information | [Specify] | [Specify] | [Specify] | [Specify] |
| Account and authentication data | [Specify] | [Specify] | [Specify] | [Specify] |
| Transaction and commercial data | [Specify] | [Specify] | [Specify] | [Specify] |
| Device, network, and online activity | [Specify] | [Specify] | [Specify] | [Specify] |
| Location data | [Specify] | [Specify] | [Specify] | [Specify] |
| Communications and user content | [Specify] | [Specify] | [Specify] | [Specify] |
| Preferences and inferences | [Specify] | [Specify] | [Specify] | [Specify] |
| Sensitive data | [Specify or state none] | [Specify] | [Specify] | [Specify] |
| Known-child data | [Specify or state none] | [Specify] | [Specify] | [Specify] |
| Other personal data | [Specify] | [Specify] | [Specify] | [Specify] |
For this Notice, sensitive data includes the categories stated in § 541.001(29): specified protected-characteristic and health data, genetic or biometric data processed to uniquely identify an individual, personal data collected from a known child, and precise geolocation data.
4. Purposes for Processing
We process the categories identified above for the following disclosed purposes:
- [Provide, operate, maintain, and improve specified products or services.]
- [Create and administer accounts and transactions.]
- [Communicate about support, service, security, and requested information.]
- [Authenticate users and detect fraud, abuse, and security incidents.]
- [Conduct analytics, research, advertising, or campaign measurement.]
- [Comply with law and protect rights, safety, and systems.]
- [Evaluate or complete a corporate transaction.]
- [Other purpose stated with enough detail for the affected consumer.]
Section 541.101 limits collection to what is adequate, relevant, and reasonably necessary for disclosed purposes. We obtain consent before processing for a purpose that is neither reasonably necessary to nor compatible with the disclosed purpose unless Chapter 541 otherwise permits the processing.
5. How We Share Personal Data
| Third-party category | Personal-data categories shared | Purpose |
|---|---|---|
| Hosting, cloud, security, and IT providers | [Specify] | [Specify] |
| Payment and transaction providers | [Specify] | [Specify] |
| Analytics providers | [Specify] | [Specify] |
| Advertising and social-media partners | [Specify] | [Specify] |
| Customer-support and fulfillment providers | [Specify] | [Specify] |
| Professional advisers | [Specify] | [Specify] |
| Affiliates | [Specify] | [Specify] |
| Government authorities and litigants | [Specify] | [Specify] |
| Corporate-transaction recipients | [Specify] | [Specify] |
| Other recipients | [Specify] | [Specify] |
Section 541.102 requires the applicable categories of personal data shared with third parties and the applicable categories of third parties. Confirm that this table covers both.
6. Sale, Targeted Advertising, Profiling, and Sensitive Data
Sale of Personal Data
☐ We do not sell personal data as defined by § 541.001(28).
☐ We sell these categories of personal data: [________________________________].
Categories of third-party purchasers or recipients: [________________________________]
Sale opt-out method: [________________________________]
Targeted Advertising
☐ We do not process personal data for targeted advertising as defined by § 541.001(31).
☐ We process these categories for targeted advertising: [________________________________].
Targeted-advertising opt-out method: [________________________________]
Profiling
☐ We do not use solely automated profiling in furtherance of a decision producing a legal or similarly significant effect concerning a consumer.
☐ We conduct the following covered profiling: [________________________________].
Profiling opt-out method: [________________________________]
Sensitive Data and Required Sale Notices
We obtain consent before processing sensitive data when § 541.101(b)(4) applies. We process sensitive data of a known child in accordance with that subsection's Children's Online Privacy Protection Act requirement.
☐ We do not sell sensitive personal data.
☐ We sell sensitive personal data and post the following notice in the same location and manner as this Notice:
NOTICE: We may sell your sensitive personal data.
☐ We do not sell biometric personal data.
☐ We sell biometric personal data and post the following notice in the same location and manner as this Notice:
NOTICE: We may sell your biometric personal data.
If we sell personal data or process it for targeted advertising, § 541.103 requires a clear and conspicuous disclosure of the activity and the opt-out method.
7. Texas Consumer Rights
Subject to authentication and applicable statutory provisions, a Texas consumer may request to:
- confirm whether we process the consumer's personal data and access that data;
- correct inaccuracies, considering the data's nature and processing purposes;
- delete personal data provided by or obtained about the consumer;
- when available digitally, obtain a portable and readily usable copy of personal data the consumer previously provided to us; and
- opt out of targeted advertising, sale of personal data, or profiling in furtherance of a decision producing a legal or similarly significant effect.
A parent or legal guardian may exercise § 541.051 rights regarding personal data belonging to a known child.
We do not discriminate against a consumer for exercising a Chapter 541 right, subject to the qualifications in § 541.101(c).
8. Submitting and Authenticating Requests
Request methods:
- Web form: [________________________________]
- Email: [________________________________]
- Telephone: [________________________________]
- Postal address: [________________________________]
- Other secure method: [________________________________]
Section 541.055 generally requires at least two secure and reliable request methods. A controller operating exclusively online with a direct relationship to the consumer from whom it collects personal information may qualify for the email-only rule in § 541.055(d).
We do not require a consumer to create a new account to exercise a right. We may require use of an existing account and may request information reasonably necessary to authenticate a consumer and the request.
Authorized Agents and Technology-Based Opt-Out Requests
A consumer may designate an authorized agent to opt out of sale or targeted advertising. The designation may use qualifying technology described by § 541.055(e)-(f).
Technology or signal evaluated: [________________________________]
Clear, affirmative, freely given, and unambiguous choice confirmed: ☐ Yes ☐ No
Texas residency, consumer identity, and agent authority verification: [________________________________]
Technical capability and comparable-request handling: [________________________________]
Do not state that every browser signal is automatically honored. Document the statutory verification requirements and exceptions, then describe the controller's actual implementation accurately.
9. Response Timing, Fees, and Appeals
We respond without undue delay and no later than 45 days after receiving a request. When reasonably necessary because of complexity or request volume, we may extend once for an additional 45 days if we notify the consumer within the initial period and explain the reason.
We provide request information free at least twice annually per consumer. If a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee or decline to act, and we bear the burden specified in § 541.052(d).
If we decline a request, we provide the justification and appeal instructions without undue delay and no later than 45 days after receipt.
Appeal method: [________________________________]
Our appeal process is conspicuously available and similar to the request process. We respond in writing no later than 60 days after receiving an appeal and explain the decision. If we deny the appeal, we provide the Texas Attorney General's current online complaint mechanism.
10. Security, Minimization, and Deidentified Data
We maintain reasonable administrative, technical, and physical data-security practices appropriate to the volume and nature of the personal data. No security measure guarantees absolute security.
We limit collection as described in Section 4. For deidentified data, complete the § 541.106 control record before making any public commitment:
| Deidentified-data control | Implementation |
|---|---|
| Reasonable measures against association with an individual | [________________________________] |
| Public commitment not to attempt reidentification | [________________________________] |
| Contractual obligations imposed on recipients | [________________________________] |
| Oversight of contractual commitments | [________________________________] |
11. Retention and Processing Locations
We retain each category of personal data for [STATE PERIOD OR CRITERIA], considering the disclosed purpose and applicable legal, accounting, security, fraud-prevention, and dispute needs.
Personal data may be processed in [COUNTRIES OR REGIONS] by [CONTROLLER / PROCESSOR CATEGORIES]. Describe any applicable transfer safeguards here: [________________________________].
12. Changes and Contact Information
The "Last updated" date identifies this Notice's current version. We will provide additional notice or obtain consent before a changed or incompatible processing purpose when Chapter 541 or another applicable law requires it.
Questions, requests, or complaints may be directed to:
[CONTROLLER LEGAL NAME]
Attn: [PRIVACY TEAM OR OFFICER]
[ADDRESS]
[EMAIL]
[PHONE]
13. Internal Controller Compliance Record
Required-Notice Cross-Check
| § 541.102 or § 541.103 item | Notice section | Verified against data inventory |
|---|---|---|
| Categories processed, including sensitive data if applicable | Section 3 | ☐ |
| Processing purposes | Section 4 | ☐ |
| Rights and appeal process | Sections 7-9 | ☐ |
| Categories shared with third parties | Section 5 | ☐ |
| Categories of third parties | Section 5 | ☐ |
| Request methods | Section 8 | ☐ |
| Sensitive-data sale notice, if applicable | Section 6 | ☐ |
| Biometric-data sale notice, if applicable | Section 6 | ☐ |
| Sale and targeted-advertising disclosure and opt-out | Section 6 | ☐ |
Processor Contract and Assistance Check
Section 541.104 governs processor duties and controller-processor contracts. As amended effective January 1, 2026, processor security assistance includes applicable personal data collected, stored, and processed by an artificial intelligence system.
| Control | Evidence |
|---|---|
| Processing instructions, nature, purpose, data type, and duration | [________________________________] |
| Rights and obligations of both parties | [________________________________] |
| Confidentiality duty | [________________________________] |
| Consumer-request assistance | [________________________________] |
| Security and breach assistance, including applicable AI-system data | [________________________________] |
| Return or deletion after service, subject to law | [________________________________] |
| Compliance information and assessment cooperation | [________________________________] |
| Written subcontractor flow-down | [________________________________] |
Data Protection Assessment Check
Section 541.105 requires a documented assessment for each listed activity. Complete a separate assessment; this Notice does not satisfy that duty.
| Activity | Present? | Assessment reference and date |
|---|---|---|
| Targeted advertising | ☐ Yes ☐ No | [________________________________] |
| Sale of personal data | ☐ Yes ☐ No | [________________________________] |
| Profiling with a listed reasonably foreseeable risk | ☐ Yes ☐ No | [________________________________] |
| Sensitive-data processing | ☐ Yes ☐ No | [________________________________] |
| Other processing presenting heightened risk of harm | ☐ Yes ☐ No | [________________________________] |
Enforcement Awareness
The Texas Attorney General has exclusive authority to enforce Chapter 541. Section 541.154 provides a 30-day notice-and-cure process before an enforcement action. Section 541.155 authorizes a civil penalty not exceeding $7,500 per violation after the cure period or for breach of a cure statement. Section 541.156 creates no private right of action.
Do not present the cure process as permission to delay compliance.
14. Approval and Version Control
| Role | Name | Approval / date |
|---|---|---|
| Privacy owner | [________________________________] | [________________________________] |
| Security owner | [________________________________] | [________________________________] |
| Data owner | [________________________________] | [________________________________] |
| Marketing / advertising owner | [________________________________] | [________________________________] |
| Qualified legal reviewer | [________________________________] | [________________________________] |
| Version | Effective date | Summary of change | Approved by |
|---|---|---|---|
| [____] | [__/__/____] | [________________________________] | [________________________________] |
Sources and References
- Current Texas Business & Commerce Code Chapter 541
- H.B. 4 enrolled text establishing the TDPSA
- H.B. 149 enrolled text containing the 2026 processor amendment
- Texas Attorney General TDPSA information and complaint link
Conform every statement to the controller's actual data inventory, technology, contracts, request operations, and current law before publication.
About this template
- Last updated
- August 30, 2026
- Citations checked
- August 30, 2026
- Jurisdiction
- Texas
- Category
- Compliance & Regulatory
Legal authority
- Tex. Bus. & Com. Code § 541.001(7), (19), (24), (28)-(31) (core definitions)
- Tex. Bus. & Com. Code § 541.002 (applicability)
- Tex. Bus. & Com. Code § 541.051(b) (consumer rights)
- Tex. Bus. & Com. Code § 541.052(b)-(e) (responses, fees, and authentication)
- Tex. Bus. & Com. Code § 541.053 (appeals)
- Tex. Bus. & Com. Code § 541.054 (waiver prohibition)
- Tex. Bus. & Com. Code § 541.055 (request methods and authorized-agent opt-outs)
- Tex. Bus. & Com. Code § 541.101 (controller duties)
- Tex. Bus. & Com. Code § 541.102 (privacy notice)
- Tex. Bus. & Com. Code § 541.103 (sale and targeted-advertising disclosure)
- Tex. Bus. & Com. Code § 541.104 (processor duties and contracts)
- Tex. Bus. & Com. Code § 541.105 (data protection assessments)
- Tex. Bus. & Com. Code § 541.106(a), (d) (deidentified-data controls)
- Tex. Bus. & Com. Code § 541.107 (small-business sensitive-data sale rule)
- Tex. Bus. & Com. Code §§ 541.151, 541.154-.156 (exclusive public enforcement, cure, penalty, and no private action)
- 2023 Tex. H.B. 4, § 7 (effective dates)
- 2025 Tex. H.B. 149, §§ 3, 10 (processor AI-system amendment effective January 1, 2026)
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on August 30, 2026.
Tex. Bus. & Com. Code § 541.001(7), (19), (24), (28)-(31) (checked August 30, 2026): ""Consumer" means an individual who is a resident of this state acting only in an individual or household context. The term does not include an individual acting in a commercial or employment context. "Personal data" means any information, including sensitive data, that is linked or reasonably linkable to an identified or identifiable individual. The term does not include deidentified data or publicly available information. "Profiling" means any form of solely automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location, or movements. "Sale of personal data" means the sharing, disclosing, or transferring of personal data for monetary or other valuable consideration by the controller to a third party. "Sensitive data" means a category of personal data. The term includes personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; genetic or biometric data that is processed for the purpose of uniquely identifying an individual; personal data collected from a known child; or precise geolocation data. "Targeted advertising" means displaying to a consumer an advertisement that is selected based on personal data obtained from that consumer's activities over time and across nonaffiliated websites or online applications to predict the consumer's preferences or interests."
Tex. Bus. & Com. Code § 541.002 (checked August 30, 2026): "This chapter applies only to a person that: (1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision."
Tex. Bus. & Com. Code § 541.051(b) (checked August 30, 2026): "A controller shall comply with an authenticated consumer request to exercise the right to: (1) confirm whether a controller is processing the consumer's personal data and to access the personal data; (2) correct inaccuracies in the consumer's personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer's personal data; (3) delete personal data provided by or obtained about the consumer; (4) if the data is available in a digital format, obtain a copy of the consumer's personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another controller without hindrance; or (5) opt out of the processing of the personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer."
Tex. Bus. & Com. Code § 541.052(b)-(e) (checked August 30, 2026): "A controller shall respond to the consumer request without undue delay, which may not be later than the 45th day after the date of receipt of the request. The controller may extend the response period once by an additional 45 days when reasonably necessary, taking into account the complexity and number of the consumer's requests, so long as the controller informs the consumer of the extension within the initial 45-day response period, together with the reason for the extension. A controller shall provide information in response to a consumer request free of charge, at least twice annually per consumer."
Draft your Texas TDPSA Privacy Notice in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.