Law / United States /
Texas
Texas Data Privacy and Security Act, Attorney General enforcement
Tex. Bus. & Com. Code secs. 541.151, 541.154-541.156
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 July 2024.
An enforcement supervision rule binding private bodies.
As of 23 August 2026.
What it requires
- Expect TDPSA violations to be enforced exclusively by the Texas Attorney General, never by a private plaintiff.
- Cure a violation and confirm the cure in writing within 30 days of Attorney General notice to avoid a civil penalty of up to $7,500 per violation.
- Do not treat the absence of individual lawsuits as low risk. The Attorney General is actively litigating a TDPSA enforcement action over data sales through embedded SDKs.
If you get it wrong
Private right of actionNo
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Texas Attorney General has exclusive authority to enforce TDPSA. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated; curing the violation within that period and confirming the cure in writing bars the action. An uncured violation is subject to a civil penalty of up to $7,500 per violation, and the chapter expressly bars any private right of action.
The Attorney General filed the state's first TDPSA enforcement action against Allstate Corp. and Arity LLC on January 13, 2025, over the sale of geolocation and driving-behavior data collected through SDKs embedded in third-party apps, and that case remains pending.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.