Law / United States / Texas

Texas

United States law applies in Texas Texas is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of Texas, described on this page below, applies here too.

All 22 named instruments researched to a stage, across five of the six areas of law we track: 21 in force and 1 repealed, withdrawn or blocked. As of 12 September 2026.

When they take effect22 of 22 carry a date. Earlier is before 2014.
Before 2014: 4 instruments (4 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 1 instrument (1 in force) 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 1 instrument (1 in force) 2024: 6 instruments (5 in force, 1 repealed, withdrawn or blocked) 2025: 6 instruments (6 in force) 2026: 4 instruments (4 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 8
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 3
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law8 instruments, 8 in force

Research summary (345 words)

Texas enacted the Texas Responsible Artificial Intelligence Governance Act (TRAIGA, H.B. 149), effective January 1, 2026, which bars any person from developing or deploying an AI system to manipulate someone into self-harm or crime, to infringe constitutional rights, to discriminate unlawfully, or to produce AI-generated child sexual abuse material or nonconsensual deepfake pornography, and separately requires a governmental agency, and any health care provider using diagnostic or treatment AI, to disclose AI interaction to the person on the other end; both duties are enforced exclusively by the Attorney General with a 60-day cure period and civil penalties up to $200,000 per violation, and TRAIGA also created a 36-month AI regulatory sandbox.

Texas layers AI-specific criminal and civil liability onto its deepfake and child-exploitation statutes: Penal Code 21.165, amended by S.B. 441 (2025), criminalizes producing or distributing nonconsensual AI deepfake pornography; a parallel Civil Practice and Remedies Code chapter 98B, also added by S.B. 441, gives the depicted person a damages claim against the creator and against a website or nudification-application owner who fails to remove flagged material within 72 hours of a request; Penal Code 43.235, added by S.B. 20 (2025), criminalizes AI-generated or apparent child pornography regardless of whether an actual child is depicted; and H.B. 3133 (2025) requires a social media platform to operate a complaint system that removes reported AI deepfake material and updates the reporting user within seven days.

A 2019 statute banning the creation and pre-election distribution of a political deepfake video with intent to injure a candidate, Election Code 255.004(d)-(e), remains in force even though the Texas Court of Criminal Appeals struck down the same section's separate general true-source-misrepresentation provision, subsection (b), as facially unconstitutional in Ex parte Stafford (2024).

S.B. 1188 (2025) separately requires a health care practitioner using diagnostic AI to disclose that use to the patient. Texas's state-agency-only AI governance provisions, including the Department of Information Resources' oversight functions under Government Code chapter 2054 and TRAIGA's own government-only social-scoring and biometric-AI bans (Business & Commerce Code 552.053-552.054), bind government bodies alone and are not catalogued here.

AI governance

H.B. 3133 (2025), social media platform complaint system for explicit deep fake material

Tex. Bus. & Com. Code §§ 120.101, 120.1001, 120.102, 120.1015, 120.1025, 120.152official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force since 1 September 2025. Binds private bodies.

What this law does

A social media platform must provide an easily accessible complaint system, with clear and conspicuous notice of it, letting a user report explicit deep fake material (deep fake material, meaning AI-altered or AI-created visual material made with intent to deceive, that depicts sexual conduct or exposes intimate parts).

On receiving such a report the platform must immediately confirm awareness to the user, remove the reported content and any identical known copies, and provide a status update within seven days; if the platform determines the content is not explicit deep fake material it may restore it, and if it determines the content is explicit deep fake material it must take measures to prevent the same material from being reposted.

A violation is a deceptive trade practice actionable under the Texas Deceptive Trade Practices-Consumer Protection Act. This chapter reaches only a social media platform with more than 50 million active United States users in a calendar month, so it binds a small number of the largest commercial platforms rather than every online service.

What it requires

AI prohibited practices

Political deep fake video ban (originally S.B. 751, 2019)

Tex. Elec. Code § 255.004(d)-(e)official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force since 1 September 2019. Binds public and private bodies.

What this law does

A person commits an offense if, with intent to injure a candidate or influence the result of an election, the person creates a deep fake video, defined as a video created with intent to deceive that appears to depict a real person doing something that did not occur, and causes it to be published or distributed within 30 days of an election.

This deep fake-specific offense is unaffected by Ex parte Stafford, in which the Texas Court of Criminal Appeals struck down as facially unconstitutional the same section's separate general provision, subsection (b), which had made it an offense to knowingly misrepresent in a campaign communication that it emanates from a source other than its true source; the court's holding was confined to that provision.

What it requires

S.B. 20 (2025), possession, promotion, or production of AI-generated or apparent child pornography

Tex. Penal Code § 43.235official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force since 1 September 2025. Binds public and private bodies.

What this law does

A person commits an offense by knowingly possessing, accessing with intent to view, or promoting obscene visual material that appears to depict a child younger than 18 engaging in sexual conduct, regardless of whether the depiction is of an actual child, a cartoon or animation, or an image created with an AI application or other computer software. A separate offense covers using an image of an actual child to train an AI model to produce material constituting child pornography.

The offense is a state jail felony, rising to a third-degree felony on one prior conviction under this section or the related child-pornography sections, and a second-degree felony on two or more.

What it requires

S.B. 441 (2025), civil liability for artificial intimate visual material and nudification applications

Tex. Civ. Prac. & Rem. Code §§ 98B.0021-98B.009official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force since 1 September 2025. Binds public and private bodies.

What this law does

A defendant who, without effective consent and with intent to harm, produces, solicits, discloses, or promotes artificial intimate visual material (AI-produced depictions of a person's exposed intimate parts or of them engaging in sexual conduct) that reveals the depicted person's identity is civilly liable to that person for damages.

A website, application, or social media platform owner who recklessly facilitates production or disclosure of the material for payment, or who owns a nudification application, an AI application primarily designed and marketed to produce artificial intimate visual material, is separately liable for damages. An owner is also liable for damages if the depicted person requests removal and the owner fails to remove the material, and known identical copies, within 72 hours of the request.

Every such owner must provide an accessible removal-request system and a clear, plain-language notice of it, and a violation of the removal, system, or notice duties is a deceptive trade practice actionable under the Texas Deceptive Trade Practices-Consumer Protection Act. A claim under this chapter must be brought not later than 10 years after the later of the depicted person's discovery of the material or the date the depicted person turns 18.

What it requires

S.B. 441 (2025), unlawful production or distribution of AI deep fake sexually explicit media

Tex. Penal Code § 21.165official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force since 1 September 2025. Binds public and private bodies.

What this law does

A person commits an offense by knowingly producing or distributing, by electronic means and without the depicted person's effective consent, deep fake media (visual material created or altered by software, machine learning, artificial intelligence, or other technological means) that appears to depict that person with computer-generated intimate parts or engaging in sexual conduct they did not engage in.

A separate offense covers intentionally threatening to produce or distribute such media to coerce, extort, harass, or intimidate.

The provision was originally enacted in 2023 and has since been amended, effective September 1, 2025; a general-purpose AI application or software provider has an affirmative defense if its terms prohibit this use and it takes active technical steps against it, such as training the system to identify prohibited content, providing reporting tools, and filtering it from outputs and training data. A disclaimer that the media is unauthorized or inauthentic is not a defense.

What it requires

TRAIGA (H.B. 149, 2025), prohibited AI practices binding any person

Tex. Bus. & Com. Code §§ 552.052, 552.055-552.057official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

A person may not develop or deploy an AI system that intentionally aims to incite self-harm, harm to another, or criminal activity; may not develop or deploy an AI system with the sole intent of infringing a constitutional right; may not develop or deploy an AI system with intent to unlawfully discriminate against a protected class, though disparate impact alone does not show that intent; and may not develop or distribute an AI system with the sole intent of producing AI-generated child pornography or deepfake sexually explicit media, or that engages a minor in simulated sexual conversation while impersonating a child.

Enforcement is exclusively by the Attorney General, with no private right of action and a 60-day notice-and-cure period. Civil penalties run from $10,000 to $12,000 per curable violation, $80,000 to $200,000 per uncurable violation, and $2,000 to $40,000 per day for a continuing violation, and the Attorney General cannot bring an action over a system that has not been deployed.

What it requires

AI sector rules

S.B. 1188 (2025), AI diagnostic disclosure duty in electronic health records

Tex. Health & Safety Code § 183.005official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force since 1 September 2025. Binds public and private bodies.

What this law does

A health care practitioner, public or private, may use AI for diagnostic purposes, including AI-generated recommendations on diagnosis or treatment based on a patient's medical record, only if the practitioner stays within the scope of their license, the use is not otherwise restricted by law, and the practitioner reviews all AI-created records consistent with Texas Medical Board standards; a practitioner who uses AI for diagnosis must disclose that use to the patient.

This layers onto, and is narrower than, TRAIGA's own health-care AI disclosure duty at Business & Commerce Code 552.051(f). The chapter's covered entities may face a civil penalty of $5,000 per negligent violation, $25,000 per knowing or intentional violation, or $250,000 per violation where protected health information was knowingly or intentionally used for financial gain, plus regulatory investigation and disciplinary action.

What it requires

AI transparency

TRAIGA (H.B. 149, 2025), consumer AI-interaction disclosure duty

Tex. Bus. & Com. Code § 552.051official codified text, Texas Constitution and Statutes, Texas Legislative Council

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

A governmental agency that makes an AI system available to interact with consumers must disclose, before or at the time of interaction, that the consumer is interacting with an AI system, regardless of whether that would already be obvious; the disclosure must be clear, conspicuous, in plain language, free of dark patterns, and may be given by hyperlink.

The same disclosure duty extends to any provider of a health care service or treatment, public or private, that uses an AI system in that service or treatment, who must give it to the patient or the patient's representative by the time the service is first provided, or as soon as reasonably possible in an emergency.

What it requires

Privacy law6 instruments, 6 in force

Research summary (204 words)

Texas has no single omnibus privacy authority but layers three private-sector duty streams. The Texas Data Privacy and Security Act (TDPSA, Tex. Bus. & Com. Code ch. 541) is the general comprehensive regime, effective July 1, 2024, requiring opt-in consent for sensitive data and giving consumers access, correction, deletion, portability, and opt-out rights.

The Capture or Use of Biometric Identifier Act (CUBI, Tex. Bus. & Com. Code sec. 503.001), in force since April 1, 2009 and amended effective January 1, 2026 by HB 149, is a dedicated biometric statute covering voiceprints and hand or face geometry with its own consent, retention, and destruction duties, and its biometric identifier definition carries no exclusion for a recording-derived identifier, unlike TDPSA's narrower biometric data definition.

A separate section of the Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code sec. 521.053) governs breach notification, triggered by Social Security, driver's license, or financial account data rather than by biometric data alone.

All three tracks vest primary enforcement in the Texas Attorney General; neither TDPSA nor CUBI creates a private right of action, though a violation of the breach chapter's safeguard duty (Sec. 521.052, via Sec. 521.152) is actionable as a deceptive trade practice under the DTPA.

Biometric privacy

Capture or Use of Biometric Identifier Act (CUBI), as amended by HB 149

Tex. Bus. & Com. Code sec. 503.001, as amended by Tex. HB 149, 89th Legislature (2025)official Texas statute text, Business and Commerce Code chapter 503, Texas Constitution and Statutes System

In force since 1 April 2009. Binds private bodies.

What this law does

CUBI is Texas's dedicated biometric-identifier statute. It defines 'biometric identifier' as a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry, with no exclusion for an identifier derived from a photograph, video, or audio recording.

A person may not capture an individual's biometric identifier for a commercial purpose without first informing the individual and obtaining consent, may not sell, lease, or disclose a captured identifier outside narrow statutory exceptions, must store and transmit it with reasonable care equal to or better than its other confidential information, and must destroy it within a reasonable time, no later than the first anniversary of when the collection purpose expires.

HB 149 (89th Legislature, 2025), effective January 1, 2026, added that an individual's biometric identifiers appearing in publicly available online media do not by themselves establish consent to capture unless that individual made the media publicly available, and added exemptions for biometric identifiers used only to train, process, or store data for developing or evaluating an AI model, and for AI systems used to prevent fraud, harassment, or other illegal activity.

What it requires

Breach notification

Identity Theft Enforcement and Protection Act, breach notification

Tex. Bus. & Com. Code sec. 521.053, as amended by Tex. SB 768, 88th Legislature (2023)official Texas statute text, Business and Commerce Code chapter 521, Texas Constitution and Statutes System

In force since 1 April 2009. Binds private bodies.

What this law does

A person conducting business in Texas that owns or licenses computerized data including sensitive personal information (a Social Security, driver's license, or government identification number, or a financial account number with an access code, each combined with a name, or certain health information) must notify affected Texas residents without unreasonable delay and no later than 60 days after determining a breach of system security occurred.

If 250 or more Texas residents are affected, the person must also notify the Texas Attorney General as soon as practicable and no later than 30 days after that determination, and a person notifying more than 10,000 persons at one time must also notify each nationwide consumer reporting agency.

Biometric data such as a fingerprint, voiceprint, or retina or iris image sits in the chapter's separate, broader personal identifying information definition and does not itself trigger this notification duty.

Enforcement of this notification duty is exclusive to the Attorney General, with a civil penalty of $2,000 to $50,000 per violation, and this section creates no private right of action, though a separate provision of the same chapter (sec. 521.152) ties a violation of the identity theft prohibition in sec. 521.051 to a private action under the Deceptive Trade Practices Act.

What it requires

Comprehensive regime

Texas Data Privacy and Security Act (HB 4), general applicability and scope

Tex. Bus. & Com. Code ch. 541, secs. 541.001-541.002official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

In force since 1 July 2024. Binds private bodies.

What this law does

TDPSA governs private-sector processing of Texas residents' personal data. It applies to a person who conducts business in Texas, or produces a product or service consumed by Texas residents, and who processes or sells personal data, unless the person is a small business under SBA size standards (a limited exception for selling sensitive data under sec. 541.107 applies regardless of size).

The Act excludes state agencies, political subdivisions, Gramm-Leach-Bliley Act (GLBA)-regulated financial institutions, Health Insurance Portability and Accountability Act (HIPAA) covered entities, nonprofits, higher-education institutions, and electric utilities, and 'personal data' excludes deidentified data and publicly available information.

What it requires

Data subject rights

Texas Data Privacy and Security Act, consumer rights and assessments

Tex. Bus. & Com. Code secs. 541.051-541.053, 541.105official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

In force since 1 July 2024. Binds private bodies.

What this law does

TDPSA gives a Texas consumer the right to confirm and access their personal data, correct inaccuracies, delete data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling that produces a legal or similarly significant effect, exercisable against the controller.

A controller must respond without undue delay and no later than 45 days after receipt, with one 45-day extension available, must answer an appeal of a refusal within 60 days, and must conduct and document a data protection assessment before targeted advertising, sale, certain profiling, sensitive-data processing, or other heightened-risk processing.

What it requires

Enforcement supervision

Texas Data Privacy and Security Act, Attorney General enforcement

Tex. Bus. & Com. Code secs. 541.151, 541.154-541.156official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

In force since 1 July 2024. Binds private bodies.

What this law does

The Texas Attorney General has exclusive authority to enforce TDPSA. Before suing, the Attorney General must give an alleged violator 30 days' written notice identifying the specific provisions violated; curing the violation within that period and confirming the cure in writing bars the action. An uncured violation is subject to a civil penalty of up to $7,500 per violation, and the chapter expressly bars any private right of action.

The Attorney General filed the state's first TDPSA enforcement action against Allstate Corp. and Arity LLC on January 13, 2025, over the sale of geolocation and driving-behavior data collected through SDKs embedded in third-party apps, and that case remains pending.

What it requires

Sensitive categories

Texas Data Privacy and Security Act, sensitive data and biometric consent

Tex. Bus. & Com. Code secs. 541.001, 541.101(b)(4)official Texas statute text, Business and Commerce Code chapter 541, Texas Constitution and Statutes System

In force since 1 July 2024. Binds private bodies.

What this law does

TDPSA classifies genetic or biometric data processed to uniquely identify a person, along with racial or ethnic origin, religious belief, a mental or physical health diagnosis, sexuality, citizenship or immigration status, precise geolocation, and a known child's data, as sensitive data requiring the consumer's prior consent before a controller may process it.

'Biometric data' means data from automatic measurement of an individual's biological characteristics used to identify them, including a fingerprint, voiceprint, or eye retina or iris, but the definition expressly excludes data generated from a photograph, or from a video or audio recording, so an identifier derived solely from such a recording falls outside this consent duty.

What it requires

Scraping law3 instruments, 3 in force

Research summary (171 words)

Texas diverges from the federal baseline in three concrete ways: a computer-crime statute that ties enhanced, felony-adjacent liability to a clear and conspicuous posted prohibition by a site owner, comprehensively covering the ToS-enforcement question the Computer Fraud and Abuse Act (CFAA) circuit split leaves unresolved; the Texas Data Privacy and Security Act (TDPSA), unusual among enacted state privacy laws for having no fixed dollar-revenue or consumer-count threshold at all; and the Capture or Use of Biometric Identifier Act (CUBI), Texas's own biometric statute predating Biometric Information Privacy Act (BIPA)-style national attention, enforced solely by the Attorney General with no private right of action and, since a 2025 amendment, an express rule on scraped public biometric media.

Copyright, text-and-data-mining, and database rights are federal only; Texas adds nothing there. ToS civil enforceability rests on ordinary Texas contract law (Texas's own Deceptive Trade Practices Act and common-law trespass to chattels are available in principle for unfair competition, untested against scraping specifically), and robots.txt carries no independent statutory weight, though a sufficiently prominent posted notice can feed the computer-crime statute's own notice element.

Computer misuse

Texas Breach of Computer Security, effective-consent and posted-prohibition offenses

Tex. Penal Code § 33.02official text, Texas Constitution and Statutes (statutes.capitol.texas.gov)

In force since 1 September 1985. Binds public and private bodies.

What this law does

Subsection (a) makes it a Class B misdemeanor to knowingly access a computer, computer network, or computer system without the effective consent of the owner.

A separate, more serious offense, subsection (b-1), is Texas's own statutory answer to the ToS and robots.txt authorization question: it applies where a person, with intent to defraud or harm another or to alter, damage, or delete property, knowingly accesses a computer system owned by government or a business in violation of either a clear and conspicuous prohibition posted by the owner or a contractual agreement the person expressly agreed to.

A posted no-scraping notice or a clickwrap agreement therefore carries independent legal weight in Texas, but only elevates exposure when paired with fraudulent or harmful intent, not for ordinary commercial data collection alone. Verified against the official Texas statutes site, which serves only a JavaScript shell without a full browser render. No Texas case law applying subsection (b-1) or CUBI's publicly available media clause to a scraping fact pattern was found.

What it requires

Personal data

Texas Capture or Use of Biometric Identifier Act (CUBI), publicly available media clause

Tex. Bus. & Com. Code § 503.001official text, Texas Constitution and Statutes (statutes.capitol.texas.gov)

In force 9 months, effective 1 January 2026. Binds public and private bodies.

What this law does

CUBI, originally enacted in 2009 (exact enactment date not independently confirmed) and amended by HB 149 (TRAIGA, 2025 Legislature, effective January 1, 2026), requires that a person inform an individual before capturing a biometric identifier (a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry) for a commercial purpose and receive that individual's consent.

The 2025 amendment adds a rule bearing directly on scraping: the mere existence of an image or other media containing someone's biometric identifiers on the Internet or another publicly available source does not, by itself, count as that person having been informed of or having consented to the capture or storage of their biometric identifier for a commercial purpose, unless the individual themselves made that image or media publicly available.

A separate 2025 amendment adds an exemption for biometric identifiers used in training, processing, or storing data to develop or evaluate an AI model, which is reported to lapse once the resulting system is deployed to uniquely identify a specific individual; this exemption's exact deployment boundary is not independently verified word for word.

A civil penalty of not more than $25,000 per violation is recoverable solely by the Attorney General; CUBI carries no private right of action, unlike Illinois's Biometric Information Privacy Act (BIPA).

What it requires

Texas Data Privacy and Security Act (TDPSA), no fixed applicability threshold

Tex. Bus. & Com. Code Ch. 541official text, Texas Constitution and Statutes (statutes.capitol.texas.gov)

In force since 1 July 2024. Binds private bodies.

What this law does

TDPSA applies to any person conducting business in Texas, or producing a product or service consumed by Texas residents, that processes or sells personal data and is not a small business as defined by the United States Small Business Administration, except that the sensitive-data-sale consent duty in section 541.107 applies even to a small business.

This is deliberately not a fixed dollar-revenue or consumer-count threshold; the SBA's small-business size standards vary by industry, often revenue in the tens of millions or employee counts in the hundreds, so TDPSA reaches many mid-sized data collectors that fall below other states' 100,000-consumer or $25-million thresholds.

Personal data excludes deidentified data and publicly available information, defined as information lawfully available through government records or that a business has a reasonable basis to believe is lawfully available to the public through widely distributed media, by the consumer, or by a person the consumer disclosed it to. Enforcement is by the Attorney General only, with a 30-day cure period; TDPSA carries no private right of action.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (725 words)

Texas's security posture rests on three enacted state statutes plus one new state cybersecurity-coordination body whose reach to a private operator is contractual rather than a status-based duty, and it has no separate connected-device or product-security statute.

The Identity Theft Enforcement and Protection Act's Business and Commerce Code Section 521.052, added by Acts 2007, 80th Leg., R.S., Ch. 885 (H.B. 2278), effective April 1, 2009, requires any business, a financial institution as defined by 15 U.S.C. § 6809 excepted, to implement and maintain reasonable procedures, including appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information it collects or maintains in the regular course of business, and to destroy or arrange for the destruction of customer records containing that information once it is no longer to be retained; the section states no further content for what 'reasonable' requires beyond that general standard.

The Texas Data Privacy and Security Act (H.B. 4, 2023), Business and Commerce Code Section 541.101(a)(2), effective July 1, 2024, layers a second, narrower security duty onto any controller the chapter reaches, a person conducting business in Texas or producing a product or service consumed by a Texas resident, that processes or sells personal data and is not a small business as defined by the United States Small Business Administration: to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue, for the purpose of protecting its confidentiality, integrity, and accessibility.

S.B. 2610 (2025), Business and Commerce Code Chapter 542, effective September 1, 2025, is a genuine security instrument built as an incentive rather than a mandate: a business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information may not be held liable for exemplary damages in an action arising from a breach of system security if it demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program conforming to a named industry framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, the HITRUST Common Security Framework, the Secure Controls Framework, SOC 2, or a similar framework), scaled to size: simplified measures such as password policies and employee training for an entity with fewer than 20 employees, the CIS Controls Implementation Group 1 for one with 20 to 99 employees, and full conformance with a named framework for one with 100 to 249 employees.

No enacted Texas statute sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's connected-device statute or the Cyber Resilience Act; this is a researched absence rather than a gap in coverage.

Texas has no general private-sector duty to report an exploited vulnerability or a security incident to an authority: House Bill 150 (2025), effective September 1, 2025, created the Texas Cyber Command (Government Code Chapter 2063) as a state coordination body, and a private entity operating critical infrastructure becomes a 'covered entity' bearing reporting and coordination duties only if it contracts with the Command for cybersecurity services, a contractual relationship rather than a status-based regulatory duty the LexLint activity vocabulary can express, so it is recorded here rather than flagged on a guess or filed as an instrument.

Section 521.052 is enforced solely by the attorney general, who may recover a civil penalty of $2,000 to $50,000 per violation and injunctive relief under Section 521.151; Section 541.101 is enforced solely by the attorney general under the Texas Data Privacy and Security Act's own exclusive-enforcement provision, Section 541.151, after a mandatory 30-day cure notice under Section 541.154, with a civil penalty of up to $7,500 per violation under Section 541.155 and no private right of action under Section 541.156.

Texas's breach-notification duty, Business and Commerce Code Section 521.053, the other half of the Identity Theft Enforcement and Protection Act, is already this jurisdiction's privacy row rather than repeated here.

The Texas Data Privacy and Security Act's own data-security duty, section 541.101(a)(2), belongs to the privacy topic rather than here: it is one subsection of the comprehensive regime addressed to a controller, the same place the General Data Protection Regulation's Article 32 sits, and the chapter's other controller duties are already researched there.

Security baseline statutes

Cybersecurity Program safe harbor from exemplary damages (S.B. 2610)

Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004)Official statute text, Texas Business and Commerce Code, Cybersecurity Program (S.B. 2610, 2025)

In force since 1 September 2025. Binds private bodies.

What this law does

A business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information may invoke a safe harbor from exemplary damages. In an action arising from a breach of system security, such an entity may not be held liable for exemplary damages if it demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program conforming to a named industry-recognized framework and scaled to its size. The chapter creates a safe harbor from a category of damages, not a freestanding duty to adopt a program.

What it requires

Identity Theft Enforcement and Protection Act, business duty to protect sensitive personal information

Tex. Bus. & Com. Code sec. 521.052Official statute text, Texas Business and Commerce Code, Identity Theft Enforcement and Protection Act

In force since 1 April 2009. Binds private bodies.

What this law does

A business must implement and maintain reasonable procedures, including taking any appropriate corrective action, to protect from unlawful use or disclosure any sensitive personal information it collects or maintains in the regular course of business. A business must also destroy or arrange for the destruction of customer records containing sensitive personal information no longer to be retained, by shredding, erasing, or otherwise rendering it unreadable or indecipherable.

A financial institution as defined by 15 U.S.C. § 6809 is exempt from the destruction duty, and the section states no further content for what 'reasonable' requires beyond the general standard.

What it requires

Age gating law3 instruments, 2 in force, 1 repealed, withdrawn or blocked

Research summary (110 words)

Texas has the most consequential adult content age verification law in the country: HB 1181 (2023), upheld by the U.S. Supreme Court in Free Speech Coalition v. Paxton on June 27, 2025 under intermediate scrutiny. The core provisions of its 2023 SCOPE Act, which covers social media and other digital services used by minors, remain enjoined statewide pending consolidated Fifth Circuit appeals.

Its 2025 App Store Accountability Act (SB 2420) is currently enforceable after the Fifth Circuit stayed a district court injunction and the Supreme Court declined to disturb that stay in July 2026, though the merits appeal is still pending. Texas has not enacted a standalone design code law.

Adult content age verification (AV)

HB 1181 (2023), age verification for material harmful to minors

Tex. Civ. Prac. & Rem. Code ch. 129Bofficial Texas Civil Practice and Remedies Code statute text

In force since 1 September 2023. Binds private bodies.

What this law does

Requires a commercial entity that knowingly and intentionally publishes or distributes material on a website, including a social media platform, more than one third of which is sexual material harmful to minors, to use reasonable age verification methods for Texas visitors and to protect any identifying information it collects.

Note and primary source

App store age verification (AV)

SB 2420 (2025), App Store Accountability Act

Tex. Bus. & Com. Code ch. 121 (Subtitle C, Title 5)official enrolled session law text, Texas Legislature

In force 9 months, effective 1 January 2026. Binds private bodies.

What this law does

Requires app store providers to verify a user's age category, link a minor's account to a parent account, and obtain parental consent before a minor can download an app or make an in app purchase, and to share age and consent information with app developers. Violations are deceptive trade practices under Texas consumer protection law.

Note and primary source

Social media and minors

HB 18 (2023), Securing Children Online through Parental Empowerment (SCOPE) Act

Tex. Bus. & Com. Code ch. 509official Texas Business and Commerce Code statute text

Enjoined: enforcement paused by a court, effective 1 September 2024. Binds private bodies.

What this law does

Requires digital service providers to determine whether a Texas account holder is a known minor based on self reported age at registration, obtain parental consent for certain data uses, and restrict targeted advertising, data sharing, and specified design features for known minors. Federal courts have enjoined the law's core provisions statewide, including its monitoring and filtering, targeted advertising, and age verification requirements, while Texas appeals.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.