Melissa Krasnow | July 21, 2023
The Texas Data Privacy and Security Act (TDPSA) will take effect July 1, 2024, except that Texas Bus. & Comm. Code § 541.055(e) regarding a consumer's authorized agent acting on behalf thereof to opt out of the processing of the consumer's personal data under Texas Bus. & Comm. Code §§ 541.051(b)(5)(A) and (B), among other things, as added by the TDPSA, will take effect January 1, 2025.
The Texas attorney general has exclusive authority to enforce the TDPSA.
This article discusses TDPSA application, definitions, consumer rights, and notice requirements. TDPSA controller and processor responsibilities, controller-processor contracts, data protection assessments, deidentified data, and Texas attorney general enforcement are discussed in "Texas Data Privacy Act: Controllers, Assessments, Data, Enforcement," and exceptions in the law are addressed in "Texas Data Privacy Act: Exceptions."
The TDPSA applies to a person that does the following.
Under Texas Bus. & Comm. Code § 541.107, a small business may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer.
"Consumer" means an individual who is a Texas resident acting only in an individual or household context and does not include an individual acting in a commercial or employment context.
"Controller" means an individual or other person that, alone or jointly with others, determines the purpose and means of processing personal data.
A determination of whether a person is acting as a controller or processor with respect to a specific processing of data is a fact-based determination that depends on the context in which personal data is to be processed.
"Processor" means a person that processes personal data on behalf of a controller.
A determination of whether a person is acting as a controller or processor with respect to a specific processing of data is a fact-based determination that depends on the context in which personal data is to be processed. A processor that continues to adhere to a controller's instructions with respect to a specific processing of personal data remains in the role of a processor.
"Process" or "processing" means an operation or set of operations performed, whether by manual or automated means, on personal data or on sets of personal data, such as the collection, use, storage, disclosure, analysis, deletion, or modification of personal data.
"Personal data" means any information, including sensitive data, that is linked or reasonably linkable to an identified or identifiable individual, includes pseudonymous data when the data is used by a controller or processor in conjunction with additional information that reasonably links the data to an identified or identifiable individual, and does not include deidentified data or publicly available information.
"Identified or identifiable individual" means a consumer who can be readily identified, directly or indirectly.
"Pseudonymous data" means any information that cannot be attributed to a specific individual without the use of additional information, provided that the additional information is kept separately and is subject to appropriate technical and organizational measures to ensure that the personal data is not attributed to an identified or identifiable individual.
"Deidentified data" means data that cannot reasonably be linked to an identified or identifiable individual or a device linked to that individual.
"Sale of personal data" means the sharing, disclosing, or transferring of personal data for monetary or other valuable consideration by the controller to a third party and does not include the following disclosures.
"Third party" means a person, other than a consumer, the controller, the processor, or an affiliate of the processor or the controller.
"Affiliate" means a legal entity that controls, is controlled by, or is under common control with another legal entity or shares common branding with another legal entity. "Control" or "controlled" means the following.
"Targeted advertising" means displaying to a consumer an advertisement that is selected based on personal data obtained from that consumer's activities over time and across nonaffiliated websites or online applications to predict the consumer's preferences or interests and does not include the following.
"Profiling" means any form of solely automated processing performed on personal data to evaluate, analyze, or predict personal aspects related to an identified or identifiable individual's economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
"Decision that produces a legal or similarly significant effect concerning a consumer" means a decision made by the controller that results in the provision or denial by the controller of financial and lending services; housing, insurance, or healthcare services; education enrollment; employment opportunities; criminal justice; or access to basic necessities, such as food and water.
"Consent," when referring to a consumer, means a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to process personal data relating to the consumer, includes a written statement, such as a statement written by electronic means, or any other unambiguous affirmative action, and does not include the following.
"Dark pattern" means a user interface designed or manipulated with the effect of substantially subverting or impairing user autonomy, decision-making, or choice and includes any practice the Federal Trade Commission refers to as a dark pattern.
"Sensitive data" means a category of personal data and includes the following.
"Child" means an individual younger than 13 years of age.
"Known child" means a child under circumstances where a controller has actual knowledge of, or willfully disregards, the child's age.
"Biometric data" means data generated by automatic measurements of an individual's biological characteristics, includes a fingerprint, voiceprint, eye retina or iris, or other unique biological pattern or characteristic that is used to identify a specific individual and does not include a physical or digital photograph or data generated from a physical or digital photograph, video, or audio recording or information collected, used, or stored for healthcare treatment, payment, or operations under the Health Insurance Portability and Accountability Act of 1996.
"Precise geolocation data" means information derived from technology, including global positioning system level latitude and longitude coordinates or other mechanisms, that directly identifies the specific location of an individual with precision and accuracy within a radius of 1,750 feet and does not include the content of communications or any data generated by or connected to an advanced utility metering infrastructure system or to equipment for use by a utility.
A consumer is entitled to exercise consumer rights by submitting a request to a controller specifying the consumer rights the consumer wishes to exercise, including the following.
If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller must clearly and conspicuously disclose that process and the manner in which a consumer may exercise the right to opt out of that process.
A controller must provide consumers with a reasonably accessible and clear privacy notice that includes all of the following.
If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller must clearly and conspicuously disclose that process and the manner in which a consumer may exercise the right to opt out of that process.
If a controller engages in the sale of personal data that is the following, each such notice must be posted in the same location and in the same manner as the privacy notice.
Opinions expressed in Expert Commentary articles are those of the author and are not necessarily held by the author's employer or IRMI. Expert Commentary articles and other IRMI Online content do not purport to provide legal, accounting, or other professional advice or opinion. If such advice is needed, consult with your attorney, accountant, or other qualified adviser.
Footnotes