ACE Rebrand Update: The Alliance for Citizen Engagement is now the Alliance for Civic Engagement.

The Texas Data Privacy and Security Act (TDPSA): A State-Level Approach to Consumer Data Protection

Texas data privacy and security act TPDSA

In an era where people generate data with every swipe, click, and tap, concerns over data privacy have become commonplace. Despite its widespread collection and use, most Americans do not know how their data is handled. According to Pew Research, approximately 67 percent of Americans understand “little to nothing” about what companies do with their personal data, and 73 percent feel they have little to no control over its collection. Additionally, 77 percent of people say they have little or no trust in social media executives to take responsibility for the misuse of user data. 

While the federal government has introduced proposals like the American Data Privacy and Protection Act (ADPPA) and the American Privacy Rights Act (APRA) to address these concerns, neither have passed. The ADPPA aimed to limit the collection of personal data and prohibit the sharing of such data without consumer consent. Similarly, the APRA mimicked the ADPPA’s design but strengthened certain provisions, such as enhancing protections for the data of consumers under the age of 17. With both bills unpassed, the legislative gap has left states to take independent approaches to data privacy. These approaches have left considerable differences in state policies, with states like Maine, Nevada, and New York having narrow consumer privacy laws, while others like California and Virginia have comprehensive laws. 

What is the TDPSA?

Texas recently passed the Texas Data Privacy and Security Act (TDPSA), joining other state efforts to set rules on how personal data is collected, used, and shared. Comparable bills include the Florida Digital Bill of Rights (FDBR), the Oregon Consumer Data Privacy Act (OCDPA), and the Montana Consumer Data Privacy Act (MCDPA). The TDPSA builds on prior acts like the Texas Identity Theft Enforcement and Protection Act (2005) and the Deceptive Trade Practices Act (1973), but expands protections into the digital realm. It also mirrors the growing number of comprehensive data laws in places like California, Virginia, and Colorado. However, the TDPSA applies to a wider range of businesses and instructs for explicit consent for processing sensitive data of others.

The Texas Data Privacy and Security Act is designed to give Texas consumers greater control over their personal data while creating compliance mechanisms for businesses that handle that kind of data.

The TDPSA allocates rights to users, allowing them to delete their personal data and opt out of processing personal data for uses such as targeted advertising, the selling of personal data, and more. Companies selling personal data to third parties or using the data for targeted advertising also must disclose these actions to users.

Pros of the TDPSA

TDPSA is written with clearly defined terms and actions for the comprehension of both consumers and businesses. Some have argued that clear definitions and scope help companies prepare their internal systems and reduce legal enmity by providing definitions regarding sensitive data requirements, the right of Texans to appeal any denial of requests, and more. In addition, some have mentioned how the bill highlights clarity and compliance structures, as it provides avenues for consumers and the Texas Attorney General to act if businesses violate the law. It also clarifies how consumers may submit requests to exercise their rights in lieu of a privacy notice from the interacting business. Some legal analysts have mentioned how the law provides specific definitions and language. TDPSA explicitly defines personal data” as any information that is linked or possibly linkable to a person, giving insight into what data may be protected or regulated. 

TDPSA may bring control back to consumers regarding their personal data. The bill gives consumers greater awareness and control over how companies use their data and encourages ethical data handling through mandated transparency. In turn, it may give Texans rights to ways they can access, correct, delete, and opt out of data collection, furthering digital autonomy. 

As the TDPSA may be the strongest consumer privacy law in the U.S., it may bring more awareness to data rights. Experts like those in the National Law Review have described the TDPSA as applying broadly to most businesses with some exceptions and other specific provisions covering various data collection actions. Advocacy groups, such as Texas Appleseed, praised it for helping people understand how to protect their personal information by highlighting their right to access, the right to data portability, the right to correct, the right to delete, and the right to opt out.

Opposition to the TDPSA

While the law establishes rights on paper, critics argue there are still some passages that can indirectly lead to misuse or a lack of clear enforcement boundaries. Some phrases, such as the “right to be forgotten” in the bill, may not emphasize a right to public access of data. Others have mentioned the bill does not specify classifications for “small businesses.” Since the US Small Business Administration (SBA), tasked with defining the term, also does not have a specific definition for a small business, the TDPSA could create confusion regarding which businesses are bound by the law. In turn, this vague provision may clash with other state frameworks and contribute to a disjointed regulatory landscape between definitions of small business determined by revenue or number of employees.

Some opponents have warned that it may pose economic and operational burdens on businesses. Those without existing privacy infrastructure may face heavy financial and logistical burdens adapting to the new law’s regulations. More requirements could lead to increased compliance costs, driving businesses out of Texas due to struggles maintaining clear privacy notices and implementing ways to handle consumer data requests.

Legal analysts and interest groups have opposed the bill, claiming it needs more extensive protections for consumers and insisting it will clash with other state frameworks. For example, the bill includes a 30-day period allowing companies to fix any violations without penalty. The Electronic Frontier Foundation (EEF) calls this cure period practically a “‘get-out-of-jail-free’ card” for companies to avoid penalties for their mistakes. The law’s reliance on the Attorney General also creates uneven enforcement abilities, as consumers cannot take businesses to court, leaving decisions to the Attorney General. The U.S. PIRG Education Fund has warned the TDPSA may not go far enough to enforce its protections, as it does not clarify what companies’ intended ends for consumer data are.

Looking Ahead

The Texas Data Privacy and Security Act shifts how the state approaches digital rights and consumer protections. While it may be a necessary first step toward restoring balance between individuals and companies in the digital landscape, critics point out that without strong enforcement or national coordination, the law’s protections may lead to more confusion.

As more states consider similar legislation, Texas’s law may serve as both a blueprint and a warning. Whether it becomes a model for responsible regulation or another example of decentralized digital privacy’s challenges remains to be seen.

[pvc_stats postid="" increase="1" show_views_today="0"]

Share this post

Related Briefs

Give feedback on this brief:

Free to read. Funded by people like you. Support the Fellows making it possible.