Skip to main content
Framework library
Framework module · texas-tdpsa

Texas Data Privacy and Security Act

Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.

HB 4 (Texas Business and Commerce Code Chapter 541) · Texas Legislature — HB 4 (88th R.S.) · published 2023-06-18

Standing today
Directory entry

00Answer

from the registry record
What is Texas Data Privacy and Security Act?
Texas's comprehensive consumer-privacy statute, pulled out of the generic state-privacy bundle because of its own enforcement record — the Texas AG has reached the two largest single-state privacy settlements in US history — and because TRAIGA now amends it with AI-specific processor duties.
Who does Texas Data Privacy and Security Act apply to?
Texas Data Privacy and Security Act applies to all sectors, US-TX, per Texas Legislature — HB 4 (88th R.S.).
What is the current version of Texas Data Privacy and Security Act?
The current edition is HB 4 (Texas Business and Commerce Code Chapter 541), issued by Texas Legislature — HB 4 (88th R.S.) and published 2023-06-18. Source: https://capitol.texas.gov/BillLookup/History.aspx?LegSess=88R&Bill=HB4.
What does an assessment under Texas Data Privacy and Security Act require?
No control catalog has been ingested for Texas Data Privacy and Security Act yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

Texas Data Privacy and Security Act is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; obligations not modelled as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Consumer rights · Controller obligations · Data protection assessments · Sensitive data authorization · Universal opt-out
Applies to
all sectors · US-TX
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
The Act took effect 2024-07-01; the universal opt-out signal requirement took effect 2025-01-01. Texas HB 149 (TRAIGA) separately amends the Act with AI-specific processor duties.Expected: In force

03Version ledger

1 edition
HB 4 (Texas Business and Commerce Code Chapter 541)Current edition2023-06-18

06Related frameworks

scored from registry facts
  1. CCPA/CPRA + US state privacyCCPA/CPRA with 2026 CPPA regulations

    Also applies to all sectors · California's consumer privacy regime and the state laws that followed it. The 2026 CPPA regulations add automated decision-making rules, mandatory risk assessments, and certified cybersecurity audits.

  2. GDPRRegulation (EU) 2016/679

    Also applies to all sectors · The EU's baseline for processing personal data — lawful basis, data-subject rights, controller and processor duties, and cross-border transfers.

  3. UK GDPRUK GDPR + DPA 2018, as amended by DUAA 2025 (in force via Commencement No. 6, SI 2026/82)

    Also applies to all sectors · The UK's post-Brexit data protection regime, materially reshaped by the Data (Use and Access) Act 2025 — new recognised legitimate interests, narrower automated-decision protections, and a pausable DSAR clock. The core amending provisions were brought into force by the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), effective 2026-02-05.

  4. Also applies to all sectors · Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.

Texas Data Privacy and Security Act | ControlFrame