Privacy · Texas law
The Texas Data Privacy and Security Act for fintechs
Texas has had a comprehensive consumer privacy law since July 1, 2024. Whether it applies to a fintech depends largely on the federal Gramm-Leach-Bliley Act. This guide walks through the exemption, what the law requires when it does apply, and the separate Texas breach notification rules.
Not legal advice. Statute text checked September 2026 in Chapter 541 and Chapter 521 of the Texas Business and Commerce Code. The Texas Attorney General enforces both.
Does the TDPSA apply to your company?
The Texas Data Privacy and Security Act (TDPSA), Chapter 541 of the Business and Commerce Code, applies to a person that meets all three conditions in Section 541.002(a):
- it conducts business in Texas or produces a product or service consumed by Texas residents;
- it processes or sells personal data; and
- it is not a small business as defined by the U.S. Small Business Administration, with one exception described below.
Section 541.002(b) then lists who is outside the law entirely. For fintechs, the key entry is "a financial institution or data subject to Title V, Gramm-Leach-Bliley Act." Nonprofits, HIPAA-covered entities and business associates, state agencies, higher education institutions and certain electric utilities are also excluded.
Reading the GLBA exemption
The wording covers two things: financial institutions subject to GLBA Title V, and data subject to it. That leaves fintechs in three broad positions:
| Your position | Likely effect |
|---|---|
| A financial institution under GLBA, such as a lender, money transmitter or other company significantly engaged in financial activities | Generally outside the TDPSA, with GLBA privacy and security rules applying instead |
| A technology company that handles GLBA-covered data for a financial institution | That data is likely excluded, while other personal data you hold, such as marketing leads, may not be |
| A company that is not a GLBA financial institution, such as a budgeting tool that does not provide financial services, or a B2B software vendor processing its own users' data | The TDPSA may apply in full if the other conditions are met |
Whether a company is a GLBA "financial institution" is its own question. Work it out first, and write down the answer, because the privacy program you build depends on it.
What the TDPSA requires when it applies
| Obligation | Summary | Section |
|---|---|---|
| Consumer rights | Access, correction, deletion, portability, and opt-out of targeted advertising, sale and certain profiling | 541.051 |
| Response time | Within 45 days, extendable once by 45 days with notice | 541.052 |
| Appeals | A process to appeal a refusal, with a written decision within 60 days | 541.053 |
| Request methods | Two or more secure and reliable ways to submit requests | 541.055 |
| Data minimization and security | Collect what is reasonably necessary; keep reasonable security practices | 541.101 |
| Sensitive data | Process only with the consumer's consent | 541.101(b)(4) |
| Privacy notice | Categories of data, purposes, rights, sharing and request methods | 541.102 |
| Data protection assessments | For targeted advertising, sale, risky profiling, sensitive data and other heightened-risk processing | 541.105 |
| Processor contracts | Duties for vendors that process data on your behalf | 541.104 |
The small-business carve-out is not complete. Under Section 541.107, a small business still may not sell sensitive personal data without the consumer's prior consent.
Enforcement
- The Attorney General has exclusive enforcement authority, and there is no private right of action (Sections 541.151 and 541.156).
- Before suing, the Attorney General must give written notice and a 30-day opportunity to cure (Section 541.154).
- Violations after the cure period can bring civil penalties of up to $7,500 per violation, plus injunctions and the state's costs (Section 541.155).
Texas breach notification applies more broadly
Chapter 521 of the Business and Commerce Code applies to a person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. It has no GLBA exemption like the TDPSA's, so a fintech exempt from the privacy law can still be covered by the breach law. Under Section 521.053:
- Individuals must be notified without unreasonable delay and no later than 60 days after the business determines that the breach occurred, subject to law enforcement delay.
- The Attorney General must be notified as soon as practicable and no later than 30 days after that determination if the breach involves at least 250 Texas residents, using the form on the Attorney General's website.
- Service providers that hold data they do not own must notify the owner immediately after discovering a breach.
Federal rules can add their own clocks. The FTC Safeguards Rule, for example, requires covered non-bank financial institutions to notify the FTC of certain security events affecting 500 or more consumers.
A privacy plan for a Texas fintech
- Decide your GLBA status and whether the TDPSA exemption covers the company, some data, or nothing.
- Inventory personal data by source, purpose, system, vendor and retention period, and flag sensitive data, which the TDPSA defines to include precise geolocation data and biometric data processed to uniquely identify a person. A selfie match during identity verification can fall in that category.
- Write the notices: a GLBA privacy notice if you are a financial institution, and a TDPSA-compliant notice for any data the exemption does not reach.
- Build the request process with identity checks, deadlines and an appeal route.
- Sign processor terms with every vendor that handles personal data.
- Test the breach plan against the Chapter 521 deadlines and any contract deadlines owed to your bank partner.
Common questions
Are fintechs exempt from the Texas privacy law?
Many are, but not all. The TDPSA excludes financial institutions and data subject to GLBA Title V. A fintech that is not a GLBA financial institution, or that holds personal data outside GLBA, may still be covered.
Does the TDPSA have a revenue threshold?
No revenue or record-count threshold appears in Section 541.002. Instead, the law excludes businesses that are small under SBA definitions, except for the rule on selling sensitive data.
How long do we have to report a breach in Texas?
Individuals: no later than 60 days after determining the breach occurred. The Attorney General: no later than 30 days, if at least 250 Texas residents are involved.
Can a customer sue us under the TDPSA?
No. Section 541.156 states that the chapter creates no private right of action. Enforcement is by the Attorney General.
Identity data collected at onboarding is covered in KYC and KYB requirements. The rest of the program is on the compliance checklist.
Last reviewed 2026-09-17