FintechAustin

Privacy · Texas law

The Texas Data Privacy and Security Act for fintechs

Texas has had a comprehensive consumer privacy law since July 1, 2024. Whether it applies to a fintech depends largely on the federal Gramm-Leach-Bliley Act. This guide walks through the exemption, what the law requires when it does apply, and the separate Texas breach notification rules.

Not legal advice. Statute text checked September 2026 in Chapter 541 and Chapter 521 of the Texas Business and Commerce Code. The Texas Attorney General enforces both.

Does the TDPSA apply to your company?

The Texas Data Privacy and Security Act (TDPSA), Chapter 541 of the Business and Commerce Code, applies to a person that meets all three conditions in Section 541.002(a):

  1. it conducts business in Texas or produces a product or service consumed by Texas residents;
  2. it processes or sells personal data; and
  3. it is not a small business as defined by the U.S. Small Business Administration, with one exception described below.

Section 541.002(b) then lists who is outside the law entirely. For fintechs, the key entry is "a financial institution or data subject to Title V, Gramm-Leach-Bliley Act." Nonprofits, HIPAA-covered entities and business associates, state agencies, higher education institutions and certain electric utilities are also excluded.

Reading the GLBA exemption

The wording covers two things: financial institutions subject to GLBA Title V, and data subject to it. That leaves fintechs in three broad positions:

Your positionLikely effect
A financial institution under GLBA, such as a lender, money transmitter or other company significantly engaged in financial activitiesGenerally outside the TDPSA, with GLBA privacy and security rules applying instead
A technology company that handles GLBA-covered data for a financial institutionThat data is likely excluded, while other personal data you hold, such as marketing leads, may not be
A company that is not a GLBA financial institution, such as a budgeting tool that does not provide financial services, or a B2B software vendor processing its own users' dataThe TDPSA may apply in full if the other conditions are met

Whether a company is a GLBA "financial institution" is its own question. Work it out first, and write down the answer, because the privacy program you build depends on it.

What the TDPSA requires when it applies

ObligationSummarySection
Consumer rightsAccess, correction, deletion, portability, and opt-out of targeted advertising, sale and certain profiling541.051
Response timeWithin 45 days, extendable once by 45 days with notice541.052
AppealsA process to appeal a refusal, with a written decision within 60 days541.053
Request methodsTwo or more secure and reliable ways to submit requests541.055
Data minimization and securityCollect what is reasonably necessary; keep reasonable security practices541.101
Sensitive dataProcess only with the consumer's consent541.101(b)(4)
Privacy noticeCategories of data, purposes, rights, sharing and request methods541.102
Data protection assessmentsFor targeted advertising, sale, risky profiling, sensitive data and other heightened-risk processing541.105
Processor contractsDuties for vendors that process data on your behalf541.104

The small-business carve-out is not complete. Under Section 541.107, a small business still may not sell sensitive personal data without the consumer's prior consent.

Enforcement

Texas breach notification applies more broadly

Chapter 521 of the Business and Commerce Code applies to a person who conducts business in Texas and owns or licenses computerized data that includes sensitive personal information. It has no GLBA exemption like the TDPSA's, so a fintech exempt from the privacy law can still be covered by the breach law. Under Section 521.053:

Federal rules can add their own clocks. The FTC Safeguards Rule, for example, requires covered non-bank financial institutions to notify the FTC of certain security events affecting 500 or more consumers.

A privacy plan for a Texas fintech

  1. Decide your GLBA status and whether the TDPSA exemption covers the company, some data, or nothing.
  2. Inventory personal data by source, purpose, system, vendor and retention period, and flag sensitive data, which the TDPSA defines to include precise geolocation data and biometric data processed to uniquely identify a person. A selfie match during identity verification can fall in that category.
  3. Write the notices: a GLBA privacy notice if you are a financial institution, and a TDPSA-compliant notice for any data the exemption does not reach.
  4. Build the request process with identity checks, deadlines and an appeal route.
  5. Sign processor terms with every vendor that handles personal data.
  6. Test the breach plan against the Chapter 521 deadlines and any contract deadlines owed to your bank partner.

Common questions

Are fintechs exempt from the Texas privacy law?

Many are, but not all. The TDPSA excludes financial institutions and data subject to GLBA Title V. A fintech that is not a GLBA financial institution, or that holds personal data outside GLBA, may still be covered.

Does the TDPSA have a revenue threshold?

No revenue or record-count threshold appears in Section 541.002. Instead, the law excludes businesses that are small under SBA definitions, except for the rule on selling sensitive data.

How long do we have to report a breach in Texas?

Individuals: no later than 60 days after determining the breach occurred. The Attorney General: no later than 30 days, if at least 250 Texas residents are involved.

Can a customer sue us under the TDPSA?

No. Section 541.156 states that the chapter creates no private right of action. Enforcement is by the Attorney General.

Identity data collected at onboarding is covered in KYC and KYB requirements. The rest of the program is on the compliance checklist.

Last reviewed 2026-09-17