07/26/2024
New Texas Laws on PII and Data Privacy
As of July 1, 2024, Texas has implemented the Texas Data Privacy and Security Act (TDPSA), a comprehensive law aimed at protecting the personal data of its residents. This legislation marks a significant step in the state’s efforts to enhance data privacy and security, aligning Texas with other states that have enacted similar laws.
Key Provisions of the TDPSA
The TDPSA introduces several important provisions that businesses and consumers should be aware of:
Consumer Rights:
Right to Access: Consumers have the right to know whether a company is processing their personal data and to obtain a readable copy of this data. Right to Correct: Consumers can request corrections to inaccuracies in their personal data. Right to Delete: Consumers can request the deletion of their personal data. Right to Opt-Out: Consumers can opt out of the processing of their personal data for targeted advertising, the sale of personal data, or profiling.
Business Obligations:
Privacy Notices: Businesses must provide clear and accessible privacy notices detailing the categories of personal data processed, the purposes of processing, and the categories of third parties with whom data is shared. Data Security: Businesses are required to implement reasonable security measures to protect personal data from unauthorized access, use, or disclosure. Consent for Sensitive Data: Businesses must obtain explicit consent from consumers before processing sensitive data, such as precise geolocation data or the personal data of children under 131.
Scope and Applicability:
The TDPSA applies to entities that conduct business in Texas or produce products or services consumed by Texas residents. This broad scope ensures that a wide range of businesses are covered, regardless of their physical location.
Implications for Businesses
Businesses operating in Texas or serving Texas residents need to take several steps to comply with the TDPSA: Review and Update Privacy Policies: Ensure that privacy policies are up-to-date and clearly communicate consumer rights and business practices regarding personal data. Implement Data Security Measures: Adopt robust security measures to protect personal data and prevent breaches. Obtain Necessary Consents: Ensure that explicit consent is obtained for processing sensitive data, especially for minors.
The Texas Data Privacy and Security Act represents a significant advancement in protecting consumer data privacy in Texas. By granting consumers greater control over their personal data and imposing stricter obligations on businesses, the TDPSA aims to create a safer and more transparent data environment. Businesses must take proactive steps to comply with these new regulations to avoid penalties and build trust with their customers.
For more detailed information, you can refer to the full text of the Texas Data Privacy and Security Act.