Texas biometric privacy law (CUBI): does it apply to you?
Texas's biometric privacy law, known as CUBI, applies to any person or business that captures a biometric identifier, such as a fingerprint, face geometry, iris scan, or voiceprint, for a commercial purpose. It sets no revenue or consumer-count threshold, so a business of any size must obtain consent before capturing biometric data.
Applies to: Any person or business that captures a biometric identifier of an individual for a commercial purpose in Texas; there is no revenue, consumer-count, or small-business threshold.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Texas has two separate privacy laws, and businesses often notice only one of them. The comprehensive Texas Data Privacy and Security Act has a small-business gate, so plenty of companies read it and conclude they are exempt. The biometric law is different. It turns on what data you handle, not how big you are, and it can reach a company that sits well below every other threshold in the state.
Who does the Texas biometric law cover?
Texas's biometric rule lives in the Capture or Use of Biometric Identifier Act, known as CUBI, at Tex. Bus. & Com. Code Section 503.001. It applies to any person who captures a biometric identifier of an individual for a commercial purpose. A biometric identifier means a retina or iris scan, a fingerprint, a voiceprint, or a record of hand or face geometry. There is no revenue floor, no consumer-count trigger, and no small-business exemption. If biometric identifiers pass through your systems for a commercial reason, you are in scope whatever your size, which is what makes CUBI catch companies that assume state privacy law does not reach them.
What must you do before capturing biometric data?
The core rule is about timing. Under Section 503.001(b) you must inform the individual and receive their consent before you capture the identifier, not after. Consent added later does not cure a capture that already happened. Posting a face-recognition camera, a fingerprint time clock, or a voiceprint feature means the notice and consent step has to be in place first. A 2025 amendment (H.B. 149, effective January 1, 2026) also confirmed that a photo or recording already on the internet does not count as consent unless the individual themselves made it public.
How long can you keep it, and can you share it?
You must store, transmit, and protect a biometric identifier with reasonable care, at least as protective as the way you handle your other confidential information. You must destroy it within a reasonable time, and no later than the first anniversary of the date the purpose for collecting it expires. Where an employer collects a biometric identifier for security, that purpose is presumed to expire when the employment relationship ends. You may not sell, lease, or otherwise disclose a biometric identifier except in the narrow situations the statute lists, such as completing a financial transaction the individual authorized or responding to a warrant.
How is CUBI enforced, and how is it different from Illinois?
CUBI carries a civil penalty of up to $25,000 for each violation, and only the Texas Attorney General may bring an action to recover it under Section 503.001(d). That is the key contrast with Illinois's BIPA statutory damages: Texas gives no private right of action, so individuals cannot sue you directly, and there is no separate written-policy mandate. Our biometric privacy laws by state roundup shows how Illinois, Washington, and Colorado treat the same data differently, and the Texas TDPSA covers the state's comprehensive law that runs alongside CUBI.
Next step
If you use any biometric technology and touch people in Texas, the free 2-minute Obligation Scan checks whether CUBI applies and lists the notice, consent, retention, and deletion steps you owe, so nothing slips through because you assumed you were too small. The US state privacy laws hub shows how data-type triggers like this differ from the revenue and volume tests elsewhere.
Compliance checklist
- Map every point where you capture a biometric identifier, such as a fingerprint, face or hand geometry, retina or iris scan, or voiceprint, for a commercial purpose.
- Inform the individual and obtain consent before you capture the identifier, not afterward, as Section 503.001(b) requires.
- Store, transmit, and protect biometric identifiers with reasonable care, at least as protective as your other confidential data.
- Destroy each biometric identifier within a reasonable time and no later than one year after the purpose for collecting it ends.
- Do not sell, lease, or disclose biometric identifiers except in the narrow situations Section 503.001(c) allows.
Sources
Last verified: 2026-08-05
Informational, not legal advice.