Back to the hub

Texas data broker registration: who has to register and what it costs

Texas data broker registration now sits at Business and Commerce Code Chapter 510, redesignated from Chapter 509 on 1 September 2025. A data broker meeting the Section 510.003 revenue or 50,000-individual test must register with the secretary of state and pay a $300 fee each year.

Applies to: Companies that process or transfer personal data they did not collect directly from the individual, including enrichment vendors, list providers, ad-tech intermediaries and analytics firms doing business in Texas.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

If you look up Texas data broker registration and land on Business and Commerce Code Chapter 509, you are reading the wrong chapter. Chapter 509 is now the SCOPE Act. The data broker rules moved, the definition of "data broker" was broadened, and the registration statement gained a new required field, all with effect from 1 September 2025.

The chapter moved, and the reason is worth knowing

Two bills in the 2023 session both added a "Chapter 509" to the Business and Commerce Code. S.B. 2105 created the data broker chapter, effective 1 September 2023. H.B. 18 created the SCOPE Act, covering digital service providers and minors, effective 1 September 2024. Texas resolves that kind of collision in a later non-substantive codification act.

The credit line printed under each section of the current chapter records what happened:

"Added by Acts 2023, 88th Leg., R.S., Ch. 963 (S.B. 2105), Sec. 1, eff. September 1, 2023. Redesignated from Business and Commerce Code, Chapter 509 by Acts 2025, 89th Leg., R.S., Ch. 204 (H.B. 1620), Sec. 22.001(3), eff. September 1, 2025."

Nothing substantive turned on the renumbering itself. But section numbers shifted by one across the whole chapter, so 509.005 became 510.005, and any internal policy, contract or vendor questionnaire citing the old numbers now points at a law about social media and minors.

The definition changed in 2025, and it got wider

This is the substantive change, and it is easy to miss because it is a single clause.

As enacted in 2023, Section 509.001(4) defined a data broker as "a business entity whose principal source of revenue is derived from the collecting, processing, or transferring of personal data that the entity did not collect directly from the individual".

The current Section 510.001(4) reads:

"'Data broker' means a business entity that collects, processes, or transfers personal data that the business entity did not collect directly from the individual linked or linkable to the data."

The "principal source of revenue" qualifier is gone. The revenue question now lives only in the applicability section, which matters because the two provisions do different jobs: the definition describes the activity, and Section 510.003 decides which of those entities the chapter actually reaches.

Who has to register

Section 510.003(a) narrows the chapter to a data broker that, in a 12-month period, derives:

(1) more than 50 percent of its revenue directly from processing or transferring personal data not collected by the data broker directly from the individuals to whom the data pertains; or

(2) revenue directly from processing or transferring the personal data of more than 50,000 individuals not collected by the data broker directly from the individuals to whom the data pertains.

Limb (2) has no revenue floor. Any revenue at all, attached to more than 50,000 individuals' second-hand data, brings you in. For a mid-sized enrichment or analytics vendor that is the limb that bites, not the 50 percent test.

The word "directly" appears in both limbs in the current text and did not in the 2023 enrolled version. It was added by Acts 2025, 89th Leg., R.S., Ch. 1013 (S.B. 2121).

Who is excluded

Section 510.003(b) excludes six categories of entity: service providers, including one processing employee data for a third-party employer solely to provide employee benefits; a person or entity collecting personal data from another entity related by common ownership or corporate control, provided a reasonable consumer would expect them to share data; federal, state, tribal, territorial or local governmental entities; a congressionally designated nonprofit or national resource center assisting on missing and exploited children issues; a consumer reporting agency or furnisher or user, but only to the extent of activity regulated or authorized by the Fair Credit Reporting Act; and a financial institution subject to Title V of the Gramm-Leach-Bliley Act.

Section 510.002(b) separately excludes categories of data even for a covered broker: qualifying deidentified data, employee data, publicly available information, inferences drawn exclusively from multiple independent sources of publicly available information that do not reveal sensitive data, and GLBA Title V data.

The deidentified-data exclusion has three cumulative conditions: reasonable technical measures against reidentification, a clear and conspicuous public commitment both to process and transfer the data only in deidentified form and not to attempt reidentification, and contractual obligations on recipients that must be carried forward into any onward transfer.

What registration involves

Section 510.005(a) requires a covered data broker, to conduct business in Texas, to register with the secretary of state by filing a registration statement and paying a $300 fee. Under 510.005(d), the certificate expires on the first anniversary of issuance and renewal costs another $300.

The registration statement under 510.005(b) must include the legal name; a contact person and the primary physical address, email address, telephone number and website; a description of the categories of data processed and transferred; whether the broker operates a purchaser credentialing process; where the broker has actual knowledge it holds the personal data of a known child, statements on collection practices, databases, sales activities and opt-out policies for that data and on compliance with applicable child privacy law; and the number of security breaches experienced in the preceding year with the number of consumers affected where known.

Added in 2025 by S.B. 1343, Section 510.005(b)(2-a) now also requires "a link to a page on the data broker's Internet website that provides consumers with specific instructions, which must be prominently displayed, on how to exercise their consumer rights under Section 541.051, and any other applicable data privacy rights under Chapter 541". That ties registration directly to the Texas Data Privacy and Security Act rights machinery.

Section 510.006 requires the secretary of state to maintain a searchable public registry containing the 510.005(b) information for each broker, which makes registration status verifiable by anyone, including a plaintiff.

The website notice and the security program

Section 510.004 requires a data broker maintaining a website or mobile application to post a conspicuous notice stating that the entity is a data broker, that is clear, not misleading and readily accessible to the general public including individuals with a disability, that contains language prescribed by secretary of state rule, and, as amended in 2025, that informs a consumer how to exercise any consumer rights they may have under Chapter 541.

Section 510.007 imposes a standalone duty to protect personal data through a written comprehensive information security program with administrative, technical and physical safeguards appropriate to the broker's size, scope and type of business, resources, volume of stored data, and the need for security and confidentiality.

What it costs to get this wrong

Section 510.008 sets the civil penalty for violating the notice duty in 510.004 or the registration duty in 510.005. It may not be less than the total of $100 for each day in violation plus unpaid registration fees for each year of non-registration, and may not exceed $10,000 against the same data broker in a 12-month period. The attorney general brings the action and may recover reasonable attorney's fees and court costs.

The security-program duty is enforced differently. Section 510.009 makes a violation of Section 510.007 a deceptive trade practice in addition to the practices described by Subchapter E, Chapter 17, and actionable under that subchapter. That routes it into the Texas Deceptive Trade Practices Act rather than the $10,000 cap, which is the more consequential exposure of the two.

Next step

Compliance checklist

  • Apply the Section 510.003(a) test over a 12-month period: more than 50 percent of revenue derived directly from processing or transferring personal data not collected directly from the individuals, or revenue derived directly from processing or transferring the personal data of more than 50,000 individuals not collected directly from them.
  • Check the Section 510.003(b) entity exclusions, which cover service providers, affiliates under common ownership where a reasonable consumer would expect data sharing, governmental entities, FCRA-regulated activity, and financial institutions subject to Title V of the Gramm-Leach-Bliley Act.
  • Check the Section 510.002(b) data exclusions, which cover deidentified data meeting three conditions, employee data, publicly available information, inferences drawn exclusively from multiple independent public sources, and GLBA Title V data.
  • Register with the secretary of state under Section 510.005 and pay the $300 fee. The certificate expires on the first anniversary of issuance and renewal costs $300.
  • Include the item added in 2025: Section 510.005(b)(2-a) requires a link to a page giving prominently displayed instructions on exercising consumer rights under Section 541.051 and other Chapter 541 rights.
  • Post the website notice required by Section 510.004, which must state that the entity is a data broker, be clear and accessible, contain the language prescribed by secretary of state rule, and inform consumers how to exercise Chapter 541 rights.
  • Maintain the written comprehensive information security program required by Section 510.007, since a violation of that section is a deceptive trade practice under Section 510.009.

Sources

Last verified: 2026-09-16

Informational, not legal advice.