Back to the hub

How must a business let Texas consumers submit a privacy request?

Texas Business and Commerce Code Section 541.055(a) requires a controller to establish two or more secure and reliable methods for consumers to submit privacy requests. Section 541.055(b) bars requiring a new account, and a controller operating exclusively online with a direct consumer relationship need only provide an email address.

Applies to: Controllers subject to the Texas Data Privacy and Security Act that need to build or check the intake side of their privacy program, including the website mechanism and the methods listed in their privacy notice.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Most Texas privacy programs are built around the 45-day response clock in Section 541.052. Fewer are built around the section that governs how the request is allowed to reach you in the first place, which is where a surprising number of programs fail on paper.

Two methods, not one

Section 541.055(a) requires a controller to establish two or more secure and reliable methods to enable consumers to submit a request to exercise their rights under the chapter. A single contact form is one method. A single email address is one method.

The statute then tells you how to pick them. The methods must take into account the ways in which consumers normally interact with the controller, the necessity for secure and reliable communications of those requests, and the ability of the controller to authenticate the identity of the consumer making the request.

That third factor is the one that shapes the design. A method you cannot authenticate through is a method that will produce requests you are entitled to refuse under Section 541.052(e), which helps nobody. Pairing an in-product flow for logged-in users with a public form for everyone else is the pattern that satisfies all three factors at once.

You cannot make someone sign up to exercise a right

Section 541.055(b) is short and absolute: a controller may not require a consumer to create a new account to exercise the consumer's rights under the subchapter, but may require a consumer to use an existing account.

The two halves of that sentence are doing different work. If the person already has an account with you, routing them through it is fine and is usually the strongest authentication you have. If they do not, a signup wall in front of a deletion request is a violation, even when the account is free and takes ten seconds to create.

This catches a specific and common product decision, which is putting the privacy request flow inside an authenticated dashboard because that is where the engineering was easiest.

The website mechanism, and the online-only exception

Section 541.055(c) requires a controller that maintains an internet website to provide a mechanism on the website for consumers to submit requests for information required to be disclosed under the chapter.

Section 541.055(d) then carves out a narrow case. A controller that operates exclusively online and has a direct relationship with a consumer from whom it collects personal information is only required to provide an email address for the submission of requests described by Subsection (c).

Read the conditions carefully before relying on it. "Exclusively online" and "direct relationship" are both required. A business with a retail presence does not qualify. A business that acquires most of its data from third parties rather than from the consumer does not have the direct relationship the subsection describes.

The privacy notice has to describe the methods

The intake requirement connects to the disclosure requirement. Section 541.102(a)(6) requires the privacy notice to include a description of the methods required under Section 541.055 through which consumers can submit requests to exercise their rights. Section 541.102(a)(3) separately requires the notice to explain how consumers may exercise those rights, including the process for appealing a controller's decision.

So the notice is where an assessment starts. If your privacy notice describes one method, you have documented the gap yourself.

Why this is worth fixing early

Section 541.154 gives the attorney general a thirty-day cure period before an action, and Section 541.155(a) sets a civil penalty of up to $7,500 for each violation after it. Intake design is one of the cheapest things on that list to fix, and one of the easiest for a regulator or a competitor to check from the outside without ever filing a request.

Compliance checklist

  • Count your intake channels and confirm there are at least two, as Section 541.055(a) requires two or more secure and reliable methods rather than a single form.
  • Choose the methods against the three factors in Section 541.055(a): how consumers normally interact with you, the need for secure and reliable communication, and your ability to authenticate the person making the request.
  • Remove any requirement to register, because Section 541.055(b) prohibits requiring a new account while expressly allowing you to use an existing one.
  • If you maintain a website, provide an on-site mechanism for submitting requests under Section 541.055(c), unless the online-only exception applies.
  • If you operate exclusively online with a direct consumer relationship, confirm you qualify for Section 541.055(d) before relying on an email address alone.
  • List the methods in your privacy notice, since Section 541.102(a)(6) requires a description of the Section 541.055 methods through which consumers can submit requests.

Sources

Last verified: 2026-09-04

Informational, not legal advice.