Back to the hub

Does Texas give businesses a chance to cure a privacy violation?

Yes. Texas Business and Commerce Code Section 541.154 requires the attorney general to give written notice at least 30 days before suing, and bars the action if the business cures the violation and sends a written statement within that window. Penalties reach $7,500 per violation only afterwards.

Applies to: Controllers and processors subject to the Texas Data Privacy and Security Act that receive a notice of violation from the Texas attorney general, who has exclusive authority to enforce the chapter.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Texas built a gate in front of its own enforcement. The attorney general cannot go straight to court over a TDPSA violation; a written notice has to come first, and the business gets 30 days to make the problem go away. Used properly, that is the difference between a fixable compliance defect and a civil penalty.

What Section 541.154 actually says

Before bringing an action under Section 541.155, the attorney general shall notify a person in writing, not later than the 30th day before bringing the action, identifying the specific provisions of the chapter the attorney general alleges have been or are being violated.

The notice has to identify provisions, not merely assert that something is wrong. That is useful: it tells you what has to be cured, and it bounds the work.

The two things you must do inside 30 days

The statute then bars the action if two conditions are met. First, within the 30-day period, the person cures the identified violation. Second, the person provides the attorney general a written statement that the person:

Cured the alleged violation. Notified the consumer that the consumer's privacy violation was addressed, if the consumer's contact information has been made available to the person. Provided supportive documentation to show how the privacy violation was cured. And made changes to internal policies, if necessary, to ensure that no such further violations will occur.

Both conditions. A business that quietly fixes the defect and sends nothing has not satisfied Section 541.154, and a business that sends a confident letter without fixing anything certainly has not. The four elements of the statement are not boilerplate either; two of them, the consumer notification and the supportive documentation, require work you can only do if you started early.

What happens if you miss it

Section 541.155(a) is narrower than it is usually described. A person is liable for a civil penalty of not more than $7,500 for each violation if they violate the chapter following the cure period described by Section 541.154, or if they breach a written statement provided to the attorney general under that section.

Read that carefully, because it sets the two doors into liability. One is failing to cure in time. The other is curing, promising, and then not keeping the promise. The written statement is an enforceable commitment, and going back on it exposes you to the same $7,500 per violation.

Under Section 541.155(b) the attorney general may sue to recover the penalty, to restrain or enjoin the conduct, or both, and under Section 541.155(c) may recover reasonable attorney's fees and other reasonable expenses incurred in investigating and bringing the action. The investigation costs are recoverable, which quietly raises the real number well above the headline penalty.

Only the attorney general can bring the case

Section 541.151 gives the attorney general exclusive authority to enforce the chapter, and Section 541.156 provides that the chapter may not be construed as providing a basis for a private right of action.

That is a meaningful contrast with California, where Cal. Civ. Code Section 1798.150 gives consumers a limited private right of action for certain data breaches. In Texas the entire enforcement risk runs through one office, which is why the notice-and-cure mechanism matters so much: it is the only channel, and it opens with a warning.

Where the 30 days usually goes wrong

The failure is rarely legal. It is that the notice arrives addressed to a registered agent or a general counsel inbox, sits for a fortnight, and reaches the people who can actually change a data flow with ten days left. Curing a real violation, notifying affected consumers, gathering evidence, and amending internal policy is not a ten-day job.

Decide now who opens that envelope and what happens in the first 48 hours.

Next step

The cheapest cure is not needing one. The free 2-minute Obligation Scan checks your business against every US state privacy law and GDPR at once and shows you which obligations already apply to you. For applicability, see the Texas TDPSA overview; for the penalty detail, see Texas TDPSA fines and penalties; and for the deadlines that generate most violations in the first place, see the Texas response deadline.

Compliance checklist

  • Treat a notice under Section 541.154 as a 30-day project with a hard deadline, because the attorney general may bring the action on day 31 if the violation is not cured.
  • Read the notice for the specific provisions cited: Section 541.154 requires the attorney general to identify the provisions alleged to have been violated, which scopes the work.
  • Fix the underlying violation, and separately assemble the written statement, since Section 541.154 requires both before the bar on suit applies.
  • Notify affected consumers that the violation was addressed where you hold their contact information, which is one of the four required elements.
  • Keep the supportive documentation that shows how the violation was cured; it is a statutory element, not an optional attachment.
  • Update internal policies where necessary and record that you did, then honor the statement afterwards, because Section 541.155(a) makes breaching it a separate route to liability.

Sources

Last verified: 2026-08-28

Informational, not legal advice.