Back to the hub

What are the penalties for violating the Texas Data Privacy and Security Act?

Texas caps civil penalties at $7,500 for each violation of the Data Privacy and Security Act, but only after a 30-day cure period has run. The attorney general has exclusive enforcement authority, may also recover attorney's fees and investigation costs, and there is no private right of action.

Applies to: Controllers and processors subject to the Texas Data Privacy and Security Act that receive a notice of violation from the Texas attorney general, and any business assessing its enforcement exposure in Texas.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Texas set its maximum penalty at a level that sounds serious and then built a cure process in front of it that most businesses will never get past. Understanding the sequence matters more than memorizing the number.

The number, and what triggers it

Section 541.155(a): a person who violates this chapter following the cure period described by Section 541.154, or who breaches a written statement provided to the attorney general under that section, is liable for a civil penalty in an amount not to exceed $7,500 for each violation.

Read the conditions carefully. The penalty does not attach to the original violation. It attaches to violating after the cure period has run, or to breaking the promise you made in the written statement. A business that cures properly the first time never gets as far as the $7,500.

"Each violation" is where exposure compounds. The statute does not define a violation as one enforcement matter, so a practice affecting many consumers is the scenario that turns a capped number into a large one.

The 30-day cure period, which has not expired

Section 541.154 requires that before bringing an action under Section 541.155, the attorney general shall notify a person in writing, not later than the 30th day before bringing the action, identifying the specific provisions of the chapter the attorney general alleges have been or are being violated.

The attorney general then may not bring an action if two things happen. First, within the 30-day period, the person cures the identified violation. Second, the person provides the attorney general a written statement that the person cured the alleged violation; notified the consumer that the consumer's privacy violation was addressed, if the consumer's contact information has been made available to the person; provided supportive documentation to show how the privacy violation was cured; and made changes to internal policies, if necessary, to ensure that no such further violations will occur.

This is the detail that separates Texas from California. The CCPA's cure period sunset when the CPRA took effect. Texas wrote no expiry into Section 541.154, so the cure right is a standing feature of the law rather than a transitional grace period.

It is also more demanding than it first appears. Curing the technical problem satisfies only the first condition. The written statement carries four distinct commitments, and one of them, changing internal policies, is a forward-looking promise that Section 541.155(a) then makes independently enforceable if you break it.

Who can come after you

Section 541.151 is one sentence: the attorney general has exclusive authority to enforce this chapter.

Section 541.156 closes the other door: the chapter may not be construed as providing a basis for, or being subject to, a private right of action for a violation of the chapter or any other law.

Together those two sections put Texas in a very different risk category from Illinois, where BIPA's private right of action produces the class actions that dominate US biometric litigation. In Texas there is exactly one plaintiff, and it must warn you first.

How an action actually starts

Section 541.153(a) gives the attorney general a civil investigative demand whenever there is reasonable cause to believe that a person has engaged in or is engaging in a violation. The procedures established for issuing a civil investigative demand under Section 15.10 apply in the same manner.

Section 541.152 requires the attorney general to post information on its Internet website, including a mechanism for consumers to submit complaints. Complaints are the most likely origin of a matter, so a functioning consumer request process is your first line of defense long before any penalty question arises.

What it costs beyond the penalty

Two provisions add to the bill. Section 541.155(c) allows the attorney general to recover reasonable attorney's fees and other reasonable expenses incurred in investigating and bringing an action. Section 541.155(d) directs that a civil penalty collected be deposited in accordance with Section 402.007, Government Code.

Section 541.155(b) sets out what the attorney general can ask a court for: to recover a civil penalty, to restrain or enjoin the person from violating the chapter, or to recover the penalty and seek injunctive relief together. The injunction is often the more disruptive outcome, because it can force a product change on a court's timetable rather than yours.

Next step

Penalty exposure only matters if the law applies to you, and Texas decides that with a small-business test rather than a revenue or headcount threshold. The free 2-minute Obligation Scan tells you which US state privacy laws reach your business and what each requires. See the Texas TDPSA overview for the applicability test, Texas TDPSA vs CCPA for how the two regimes differ, and CCPA fines and penalties for the California comparison.

Compliance checklist

  • Treat any written notice from the Texas attorney general as a 30-day clock, because Section 541.154 requires notice at least 30 days before an action is filed.
  • Cure the identified violation inside that 30-day window; curing alone is not enough to stop an action without the written statement that follows.
  • Send the attorney general a written statement confirming all four points in 541.154(2): that you cured the violation, notified the affected consumer where you have their contact details, provided supporting documentation showing how you cured it, and changed internal policies where needed to prevent recurrence.
  • Do not breach that written statement afterward. Section 541.155(a) makes breaching it independently penalizable, on the same $7,500-per-violation basis as violating after the cure period.
  • Budget for more than the penalty. Section 541.155(c) lets the attorney general recover reasonable attorney's fees and other reasonable expenses of investigating and bringing the action.
  • Expect a civil investigative demand before anything else, since Section 541.153(a) allows one whenever the attorney general has reasonable cause to believe a violation is occurring.

Sources

Last verified: 2026-08-23

Informational, not legal advice.