Back to the hub

What must a Texas TDPSA processor agreement include?

Texas Business and Commerce Code section 541.104(b) requires a written contract governing any processing a processor performs for a controller. It must set out clear processing instructions, the nature and purpose of processing, the type of data, the duration, the parties' rights and obligations, and six specific processor duties.

Applies to: Controllers subject to the Texas Data Privacy and Security Act and the vendors that process personal data on their behalf, both of whom need a contract meeting Tex. Bus. & Com. Code Section 541.104(b).

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Texas puts the controller-processor relationship on paper and then says exactly what has to be on that paper. If you buy or sell data processing services and operate in Texas, Section 541.104(b) is the clause list your contract gets measured against.

The contract requirement

Section 541.104(b): a contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller. Five framing terms must be in it:

clear instructions for processing data; the nature and purpose of processing; the type of data subject to processing; the duration of processing; and the rights and obligations of both parties.

None of these are unusual if you have written a GDPR Article 28 agreement. The value is in the specificity: "we may process your data as needed to provide the services" does not meet a requirement for clear instructions, a stated purpose, a defined data type, and a duration.

The six duties the contract must impose

Section 541.104(b)(6) requires the contract to include a requirement that the processor shall:

ensure that each person processing personal data is subject to a duty of confidentiality with respect to the data; at the controller's direction, delete or return all personal data to the controller as requested after the provision of the service is completed, unless retention of the personal data is required by law; make available to the controller, on reasonable request, all information in the processor's possession necessary to demonstrate the processor's compliance with the requirements of this chapter; allow, and cooperate with, reasonable assessments by the controller or the controller's designated assessor; and engage any subcontractor pursuant to a written contract that requires the subcontractor to meet the requirements of the processor with respect to the personal data.

The confidentiality duty runs to each person, not to the company in the abstract. The deletion duty is triggered at the controller's direction after the service ends, with a legal-retention carve-out. And the subcontractor clause is a flow-down: your vendor's vendors have to be under equivalent written terms.

The audit alternative most negotiations end up using

Section 541.104(c) gives processors a way out of bespoke customer audits. Notwithstanding the requirement in Subsection (b)(6)(D), a processor may instead arrange for a qualified and independent assessor to conduct an assessment of the processor's policies and technical and organizational measures in support of the chapter's requirements, using an appropriate and accepted control standard or framework and assessment procedure. The processor shall provide a report of the assessment to the controller on request.

This is why a SOC 2 report or equivalent usually ends the audit-rights argument in a Texas negotiation. Note the limits: the assessor must be qualified and independent, the standard must be an accepted one, and the report has to actually be provided on request.

Roles are decided by facts, not by the contract label

Two provisions stop parties from drafting their way out of responsibility.

Section 541.104(d): the section may not be construed to relieve a controller or a processor from the liabilities imposed on it by virtue of its role in the processing relationship as described by the chapter.

Section 541.104(e): a determination of whether a person is acting as a controller or processor with respect to a specific processing of data is a fact-based determination that depends on the context in which personal data is to be processed. A processor that continues to adhere to a controller's instructions with respect to a specific processing of personal data remains in the role of a processor.

Read the second one the other way round and the risk becomes clear. A vendor that starts using customer data for its own purposes has stopped following instructions, and has stopped being a processor for that activity, with a controller's duties attaching instead. California draws a similar line, covered on our service provider vs third party page.

What the processor owes beyond the contract

Section 541.104(a) requires a processor to adhere to the controller's instructions and to assist the controller in meeting its duties under the chapter, including assistance with the security of processing, with breach notification, and with the controller's data protection assessments under Section 541.105. That subsection was amended by H.B. 149 in the 2025 session, effective January 1, 2026, to expand the assistance duty and to address personal data collected, stored, and processed by an artificial intelligence system.

If you are the controller, that assistance duty is what makes your data protection assessment workable when the processing sits inside a vendor's systems.

Next step

If you already maintain GDPR Article 28 data processing agreements, the Texas clause list is close enough that one paper usually covers both, with a Texas-specific rider. The free 2-minute Obligation Scan tells you which state privacy laws reach your business and which vendor contracts they expect you to hold.

Compliance checklist

  • Put a written contract in place before processing starts; Section 541.104(b) requires the contract to govern the processor's data processing procedures on the controller's behalf.
  • Cover the five framing terms: clear instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties.
  • Impose the confidentiality duty on every person who touches the data, and set the deletion-or-return step at the end of the service, subject to legal retention.
  • Include audit rights, and decide up front whether you will accept the independent-assessor report route that Section 541.104(c) permits instead of your own assessment.
  • Require written flow-down contracts for subcontractors, imposing the same requirements on them with respect to the personal data.

Sources

Last verified: 2026-08-19

Informational, not legal advice.