How long does a business have to respond to a Texas privacy request?
Under Texas Business and Commerce Code Section 541.052(b), a controller must respond to a consumer privacy request without undue delay and no later than the 45th day after receipt. The period may be extended once by 45 more days if the controller tells the consumer within the first 45 days.
Applies to: Controllers subject to the Texas Data Privacy and Security Act that receive a consumer request to access, correct, delete, port, or opt out under Section 541.051, and that must also run an appeal process.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanTexas runs two clocks, and most teams only build for one of them. The 45-day request deadline is well known. The 60-day appeal deadline sits in the next section and catches people out, because an appeal usually arrives after a refusal, which is exactly when a process is under strain.
The 45-day rule, in the statute's own words
Section 541.052(b) says a controller shall respond to the consumer request without undue delay, which may not be later than the 45th day after the date of receipt of the request.
Two parts of that sentence do work. "Without undue delay" is the standing obligation; the 45th day is the outer limit, not the target. And the clock runs from receipt. Not from the day you decide the request is valid, not from the day it reaches the right inbox. If a request lands in a support queue on the 1st and reaches your privacy team on the 20th, you have spent nineteen days of your allowance.
The extension is conditional, and the condition is a notice
The same subsection allows one extension of 45 additional days when reasonably necessary, taking into account the complexity and number of the consumer's requests. But it is conditional: the controller must inform the consumer of the extension within the initial 45-day response period, together with the reason for the extension.
That makes the extension a thing you have to claim, in time, in writing. A controller that quietly runs past day 45 and sends the substantive answer on day 60 has not used an extension. It has missed a deadline. The practical fix is unglamorous: a calendar trigger around day 30 that forces a decision on whether the extension is needed, while there is still room to send the notice.
Declining still has to happen inside 45 days
Section 541.052(c) covers the case where you say no. If a controller declines to take action regarding the consumer's request, it shall inform the consumer without undue delay, and not later than the 45th day after receipt, of the justification for declining.
So there is no slower track for refusals. A "no" is due on the same schedule as a "yes", and it has to carry a reason.
The second clock: 60 days for appeals
Section 541.053(a) requires a controller to establish a process for a consumer to appeal a refusal to act. Section 541.053(b) requires that process to be conspicuously available and similar to the process for submitting a request in the first place, which rules out burying appeals behind a support ticket when requests go through a self-serve form.
Then Section 541.053(c): the controller shall inform the consumer in writing of any action taken or not taken in response to an appeal not later than the 60th day after the date of receipt of the appeal, including a written explanation of the reason or reasons for the decision.
Sixty days, from receipt of the appeal, in writing, with reasons. And under Section 541.053(d), if you deny the appeal you must give the consumer the online mechanism described in Section 541.152 through which they can contact the attorney general to complain. You are required to hand the consumer the escalation path.
Which requests the clocks apply to
The deadlines attach to the rights in Section 541.051(b): confirming whether you are processing the consumer's personal data and accessing it, correcting inaccuracies, deleting personal data provided by or obtained about the consumer, obtaining a copy where the data is available in a digital format, and opting out. A parent or legal guardian may exercise these rights on behalf of a known child.
Why the appeal clock is the one that hurts
Request deadlines are easy to instrument because requests arrive through a channel you built. Appeals arrive as a reply to a rejection email, often to a person rather than a queue, and they are rare enough that nobody has a habit for them. That combination produces the failure mode: a well-run 45-day process feeding an unmonitored 60-day one.
If you do one thing after reading this, route appeals into the same tracked system as requests rather than leaving them in an inbox.
Next step
Texas is not alone in using 45 days, but its 60-day appeal deadline and its small-business applicability gate are its own. The free 2-minute Obligation Scan checks your business against every US state privacy law and GDPR at once and tells you which deadlines you are actually on the hook for. For the applicability test, see the Texas TDPSA overview; for the enforcement side of a missed deadline, see the Texas cure period; and to compare the clocks side by side, see privacy request response deadlines by state.
Compliance checklist
- Date-stamp every request on receipt, because Section 541.052(b) runs the 45 days from the date of receipt rather than from the date you validate or triage it.
- Build the extension notice into the workflow at day 30, since the extension only exists if you tell the consumer within the initial 45-day period and give the reason.
- If you decline a request, still answer inside 45 days: Section 541.052(c) requires you to give the justification for declining within the same period.
- Stand up the appeal process required by Section 541.053(a) and make it conspicuously available and similar to your request intake, as Section 541.053(b) requires.
- Track appeals on a separate 60-day clock under Section 541.053(c), and put the written explanation of the decision in the response.
- When you deny an appeal, include the attorney general's online complaint mechanism, which Section 541.053(d) requires you to provide.
Sources
- Tex. Bus. & Com. Code Section 541.052, Controller Response to Consumer Request, Texas Statutes
- Tex. Bus. & Com. Code Section 541.053, Appeal, Texas Statutes
- Tex. Bus. & Com. Code Section 541.051, Consumer's Personal Data Rights; Request to Exercise Rights, Texas Statutes
Last verified: 2026-08-28
Informational, not legal advice.