TDPSA § 541.055

Methods for Submitting Consumer Requests

Reference only. The Privisy audit does not test this section.

Source
Statute
In force from
January 1, 2025
Last reviewed
September 2026
Framework
TDPSA

What it requires

Section 541.055 governs the methods a controller must provide for consumers to submit requests. Its authorized-agent provision (subsection (e)) implements a universal opt-out signal as a technology-based agent designation: a consumer may designate an agent via an internet link, a browser setting or extension, or a global device setting (e.g., GPC) to signal intent to opt out of targeted advertising and the sale of personal data (§ 541.051(b)(5)(A)-(B)). Starting January 1, 2025 (six months after the Act's general July 1, 2024 effective date), a controller must comply with such an opt-out request if it can verify, with commercially reasonable effort, the consumer's identity and the agent's authority to act for the consumer. The duty is conditional: a controller is not required to comply if the agent does not communicate the request clearly and unambiguously, the controller cannot verify with commercially reasonable effort that the consumer is a Texas resident, the controller lacks the ability to process the request, or the controller does not process similar or identical requests it receives from consumers to comply with similar or identical laws or regulations of another state (§ 541.055(e)(1)-(4)). Under § 541.055(f), the technology may not unfairly disadvantage another controller, may not use a default setting (it must require the consumer's affirmative, freely given, and unambiguous choice to opt out), and must be consumer-friendly, so a signal that is switched on by default may not qualify.

Statute text

A consumer may designate another person to serve as the consumer's authorized agent and act on the consumer's behalf to opt out of the processing of the consumer's personal data under Sections 541.051(b)(5)(A) and (B). A consumer may designate an authorized agent using a technology, including a link to an Internet website, an Internet browser setting or extension, or a global setting on an electronic device, that allows the consumer to indicate the consumer's intent to opt out of the processing. A controller shall comply with an opt-out request received from an authorized agent under this subsection if the controller is able to verify, with commercially reasonable effort, the identity of the consumer and the authorized agent's authority to act on the consumer's behalf.

Texas Data Privacy and Security Act, § 541.055Read the full section from Texas Office of the Attorney General

This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.

See what your site actually does under these rules.

The Privisy audit runs 56 checks on your live site and cites the section behind every finding.

Get Your Audit