TDPSA § 541.101
Controller Duties; Transparency
Reference only. The Privisy audit does not test this section.
- Source
- Statute
- In force from
- July 1, 2024
- Last reviewed
- September 2026
- Framework
- TDPSA
What it requires
Sets out controller duties: data minimization limited to what is adequate, relevant, and reasonably necessary for the disclosed purposes (subsection (a)(1)) and reasonable administrative, technical, and physical data security (subsection (a)(2)). Subsection (b) prohibits processing data for incompatible purposes without consent, unlawful discrimination against consumers, and processing a consumer's sensitive data without consent (or, for a known child, other than in accordance with COPPA). The privacy-notice content requirements are set out separately in § 541.102.
Statute text
(a) A controller: (1) shall limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which that personal data is processed, as disclosed to the consumer; and (2) for purposes of protecting the confidentiality, integrity, and accessibility of personal data, shall establish, implement, and maintain reasonable administrative, technical, and physical data security practices that are appropriate to the volume and nature of the personal data at issue. (b) A controller may not: [...] (4) process the sensitive data of a consumer without obtaining the consumer's consent, or, in the case of processing the sensitive data of a known child, without processing that data in accordance with the Children's Online Privacy Protection Act of 1998 (15 U.S.C. Section 6501 et seq.).
Texas Data Privacy and Security Act, § 541.101Read the full section from Texas Office of the Attorney General
This page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.