Orange textured background

US state law

TDPSA and browser fingerprinting

How the Texas Data Privacy and Security Act regulates device fingerprinting, the small-business test that replaces numeric consumer thresholds, and the explicit notice-at-collection requirement that other state laws lack.

Reviewed

RegionTexas, USA
RegulatorTexas Attorney General (Consumer Protection Division)
Effective1 July 2024
Max penaltyUp to $7,500 per violation in civil penalties (Tex. Bus. & Com. Code §541.155)
Status in-force

What TDPSA says about fingerprinting

The Texas Data Privacy and Security Act took effect on 1 July 2024 and is codified at Tex. Bus. & Com. Code Chapter 541. Texas imported the Virginia template largely intact, with two distinctive modifications that change the operational posture for a fingerprinting deployment: the small-business applicability test and the notice-at-collection requirement.

Section 541.001(20) defines personal data as 'any information, including sensitive data, that is linked or reasonably linkable to an identified or identifiable individual'. The shared linked-or-reasonably-linkable wording lands a fingerprint hash inside the definition the moment it is used to recognise a returning Texas resident.

Texas does something none of the other Virginia-cluster states do at the applicability layer. There is no statutory 100,000-or-25,000-consumer threshold. Instead, §541.002 applies the act to controllers that conduct business in Texas (or produce products or services that are consumed by Texas residents), process or engage in the sale of personal data, AND are not 'small businesses' as defined by the United States Small Business Administration under 13 C.F.R. Part 121. The SBA size standards vary by NAICS code, a software-publishing business is a small business below $47 million in annual revenue, while a retail business may fall below the threshold below 100 employees.

The notice-at-collection rule

Section 541.052 requires every controller to maintain a 'reasonably accessible, clear, and meaningful privacy notice' that includes (a) the categories of personal data processed, (b) the purposes for processing, (c) the categories of personal data shared with third parties, (d) the categories of those third parties, and (e) an active rights-request mechanism. This is more prescriptive than VCDPA's analogous §59.1-578 notice rule and closer to CCPA's notice-at-collection requirement.

For a fingerprinting deployment, the operational implication is that the privacy notice must name 'device or browser fingerprinting' (or an equivalent functional description) as a processing activity, name every ad-tech partner or analytics vendor that receives the fingerprint, and state the purpose. A privacy notice that buries fingerprinting inside a generic 'we collect device information' clause is non-compliant by construction. The Texas AG has flagged this in early guidance as a documentation-failure trap that catches mid-size controllers by surprise.

The opt-out triggers and how they apply to fingerprinting

Section 541.051 grants Texas consumers six rights, including the right to opt out of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects. The mechanical operation tracks VCDPA closely.

Sale of personal data under §541.001(28) requires monetary consideration only. This is the narrowest sale definition in the cluster after Virginia. Sharing fingerprint hashes with an ad-tech partner for mutual lift, without a direct dollar payment, is less likely to qualify as sale in Texas than in Colorado or Connecticut.

Targeted advertising at §541.001(33) and profiling at §541.001(24) carry the standard Virginia-template scope. The profiling opt-out applies only to decisions with legal or similarly significant effects, financial services, housing, insurance, education, criminal justice, employment, healthcare, or essential goods and services.

Common fingerprinting purposes under TDPSA

PurposePersonal data?DPA required (§541.105)?Opt-out right applies?
Anti-fraud at login or paymentYesNo (security-of-service carve-out)No
Account-takeover detectionYesNoNo
Bot mitigation on a public formYesNoNo
Cross-site targeted advertisingYesYesYes (targeted advertising)
Sharing fingerprint hashes for non-monetary valueYesProbably not (monetary-only sale definition)Probably no for sale; yes if used for targeted ads
Selling fingerprint-derived audience segments for a feeYesYesYes (sale)
Profiling for credit / insurance / employmentYesYesYes (profiling with legal effect)
Product analytics on your own serviceYesNoNo
Fingerprinting on an internal employee toolNo (employee carve-out)NoNo

Data Protection Assessments under §541.105

Texas requires a Data Protection Assessment before engaging in targeted advertising, sale of personal data, processing of sensitive data, or profiling that presents a 'reasonably foreseeable risk' of unfair or deceptive treatment, financial injury, physical injury, or other substantial injury. The §541.105 assessment requirements track VCDPA's §59.1-580 language closely, with one Texas-specific addition: the assessment must be made available to the AG on request within 30 days.

The 30-day production window is shorter than Colorado's and creates a documentation cadence: assessments must exist contemporaneously, not be drafted reactively when the AG asks. Treat the assessment as a build-time artefact, not a compliance afterthought.

Universal Opt-Out Mechanism handling

Texas requires Universal Opt-Out Mechanism support effective 1 January 2025 under §541.055. The Texas AG has indicated alignment with the multi-state norm: Global Privacy Control is the operative UOOM. A fingerprinting script that fires for a targeted-advertising or sale-flagged purpose without first checking the GPC header is non-compliant.

The operational mechanic is identical to Colorado and Connecticut. The CMP and the UOOM check both resolve before Benny is invoked; Benny does not implement consent gating internally.

The cure period is still in place

Section 541.155(a)(2) gives controllers 30 days to cure after receiving notice of a violation from the Texas AG. Unlike Colorado and Connecticut, Texas did not sunset this provision. As of 2026, the cure mechanism is still available for first-time violations. Practical implication: the operational compliance posture in Texas is materially less first-strike than in Colorado, Connecticut, Oregon, Montana, Delaware, or New Hampshire.

The AG's office has signalled that the cure mechanism is for genuine documentation gaps and inadvertent processing errors, not for controllers who knew the law and ignored it. Repeat or wilful violations are likely to bypass the cure window even while it formally exists.

Enforcement to date

  • The Texas AG's Consumer Protection Division opened the first TDPSA inquiries in late 2024, focused on missing privacy notices under §541.052 and the absence of UOOM handling.
  • Texas has not yet published a major TDPSA settlement at the time of writing, but the AG's office has been the most active enforcer of the Texas Identity Theft Enforcement and Protection Act and the broader Deceptive Trade Practices Act, both of which can attach as parallel claims to a TDPSA matter.
  • There is no private right of action under TDPSA. Class plaintiffs cannot bring TDPSA claims directly. Parallel DTPA private actions exist for deceptive-trade-practice claims, but the TDPSA-to-DTPA attachment path has not yet been tested.
  • The cure-period mechanism has been used in the public AG inquiries known so far; first-strike enforcement remains the AG's stated stance for wilful violations only.

How Benny the Doorman fits into a TDPSA-aware deployment

Four steps for a TDPSA-aware deployment. First, verify your SBA size status. If you are a small business under 13 C.F.R. Part 121 for your NAICS code, TDPSA does not apply to you. If you are not, proceed to the next three.

Second, update the §541.052 privacy notice to name fingerprinting as a processing activity, name the recipients (every ad-tech, analytics, or fraud-detection partner that receives the fingerprint), and state the purposes. A generic 'we collect device information' clause is non-compliant.

Third, install a GPC header check upstream of every Benny call used for targeted advertising or sale-flagged purposes, the same upstream pattern Colorado and Connecticut require.

Fourth, complete and document a §541.105 Data Protection Assessment before going live, and treat it as a build-time artefact: the 30-day AG production window is shorter than Colorado's.

Frequently asked questions

Is browser fingerprinting illegal under TDPSA?

No. Fingerprinting is regulated as personal data when it can be linked back to a Texas resident. Lawful use requires the SBA small-business test (you must be above it), an explicit §541.052 privacy notice naming fingerprinting, Universal Opt-Out Mechanism support for targeted-advertising and sale purposes, and a §541.105 Data Protection Assessment for regulated processing activities.

Does TDPSA apply to my company?

It applies if you conduct business in Texas or produce products consumed by Texas residents, you process or sell personal data, and you are NOT a 'small business' under SBA size standards (13 C.F.R. Part 121). Unlike other state laws, there is no numeric consumer-count threshold, the test is your industry-specific revenue or employee size.

What is the SBA small-business test?

The Small Business Administration publishes size standards for every NAICS industry code. Software publishing is small below $47 million in annual revenue; retail trade is typically size-tested by employee count below 100 to 500 depending on the specific sub-sector. Look up your primary NAICS code at sba.gov/document/support-table-size-standards and compare against your average annual receipts or employee count over the prior three years.

Do I need to honour Global Privacy Control under Texas law?

Yes, since 1 January 2025. TDPSA §541.055 requires Universal Opt-Out Mechanism support, and the Texas AG has aligned with the multi-state norm of treating GPC as the operative UOOM. A fingerprinting script that fires for a targeted-advertising or sale-flagged purpose without first checking the GPC header is non-compliant.

Is sharing fingerprint hashes for ad-tech 'sale' under Texas law?

Usually no, if the exchange is not for monetary consideration. TDPSA's sale definition at §541.001(28) requires monetary consideration, matching Virginia and narrower than Colorado or Connecticut. Sharing fingerprint hashes for mutual lift without a direct dollar payment is more likely to count as targeted advertising (still opt-out-able) than as sale.

What is the cure period under TDPSA?

30 days from the AG's notice of violation, under §541.155(a)(2). Unlike Colorado and Connecticut, Texas did not sunset its cure window. As of 2026, the cure mechanism is still in place for genuine documentation gaps and inadvertent processing errors; wilful violations may bypass it.

What are the fines for non-compliant fingerprinting under TDPSA?

Civil penalties under §541.155 reach $7,500 per violation, matching Virginia's cap. The Texas AG can also seek injunctive relief and recover investigation costs. Parallel Deceptive Trade Practices Act claims, if pleaded, can attach treble damages, but the DTPA-attachment path has not been tested against a TDPSA-grounded fingerprinting case.

Can I sell fingerprint-derived precise geolocation under TDPSA?

No, never. Section 541.107(a) prohibits the sale of sensitive data outright, including precise geolocation. Consent does not override this prohibition. If your data pipeline monetises geolocation derived from a fingerprint, the flow is illegal under Texas law regardless of how clean the consent collection is.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06