Texas's privacy enforcement team has investigated more than 200 companies since its Data Privacy and Security Initiative launched in June 2024, according to the Texas Attorney General's July 2025 progress update. That figure spans data brokers, car manufacturers, social media platforms, and companies tied to foreign adversaries, and it sits alongside the first lawsuit filed directly under the Texas Data Privacy and Security Act (TDPSA), a data broker registration sweep, and two multibillion-dollar settlements reached under separate Texas privacy statutes.
The TDPSA itself took effect July 1, 2024, with its universal opt-out mechanism requirement following on January 1, 2025. Enforcement sits entirely with the Attorney General's office. There is no private right of action, so every case below started with a state investigator, not a plaintiff's lawyer. Texas is one of 20 states with a comprehensive consumer privacy law now in effect, and its enforcement record so far is one of the most active of that group.
How many companies has Texas investigated under its privacy enforcement initiative?
More than 200 companies have been investigated since the Data Privacy and Security Initiative launched in June 2024, housed inside the Attorney General's Consumer Protection Division, per the office's July 2025 update. That number breaks down into a few distinct enforcement tracks rather than one uniform sweep: a mass data broker registration check, a smaller batch of TDPSA-specific violation notices, and a single formal lawsuit filed to date.
Figure 1: The 200-plus figure is a cumulative investigation count, not 200 separate enforcement notices. Source: Texas Attorney General, July 2025 update; Texas Attorney General, June 2024 data broker notice.
Most of the 200-plus companies never received a public violation notice; an investigation can close quietly if a company's practices check out or if it cures a gap before the Attorney General escalates. The Attorney General's office has been explicit that data brokers, connected-car manufacturers, and companies with ties to foreign adversaries are priority categories, which is one reason the case count keeps climbing even though only a handful of matters have become public lawsuits.
What was the first enforcement action filed under the TDPSA?
The first TDPSA-specific lawsuit was filed January 13, 2025, when Texas sued Allstate and its Arity subsidiary over the collection and sale of geolocation and driving-behavior data pulled from more than 45 million Americans' cellphones. The state alleges Arity paid app developers, including GasBuddy, Fuel Rewards, and Routely, to embed tracking software that collected precise location data without adequate notice, then packaged it into a driving-behavior database sold to insurers to help justify premium increases.
Figure 2: A single year separates the TDPSA taking effect and Texas reporting a 200-plus company investigation count. Source: Texas Attorney General press releases, 2024 to 2025.
The lawsuit also alleges Arity failed to register as a data broker by the state's March 1, 2024 deadline, meaning a single case can trigger findings under both the TDPSA and the separate Data Broker Law at once. As of this writing the case remains in active litigation, so no fine or settlement figure has been set.
How does Texas enforce its data broker registration law?
Texas's Data Broker Law, a companion statute to the TDPSA under Chapter 509 of the Business and Commerce Code, required data brokers to register with the Texas Secretary of State by March 1, 2024. In June 2024, the Attorney General notified more than 100 companies that they had apparently failed to register, opening the state's first large-scale privacy enforcement sweep of the year.
The registration penalty is modest compared to the TDPSA's own civil-penalty structure: $100 per day of non-compliance, capped at $10,000 per entity per year. That cap matters for site owners using a privacy policy generator built for state disclosure requirements: a business that only sells or licenses consumer data as part of its core service, rather than as a third-party data broker, generally sits outside Chapter 509 entirely and only needs to worry about TDPSA's own notice and consent obligations.
Sites collecting Texas residents' data face two separate compliance questions as a result: whether Chapter 509's data broker registration duty applies at all, and whether the TDPSA's consumer notice, opt-out, and consent requirements are met regardless of registration status.
What are the penalties for violating the TDPSA?
A confirmed TDPSA violation carries a civil penalty of up to $7,500 per violation, but only after a mandatory 30-day cure period. A company that receives a violation notice can avoid the penalty entirely by fixing the problem, notifying affected consumers if their contact information is available, documenting how the issue was cured, and updating internal policy to prevent a repeat, all within 30 days.
Figure 3: The cure-then-penalize sequence Texas applies before assessing a TDPSA fine. Source: Texas Data Privacy and Security Act, Section 541.156; Texas Attorney General guidance.
Texas's right to cure has no sunset date, which sets it apart from several peer states. Colorado's and Connecticut's cure periods were both written with expiration dates that phase the safety net out over time, while Texas's version is written to remain a permanent feature of the statute. That is a meaningfully longer runway for a company that gets a notice wrong the first time, but it also means the Attorney General has never had to weigh a TDPSA penalty against a company that had already exhausted its cure right, since that scenario cannot currently occur under the law as written.
How do Texas's billion-dollar Meta and Google settlements relate to the TDPSA?
Texas's two largest privacy recoveries did not come from the TDPSA at all. The $1.4 billion Meta settlement, announced July 30, 2024, resolved a lawsuit filed under the state's Capture or Use of Biometric Identifier Act over Facebook's facial-recognition "Tag Suggestions" feature, which the state said affected up to 20.5 million Texans without their consent. It remains the largest privacy settlement ever obtained by a single state acting alone.
| Enforcement track | Governing statute | Outcome | Date |
|---|---|---|---|
| Data broker registration sweep | Data Broker Law (Ch. 509) | 100+ companies notified, up to $10,000/entity/year | June 2024 |
| Meta biometric lawsuit | Capture or Use of Biometric Identifier Act | $1.4 billion settlement | July 2024 |
| Allstate/Arity lawsuit | TDPSA | Active litigation, no fine set yet | Filed January 2025 |
| Google privacy lawsuit | Deceptive Trade Practices Act | $1.375 billion settlement | Announced May 2025 |
Source: Texas Attorney General press releases, 2024 to 2025.
Figure 4: Share of Texas's two billion-dollar privacy recoveries by settlement. Source: Texas Attorney General, July 2024 and May 2025 press releases.
The $1.375 billion Google settlement, announced May 9, 2025, and finalized that October, covered a mix of claims under the state's Deceptive Trade Practices Act rather than the TDPSA: location tracking that continued despite privacy settings suggesting otherwise, misleading claims about Incognito mode, and the collection of biometric identifiers including voiceprints and face geometry. Together the two settlements total roughly $2.775 billion, more than double the combined value of every other state's individual privacy settlements against Meta or Google to date, but neither one is a TDPSA case. Businesses reading headline settlement numbers as a preview of TDPSA fine exposure are comparing the wrong statute; the TDPSA's own $7,500-per-violation cap operates on a completely different scale.
Which sectors does Texas's privacy enforcement target most?
Data brokers, connected-car and telematics companies, and companies with ties to foreign adversaries have drawn the most attention from Texas's Privacy and Security Initiative so far. The Allstate/Arity case fits the connected-car category directly, and the Attorney General's office has been explicit that entities linked to China are a standing priority.
On February 14, 2025, the Attorney General opened an investigation into DeepSeek, a Chinese artificial intelligence company, and formally notified it of a TDPSA violation, one of the clearest examples of the statute being applied to an AI company rather than a traditional data broker or adtech firm. The office has separately put TP-Link, Alibaba, CapCut, and other China-linked companies on notice over Texans' privacy rights, giving each 30 days to demonstrate compliance under the same cure mechanism described above. AI companies now face a second layer of Texas disclosure duty on top of the TDPSA: our guide to Texas's Responsible AI Governance Act covers the separate AI-specific rules that took effect January 1, 2026.
Figure 5: Cumulative dollar value recovered across Texas's two largest privacy-related settlements, neither of which is a TDPSA case. Source: Texas Attorney General, July 2024 and May 2025 press releases.
The pattern across these cases is consistent even where the underlying statute differs: Texas pursues sensitive-category data (location, biometric identifiers, driving behavior) and companies that either failed to disclose data sharing clearly or misrepresented what a privacy control actually did.
How does the TDPSA's penalty compare to other state privacy laws?
The TDPSA's $7,500-per-violation cap sits in the middle of the state privacy law field rather than at either extreme. California's CCPA allows up to $7,500 per intentional violation (and $2,500 for unintentional violations), matching the TDPSA's ceiling almost exactly, while Colorado's CPA reaches up to $20,000 per violation, nearly triple the TDPSA's cap.
Figure 6: Comparison limited to states with a clearly published maximum per-violation figure. Source: Colorado Privacy Act; Texas Data Privacy and Security Act; California Consumer Privacy Act.
Colorado's $20,000 ceiling, detailed in our Colorado Privacy Act penalty and deadline breakdown, carries no aggregate cap on the total a company can owe, which is part of why it sits well above the TDPSA's figure despite both laws sharing an AG-only enforcement model. A per-violation cap only tells part of the story, since Texas counts each affected consumer as a separate violation. A company with a systemic notice failure touching tens of thousands of Texas consumers faces an exposure ceiling far higher than the flat $7,500 figure suggests, even though no confirmed TDPSA case has reached that scale yet.
The Bottom Line
As of August 2026, two years into the TDPSA, Texas's enforcement record looks less like a single new law being tested and more like an entire enforcement apparatus standing up at once: a data broker registration sweep, a dedicated Privacy and Security Initiative that has now touched more than 200 companies, a first TDPSA lawsuit against Allstate and Arity, and the country's two largest privacy settlements running in parallel under separate statutes. For a business handling Texas residents' data, the practical read is not "TDPSA fines are enormous," since the $7,500 per-violation cap is squarely in line with California's, but rather that Texas's Attorney General has built the staffing and investigative reach to actually open 200-plus cases in two years. A current privacy notice, a working opt-out mechanism, and clear disclosure of any sensitive data sharing address the fact pattern behind nearly every public TDPSA notice issued so far.
Frequently Asked Questions
How many companies has Texas investigated under its privacy enforcement initiative? More than 200 companies since the Data Privacy and Security Initiative launched in June 2024, according to the Texas Attorney General's July 2025 progress update. The count spans data brokers, car manufacturers, social media platforms, and companies tied to foreign adversaries.
What was the first lawsuit filed under the TDPSA? State of Texas v. Allstate and Arity, filed January 13, 2025, over the sale of geolocation and driving-behavior data collected from more than 45 million Americans' cellphones without proper notice or an opt-out mechanism.
What is the maximum penalty for violating the TDPSA? Up to 7,500 dollars per violation after a 30-day cure period, enforced exclusively by the Texas Attorney General since the TDPSA carries no private right of action. Unlike Colorado's and Connecticut's cure periods, Texas's right to cure has no sunset date.
Are the Meta and Google settlements part of the TDPSA? No. Texas's 1.4 billion dollar Meta settlement (July 2024) was reached under the state's Capture or Use of Biometric Identifier Act, and its 1.375 billion dollar Google settlement (announced May 2025) was reached under the Texas Deceptive Trade Practices Act. Both predate or run parallel to TDPSA-specific enforcement rather than arising from it.
Where the Numbers Come From
- Texas Attorney General. (2025). "Attorney General Ken Paxton Leads Nation in Protecting Americans' Data Privacy and Security from Big Tech, Foreign Threats, and Bad Actors." Published July 21, 2025; more than 200 companies investigated since the Data Privacy and Security Initiative launched in June 2024.
- Texas Attorney General. (2024). "Attorney General Ken Paxton Notifies Over 100 Companies of their Apparent Failure to Comply with the Texas Data Broker Law." Published June 18, 2024.
- Vinson & Elkins. (2025). "Texas AG Targets Allstate in First Enforcement of Texas Data Privacy and Security Act." Lawsuit filed January 13, 2025, alleging geolocation data collected from over 45 million Americans.
- Texas Attorney General. (2024). "Attorney General Ken Paxton Secures $1.4 Billion Settlement with Meta Over Its Unauthorized Capture of Personal Biometric Data." Announced July 30, 2024; up to 20.5 million Texans affected.
- Texas Attorney General. (2025). "Attorney General Ken Paxton Secures Historic $1.375 Billion Settlement with Google Related to Texans' Data Privacy Rights." Announced May 9, 2025.
- Texas Attorney General. (2025). "Attorney General Ken Paxton Announces Investigation into DeepSeek and Notifies the Chinese AI Company of its Violation of Texas State Law." Published February 14, 2025.
- SC World. (2024). "Texas flags Sirius XM, three others for data privacy law violations." Notices issued November 2024 to SiriusXM, MyRadar, Miles, and Tapestri.
- Recording Law. "What Is the TDPSA? Texas Data Privacy and Security Act." Civil penalty up to $7,500 per violation; 30-day cure period with no statutory sunset.
Note: All figures verified as of August 2026. The Allstate/Arity TDPSA lawsuit remains in active litigation and has not yet produced a settlement or fine figure; this post will be updated when one is reached. Enforcement counts are refreshed at least twice a year to track new Texas Attorney General press releases.