Guide

Personal Data and Biometric Information in AI Systems

How the Texas Data Privacy and Security Act and the biometric identifier statute apply when AI systems collect, infer or train on information about people.

Law checked through

Short Answer

The Texas Data Privacy and Security Act (TDPSA) covers businesses that operate in Texas or offer products or services Texans use and that process personal data, unless they are small businesses as the U.S. Small Business Administration defines them; even a small business may not sell sensitive data without consent. Texas consumers may access, correct, delete and port their data and opt out of targeted advertising, sales and profiling in furtherance of decisions with legal or similarly significant effects. Processing sensitive data requires consent, and profiling and sensitive-data processing require data protection assessments. Separately, the Capture or Use of Biometric Identifier Act (CUBI) requires notice and consent before capturing a retina or iris scan, fingerprint, voiceprint or hand or face geometry for a commercial purpose, limits disclosure and requires destruction within a year after the purpose ends, with penalties up to $25,000 per violation. HB 149 clarified how both statutes apply to AI. The Attorney General enforces both.

Which Laws Apply

  • Texas AI-specific: Business and Commerce Code § 503.001(b-1), (e) and (f) and Business and Commerce Code § 541.104(a)(2) as amended by HB 149; Business and Commerce Code § 552.054 (government biometric identification).
  • Generally applicable Texas law: TDPSA, Business and Commerce Code chapter 541; biometric statute, Business and Commerce Code § 503.001; Deceptive Trade Practices-Consumer Protection Act (DTPA).
  • Federal: Children’s Online Privacy Protection Act (COPPA); Health Insurance Portability and Accountability Act (HIPAA); Gramm-Leach-Bliley Act for financial institutions; Federal Trade Commission (FTC) Act.

The TDPSA and AI

Coverage turns on activity, not size thresholds, apart from the small business exemption. “Consumer” means a Texas resident acting in an individual or household context, so employee and business-contact data generally fall outside the Act. Several exemptions apply to entities and data regulated under federal law, such as HIPAA-covered entities and financial institutions subject to the Gramm-Leach-Bliley Act.

For AI, four duties matter most:

  • Consumers may opt out of profiling in furtherance of decisions with legal or similarly significant effects (Business and Commerce Code § 541.051(b)(5)). The definition in Business and Commerce Code § 541.001 includes decisions about specified services and opportunities. Because consumer excludes employment and commercial contexts, the inclusion of employment in the decision definition does not erase that separate coverage limit. Chapter 21 and federal employment law must be analyzed independently.
  • Sensitive data. Processing sensitive data, which includes biometric data processed to identify a person, health diagnoses, precise geolocation and children’s data, requires the consumer’s consent.
  • Assessments. A controller must conduct and document a data protection assessment for targeted advertising, sales, certain profiling, sensitive data and other processing with heightened risk of harm, and provide it to the Attorney General on request.
  • Business and Commerce Code § 541.101(b)(1) requires collection limited to data adequate, relevant and reasonably necessary for the disclosed purposes. Subsection (b)(3) bars processing for neither reasonably necessary nor compatible purposes without consent. Business and Commerce Code § 541.102 specifies notice content. A new use for model training needs that purpose analysis, not merely a statement that AI appears somewhere in a privacy notice.

Enforcement belongs to the Attorney General. Before suing, the Attorney General must give written notice identifying the provisions allegedly violated, and may not sue if the person cures within 30 days and provides the written statement the statute requires (Business and Commerce Code § 541.154). A person who violates the chapter after that cure period, or who breaches the written cure statement, faces a civil penalty of up to $7,500 per violation (Business and Commerce Code § 541.155(a)). There is no private right of action.

The Biometric Statute and AI

The biometric statute covers a “biometric identifier,” meaning a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry. Before capturing one for a commercial purpose, a business must inform the person and obtain consent (Business and Commerce Code § 503.001(b)); it may not sell or disclose the identifier except in narrow cases and must protect it with reasonable care (Business and Commerce Code § 503.001(c)(1) and (2)); and it must destroy it within a reasonable time, no later than one year after the purpose for collection expires (Business and Commerce Code § 503.001(c)(3)), with longer retention for an identifier used with an instrument or document another law requires to be maintained (Business and Commerce Code § 503.001(c-1)) and a presumed expiration at employment termination for identifiers collected for security purposes (Business and Commerce Code § 503.001(c-2)). A violation carries a civil penalty of up to $25,000 per violation, recoverable by the Attorney General (Business and Commerce Code § 503.001(d)).

HB 149 made three AI-related changes:

  • An image or media containing a person’s biometric identifiers that is available on the internet or another public source does not, by itself, constitute notice and consent, unless the person made it public (Business and Commerce Code § 503.001(b-1)). Scraping faces from the web to build a recognition system does not avoid the consent requirement.
  • The statute does not apply to developing, training, evaluating, distributing or offering AI with biometric identifiers, unless the system is used to uniquely identify a specific individual; nor to AI used to prevent or respond to security incidents, fraud and other illegal activity; and voiceprint data held by financial institutions is excluded (Business and Commerce Code § 503.001(e)).
  • Biometric identifiers collected for training and later used for another commercial purpose fall back under the statute’s possession and destruction rules (Business and Commerce Code § 503.001(f)).

TRAIGA also bars governmental entities from using AI to identify people by biometric data where that would infringe their rights, and makes a violation of Business and Commerce Code § 503.001 a violation of TRAIGA as well (Business and Commerce Code § 552.054). Its definition of biometric data for that section excludes photographs and recordings.

Enforcement Record

The Attorney General announced a $1.4 billion Meta biometric settlement July 30, 2024. The Google settlement was finalized October 31, 2025 for $1.375 billion, concluding two of the Attorney General’s data privacy enforcement actions; its allegations covered geolocation, incognito browsing and biometric data, so the amount is a combined resolution rather than a penalty for a single biometric violation. On January 13, 2025, the Attorney General announced the filing of a TDPSA enforcement suit against Allstate and Arity entities over alleged driving-data collection, use, and sale. The announcement’s accusations are allegations, not adjudicated findings, and no current docket disposition is stated here. These announcements and resolutions do not establish that the same allegations or exemptions apply to another company.

Illustrative Example (Hypothetical)

Hypothetical: a Texas retailer proposes cameras that recognize repeat shoplifters. Unique identification defeats the AI-activity exception in Business and Commerce Code § 503.001(e)(2). The separate security and fraud exception in § 503.001(e)(3) needs its own facts; it should not be assumed from the project’s label. If no exception applies, commercial capture requires informed consent and the other CUBI safeguards. A covered TDPSA controller separately needs sensitive-data consent under Business and Commerce Code § 541.101(b)(4). A small business has the narrower sensitive-data sale restriction in Business and Commerce Code § 541.107; it is not automatically subject to every controller-processing duty.

What Is Unsettled

Whether a loss-prevention workflow meets the separate security exception depends on its purpose and operation. Model deletion raises factual questions about what data remains identifiable, where it is held and what the provider can remove. These uncertainties do not erase an express retention or deletion duty that applies to the underlying data.

Sources