⚖ SoapBox law
ConstitutionTreatiesCasesDocketsStatutesRegulationsPrivacy lawAppeals & writsYour rightsDoctrinesMaximsJudgesLawyersFile a complaintOversightDataLibrary

Privacy law — federal vs. Texas

The standard (federal) privacy law, and where Texas replaces, adds to, fills a gap in, or is limited by it. Click a topic to open the two statutes side by side, then pull the cases interpreting them. Federal privacy law is sectoral — there is no single comprehensive federal privacy statute — which is exactly why the states matter. Informational only, not legal advice.

Texas goes further Texas fills a gap= Texas parallels federal Federal preempts (state role limited)
Comprehensive consumer privacy ◆ Texas fills a gap

There is no comprehensive federal consumer-privacy statute — the FTC Act’s "unfair or deceptive practices" power (15 U.S.C. § 45) is the only general federal backstop. Texas enacted its own comprehensive law, the TDPSA. Notably it has no revenue threshold but exempts small businesses (by the U.S. SBA definition) — a Texas-specific twist. AG-enforced, with a 30-day cure period.

Federal baseline
FTC Act § 5 (general backstop — no comprehensive federal privacy law)
15 U.S.C. § 45
Texas
Texas Data Privacy and Security Act (TDPSA)
Tex. Bus. & Com. Code Ch. 541
Effective July 1, 2024; universal opt-out mechanism from Jan 1, 2025 — confirm at the official link before relying
Data-breach notification ◆ Texas fills a gap

There is no general federal data-breach-notification statute — only sector fragments (e.g. the HIPAA Breach Notification Rule). Texas supplies the general rule through its Identity Theft Enforcement and Protection Act, which carries BOTH the data-safeguard duty (§ 521.052) and the breach-notice requirement (§ 521.053) in the same chapter.

Federal baseline
No general federal breach law (sectoral only — e.g. HIPAA Breach Notification Rule)
45 C.F.R. §§ 164.400–414 (HIPAA breach rule, health sector only)
Texas
Texas Identity Theft Enforcement and Protection Act (ITEPA)
Tex. Bus. & Com. Code Ch. 521 (§§ 521.052, 521.053)
Health / medical-records privacy ▲ Texas goes further

HIPAA is the federal floor for protected health information. Texas goes further: its Medical Records Privacy Act defines "covered entity" far more broadly — essentially anyone who obtains, stores, or uses PHI, not just HIPAA-covered entities and their business associates — and adds training and stricter consent duties.

Federal baseline
HIPAA Privacy & Security Rules
45 C.F.R. Parts 160 & 164
Texas
Texas Medical Records Privacy Act (TMRPA)
Tex. Health & Safety Code Ch. 181
Driver / motor-vehicle records = Texas parallels federal

The federal Driver’s Privacy Protection Act restricts disclosure of motor-vehicle records. Texas mirrors it at the state level with its Motor Vehicle Records Disclosure Act — a parallel scheme rather than an expansion.

Federal baseline
Driver’s Privacy Protection Act (DPPA)
18 U.S.C. § 2721 et seq.
Texas
Texas Motor Vehicle Records Disclosure Act
Tex. Transp. Code Ch. 730
Credit reporting ⊘ Federal preempts (state role limited)

The Fair Credit Reporting Act governs consumer credit reporting — and it expressly PREEMPTS much state credit-reporting law, so Texas’s role here is limited (mainly security-freeze mechanics under Bus. & Com. Code Ch. 20). This is the teaching contrast to the topics above: sometimes federal law leaves room for the state, and sometimes it takes it away. To dispute a credit error, the FCRA path (and the CFPB) is usually the operative one.

Federal baseline
Fair Credit Reporting Act (FCRA)
15 U.S.C. § 1681 et seq.
Texas
Texas consumer credit reporting / security freeze
Tex. Bus. & Com. Code Ch. 20