Texas · verified through August 25, 2026

Texas: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

TX · 6 requirements mapped / control outcomes supported

Law status

Verified comprehensive law

Yes - Texas Data Privacy and Security Act (TDPSA)

Official name / citation
Tex. Bus. & Com. Code ch. 541
Status / effective date
In force; effective July 1, 2024, with § 541.055(e) effective January 1, 2025
Principal enforcer
Texas Attorney General (exclusive enforcement)

Direct attached-library attribution

2 cases · $2,775,000,000

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

Also: Texas Identity Theft Enforcement and Protection Act, Tex. Bus. & Com. Code § 521.001 et seq. - https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-privacy-rights/identity-theft-enforcement-and-protection-act

Public enforcement context

Tier 1

23andMe (bankruptcy claims)

$150 million multistate settlement with recovery limited to $18 million; Texas share stated as $1,266,860 · n.a. (date not stated on page)

Texas joined the 42-state 23andMe settlement over the 2023 genetic-data breach.

Legal basis: State privacy/consumer-protection claims in bankruptcy

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.