Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

Texas TDPSA for Banks and Fintechs: Where the GLBA Exemption Ends and Compliance Begins

Texas TDPSA took effect July 1, 2024, with no revenue threshold and no processing volume threshold. The GLBA entity-level exemption is more limited than most financial institutions assume — your marketing stack, website analytics, and pre-application data are likely covered. Here's what you still need to do.

By Rebecca Leung · June 8, 2026 ·
Table of Contents

TL;DR:

  • Texas TDPSA took effect July 1, 2024, with no revenue threshold and no data processing volume threshold. Any company with Texas customers and any non-trivial data processing footprint is covered unless a specific exemption applies.
  • The GLBA entity-level exemption protects banks and financial institutions for NPI — but NPI means data collected in the context of providing financial products or services. Your marketing website, retargeting audiences, pre-application visitor data, and lead generation lists are not NPI.
  • On January 13, 2025, the Texas AG filed the first-ever enforcement action under any state comprehensive privacy law — targeting Allstate/Arity for SDK-based location data collection. The action signals that marketing data practices, SDK collection, and sensitive geolocation data are active enforcement priorities.
  • Universal opt-out (GPC signal recognition) has been mandatory since January 1, 2025. Targeted advertising scripts and retargeting pixels must be suppressed when a Texas consumer opts out.
  • Most financial institutions need compliance work in three areas: update privacy notices to cover non-NPI data, implement opt-out for targeted advertising, and complete data protection assessments for marketing and profiling activities.

The GLBA Assumption That Keeps Getting Financial Services Teams in Trouble

Texas TDPSA — the Texas Data Privacy and Security Act — has been enforceable since July 1, 2024. Every financial services legal team reviewed it when it passed and concluded, essentially, “GLBA exemption covers us.” Then they moved on.

That conclusion is partially correct. TDPSA does provide an entity-level GLBA exemption that is actually more generous than California’s CCPA — where financial institutions get a data-level exemption but no entity-level exemption. Under TDPSA, banks and financial institutions subject to GLBA Title V are broadly exempt from TDPSA compliance for their core financial data processing activities.

Here’s what that assumption misses: the GLBA exemption covers nonpublic personal information — a defined term meaning information about consumers collected in connection with providing a financial product or service. It does not cover everything a financial institution does with data.

The gap between “financial institution” and “everything that institution does with data” is exactly where the Texas AG just filed its first-ever enforcement action under any state comprehensive privacy law — against Allstate Insurance and its data analytics subsidiary, Arity.

TDPSA Basics: Broader Than You Think

Before getting to the exemption gap, the basics are worth understanding because TDPSA’s threshold design is notably aggressive.

Who TDPSA covers: Any entity that conducts business in Texas or produces products or services consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration.

That last clause is significant — and different from California. CCPA applies to businesses with over $25 million in annual revenue, or that process data on 100,000+ California consumers, or derive 50%+ of revenue from data sales. TDPSA has none of those thresholds. The only exemption is the SBA small business definition, which varies by industry. For financial services, this typically means a bank with fewer than 500 employees qualifies — but community banks, large fintechs, insurance companies, and broker-dealers generally do not.

No revenue threshold. No processing volume threshold. If you have Texas customers and you’re not an SBA small business, you’re in scope.

What TDPSA requires of covered entities:

  • Publish a reasonably accessible privacy notice disclosing categories of personal data collected, processing purposes, third-party sharing, and consumer rights
  • Respond to consumer rights requests within 45 days (extendable by 45 more with notice)
  • Conduct data protection assessments before higher-risk processing activities
  • Enter written data processing agreements with all data processors
  • Implement opt-out mechanisms for targeted advertising, data sales, and profiling
  • Recognize universal opt-out signals (GPC) effective January 1, 2025
  • Not process sensitive data categories without opt-in consent

Penalties: Up to $7,500 per violation. The AG has exclusive enforcement with a permanent 30-day cure right for first violations. No private right of action. Civil investigative demands and injunctive relief available.

The GLBA Exemption Anatomy: What It Covers, What It Doesn’t

TDPSA Section 541.002 exempts “a financial institution or data subject to Title V, Gramm-Leach-Bliley Act (15 U.S.C.).” This provides two types of protection:

Entity-level exemption: A financial institution that is subject to GLBA Title V is broadly exempt from TDPSA as an entity. The institution itself doesn’t need to register as a TDPSA data controller for its financial services activities.

Data-level exemption: Even at a non-GLBA entity, data that is itself “subject to” GLBA (i.e., GLBA-regulated NPI) is exempt. This means a vendor handling a bank’s NPI data can also claim data-level protection for that specific data, even though the vendor isn’t itself a GLBA financial institution.

That dual protection is more generous than California, where CCPA provides only the data-level exemption — meaning California financial institutions still have CCPA obligations for their non-NPI data processing. By contrast, a Texas-based bank’s core financial data operations are largely shielded by TDPSA’s entity-level exemption.

But here’s the catch:

The GLBA NPI definition covers information about consumers obtained in the course of providing financial products or services. The operative phrase is “in the course of providing financial products or services.” It doesn’t mean “all data a financial institution touches.”

Data that is not GLBA NPI — and therefore not covered by TDPSA’s exemptions — includes:

Data TypeWhy It’s Outside GLBA NPI
Pre-application website visitor dataConsumer is not yet in a financial product/service relationship
Retargeting audiences and ad pixelsData collected for marketing purposes, not product delivery
Lead generation listsPre-customer marketing data
Non-customer contact data for email campaignsNo financial services relationship established
Web analytics from non-customer sessionsBehavioral data outside financial product context
Browsing/clickstream data from anonymous visitorsNo consumer relationship exists

Multiple legal authorities confirm this interpretation: “GLBA does not encompass information collected prior to a consumer’s application for a financial product or service, such as that collected through marketing campaigns and promotions.”

The Allstate enforcement action illustrates this directly. Allstate is an insurance company — clearly a financial institution subject to GLBA for its insurance product data. But the Texas AG’s complaint alleged Allstate and Arity were collecting real-time location and driving behavior data through SDKs embedded in third-party apps — data collection that happened entirely outside any customer’s insurance product relationship. That data was not GLBA NPI. The GLBA exemption didn’t protect it.

The Four Areas Where TDPSA Applies to Financial Institutions

1. Marketing Website Tracking and Analytics

Your corporate website is visited by thousands of people who are not your customers — prospects researching products, job seekers, journalists, regulators. The behavioral data collected from those visitors via analytics tools (Google Analytics, Mixpanel, Amplitude), advertising pixels (Meta Pixel, Google Ads), and retargeting scripts is not GLBA NPI.

For Texas visitors who are not yet customers:

  • Behavioral tracking for targeted advertising requires opt-out capability
  • If you run Meta retargeting audiences or Google Lookalike audiences built from site visitor data, you are selling or processing personal data for targeted advertising — TDPSA applies
  • GPC signals from Texas visitors must suppress advertising pixels since January 1, 2025

The compliance fix isn’t complex: a cookie consent banner that defaults to suppressing ad tracking for GPC-signal users, a privacy notice section disclosing the targeted advertising activity, and an opt-out link. But these need to be functional, not just present — the Allstate complaint specifically cited a privacy notice that was there but inadequate.

2. Pre-Application Lead Generation and Marketing Campaigns

Email marketing lists, pre-screened offer campaigns, purchased prospect lists, form submissions from people inquiring about products — none of these are within the GLBA financial product delivery relationship. Anyone on a marketing list who hasn’t yet applied for a product is a Texas consumer with TDPSA rights, not a GLBA customer with only GLBA rights.

This means:

  • Marketing contact lists need to honor Texas opt-out requests for targeted advertising
  • If you share or sell marketing contact data to third-party partners (co-marketing, referral programs, data co-ops), that activity is a “sale of personal data” under TDPSA — requiring disclosure and opt-out
  • Email marketing platforms and data management platforms are data processors under TDPSA — written data processing agreements required

3. Sensitive Data Processing That Isn’t Financial in Nature

TDPSA’s sensitive data categories — precise geolocation, biometric identifiers, racial or ethnic origin, health data, children’s data — require opt-in consent before collection. None of these categories are automatically GLBA NPI, and processing them without consent is both the most likely enforcement target and the hardest to remedy quickly.

For financial services teams, the specific exposure:

  • Precise geolocation from mobile apps (for fraud prevention? location-based product offers?) — TDPSA requires opt-in unless this is GLBA-covered activity
  • Voice authentication used in non-customer-service contexts — if your app uses voice for authentication at a login screen for non-GLBA purposes, this may be biometric processing under TDPSA in addition to the Texas CUBI considerations covered in our earlier biometric privacy post
  • Health data collected in application flows — if a mortgage application or insurance quote asks about health status, the health data itself may be sensitive data requiring consent before collection

4. Non-NPI Data in Third-Party Data Pipelines

Data brokers, data enrichment vendors, and marketing data vendors that supply “data about consumers” to financial institutions are operating in TDPSA territory. If the enrichment vendor’s data about your prospects or leads contains information that doesn’t fit within GLBA’s NPI definition, the financial institution that receives and processes it becomes a TDPSA controller for that data.

Financial institutions that use third-party data enrichment services to append income estimates, household composition, or behavioral data to marketing lists are processing non-NPI personal data. TDPSA requires written data processing agreements with those vendors — with specific required clauses covering data security, sub-processor obligations, and deletion rights.

The Enforcement Signal You Should Not Ignore

On January 13, 2025, Texas AG Ken Paxton filed the first-ever enforcement action under a state comprehensive privacy law, targeting Allstate and its data analytics subsidiary Arity. The allegations:

  • Arity embedded its SDK into apps including Life360, GasBuddy, Fuel Rewards, and Routely to harvest real-time location and driving behavior data from 45 million+ Americans
  • Data was collected without consumers’ knowledge and used to build a driving behavior scoring database
  • TDPSA violations: failure to provide accessible privacy notice; processing precise geolocation data (sensitive data) without consent; failure to disclose data sales; no opt-out for targeted advertising
  • Also alleged: Texas Data Broker Law registration violations
  • Penalties sought: over $1,000,000 using $7,500 per TDPSA violation plus Data Broker Law penalties

The pattern — SDK-based behavioral data collection, sensitive data (location), marketing data practices, inadequate disclosures — maps directly onto the marketing tech stack most financial institutions run. The Allstate case demonstrates that:

  1. Insurance companies are not GLBA-exempt for marketing data operations
  2. Third-party SDK collection is a priority target
  3. The TDPSA’s enforcement posture is aggressive; the AG established a dedicated privacy team before the law even took effect

For broader context on the Texas AG’s enforcement posture, see the $1.4B Meta and $1.375B Google biometric settlements, which preceded TDPSA but reflect the same enforcement culture.

The TDPSA Compliance Workstream for Financial Services

For most banks and fintechs, full GLBA-exemption analysis will show that three parallel workstreams are needed:

Workstream 1: Privacy Notice Expansion

Current privacy notices at financial institutions typically cover GLBA’s Regulation P obligations — the annual privacy notice describing NPI sharing practices. That notice does not cover non-NPI data categories, targeted advertising activities, or TDPSA consumer rights.

Update your public-facing privacy notice to add:

  • Categories of non-NPI personal data processed (web analytics, marketing data, ad data)
  • Purposes including targeted advertising and any data sales
  • Consumer rights under TDPSA (access, correction, deletion, portability, opt-out)
  • Instructions for exercising each right, including two secure submission methods
  • If you sell personal data or do targeted advertising: a conspicuous disclosure and opt-out mechanism

For DSAR response workflows that work across GDPR, CCPA, and state laws including TDPSA, see our post on DSAR Response Workflow: A Practitioner’s Guide.

Workstream 2: Opt-Out and GPC Implementation

If your website or app collects data for targeted advertising or sells personal data to third parties:

  1. Implement an opt-out mechanism (prominent link or preference center)
  2. Implement GPC signal recognition — when a Texas user’s browser sends a GPC signal, advertising pixels, retargeting scripts, and audience-building tags must be suppressed before data is transmitted to third parties. Logging the preference without suppressing the scripts is not compliant.
  3. Confirm your marketing technology vendor contracts include the required data processing agreement language

GPC has been mandatory since January 1, 2025. This is no longer a future consideration.

Workstream 3: Data Protection Assessments for Marketing Activities

Every fintech and bank with a marketing data practice likely has multiple triggers for TDPSA data protection assessments:

  • Targeted advertising campaigns (social media, programmatic, email)
  • Lead data sharing arrangements (referral partners, affinity programs)
  • Third-party data enrichment (behavioral, demographic, propensity models)
  • Retargeting audience building from website visitors

Assessments must be documented before the activity begins — not retroactively after an enforcement inquiry. The good news: these assessments are not complex documents. They’re a structured analysis weighing the business purposes against the privacy risks to consumers, with a written record you can produce to the AG. They don’t require third-party certification.

For the broader state privacy law compliance picture — including how GLBA’s safe harbor works (and doesn’t) across CCPA, TDPSA, Virginia, Colorado, and the other 20+ state laws now in effect — see our post on State Privacy Laws and the GLBA Safe Harbor: What Banks and Fintechs Can No Longer Assume.

So What? The Exemption Is Real, But It Has Edges

The TDPSA GLBA exemption is real and it matters. Banks and fully GLBA-covered financial institutions are in a significantly better position under TDPSA than under CCPA — the entity-level protection shields core financial data operations from the full TDPSA compliance program.

But the exemption has edges that are visible, documented, and increasingly the focus of state AG enforcement priorities. Marketing data, pre-application visitor data, and advertising technology operate in the gap between “financial institution” and “GLBA NPI” — and that gap runs through the marketing stack of almost every bank and fintech.

The Allstate enforcement action shows that the Texas AG is not treating financial services as a protected class. The question for compliance teams isn’t whether the exemption covers your core banking data (it probably does) — it’s whether your marketing operations, analytics infrastructure, and data sharing practices have been reviewed with the same rigor.

Most haven’t. That’s where to start.

For a structured approach to multi-state privacy compliance across TDPSA, CCPA, Virginia, Colorado, and 19 other state laws — including data mapping templates, DPA frameworks, and consumer rights response playbooks — the Data Privacy Compliance Kit provides the operational infrastructure most financial services compliance teams are still building from scratch.


Sources: Texas AG — Allstate/Arity TDPSA enforcement action, January 2025; Texas AG — TDPSA official page; WilmerHale — First-Ever State Comprehensive Privacy Lawsuit, January 2025; Vinson & Elkins — Texas AG Targets Allstate; Orrick — GLBA Exemptions Under State Data Protection Laws

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Are banks and financial institutions exempt from Texas TDPSA?
Partially. TDPSA provides an entity-level exemption for financial institutions subject to GLBA Title V — meaning the institution itself is broadly exempt from TDPSA's requirements for data it processes as a GLBA-covered financial institution. But the exemption is narrower than most institutions assume: it protects 'nonpublic personal information' (NPI) as defined by GLBA, which only covers data collected in the context of providing financial products or services to customers. Marketing data, website visitor data collected before a consumer applies for any product, retargeting audiences, lead-generation data, and analytics from non-customer visitors are generally NOT covered by the GLBA NPI definition — and are therefore subject to TDPSA.
When did Texas TDPSA take effect and who does it cover?
The main TDPSA provisions took effect July 1, 2024. The universal opt-out mechanism requirement took effect January 1, 2025. TDPSA applies to any entity that: (1) conducts business in Texas or produces products/services consumed by Texas residents, (2) processes or sells personal data, and (3) is not a small business as defined by the U.S. Small Business Administration. Unlike California's CCPA, TDPSA has no $25 million revenue threshold and no data-processing volume threshold — making its applicability among the broadest of any state privacy law. Even SBA-exempt small businesses cannot sell sensitive personal data without consent.
What was the first TDPSA enforcement action?
On January 13, 2025, Texas AG Ken Paxton filed the first-ever enforcement action under any state comprehensive privacy law, suing Allstate Insurance and its analytics subsidiary Arity for allegedly embedding an SDK into third-party apps (including Life360, GasBuddy, and Fuel Rewards) to collect real-time location and driving behavior data from over 45 million Americans without their knowledge. TDPSA violations alleged included: failure to provide an accessible privacy notice, processing sensitive data (precise geolocation) without consent, failure to notify consumers of data sales, and no opt-out process for targeted advertising. Penalties sought exceeded $1 million. The Allstate case signals that location data, SDK-based collection, and marketing-data practices are active enforcement targets.
Does Texas TDPSA require a data protection assessment (DPA)?
Yes. TDPSA requires controllers to conduct and document data protection assessments before initiating: targeted advertising, sale of personal data, profiling that presents a reasonably foreseeable risk of injury or substantial harm, processing of sensitive data, or any other processing with heightened risk. Assessments must weigh benefits against risks to consumers. They apply to processing activities initiated after July 1, 2024 — not retroactively. The Texas AG can request to review DPAs during enforcement proceedings.
What does Texas TDPSA require for cookies and website analytics?
For cookies and tracking technologies used for targeted advertising (behavioral advertising across websites) or sales of personal data, TDPSA requires: (a) disclosure in the privacy notice of the sale or targeted advertising activity plus instructions for opting out, (b) a functional opt-out mechanism, and (c) recognition of universal opt-out signals like Global Privacy Control (GPC), effective January 1, 2025. When a Texas consumer's browser sends a GPC signal, advertising pixels, retargeting tags, and audience-building scripts must be suppressed before data is transmitted. This applies even if the underlying bank or fintech is GLBA-covered — because website visitor data collected from non-customers is not GLBA NPI.
How does Texas TDPSA compare to CCPA for financial services companies?
TDPSA is actually more favorable than CCPA for GLBA-covered financial institutions — TDPSA provides an entity-level exemption (the whole institution is exempt for NPI processing), while CCPA provides only a data-level exemption (the GLBA-covered data is exempt, but the institution still must comply with CCPA for all non-NPI data). However, both laws share the same core gap: marketing data, website analytics, and pre-application data are not GLBA NPI in either state. TDPSA has no revenue threshold (CCPA requires $25M), has a permanent 30-day cure period (CCPA's cure period expired January 2023), and provides no private right of action (CCPA has a data breach private right). Overall: TDPSA creates fewer direct obligations than CCPA for GLBA entities, but the marketing and website data gap is identical.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.