Feature Data Privacy
Texas TDPSA for Banks and Fintechs: Where the GLBA Exemption Ends and Compliance Begins
Texas TDPSA took effect July 1, 2024, with no revenue threshold and no processing volume threshold. The GLBA entity-level exemption is more limited than most financial institutions assume — your marketing stack, website analytics, and pre-application data are likely covered. Here's what you still need to do.
Table of Contents
TL;DR:
- Texas TDPSA took effect July 1, 2024, with no revenue threshold and no data processing volume threshold. Any company with Texas customers and any non-trivial data processing footprint is covered unless a specific exemption applies.
- The GLBA entity-level exemption protects banks and financial institutions for NPI — but NPI means data collected in the context of providing financial products or services. Your marketing website, retargeting audiences, pre-application visitor data, and lead generation lists are not NPI.
- On January 13, 2025, the Texas AG filed the first-ever enforcement action under any state comprehensive privacy law — targeting Allstate/Arity for SDK-based location data collection. The action signals that marketing data practices, SDK collection, and sensitive geolocation data are active enforcement priorities.
- Universal opt-out (GPC signal recognition) has been mandatory since January 1, 2025. Targeted advertising scripts and retargeting pixels must be suppressed when a Texas consumer opts out.
- Most financial institutions need compliance work in three areas: update privacy notices to cover non-NPI data, implement opt-out for targeted advertising, and complete data protection assessments for marketing and profiling activities.
The GLBA Assumption That Keeps Getting Financial Services Teams in Trouble
Texas TDPSA — the Texas Data Privacy and Security Act — has been enforceable since July 1, 2024. Every financial services legal team reviewed it when it passed and concluded, essentially, “GLBA exemption covers us.” Then they moved on.
That conclusion is partially correct. TDPSA does provide an entity-level GLBA exemption that is actually more generous than California’s CCPA — where financial institutions get a data-level exemption but no entity-level exemption. Under TDPSA, banks and financial institutions subject to GLBA Title V are broadly exempt from TDPSA compliance for their core financial data processing activities.
Here’s what that assumption misses: the GLBA exemption covers nonpublic personal information — a defined term meaning information about consumers collected in connection with providing a financial product or service. It does not cover everything a financial institution does with data.
The gap between “financial institution” and “everything that institution does with data” is exactly where the Texas AG just filed its first-ever enforcement action under any state comprehensive privacy law — against Allstate Insurance and its data analytics subsidiary, Arity.
TDPSA Basics: Broader Than You Think
Before getting to the exemption gap, the basics are worth understanding because TDPSA’s threshold design is notably aggressive.
Who TDPSA covers: Any entity that conducts business in Texas or produces products or services consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration.
That last clause is significant — and different from California. CCPA applies to businesses with over $25 million in annual revenue, or that process data on 100,000+ California consumers, or derive 50%+ of revenue from data sales. TDPSA has none of those thresholds. The only exemption is the SBA small business definition, which varies by industry. For financial services, this typically means a bank with fewer than 500 employees qualifies — but community banks, large fintechs, insurance companies, and broker-dealers generally do not.
No revenue threshold. No processing volume threshold. If you have Texas customers and you’re not an SBA small business, you’re in scope.
What TDPSA requires of covered entities:
- Publish a reasonably accessible privacy notice disclosing categories of personal data collected, processing purposes, third-party sharing, and consumer rights
- Respond to consumer rights requests within 45 days (extendable by 45 more with notice)
- Conduct data protection assessments before higher-risk processing activities
- Enter written data processing agreements with all data processors
- Implement opt-out mechanisms for targeted advertising, data sales, and profiling
- Recognize universal opt-out signals (GPC) effective January 1, 2025
- Not process sensitive data categories without opt-in consent
Penalties: Up to $7,500 per violation. The AG has exclusive enforcement with a permanent 30-day cure right for first violations. No private right of action. Civil investigative demands and injunctive relief available.
The GLBA Exemption Anatomy: What It Covers, What It Doesn’t
TDPSA Section 541.002 exempts “a financial institution or data subject to Title V, Gramm-Leach-Bliley Act (15 U.S.C.).” This provides two types of protection:
Entity-level exemption: A financial institution that is subject to GLBA Title V is broadly exempt from TDPSA as an entity. The institution itself doesn’t need to register as a TDPSA data controller for its financial services activities.
Data-level exemption: Even at a non-GLBA entity, data that is itself “subject to” GLBA (i.e., GLBA-regulated NPI) is exempt. This means a vendor handling a bank’s NPI data can also claim data-level protection for that specific data, even though the vendor isn’t itself a GLBA financial institution.
That dual protection is more generous than California, where CCPA provides only the data-level exemption — meaning California financial institutions still have CCPA obligations for their non-NPI data processing. By contrast, a Texas-based bank’s core financial data operations are largely shielded by TDPSA’s entity-level exemption.
But here’s the catch:
The GLBA NPI definition covers information about consumers obtained in the course of providing financial products or services. The operative phrase is “in the course of providing financial products or services.” It doesn’t mean “all data a financial institution touches.”
Data that is not GLBA NPI — and therefore not covered by TDPSA’s exemptions — includes:
| Data Type | Why It’s Outside GLBA NPI |
|---|---|
| Pre-application website visitor data | Consumer is not yet in a financial product/service relationship |
| Retargeting audiences and ad pixels | Data collected for marketing purposes, not product delivery |
| Lead generation lists | Pre-customer marketing data |
| Non-customer contact data for email campaigns | No financial services relationship established |
| Web analytics from non-customer sessions | Behavioral data outside financial product context |
| Browsing/clickstream data from anonymous visitors | No consumer relationship exists |
Multiple legal authorities confirm this interpretation: “GLBA does not encompass information collected prior to a consumer’s application for a financial product or service, such as that collected through marketing campaigns and promotions.”
The Allstate enforcement action illustrates this directly. Allstate is an insurance company — clearly a financial institution subject to GLBA for its insurance product data. But the Texas AG’s complaint alleged Allstate and Arity were collecting real-time location and driving behavior data through SDKs embedded in third-party apps — data collection that happened entirely outside any customer’s insurance product relationship. That data was not GLBA NPI. The GLBA exemption didn’t protect it.
The Four Areas Where TDPSA Applies to Financial Institutions
1. Marketing Website Tracking and Analytics
Your corporate website is visited by thousands of people who are not your customers — prospects researching products, job seekers, journalists, regulators. The behavioral data collected from those visitors via analytics tools (Google Analytics, Mixpanel, Amplitude), advertising pixels (Meta Pixel, Google Ads), and retargeting scripts is not GLBA NPI.
For Texas visitors who are not yet customers:
- Behavioral tracking for targeted advertising requires opt-out capability
- If you run Meta retargeting audiences or Google Lookalike audiences built from site visitor data, you are selling or processing personal data for targeted advertising — TDPSA applies
- GPC signals from Texas visitors must suppress advertising pixels since January 1, 2025
The compliance fix isn’t complex: a cookie consent banner that defaults to suppressing ad tracking for GPC-signal users, a privacy notice section disclosing the targeted advertising activity, and an opt-out link. But these need to be functional, not just present — the Allstate complaint specifically cited a privacy notice that was there but inadequate.
2. Pre-Application Lead Generation and Marketing Campaigns
Email marketing lists, pre-screened offer campaigns, purchased prospect lists, form submissions from people inquiring about products — none of these are within the GLBA financial product delivery relationship. Anyone on a marketing list who hasn’t yet applied for a product is a Texas consumer with TDPSA rights, not a GLBA customer with only GLBA rights.
This means:
- Marketing contact lists need to honor Texas opt-out requests for targeted advertising
- If you share or sell marketing contact data to third-party partners (co-marketing, referral programs, data co-ops), that activity is a “sale of personal data” under TDPSA — requiring disclosure and opt-out
- Email marketing platforms and data management platforms are data processors under TDPSA — written data processing agreements required
3. Sensitive Data Processing That Isn’t Financial in Nature
TDPSA’s sensitive data categories — precise geolocation, biometric identifiers, racial or ethnic origin, health data, children’s data — require opt-in consent before collection. None of these categories are automatically GLBA NPI, and processing them without consent is both the most likely enforcement target and the hardest to remedy quickly.
For financial services teams, the specific exposure:
- Precise geolocation from mobile apps (for fraud prevention? location-based product offers?) — TDPSA requires opt-in unless this is GLBA-covered activity
- Voice authentication used in non-customer-service contexts — if your app uses voice for authentication at a login screen for non-GLBA purposes, this may be biometric processing under TDPSA in addition to the Texas CUBI considerations covered in our earlier biometric privacy post
- Health data collected in application flows — if a mortgage application or insurance quote asks about health status, the health data itself may be sensitive data requiring consent before collection
4. Non-NPI Data in Third-Party Data Pipelines
Data brokers, data enrichment vendors, and marketing data vendors that supply “data about consumers” to financial institutions are operating in TDPSA territory. If the enrichment vendor’s data about your prospects or leads contains information that doesn’t fit within GLBA’s NPI definition, the financial institution that receives and processes it becomes a TDPSA controller for that data.
Financial institutions that use third-party data enrichment services to append income estimates, household composition, or behavioral data to marketing lists are processing non-NPI personal data. TDPSA requires written data processing agreements with those vendors — with specific required clauses covering data security, sub-processor obligations, and deletion rights.
The Enforcement Signal You Should Not Ignore
On January 13, 2025, Texas AG Ken Paxton filed the first-ever enforcement action under a state comprehensive privacy law, targeting Allstate and its data analytics subsidiary Arity. The allegations:
- Arity embedded its SDK into apps including Life360, GasBuddy, Fuel Rewards, and Routely to harvest real-time location and driving behavior data from 45 million+ Americans
- Data was collected without consumers’ knowledge and used to build a driving behavior scoring database
- TDPSA violations: failure to provide accessible privacy notice; processing precise geolocation data (sensitive data) without consent; failure to disclose data sales; no opt-out for targeted advertising
- Also alleged: Texas Data Broker Law registration violations
- Penalties sought: over $1,000,000 using $7,500 per TDPSA violation plus Data Broker Law penalties
The pattern — SDK-based behavioral data collection, sensitive data (location), marketing data practices, inadequate disclosures — maps directly onto the marketing tech stack most financial institutions run. The Allstate case demonstrates that:
- Insurance companies are not GLBA-exempt for marketing data operations
- Third-party SDK collection is a priority target
- The TDPSA’s enforcement posture is aggressive; the AG established a dedicated privacy team before the law even took effect
For broader context on the Texas AG’s enforcement posture, see the $1.4B Meta and $1.375B Google biometric settlements, which preceded TDPSA but reflect the same enforcement culture.
The TDPSA Compliance Workstream for Financial Services
For most banks and fintechs, full GLBA-exemption analysis will show that three parallel workstreams are needed:
Workstream 1: Privacy Notice Expansion
Current privacy notices at financial institutions typically cover GLBA’s Regulation P obligations — the annual privacy notice describing NPI sharing practices. That notice does not cover non-NPI data categories, targeted advertising activities, or TDPSA consumer rights.
Update your public-facing privacy notice to add:
- Categories of non-NPI personal data processed (web analytics, marketing data, ad data)
- Purposes including targeted advertising and any data sales
- Consumer rights under TDPSA (access, correction, deletion, portability, opt-out)
- Instructions for exercising each right, including two secure submission methods
- If you sell personal data or do targeted advertising: a conspicuous disclosure and opt-out mechanism
For DSAR response workflows that work across GDPR, CCPA, and state laws including TDPSA, see our post on DSAR Response Workflow: A Practitioner’s Guide.
Workstream 2: Opt-Out and GPC Implementation
If your website or app collects data for targeted advertising or sells personal data to third parties:
- Implement an opt-out mechanism (prominent link or preference center)
- Implement GPC signal recognition — when a Texas user’s browser sends a GPC signal, advertising pixels, retargeting scripts, and audience-building tags must be suppressed before data is transmitted to third parties. Logging the preference without suppressing the scripts is not compliant.
- Confirm your marketing technology vendor contracts include the required data processing agreement language
GPC has been mandatory since January 1, 2025. This is no longer a future consideration.
Workstream 3: Data Protection Assessments for Marketing Activities
Every fintech and bank with a marketing data practice likely has multiple triggers for TDPSA data protection assessments:
- Targeted advertising campaigns (social media, programmatic, email)
- Lead data sharing arrangements (referral partners, affinity programs)
- Third-party data enrichment (behavioral, demographic, propensity models)
- Retargeting audience building from website visitors
Assessments must be documented before the activity begins — not retroactively after an enforcement inquiry. The good news: these assessments are not complex documents. They’re a structured analysis weighing the business purposes against the privacy risks to consumers, with a written record you can produce to the AG. They don’t require third-party certification.
For the broader state privacy law compliance picture — including how GLBA’s safe harbor works (and doesn’t) across CCPA, TDPSA, Virginia, Colorado, and the other 20+ state laws now in effect — see our post on State Privacy Laws and the GLBA Safe Harbor: What Banks and Fintechs Can No Longer Assume.
So What? The Exemption Is Real, But It Has Edges
The TDPSA GLBA exemption is real and it matters. Banks and fully GLBA-covered financial institutions are in a significantly better position under TDPSA than under CCPA — the entity-level protection shields core financial data operations from the full TDPSA compliance program.
But the exemption has edges that are visible, documented, and increasingly the focus of state AG enforcement priorities. Marketing data, pre-application visitor data, and advertising technology operate in the gap between “financial institution” and “GLBA NPI” — and that gap runs through the marketing stack of almost every bank and fintech.
The Allstate enforcement action shows that the Texas AG is not treating financial services as a protected class. The question for compliance teams isn’t whether the exemption covers your core banking data (it probably does) — it’s whether your marketing operations, analytics infrastructure, and data sharing practices have been reviewed with the same rigor.
Most haven’t. That’s where to start.
For a structured approach to multi-state privacy compliance across TDPSA, CCPA, Virginia, Colorado, and 19 other state laws — including data mapping templates, DPA frameworks, and consumer rights response playbooks — the Data Privacy Compliance Kit provides the operational infrastructure most financial services compliance teams are still building from scratch.
Sources: Texas AG — Allstate/Arity TDPSA enforcement action, January 2025; Texas AG — TDPSA official page; WilmerHale — First-Ever State Comprehensive Privacy Lawsuit, January 2025; Vinson & Elkins — Texas AG Targets Allstate; Orrick — GLBA Exemptions Under State Data Protection Laws
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Are banks and financial institutions exempt from Texas TDPSA?
When did Texas TDPSA take effect and who does it cover?
What was the first TDPSA enforcement action?
Does Texas TDPSA require a data protection assessment (DPA)?
What does Texas TDPSA require for cookies and website analytics?
How does Texas TDPSA compare to CCPA for financial services companies?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
Oregon's Privacy Law Has a Feature No Other State Has — and Financial Services Companies Are Probably in Scope
The Oregon Consumer Privacy Act's 30-day cure period ended January 1, 2026. The AG can now sue without notice. More importantly for financial services: the GLBA exemption is narrower than most assume, fintechs have significant exposure on non-NPI data, and Oregon requires something no other state does — a list of the specific named third parties that received consumer data.
Jul 17, 2026
Data Privacy
Connecticut's CTDPA Just Got a Lot Bigger — And Fintechs May Not Know They're Covered
Connecticut's CTDPA expanded on July 1, 2026 — lower thresholds, narrowed GLBA exemption, eliminated cure period, new profiling impact assessments. Here's what fintechs and nonbank lenders need to do now.
Jul 16, 2026
Data Privacy
NYDFS Part 500 in 2026: What 27 Consent Orders and $144M in Fines Tell You About Examiner Priorities
All Part 500 amended requirements are now in effect. NYDFS has 27 consent orders and $144M in fines under its belt. Here's what examiners are finding — and what to do before they show up at your door.
Jul 15, 2026