HomeObligationsUnited StatesBy stateTexas

Obligations  United States  Texas

What a Texas business has to have in writing

Texas puts its written-policy weight on data rather than employment. The Identity Theft Enforcement and Protection Act makes reasonable safeguards and secure record disposal a statutory duty for any business holding sensitive personal information, the Texas Data Privacy and Security Act forces a full privacy notice with prescribed sale disclosures on almost every non-small business, CUBI polices biometric capture, and data brokers must register with the Secretary of State and run a twelve-point security program.

Vendors selling cloud services to state agencies need TX-RAMP certification. On the employment side Texas mandates very little in writing, with two exceptions: health care facilities must adopt a written workplace violence prevention policy and plan, and employers that skip workers' compensation must post and file non-subscriber notices.

Texas has no OSHA State Plan, so federal OSHA covers private employers.

Headcount

Industry  General is always on

Share
Sponsored
Policy  Acknowledgment  Proof
TexasHandbook 2026acknowledged by name
Texas on Recordwith AllyMatter
Cover Texas the Modern WayEvery policy Texas makes you write, acknowledged by name
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every employee in Texas on record
Who read which version, and when
03
Walk into any state inspection with the trail
From $29/mo, 20 editors, unlimited staff (published)

What applies

Texas rules for a 15–19 person general business

State law only. The federal layer every employer carries sits on the business-type pages below. Each row names what you must write, post, file or certify, who enforces it, and links to the state authority.

Breach Notification 1Who you must tell after a data breach, and how fast

LawProduceWhat it requiresTriggerEnforced by
Identity Theft Enforcement and Protection Act - breach notificationAI-compiledTex. Bus. & Com. Code § 521.053Any person who conducts business in Texas and owns or licenses computerized data containing sensitive personal informationDistribute
Notice
Notify affected individuals no later than 60 days after determining a breach occurred, and when 250 or more Texans are affected file an electronic Data Breach Report with the Attorney General as soon as practicable and no later than 30 days after that determination, stating how many Texans have already been notified directly. Substitute notice by email, website posting or statewide media is only allowed when direct notice would cost over $250,000, affect over 500,000 people, or contact details are missing.
From the first employee
Texas Attorney General (civil penalties of $2,000 to $50,000 per violation, plus up to $250,000 per breach for failing to notify)

Data Security Program 2A written safeguards program the state requires before anything goes wrong

LawProduceWhat it requiresTriggerEnforced by
Identity Theft Enforcement and Protection Act - duty to safeguard and destroyAI-compiledTex. Bus. & Com. Code §§ 521.052, 521.001 et seq.Any business that collects or maintains sensitive personal information about Texans, of any sizeWrite
Written program
Implement and maintain reasonable procedures, including corrective action, to protect sensitive personal information (name plus driver licence number, Social Security number, government ID number, financial account details or health information) from unlawful use or disclosure, and destroy records the business no longer keeps by shredding, erasing or otherwise making the information unreadable.
From the first employee
Texas Attorney General
Texas Data Broker ActAI-compiledTex. Bus. & Com. Code ch. 509 (effective September 1, 2023)Business entities whose principal source of revenue comes from collecting, processing or transferring personal data they did not collect directly from the individual, where in 12 months they earn over 50 percent of revenue from that activity or handle the data of more than 50,000 individualsWrite
Written program
Register annually with the Secretary of State and pay the fee, describing the categories of data processed and transferred and, where a child's data is knowingly held, how the broker complies with child privacy law. Post a conspicuous notice on the website or app saying the business is a data broker, and run a comprehensive written information security program containing the twelve safeguards in section 509.007, including ongoing employee and contractor training, third-party service provider controls and an annual review.
From the first employee
Texas Attorney General; Texas Secretary of State (registration)

Consumer Privacy Law 1Rights, notices and assessments for consumer data

LawProduceWhat it requiresTriggerEnforced by
Texas Data Privacy and Security ActAI-compiledTex. Bus. & Com. Code § 541.001 et seq. (effective July 1, 2024)Anyone doing business in Texas, or producing a product or service consumed by Texans, that processes personal data. Businesses that meet the federal SBA small business definition are largely exempt, but still need consent before selling sensitive data. State agencies, GLBA financial institutions, HIPAA entities, nonprofits and higher education are exempt.Write
Written policy
Publish a clear privacy notice listing the categories of personal and sensitive data processed and why, the categories shared and with whom, and how consumers exercise and appeal their rights. Add the exact statutory wording 'NOTICE: We may sell your sensitive personal data' or 'NOTICE: We may sell your biometric data' where that applies, and disclose data sales and targeted advertising with an opt-out. Offer two or more request channels, answer requests within 45 days, run an appeals process, limit collection to what is necessary, and maintain reasonable data security.
From the first employee
Texas Attorney General; 30-day cure period with a written statement of cure, then civil penalties up to $7,500 per violation. No private right of action.

Biometric and Health Data 1Consent and retention rules for fingerprints, faces and health data

LawProduceWhat it requiresTriggerEnforced by
Capture or Use of Biometric Identifier Act (CUBI)AI-compiledTex. Bus. & Com. Code § 503.001 et seq.Anyone who captures a biometric identifier (retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry) for a commercial purpose, or who holds oneWrite
Written policy
Inform the individual and get consent before capturing a biometric identifier; do not sell, lease or disclose it except in the narrow statutory cases; use reasonable care to protect it in storage and transmission; and destroy it within a reasonable time and no later than one year after the purpose of collection has expired.
From the first employee
Texas Attorney General has exclusive enforcement authority; civil penalties up to $25,000 per violation

Harassment Prevention 1A written policy, and in some states annual training, on harassment

LawProduceWhat it requiresTriggerEnforced by
Sexual harassment as an unlawful employment practiceAI-compiledTex. Labor Code ch. 21, subch. C-1 (§§ 21.141-21.142), added by SB 45 (87R), effective September 1, 2021Any employer with one or more employees, and any person acting in the employer's interest toward an employeeWrite
Written policy
Texas does not mandate a written harassment policy or training. It does make an employer liable when it knew or should have known harassment was happening and failed to take immediate and appropriate corrective action, so employers keep a documented complaint route, investigation record and corrective-action trail to show they met that standard.
From the first employee
Texas Workforce Commission Civil Rights Division; private civil action

Workplace Safety Programs 1Written programs the state safety agency requires beyond federal OSHA

LawProduceWhat it requiresTriggerEnforced by
Non-subscriber annual filing and injury reportingAI-compiledTex. Labor Code §§ 406.004, 406.007, 411.032; 28 TAC § 160.2Private employers without Texas workers' compensation coverage; the injury and illness report applies at five or more employeesFile
Filing / record
File the DWC-005 notice of no coverage with the Division of Workers' Compensation between February 1 and April 30 each year, again after hiring a first employee, and again after ending a workers' compensation policy. Employers with five or more employees must also report work-related injuries with more than one day of lost time, and all work-related illnesses and deaths, within one month and seven days of the triggering event. Texas has no OSHA State Plan, so federal OSHA recordkeeping and posting also apply.
From the first employee
Texas Department of Insurance, Division of Workers' Compensation

Workplace Violence Prevention 1A written plan for preventing and responding to workplace violence

LawProduceWhat it requiresTriggerEnforced by
Workplace violence prevention in health facilitiesAI-compiledTex. Health & Safety Code ch. 331 (SB 240, 88R; policies and plans due by September 1, 2024)Licensed hospitals, nursing facilities employing at least two registered nurses, home and community support services agencies employing at least two registered nurses, ambulatory surgical centres, freestanding emergency medical care facilities and mental hospitalsWrite
Written policy
Stand up a workplace violence prevention committee that includes a direct-care registered nurse, a direct-care physician and a security employee where practicable, and have it write the plan. Adopt, implement and enforce a written workplace violence prevention policy protecting reporters from retaliation, plus a written prevention plan that defines workplace violence, requires annual training for direct-care staff, sets out incident response and investigation, addresses physical security, uses the existing occurrence reporting system and adjusts patient assignments where practicable.
From the first employee
Texas Health and Human Services Commission (facility licensing)

Insurance Data Security 1The written security program insurance licensees must certify

LawProduceWhat it requiresTriggerEnforced by
TDI cybersecurity incident reporting for regulated entitiesAI-compiledCommissioner's Bulletin B-0009-23 (July 18, 2023); Tex. Bus. & Com. Code ch. 521All TDI-regulated entities and individuals, with a separate channel for domestic insurance companies and HMOs. Texas has not adopted the NAIC Insurance Data Security Model Law, so there is no written information security program mandate or annual certification for insurers.Distribute
Notice
Report an unauthorised acquisition, release or use of personal information or sensitive company information to TDI, domestic insurers and HMOs to Financial Analysis and everyone else to the cyber reporting mailbox, and be ready to give TDI incident detail under its examination authority. The underlying safeguard and consumer notice duties come from Business and Commerce Code chapter 521.
From the first employee
Texas Department of Insurance; Texas Attorney General under chapter 521

State Vendor Security Program 1Certification a vendor needs before selling cloud services to the state

LawProduceWhat it requiresTriggerEnforced by
Texas Risk and Authorization Management Program (TX-RAMP)AI-compiledTex. Gov't Code § 2054.0593Cloud computing service providers selling to Texas state agencies, public institutions of higher education and public community colleges; agencies may only enter or renew cloud contracts with compliant vendorsCertify
Certification
Complete the TX-RAMP request form and assessment and hold a certification at the right level: Level 1 for public or non-confidential information in low-impact systems, Level 2 for confidential or regulated data in moderate and high-impact systems. StateRAMP Category 1 or 2 and FedRAMP Low or Moderate authorizations can be submitted in place of a fresh assessment. Provisional certification lets an agency contract for up to 18 months while full certification is completed, and the vendor must keep the certification and continuous monitoring current for the life of the contract.
From the first employee
Texas Department of Information Resources (cybersecurity functions transferred to the Texas Cyber Command under HB 150, 89R)

Required Postings 1The notices every workplace in the state must display

LawProduceWhat it requiresTriggerEnforced by
Workers' compensation non-subscriber notice to employeesAI-compiledTex. Labor Code §§ 406.004, 406.005; 28 TAC § 110.101Private employers that do not carry Texas workers' compensation insurance, which the state allowsPost
Posting
Post a notice of no workers' compensation coverage in the workplace in English, Spanish and any other language employees need, somewhere they see it regularly, and give written notice of no coverage to every new employee.
From the first employee
Texas Department of Insurance, Division of Workers' Compensation

Licensing and Certifications 3Registrations, licences and certifications a business or its staff must hold

LawProduceWhat it requiresTriggerEnforced by
Business entity formation and registrationAI-compiledTex. Bus. Orgs. Code (certificate of formation, registered agent, foreign registration); Tex. Bus. & Com. Code ch. 71 (assumed names)Corporations, LLCs, limited partnerships and limited liability partnerships formed or doing business in Texas; sole proprietors and general partnerships using an assumed name file with the county clerk insteadFile
Filing / record
File a certificate of formation (or a registration for an LLP, or an application for registration for an out-of-state entity) with the Secretary of State through SOSDirect, name a registered agent with a Texas address, and file assumed name certificates where a DBA is used.
From the first employee
Texas Secretary of State, Business Services
Retail food establishment permitAI-compiledTex. Health & Safety Code ch. 437; 25 TAC ch. 228 (Texas Food Establishment Rules)Retail food establishments in areas regulated by the Department of State Health Services, including restaurants, mobile units, temporary event booths and school cafeterias; many cities and counties permit locally insteadFile
Filing / record
Hold a valid DSHS permit before operating, applied for through the Regulatory Services online licensing system or the paper Retail Food Operation Permit Application; temporary event permits must be filed at least 30 days before the event and cover 14 consecutive days per event.
From the first employee
Texas Department of State Health Services; local health jurisdictions
Certified Food Manager and food handler certificationAI-compiled25 TAC ch. 229, subch. N (food managers) and subch. FF (food handlers)Food service establishments under DSHS jurisdiction, with some exemptions; food handler certification applies to food employees hired on or after September 1, 2016Certify
Certification
Employ at least one certified food protection manager with supervisory authority who has passed an accredited exam, and make sure every food employee completes an accredited food handler training course within 60 days of being hired. Keep the certificates on file at the establishment.
From the first employee
Texas Department of State Health Services

Other Written Policies 1Any other document the state makes an employer write or hand out

LawProduceWhat it requiresTriggerEnforced by
Texas Medical Records Privacy Act - protected health information trainingAI-compiledTex. Health & Safety Code § 181.101 (HB 300, 82R, as amended by SB 1609, 83R)Covered entities under the Texas definition, which is broader than HIPAA and reaches anyone who obtains, stores or transmits protected health information in the course of businessCertify + ack
Certification
Train each employee on state and federal protected health information law as needed for that employee's duties, within 90 days of hire; retrain within a year whenever a material change in the law affects their duties; have each employee sign a written or electronic statement confirming they completed the training; and keep that signed statement for six years.
From the first employee
Texas Attorney General; Texas Health and Human Services Commission; Texas Medical Board; Texas Department of Insurance

From the publisher

Keep Your Written Policies in One Place

Whatever you are working toward, AllyMatter gets your policies approved, keeps every version and records who has read each one.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Need a hand implementing it?

Find a Consultant Who Does This Work

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Sources

Texas Attorney General - Data Breach ReportingTexas Attorney General - Identity Theft Enforcement and Protection ActTexas Attorney General - Consumer Privacy RightsTexas Attorney General - Texas Data Privacy and Security ActTexas Attorney General - Biometric Identifier ActTexas Attorney General - Texas Data Broker ActTexas Secretary of State - Data BrokersTexas Legislature - SB 2105 (88R) enrolledTexas DIR - TX-RAMP Eligibility and RequirementsTexas DIR - Texas Risk and Authorization Management ProgramTexas DIR - TX-RAMP Program Manual 3.1 (PDF)Texas Legislature - SB 240 (88R) enrolled textTexas Legislature - SB 240 (88R) bill analysisTexas Legislature - SB 1609 (83R) enrolled text (current § 181.101)Texas Legislature - HB 300 (82R) enrolled textTexas Attorney General - HIPAA and Medical Privacy Laws (PDF)Texas Department of Insurance - Commissioner's Bulletin B-0009-23Texas Legislature - SB 45 (87R) enrolled textTexas Legislature - SB 45 (87R) bill analysisTexas DWC - Employer E-File online reporting and non-subscriber noticesTexas DWC - EmployersTexas DWC - Employer forms and noticesOSHA - State Plans (Texas is under federal OSHA)Texas Secretary of State - Selecting a Business StructureTexas Secretary of State - Business ServicesTexas DSHS - Permits for Retail Food EstablishmentsTexas DSHS - Permits for Retail Food EstablishmentsTexas DSHS - Licensing of Certified Food Manager Training ProgramsTexas DSHS - Licensing of Food Handler Training ProgramsTexas DSHS - Food Handler FAQs

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.