Consumer Rights Request (Texas Data Privacy and Security Act)
A request from a Texas resident asking a controller to confirm, access, correct, delete or port personal data, or to opt out of targeted advertising, sale of personal data, or certain profiling. The controller must respond within 45 days, extendable once by another 45. Two responses per consumer each year must be free, and a refusal must be appealable.
A Texas resident sends a request and a clock starts. Tex. Bus. & Com. Code § 541.051(b) lists what an authenticated consumer may ask for, and § 541.052 fixes the deadlines for answering.
The rights
A consumer may confirm whether a controller is processing the consumer's personal data and access that data. Correct inaccuracies, taking into account the nature of the personal data and the purposes of processing. Delete personal data provided by or obtained about the consumer, which reaches past what the consumer personally handed over. Obtain a copy of personal data the consumer previously provided, in a portable and readily usable format allowing transmission to another controller, where processing is carried out by automated means. And opt out of processing for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of a decision that produces a legal or similarly significant effect concerning the consumer.
Under § 541.051(a) a parent or legal guardian may exercise these rights on behalf of a known child. Employees and job applicants are outside the scheme: § 541.003 removes employment-context data, and the definition of consumer in § 541.001 reaches a resident of this state acting only in an individual or household context.
The clock
Respond without undue delay and no later than the 45th day after receipt of the request. One 45-day extension is available where reasonably necessary, and the controller must tell the consumer about the extension and the reason for it within the original period. A refusal has to go out inside the same window, with the justification and instructions for appealing.
Two responses per consumer in a twelve-month period must be free. Past that, or where a request is manifestly unfounded, excessive or repetitive, the controller may charge a reasonable fee to cover administrative costs or decline to act, and bears the burden of showing the request qualifies. Where the controller cannot authenticate the request, it may request additional information reasonably necessary to do so and need not comply until it can.
Appeals and intake
Section 541.053 requires a conspicuously available appeal process, similar to the process for submitting the original request, with a written response within 60 days explaining the reasons for the decision. If the appeal is denied, the controller must provide the consumer with a method to contact the attorney general to submit a complaint. That last step routes an unhappy consumer straight to the only party with authority to sue.
Intake is governed by § 541.055. A controller must establish two or more secure and reliable methods for submitting requests, chosen with the way consumers normally interact with the controller in mind, the need for secure and reliable communication, and the controller's ability to authenticate identity. A controller may not require a consumer to create a new account in order to make a request, though it may require use of an existing account. A controller that maintains a website must provide a mechanism there. An exclusively online controller with a direct relationship with consumers may satisfy the requirement with an email address.
Two things to build before the first request arrives. A dated intake log tied to the 45-day and 60-day clocks, because the deadlines are the easiest violations for a regulator to prove. And a written authentication standard, so the person handling requests is not deciding case by case how much proof of identity is enough. Any contract term waiving or limiting these rights is void under § 541.054.