← Texas Business Law Glossary

Texas Business Law · Glossary

Processor (Texas Data Privacy and Security Act)

A person that processes personal data on behalf of a controller. Processors act on the controller's instructions and owe duties that flow from a written contract Chapter 541 requires before processing begins. A processor that starts determining purposes for itself becomes a controller as to that processing, whatever the agreement says. Role is a fact question under the statute.

A processor handles personal data for someone else's purposes. Tex. Bus. & Com. Code § 541.001 defines it as a person that processes personal data on behalf of a controller, and everything a processor may do with that data traces back to the controller's instructions. Payroll platforms, hosting providers, email senders, CRM systems and analytics tools are the usual examples.

The contract comes first

Section 541.104(b) requires a written contract between controller and processor governing the data processing procedures. It must set out clear instructions for processing data, the nature and purpose of processing, the type of data subject to processing, the duration of processing, and the rights and obligations of both parties. It must also require the processor to ensure each person processing the data is subject to a duty of confidentiality, to delete or return all personal data at the controller's direction once the service is complete unless retention is required by law, to make available on reasonable request all information in its possession necessary to demonstrate compliance with the chapter, to allow and cooperate with reasonable assessments by the controller or the controller's designated assessor, and to engage any subcontractor under a written contract imposing the same requirements.

Section 541.104(c) gives the processor an alternative to sitting for the controller's assessment. It may arrange for a qualified and independent assessor to evaluate its policies and technical measures and provide the resulting report to the controller.

Duties running alongside the contract

Under § 541.104(a) a processor must assist the controller in responding to consumer rights requests submitted under § 541.051, using appropriate technical and organizational measures as reasonably practicable and taking into account the nature of processing and the information available to the processor. It must also assist with the security of processing and with notification of a breach of the processor's system under Chapter 521.

That second duty grew on January 1, 2026. House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, amended § 541.104(a)(2) to extend the security-assistance duty to personal data collected, stored and processed by an artificial intelligence system as that term is defined by Tex. Bus. & Com. Code § 551.001. Vendors running models over client data now owe that assistance by statute rather than by negotiation.

When a processor stops being one

Section 541.104(e) provides that whether a person is acting as a controller or a processor is a fact-based determination that depends on the context in which personal data is processed. A vendor that begins using client data to train its own model, build its own audience segments, or sell derived insights has started determining purposes. From that point it is a controller as to that processing and owes notice, consent and consumer-response duties of its own, regardless of the order form.

Section 541.104(d) is the companion caution. Nothing in the section relieves a controller or a processor of the liabilities each has under the chapter. Contractual allocation between the parties does not move statutory exposure. And because § 541.151 gives the attorney general exclusive enforcement authority and § 541.156 bars private suits, a controller's practical remedy against a misbehaving vendor is contractual indemnity plus whatever the attorney general decides to do.

Practical drafting note. Most vendor paper written before July 2024 has a data processing addendum built for Virginia or Colorado. The Texas requirements largely overlap, but the assessment-cooperation clause and the subcontractor flow-down are where older forms fall short. Diff the addendum against § 541.104(b)(6) line by line rather than assuming coverage.

See also
Controller (Texas Data Privacy and Security Act)·Consent (Texas Data Privacy and Security Act)·Sale of Personal Data (Texas Data Privacy and Security Act)
Last updated: August 15, 2026