← Texas Business Law Glossary

Texas Business Law · Glossary

Sensitive Data (Texas Data Privacy and Security Act)

A defined class of personal data a Texas controller may not process at all without prior consent. The categories are data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; genetic or biometric data processed to uniquely identify an individual; personal data collected from a known child; and precise geolocation data.

Sensitive data is the one category a Texas controller cannot process on a business-need theory. Consent comes first. Tex. Bus. & Com. Code § 541.101(b)(4) prohibits processing the sensitive data of a consumer without obtaining the consumer's consent, and where the consumer is a known child, requires compliance with the federal Children's Online Privacy Protection Act instead.

The four categories

Section 541.001 defines sensitive data to include personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status. It also covers genetic or biometric data that is processed for the purpose of uniquely identifying an individual, personal data collected from a known child, and precise geolocation data.

Two of those catch businesses that never thought of themselves as handling anything sensitive. Precise geolocation data means location identified within a radius of 1,750 feet, which ordinary mobile location output satisfies without effort. Biometric data processed to uniquely identify an individual reaches face-matching and fingerprint login features a product team added for convenience.

Notice the drafting choices. The category is health diagnosis rather than health data at large, and sexuality rather than the longer sex life and sexual orientation formulation other states use. Neither narrowing is wide enough to plan around, and a business collecting symptom descriptions or intake forms should assume it is inside the category.

Selling it carries a script

If a controller engages in the sale of sensitive personal data, § 541.102(b) requires this exact notice: "NOTICE: We may sell your sensitive personal data." If it sells biometric personal data, § 541.102(c) requires: "NOTICE: We may sell your biometric personal data." Both must appear in the same location and in the same manner as the privacy notice required by § 541.102(a).

The statute prescribes the words. Rewriting them into house voice is a violation, and the attorney general has pleaded exactly that failure. If your privacy notice sits at a footer link, the sentence belongs there too, at the same prominence.

Small businesses do not escape this piece. Section 541.107 bars a person exempt under § 541.002(a)(3) from engaging in the sale of personal data that is sensitive data without prior consent from the consumer, with the penalty in § 541.155 attached to a violation.

Assessments and the practical fix

Section 541.105 requires a documented data protection assessment for the processing of sensitive data, alongside targeted advertising, sale of personal data, certain profiling, and any processing that presents a heightened risk of harm to consumers. The attorney general can demand the assessment through the investigative authority in § 541.153, so it should be written as a document a regulator will read.

For most Texas companies the right first move is an inventory rather than a policy. Find where geolocation, face templates, health intake fields and children's data actually sit, including in analytics exports and support ticket attachments nobody has looked at in three years. Then decide whether the business use justifies building a consent flow around it. Deleting a category is frequently cheaper than defending one, and it removes the assessment obligation with it.

See also
Consent (Texas Data Privacy and Security Act)·Precise Geolocation Data (Texas Data Privacy and Security Act)·Sale of Personal Data (Texas Data Privacy and Security Act)·Texas Data Privacy and Security Act (TDPSA)
Last updated: August 15, 2026