Cyber insurance built for the state that enforces privacy through raw prosecutorial muscle — a comprehensive privacy law with $7,500-per-violation penalties, a 60-day breach-notification statute with a public Attorney General breach list, and the first state AG in America to sue under a comprehensive privacy law.
Texas gives consumers no private right of action for privacy violations — and then hands all of that leverage to one office. The Texas Data Privacy and Security Act took effect July 1, 2024 with the broadest applicability of any state privacy law, the breach statute puts every sizable incident on a public Attorney General list, and the AG has built what his office calls the largest privacy-enforcement team of any state — filing the first-in-the-nation lawsuit under a comprehensive state privacy law in January 2025. Here is what an AG-first regime means for how your cyber policy should be structured.
Texas’s comprehensive privacy statute is the Texas Data Privacy and Security Act (TDPSA), Business & Commerce Code Chapter 541, effective July 1, 2024. Unlike California or Colorado, it has no revenue or record-count threshold: it applies to essentially any entity that conducts business in Texas or serves Texans and processes or sells personal data, exempting only businesses that meet the federal SBA small-business definition — and even those must obtain consent before selling sensitive data. It requires clear privacy notices, consent for processing sensitive data such as precise geolocation, health, and biometric information, data-protection assessments for higher-risk processing, and binding contracts with processors.
Enforcement is the Attorney General’s alone — there is no private right of action — with civil penalties of up to $7,500 per violation after a 30-day cure period. And Texas has staffed for it: in June 2024 the AG launched a dedicated data privacy and security enforcement initiative, billed as the largest privacy-enforcement team of any state attorney general in the country. Within months it had secured a record $1.4 billion biometric-privacy settlement with Meta and, in January 2025, sued Allstate and its subsidiary Arity for allegedly collecting and selling driving data from 45 million consumers through embedded mobile-app software — the first enforcement lawsuit ever filed under a state comprehensive privacy law.
Texas’s breach-notification regime lives in the Identity Theft Enforcement and Protection Act, Business & Commerce Code Chapter 521, and it has three teeth worth knowing:
Because Texas concentrates enforcement in the Attorney General rather than in private lawsuits, the center of gravity of a Texas cyber policy shifts. Regulatory-defense coverage is the headline third-party grant: a TDPSA inquiry or Chapter 521 investigation arrives as a civil investigative demand from a well-staffed unit that has already shown it will litigate, and defense costs accrue whether or not a penalty ever lands. First-party breach-response coverage should be sized for the 60-day and 30-day clocks — forensics, breach counsel, notification, and call-center costs are exactly what the statute forces you to spend — and because the AG list makes every reportable breach public, crisis-communications and reputational-harm coverage stop being luxuries. Two cautions: the SBA small-business exemption under the TDPSA does not exempt anyone from the breach statute, so small Texas firms carry real notification exposure; and no privacy statute limits ransomware or funds-transfer fraud, which remain the loss drivers for most Texas businesses. We structure the policy around all of it — enforcement exposure, statutory response costs, and the crime perils the headlines forget.
Tell us about your operation and your loss history — we’ll confirm we can write Texas and structure the limits to match.