September 3, 2026

Texas: Privacy Impact Assessment

OneTrust DataGuidance
Bart Huffman | Haylie D. Treas

Data privacy and cybersecurity attorneys Bart Huffman and Haylie Treas co-authored a OneTrust DataGuidance note providing a comprehensive overview of the laws and regulations governing Privacy Impact Assessments (PIAs) in Texas. Under the Texas Data Privacy and Security Act (TDPSA), PIAs, also called Data Protection Assessments, are required for businesses that handle consumers' personal data, though small businesses are generally exempt. In their article, Bart and Haylie describe how the law defines "consumers," "personal data" and "sensitive data," what triggers the obligation to conduct a PIA/Data Protection Assessment, and what the assessment should include. They also highlight what the legislation does not explicitly state, such as what activities are considered "high risk" or what criteria should be used to assess the effects of data processing activities on consumers. The guide additionally covers retention requirements, reporting to the state attorney general, best practices for conducting the assessment and supervisory authority. Overall, Bart and Haylie offer an easy-to-follow outline of the requirements for a PIA, from what the TDPSA says about it to what those conducting an assessment as well as those counseling them on it should reference to ensure proper completion.

READ: Texas: Privacy Impact Assessment (Subscription required)

Related Insights