The Texas Data Privacy and Security Act (House Bill 4) establishes consumer rights and controller obligations for organizations that process personal data of Texas residents. Effective July 1, 2024, the Act creates compliance requirements that demand executive ownership, governance structures, and ongoing risk decisions. Unlike technical controls that IT can implement once, privacy compliance is a strategic function that requires continuous judgment about what data to collect, how to use it, what risks to accept, and how to respond when circumstances change.

What the Act Requires

Texas HB 4 applies to entities that conduct business in Texas or produce products or services targeted to Texas residents and that either: (1) process personal data of at least 100,000 consumers during a calendar year, or (2) derive more than 50% of gross revenue from the sale of personal data and process personal data of at least 25,000 consumers.

Organizations meeting these thresholds become "controllers" under the Act and must comply with specific obligations regarding how they collect, use, and secure personal data. The definition turns on volume and business model, not industry sector, which means many SaaS and technology providers fall within scope even if they do not consider themselves data brokers.

Consumer Rights Established by HB 4

The Act grants Texas residents specific rights over their personal data. Controllers must establish processes to honor these rights within defined timeframes:

  • The right to confirm whether a controller is processing their personal data and to access that data
  • The right to correct inaccuracies in their personal data
  • The right to delete personal data provided by or obtained about the consumer
  • The right to obtain a copy of their personal data in a portable format
  • The right to opt out of the processing of personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects

These rights create operational obligations. An organization must build intake mechanisms, verification procedures, fulfillment workflows, and exception handling for cases where legal obligations conflict with consumer requests. These decisions—what verification is sufficient, when an exception applies, how quickly to respond—are governance questions that require executive judgment, not IT configuration.

Controller Obligations

Controllers must comply with several substantive requirements that shape how they design products, draft policies, and manage data:

  • Limit collection to what is adequate, relevant, and reasonably necessary in relation to the disclosed purposes
  • Refrain from processing personal data for purposes that are not reasonably necessary to or compatible with the disclosed purposes, unless consent is obtained
  • Provide a reasonably accessible, clear, and meaningful privacy notice that includes the categories of personal data processed, the purposes for processing, how consumers may exercise their rights, and the categories of third parties with whom data is shared
  • Establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue
  • Conduct data protection assessments for processing activities that present heightened risk of harm, including targeted advertising, sale of personal data, profiling, processing sensitive data, or processing that presents a foreseeable risk of unfair or deceptive treatment or unlawful disparate impact

The requirement for "reasonable" security practices introduces judgment. What is reasonable depends on the sensitivity of the data, the organization's resources, the evolving threat landscape, and the potential harm to consumers. This is not a checklist compliance exercise. It requires ongoing evaluation of risk and control adequacy—a function that sits at the executive level.

Data Protection Assessments

For processing activities that present heightened risk, controllers must conduct and document data protection assessments. These assessments must identify and weigh the benefits of the processing against the potential risks to consumers, considering the use of de-identification technologies and other safeguards.

The assessment itself is a strategic artifact. It documents the risk decision the organization has made and the rationale for accepting that risk. It must be revisible as circumstances change—when a new data use is contemplated, when a vendor relationship changes, or when a breach reveals a gap. This is governance work, not a one-time compliance deliverable.

Exemptions and Limitations

The Act exempts certain entities and data types from all or part of its requirements. Exemptions include state and local government entities, financial institutions and data subject to the Gramm-Leach-Bliley Act, covered entities and business associates under HIPAA, nonprofit organizations, higher education institutions acting under specific federal laws, and consumer reporting agencies to the extent they are governed by the Fair Credit Reporting Act.

The Act also excludes certain data from the definition of personal data, including de-identified data, publicly available information, and data regulated under sector-specific federal laws such as HIPAA, GLBA, the Fair Credit Reporting Act, and the Family Educational Rights and Privacy Act.

Determining whether an exemption applies requires legal and operational analysis. An organization may be partially exempt for some data processing and fully in scope for others. This is not a technical determination.

Why This Matters to SaaS and Technology Organizations

For SaaS and technology providers serving customers in Texas, HB 4 creates obligations that extend beyond the technical controls IT teams typically manage. The Act requires governance: someone must decide what data to collect, draft privacy notices that accurately reflect those decisions, establish procedures to respond to consumer requests, assess risks before launching new features, and determine when an exception to a consumer request applies.

These decisions carry business consequences. Processing personal data beyond what the privacy notice permits exposes the organization to enforcement action by the Texas Attorney General. Failing to honor a valid consumer request creates regulatory risk. Implementing data security practices that are inadequate given the sensitivity of the data invites scrutiny and potential liability.

The Act does not prescribe specific controls. It requires that practices be "reasonable" given the context. This standard demands judgment, and judgment requires an owner who can assess risk, allocate resources, and explain the rationale to regulators, customers, and the board.

Who Owns Compliance and What Adequate Ownership Looks Like

HB 4 compliance is not solely a legal function, an IT project, or a customer support task. It is a cross-functional governance challenge that requires someone with authority to make risk decisions and accountability for the outcome.

In practice, adequate ownership includes several capabilities:

  • Authority to determine what personal data the organization will collect and for what purposes, balancing product objectives against privacy risk
  • Governance structures that ensure privacy considerations are evaluated before new processing activities begin, not retrofitted afterward
  • Procedures to respond to consumer rights requests, including intake, verification, fulfillment, and escalation for complex cases
  • Ongoing assessment of data security controls relative to the evolving threat environment and the sensitivity of data processed
  • Documentation of risk decisions, particularly data protection assessments, in a form that can withstand regulatory review
  • Coordination across legal, product, engineering, and customer-facing teams to ensure policies, systems, and practices remain aligned

For many organizations, no single internal role combines these capabilities. General counsel provides legal interpretation but does not typically control product roadmaps or IT budgets. IT leadership implements technical controls but does not make risk acceptance decisions or draft consumer-facing policies. Compliance functions may track obligations but lack the authority to halt processing activities that exceed risk appetite.

This is the gap that virtual CISO leadership closes. A [vCISO](/vciso/) provides the executive ownership, governance structures, and ongoing risk judgment that privacy compliance demands. The vCISO works across legal, product, engineering, and operations to establish policies, evaluate risks, make control decisions, and report progress to executive leadership and the board.

How This Relates to Regulatory and Framework Readiness

Texas HB 4 is one of a growing number of state privacy laws. California, Virginia, Colorado, Connecticut, Utah, and others have enacted similar statutes, each with variations in scope, consumer rights, and controller obligations. Organizations operating across multiple states face overlapping and sometimes conflicting requirements.

Frameworks such as the NIST Privacy Framework provide structured approaches to managing privacy risk across multiple regulatory regimes. The Privacy Framework is a voluntary tool designed to help organizations identify and manage privacy risk through enterprise risk management. It is organized around five functions: Identify, Govern, Control, Communicate, and Protect. Each function contains categories and subcategories that describe outcomes, not prescriptive controls.

Using a framework like the NIST Privacy Framework allows an organization to build a privacy program that satisfies multiple state laws simultaneously, rather than implementing separate compliance efforts for each jurisdiction. The framework approach also integrates privacy risk into the broader enterprise risk management process, ensuring that privacy decisions are made with the same rigor as financial, operational, and reputational risk decisions.

Regulatory readiness is not a point-in-time achievement. New laws will be enacted, existing laws will be amended, enforcement priorities will shift, and the organization's own data processing activities will evolve. Adequate readiness requires ongoing governance: someone who monitors the regulatory landscape, evaluates new obligations, adjusts the program as needed, and reports changes to executive leadership.

Practical Next Steps for Leadership

If your organization processes personal data of Texas residents and meets the thresholds in HB 4, compliance is not optional. The Attorney General has enforcement authority, and the Act allows for civil penalties.

Start with a clear assessment of whether the Act applies. Count the Texas consumers whose data you process annually. Determine whether you derive revenue from selling personal data. If you meet the thresholds, you are a controller and the Act's obligations apply.

Next, evaluate whether your current governance structure can support compliance. Ask these questions:

  • Who has authority to decide what personal data the organization collects and for what purposes?
  • Who reviews new product features or data processing activities for privacy risk before they launch?
  • Who owns the process for responding to consumer rights requests, including verification, fulfillment, and exceptions?
  • Who assesses whether your data security practices remain reasonable as the threat environment and your data holdings change?
  • Who conducts data protection assessments for high-risk processing, and who reviews and approves them?
  • Who monitors changes in state privacy laws and determines when your program needs adjustment?

If these questions do not have clear answers, or if the answers point to multiple people with overlapping but incomplete authority, you have a governance gap. Closing that gap requires executive ownership—someone accountable for the privacy program who can make risk decisions, allocate resources, and report to the board.

For organizations that lack this capability internally, a virtual CISO provides it. The vCISO establishes governance structures, makes risk decisions, builds compliance documentation, coordinates across departments, and provides the executive reporting that boards and regulators expect. This is not a consulting project with a defined end date. It is ongoing leadership of a function that requires continuous judgment.

If you are uncertain whether your current structure provides adequate ownership, or if you recognize the governance gap but are unsure how to close it, a confidential consultation can clarify your options. Heights Consulting Group offers a single consultation to assess your situation, describe what adequate ownership looks like for your organization, and outline a practical path forward. There is no obligation and no pressure. Contact Heights to arrange a conversation.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Regulatory and Framework Readiness

Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.

Read about Regulatory and Framework Readiness