Guide

Texas AI Processor Duties

What the TDPSA requires of AI vendors that process personal data for a business, and what HB 149 added.

Law checked through

Short Answer

Under the TDPSA, a processor is a person that processes personal data on behalf of a controller. Processors must follow the controller’s instructions and help the controller meet its obligations: responding to consumer requests, securing personal data, notifying of breaches under Texas breach law and supplying information for data protection assessments. HB 149 added that the security assistance covers personal data collected, stored or processed by an AI system (Business and Commerce Code § 541.104(a)(2)). A written contract must set out specific terms (Business and Commerce Code § 541.104(b)). The amendment did not create a new AI contract clause; it clarified that an AI system’s handling of personal data is part of the security the processor must help provide. Whether an AI vendor is a processor or a controller depends on what it does with the data, including whether it uses customer data for its own purposes.

Which Laws Apply

  • Texas AI-specific: Business and Commerce Code § 541.104(a)(2) as amended by HB 149.
  • Generally applicable Texas law: TDPSA Business and Commerce Code § 541.104 and Business and Commerce Code § 541.105; breach notice, chapter 521.
  • Federal: HIPAA business associate rules where applicable.

The Processor’s Duties

Business and Commerce Code § 541.104(a) requires a processor to adhere to the controller’s instructions and assist the controller in meeting its obligations, including by assisting with consumer rights requests, with the security of processing personal data (now including personal data collected, stored or processed by an AI system), with notification of a breach of system security under chapter 521, and by providing information the controller needs for data protection assessments under Business and Commerce Code § 541.105.

Required Contract Terms

The controller-processor contract must be binding and state the processing instructions, nature and purpose, data type, duration, and parties’ rights and obligations. Business and Commerce Code § 541.104(b) also requires confidentiality for each person processing data, deletion or return at the controller’s direction when services end unless law requires retention, information to show compliance, reasonable controller assessments or a qualifying independent assessment process, and written flow-down terms to subcontractors after an opportunity for the controller to object. These requirements should be listed as mandatory only when the TDPSA applies.

Controller or Processor

Business and Commerce Code § 541.104(d) makes role determination fact-based and dependent on the processing context. A person not limited to following another party’s instructions is a controller for that processing. An AI vendor can therefore have different roles for service delivery and its own model-training use. An exemption must also be checked before imposing these duties. Financial institutions subject to GLBA are among the entity exemptions in Business and Commerce Code § 541.003; coverage should not be inferred merely because some website data looks different from account data.

Illustrative Example (Hypothetical)

Hypothetical: a covered Texas retailer uses an AI vendor to classify customer support messages. For processing limited to the retailer’s instructions, the vendor is a processor and the agreement must meet Business and Commerce Code § 541.104(b). Its security assistance under Business and Commerce Code § 541.104(a)(2) expressly includes applicable personal data handled by the AI system. If the vendor independently reuses messages for a different training purpose, the role and purpose analysis must be repeated for that use.

What Is Unsettled

Whether model weights derived from a controller’s data must be deleted at the end of a contract; how the Attorney General will treat vendors that train on customer data under default settings.

Sources

Related Reading