Texas regulates the commercial capture and possession of biometric identifiers through Business and Commerce Code Chapter 503. The controlling text should be checked directly, and legal counsel should apply it to the organization’s facts.
Current as of 2026-08-15
Current Chapter 503 includes text effective January 1, 2026, including an artificial-intelligence-system definition and a rule that public availability of an image or media alone does not establish notice and consent for commercial biometric capture or storage.
Decision summary
- Identify systems that capture retina or iris scans, fingerprints, voiceprints, or hand or face geometry.
- Provide notice and obtain consent before commercial capture.
- Restrict disclosure, use reasonable care, and document destruction timing.
- Treat this page as operational guidance, not legal advice.
What CUBI covers
The Texas Attorney General’s overview lists retina or iris scans, fingerprints, voiceprints, and records of hand or face geometry. A business should map actual data fields and processing, not rely only on vendor marketing labels.
Core operational duties
- Notice and consent before commercial capture.
- Documented controls around sale, lease, or disclosure and applicable exceptions.
- Reasonable care for storage and transmission.
- Destruction within the statutory timeframe after the collection purpose expires, unless an exception applies.
- Evidence that policy and system behavior match.
January 1, 2026 text
The current statute adds AI-system language and clarifies that biometric media on the Internet or another public source does not by itself establish notice and consent unless the individual made it public. This should be reviewed in the exact statutory context with counsel.
Build an auditable program
- Inventory biometric systems, vendors, purposes, data flows, and jurisdictions.
- Version notices and consents and retain proof.
- Constrain access and disclosure.
- Set deletion triggers and verify execution.
- Review incident, complaint, and vendor-change procedures.
Next step for your environment
Have qualified counsel review the inventory, purpose, notice, consent, disclosure, retention, and deletion evidence against current law. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.
Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.
Sources and update trigger
- Texas Legislature — Business and Commerce Code Chapter 503
- Texas Attorney General — Biometric Identifier Act
Review trigger: Review after any amendment, Texas Attorney General guidance, enforcement development, or biometric system change.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles