Clavira
← Back to Blog

regulatory updates

Texas Biometric Privacy Law: What CUBI Requires in 2026

Troy Satchell9 min read

Texas biometric privacy law, explained from the statute: what CUBI requires, what changed January 1, 2026, and the four dates you must prove.

Key Takeaways

  • •CUBI (Tex. Bus. & Com. Code §503.001) requires notice and consent before capturing a biometric identifier for a commercial purpose, bars selling it, and sets a destruction deadline.
  • •The Texas Attorney General enforces it, at up to $25,000 per violation. The office used CUBI against Meta ($1.4 billion, July 2024) and in its Google case ($1.375 billion, announced May 2025).
  • •Every CUBI duty resolves into a date: notice given, consent received, purpose expired, identifier destroyed. A defense is the record behind each one.

Texas's biometric privacy law is one section long. Capture a fingerprint, voiceprint, or face geometry for a commercial purpose, and you must tell the person, get consent, and destroy it on a deadline.

The law is the Capture or Use of Biometric Identifier Act, Business and Commerce Code §503.001, usually shortened to CUBI. The statute gives enforcement to the Texas Attorney General, and the office has used it: a $1.4 billion settlement with Meta in July 2024, and a $1.375 billion settlement with Google, announced in May 2025, that covered biometric claims.

I read the current statute, including the January 1, 2026 amendments. Every duty in it resolves into a date you would have to prove, and this page is built around those dates. It is an explainer, not legal advice; run your specifics past Texas counsel.

What Texas's biometric privacy law requires

CUBI's obligations fit in five lines. Three of them produce the dates you would have to prove:

  • Notice: inform the individual before capturing a biometric identifier for a commercial purpose (§503.001(b)(1)). Date: when notice was given.
  • Consent: receive the individual's consent to the capture (§503.001(b)(2)). Date: when consent was received, before the first capture.
  • No sale: do not sell, lease, or otherwise disclose the identifier, outside four exceptions (§503.001(c)(1)).
  • Reasonable care: store and protect it at least as carefully as your other confidential information (§503.001(c)(2)).
  • Destruction: destroy it on a deadline tied to the end of its purpose (§503.001(c)(3)). Dates: when the purpose expired, and when the identifier was destroyed.

The destruction duty is the one with a clock in the text:

shall destroy the biometric identifier within a reasonable time, but not later than the first anniversary of the date the purpose for collecting the identifier expires, except as provided by Subsection (c-1).
Tex. Bus. & Com. Code §503.001(c)(3)

The four disclosure exceptions are narrow: identification after disappearance or death, with consent; a financial transaction the person requested or authorized; a disclosure a federal or state statute requires or permits; and a law enforcement warrant. Vendor convenience is not on the list, so your scanner or timekeeping contract has to keep the data inside it.

The four dates a CUBI defense turns on

Notice and consent are fixed at enrollment; the other two dates are created, or not, every day after:

DateWhat it provesThe record
Notice given(b)(1): informed before captureDated notice text, tied to the person
Consent received(b)(2): consent before captureSigned or logged consent, timestamped before enrollment
Purpose expired(c)(3): the one-year clock startedThe stated purpose, plus the event that ended it
Identifier destroyed(c)(3): deadline metDestruction log or vendor deletion confirmation, dated

The third row needs a close reading. The statute presumes a purpose-expiry date in only one case:

If a biometric identifier captured for a commercial purpose has been collected for security purposes by an employer, the purpose for collecting the identifier under Subsection (c)(3) is presumed to expire on termination of the employment relationship.
Tex. Bus. & Com. Code §503.001(c-2)

That presumption covers identifiers collected "for security purposes." A door-access scanner fits. A time clock that records hours arguably does not, and then the statute supplies no end date at all. The end date becomes whatever purpose you wrote down at enrollment. If you wrote nothing down, you cannot show when the one-year clock started, so you cannot show you met it.

Subsection (c-1) moves the date in one more case: if the identifier is used with a document another law requires you to keep longer, the clock runs from the date that retention duty ends. Record that document on day one too.

Together, those subsections define one record per enrolled person. Here it is as a template:

CUBI enrollment record: one per person

  • Person and system: employee or customer ID, the capturing device, and the identifier type.
  • Purpose stated at capture: one sentence, marked "security" or not for (c-2), plus any linked document another law makes you keep, for (c-1).
  • Notice given: date, time, and the notice text version shown. Before the first capture.
  • Consent received: date, time, method, and the consent text version. Before the first capture.
  • Purpose expired: date, and the event that ended it, such as the last day of employment.
  • Destruction deadline: a reasonable time, and no later than one year after the purpose expired or the (c-1) retention duty ended.
  • Identifier destroyed: date, who or what deleted it, and the vendor's deletion confirmation for any copy it held.

What counts as a biometric identifier in Texas

"Biometric identifier" means a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry.
Tex. Bus. & Com. Code §503.001(a)(2)

The list names geometry records, so a face template extracted from a photo is covered while the photo itself sits outside the definition. That line sits at the center of the Meta case: the Attorney General's release says Meta captured "records of the facial geometry" of people in uploaded photos.

It also separates CUBI from Texas's other privacy statute. The Texas Data Privacy and Security Act defines "biometric data" to exclude "data generated from a physical or digital photograph" (§541.001(3)). The same face template can be a CUBI identifier and fall outside the newer act's biometric definition.

Since January 1, 2026, CUBI also answers the scraping question:

For purposes of Subsection (b), an individual has not been informed of and has not provided consent for the capture or storage of a biometric identifier of an individual for a commercial purpose based solely on the existence of an image or other media containing one or more biometric identifiers of the individual on the Internet or other publicly available source unless the image or other media was made publicly available by the individual to whom the biometric identifiers relate.
Tex. Bus. & Com. Code §503.001(b-1)

Read the last clause twice. A photo someone else posted can never, on its own, stand in for notice and consent. A photo the person posted themselves falls outside (b-1), which leaves the ordinary (b) test in place and an argument open. Do not build a product on that argument without counsel.

Who enforces CUBI, and what the Attorney General has done

CUBI names one enforcer, the Attorney General, with a civil penalty of up to $25,000 for each violation (§503.001(d)). It creates no private right of action. A Texan whose fingerprint was captured without consent has no CUBI claim of their own; the route is a complaint to the Attorney General.

AG-only enforcement sounds like the soft option. The public record says otherwise:

DateActionSource
February 2022Attorney General sues Meta under CUBI and the Deceptive Trade Practices ActTexas AG release, July 30, 2024
July 30, 2024Meta agrees to pay $1.4 billion over five yearsSame release
May 9, 2025Attorney General announces a $1.375 billion settlement in principle with Google over geolocation, incognito searches, and biometric data, claims first filed in 2022Texas AG release, May 9, 2025
October 31, 2025Google signs the settlement agreement, ending two suitsTexas AG release, October 31, 2025

The Attorney General's July 30, 2024 release called the Meta deal "the largest settlement ever obtained from an action brought by a single State" and the first lawsuit and settlement under CUBI. It says Meta ran facial recognition on "virtually every face" in photos uploaded to Facebook after rolling out Tag Suggestions in 2011. The State's biometric petition against Google targeted face grouping in Google Photos, Face Match on the Nest Hub Max, and Voice Match in Google Assistant. It pleads violations of §503.001(b), (c)(2), and (c)(3). Neither Google release says how much of the $1.375 billion is attributable to the biometric claims.

The petition also shows where a destruction question gets answered. All three destruction counts read alike:

On information and belief, Google does not destroy the biometric identifiers it captures through Google Photos before the first anniversary of the date the purpose for collecting the identifiers expires.
Plaintiff's Original Petition, The State of Texas v. Google LLC, Midland County, ¶ 32; ¶¶ 44 and 57 repeat it for Nest Hub Max and Google Assistant

"On information and belief" marks a fact the filer believes but cannot yet prove. Outsiders cannot see when a template was deleted; that date lives in the company's logs. A destruction count turns on records the defendant kept, or failed to keep.

What changed on January 1, 2026

House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, amended CUBI effective January 1, 2026 (H.B. 149, §§2 and 10). The enrolled bill's certification page gives the dates: the House passed it on April 23, 2025; the Senate passed it with amendments on May 23, 2025; and the House concurred in those amendments on May 30, 2025. The changes to §503.001:

  • An AI training carve-out with a tripwire. CUBI does not apply to training, processing, or storing biometric identifiers to develop or offer AI models, "unless a system is used or deployed for the purpose of uniquely identifying a specific individual" (§503.001(e)(2)).
  • A security and fraud carve-out. Developing or deploying an AI system to prevent or respond to security incidents, identity theft, fraud, harassment, or other illegal activity is outside the section (§503.001(e)(3)).
  • A re-entry rule. An identifier captured to train AI and later used for a commercial purpose outside those carve-outs becomes subject to CUBI's possession and destruction rules and its penalties (§503.001(f)).
  • The scraping rule in (b-1) above.

Subsection (f) is a records rule in disguise. Whether an identifier sits inside or outside CUBI now depends on why it was captured and what it was used for next. The business that logged the purpose at capture can answer that question. The one that did not is guessing.

Does CUBI apply to your time clock, ID scanner, or voice line?

The trigger is capture "for a commercial purpose," and CUBI does not define that phrase. My reading from the text: (c-2) speaks of identifiers "captured for a commercial purpose" and "collected for security purposes by an employer" in the same sentence, so the statute itself treats employer capture as commercial-purpose capture. Counter by counter:

  • Fingerprint time clock: assume CUBI applies. Give notice and get consent before enrollment; it costs a form.
  • ID scanner at a bar or smoke shop: reading the license barcode captures document data. Building a face template to match returning customers captures a record of face geometry. Verify, discard, and be able to show the discard happened.
  • Call-center voice ID: voiceprints are in the definition. §503.001(e)(1) exempts voiceprint data retained by a financial institution or its affiliate. A vendor that is neither should not assume it is covered.

Can a Texas employee refuse a fingerprint time clock?

CUBI requires your employer to tell you and get your consent before enrollment. It says nothing about whether the employer may make that consent a condition of the job. Colorado, by contrast, lists the only purposes for which an employer may require biometric consent as a condition of employment (C.R.S. 6-1-1314(6), added by HB 24-1130). Texas has no such list, so a refusal falls to ordinary employment law, a question for counsel.

What CUBI does give a worker is a deadline. If the identifier was collected for security purposes, (c-2) presumes its purpose ended when the job ended, and the one-year destruction clock starts then. A template still on file more than a year later is past the statute's deadline, and the complaint goes to the Attorney General.

Which other states have biometric privacy laws?

Counts vary, so here are the statutes by name. Illinois's BIPA (740 ILCS 14) is the one that lets the scanned person sue. Washington's RCW 19.375 is enforced "solely by the attorney general" under the Consumer Protection Act (RCW 19.375.030(2)). Colorado's HB 24-1130 added biometric duties to the Colorado Privacy Act effective July 1, 2025 (HB 24-1130, §5), enforced by the attorney general and district attorneys (C.R.S. 6-1-1311).

Texas stacks two laws: CUBI, and the Texas Data Privacy and Security Act, which treats biometric data used to identify a person as sensitive data (§541.001(29)(B)). The biometric law tracker in the resources below keeps the full, current list.

Run the four-date test

Pick one former employee who used your fingerprint clock. Could you produce, by Friday, the notice they saw, the consent they gave, the date the purpose of their enrollment ended, and the record showing the template was destroyed within a year of that date?

If not, start with the two dates still being written: purpose expired and identifier destroyed. CUBI is a set of deadlines, and the businesses that clear it hold a calendar with evidence attached.