regulatory updates
Texas Biometric Privacy Law: What CUBI Requires in 2026
Texas biometric privacy law, explained from the statute: what CUBI requires, what changed January 1, 2026, and the four dates you must prove.
Key Takeaways
- •CUBI (Tex. Bus. & Com. Code §503.001) requires notice and consent before capturing a biometric identifier for a commercial purpose, bars selling it, and sets a destruction deadline.
- •The Texas Attorney General enforces it, at up to $25,000 per violation. The office used CUBI against Meta ($1.4 billion, July 2024) and in its Google case ($1.375 billion, announced May 2025).
- •Every CUBI duty resolves into a date: notice given, consent received, purpose expired, identifier destroyed. A defense is the record behind each one.
Texas's biometric privacy law is one section long. Capture a fingerprint, voiceprint, or face geometry for a commercial purpose, and you must tell the person, get consent, and destroy it on a deadline.
The law is the Capture or Use of Biometric Identifier Act, Business and Commerce Code §503.001, usually shortened to CUBI. The statute gives enforcement to the Texas Attorney General, and the office has used it: a $1.4 billion settlement with Meta in July 2024, and a $1.375 billion settlement with Google, announced in May 2025, that covered biometric claims.
I read the current statute, including the January 1, 2026 amendments. Every duty in it resolves into a date you would have to prove, and this page is built around those dates. It is an explainer, not legal advice; run your specifics past Texas counsel.
What Texas's biometric privacy law requires
CUBI's obligations fit in five lines. Three of them produce the dates you would have to prove:
- Notice: inform the individual before capturing a biometric identifier for a commercial purpose (§503.001(b)(1)). Date: when notice was given.
- Consent: receive the individual's consent to the capture (§503.001(b)(2)). Date: when consent was received, before the first capture.
- No sale: do not sell, lease, or otherwise disclose the identifier, outside four exceptions (§503.001(c)(1)).
- Reasonable care: store and protect it at least as carefully as your other confidential information (§503.001(c)(2)).
- Destruction: destroy it on a deadline tied to the end of its purpose (§503.001(c)(3)). Dates: when the purpose expired, and when the identifier was destroyed.
The destruction duty is the one with a clock in the text:
shall destroy the biometric identifier within a reasonable time, but not later than the first anniversary of the date the purpose for collecting the identifier expires, except as provided by Subsection (c-1).
The four disclosure exceptions are narrow: identification after disappearance or death, with consent; a financial transaction the person requested or authorized; a disclosure a federal or state statute requires or permits; and a law enforcement warrant. Vendor convenience is not on the list, so your scanner or timekeeping contract has to keep the data inside it.
The four dates a CUBI defense turns on
Notice and consent are fixed at enrollment; the other two dates are created, or not, every day after:
| Date | What it proves | The record |
|---|---|---|
| Notice given | (b)(1): informed before capture | Dated notice text, tied to the person |
| Consent received | (b)(2): consent before capture | Signed or logged consent, timestamped before enrollment |
| Purpose expired | (c)(3): the one-year clock started | The stated purpose, plus the event that ended it |
| Identifier destroyed | (c)(3): deadline met | Destruction log or vendor deletion confirmation, dated |
The third row needs a close reading. The statute presumes a purpose-expiry date in only one case:
If a biometric identifier captured for a commercial purpose has been collected for security purposes by an employer, the purpose for collecting the identifier under Subsection (c)(3) is presumed to expire on termination of the employment relationship.
That presumption covers identifiers collected "for security purposes." A door-access scanner fits. A time clock that records hours arguably does not, and then the statute supplies no end date at all. The end date becomes whatever purpose you wrote down at enrollment. If you wrote nothing down, you cannot show when the one-year clock started, so you cannot show you met it.
Subsection (c-1) moves the date in one more case: if the identifier is used with a document another law requires you to keep longer, the clock runs from the date that retention duty ends. Record that document on day one too.
Together, those subsections define one record per enrolled person. Here it is as a template:
CUBI enrollment record: one per person
- Person and system: employee or customer ID, the capturing device, and the identifier type.
- Purpose stated at capture: one sentence, marked "security" or not for (c-2), plus any linked document another law makes you keep, for (c-1).
- Notice given: date, time, and the notice text version shown. Before the first capture.
- Consent received: date, time, method, and the consent text version. Before the first capture.
- Purpose expired: date, and the event that ended it, such as the last day of employment.
- Destruction deadline: a reasonable time, and no later than one year after the purpose expired or the (c-1) retention duty ended.
- Identifier destroyed: date, who or what deleted it, and the vendor's deletion confirmation for any copy it held.
What counts as a biometric identifier in Texas
"Biometric identifier" means a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry.
The list names geometry records, so a face template extracted from a photo is covered while the photo itself sits outside the definition. That line sits at the center of the Meta case: the Attorney General's release says Meta captured "records of the facial geometry" of people in uploaded photos.
It also separates CUBI from Texas's other privacy statute. The Texas Data Privacy and Security Act defines "biometric data" to exclude "data generated from a physical or digital photograph" (§541.001(3)). The same face template can be a CUBI identifier and fall outside the newer act's biometric definition.
Since January 1, 2026, CUBI also answers the scraping question:
For purposes of Subsection (b), an individual has not been informed of and has not provided consent for the capture or storage of a biometric identifier of an individual for a commercial purpose based solely on the existence of an image or other media containing one or more biometric identifiers of the individual on the Internet or other publicly available source unless the image or other media was made publicly available by the individual to whom the biometric identifiers relate.
Read the last clause twice. A photo someone else posted can never, on its own, stand in for notice and consent. A photo the person posted themselves falls outside (b-1), which leaves the ordinary (b) test in place and an argument open. Do not build a product on that argument without counsel.
Who enforces CUBI, and what the Attorney General has done
CUBI names one enforcer, the Attorney General, with a civil penalty of up to $25,000 for each violation (§503.001(d)). It creates no private right of action. A Texan whose fingerprint was captured without consent has no CUBI claim of their own; the route is a complaint to the Attorney General.
AG-only enforcement sounds like the soft option. The public record says otherwise:
| Date | Action | Source |
|---|---|---|
| February 2022 | Attorney General sues Meta under CUBI and the Deceptive Trade Practices Act | Texas AG release, July 30, 2024 |
| July 30, 2024 | Meta agrees to pay $1.4 billion over five years | Same release |
| May 9, 2025 | Attorney General announces a $1.375 billion settlement in principle with Google over geolocation, incognito searches, and biometric data, claims first filed in 2022 | Texas AG release, May 9, 2025 |
| October 31, 2025 | Google signs the settlement agreement, ending two suits | Texas AG release, October 31, 2025 |
The Attorney General's July 30, 2024 release called the Meta deal "the largest settlement ever obtained from an action brought by a single State" and the first lawsuit and settlement under CUBI. It says Meta ran facial recognition on "virtually every face" in photos uploaded to Facebook after rolling out Tag Suggestions in 2011. The State's biometric petition against Google targeted face grouping in Google Photos, Face Match on the Nest Hub Max, and Voice Match in Google Assistant. It pleads violations of §503.001(b), (c)(2), and (c)(3). Neither Google release says how much of the $1.375 billion is attributable to the biometric claims.
The petition also shows where a destruction question gets answered. All three destruction counts read alike:
On information and belief, Google does not destroy the biometric identifiers it captures through Google Photos before the first anniversary of the date the purpose for collecting the identifiers expires.
"On information and belief" marks a fact the filer believes but cannot yet prove. Outsiders cannot see when a template was deleted; that date lives in the company's logs. A destruction count turns on records the defendant kept, or failed to keep.
What changed on January 1, 2026
House Bill 149, the Texas Responsible Artificial Intelligence Governance Act, amended CUBI effective January 1, 2026 (H.B. 149, §§2 and 10). The enrolled bill's certification page gives the dates: the House passed it on April 23, 2025; the Senate passed it with amendments on May 23, 2025; and the House concurred in those amendments on May 30, 2025. The changes to §503.001:
- An AI training carve-out with a tripwire. CUBI does not apply to training, processing, or storing biometric identifiers to develop or offer AI models, "unless a system is used or deployed for the purpose of uniquely identifying a specific individual" (§503.001(e)(2)).
- A security and fraud carve-out. Developing or deploying an AI system to prevent or respond to security incidents, identity theft, fraud, harassment, or other illegal activity is outside the section (§503.001(e)(3)).
- A re-entry rule. An identifier captured to train AI and later used for a commercial purpose outside those carve-outs becomes subject to CUBI's possession and destruction rules and its penalties (§503.001(f)).
- The scraping rule in (b-1) above.
Subsection (f) is a records rule in disguise. Whether an identifier sits inside or outside CUBI now depends on why it was captured and what it was used for next. The business that logged the purpose at capture can answer that question. The one that did not is guessing.
Does CUBI apply to your time clock, ID scanner, or voice line?
The trigger is capture "for a commercial purpose," and CUBI does not define that phrase. My reading from the text: (c-2) speaks of identifiers "captured for a commercial purpose" and "collected for security purposes by an employer" in the same sentence, so the statute itself treats employer capture as commercial-purpose capture. Counter by counter:
- Fingerprint time clock: assume CUBI applies. Give notice and get consent before enrollment; it costs a form.
- ID scanner at a bar or smoke shop: reading the license barcode captures document data. Building a face template to match returning customers captures a record of face geometry. Verify, discard, and be able to show the discard happened.
- Call-center voice ID: voiceprints are in the definition. §503.001(e)(1) exempts voiceprint data retained by a financial institution or its affiliate. A vendor that is neither should not assume it is covered.
Can a Texas employee refuse a fingerprint time clock?
CUBI requires your employer to tell you and get your consent before enrollment. It says nothing about whether the employer may make that consent a condition of the job. Colorado, by contrast, lists the only purposes for which an employer may require biometric consent as a condition of employment (C.R.S. 6-1-1314(6), added by HB 24-1130). Texas has no such list, so a refusal falls to ordinary employment law, a question for counsel.
What CUBI does give a worker is a deadline. If the identifier was collected for security purposes, (c-2) presumes its purpose ended when the job ended, and the one-year destruction clock starts then. A template still on file more than a year later is past the statute's deadline, and the complaint goes to the Attorney General.
Which other states have biometric privacy laws?
Counts vary, so here are the statutes by name. Illinois's BIPA (740 ILCS 14) is the one that lets the scanned person sue. Washington's RCW 19.375 is enforced "solely by the attorney general" under the Consumer Protection Act (RCW 19.375.030(2)). Colorado's HB 24-1130 added biometric duties to the Colorado Privacy Act effective July 1, 2025 (HB 24-1130, §5), enforced by the attorney general and district attorneys (C.R.S. 6-1-1311).
Texas stacks two laws: CUBI, and the Texas Data Privacy and Security Act, which treats biometric data used to identify a person as sensitive data (§541.001(29)(B)). The biometric law tracker in the resources below keeps the full, current list.
Run the four-date test
Pick one former employee who used your fingerprint clock. Could you produce, by Friday, the notice they saw, the consent they gave, the date the purpose of their enrollment ended, and the record showing the template was destroyed within a year of that date?
If not, start with the two dates still being written: purpose expired and identifier destroyed. CUBI is a set of deadlines, and the businesses that clear it hold a calendar with evidence attached.