As Texas debates the expansion of artificial intelligence and data center infrastructure, a House committee is examining a related question of who owns the personal information those systems collect, store, and process. At issue is whether Texas’ existing privacy law sufficiently protects consumers—or whether Texans should be recognized as the owners of their own data.
The House Committee on Delivery of Government Efficiency, chaired by State Rep. Giovanni Capriglione (R–Southlake), held an interim hearing Wednesday on the implementation and effectiveness of the Texas Data Privacy and Security Act.
The committee’s charge is to determine whether the state’s landmark privacy law adequately protects Texans amid the accelerating collection and monetization of personal data.
Johnathan Stone, chief of the attorney general’s Consumer Protection Division, said the Texas Data Privacy and Security Act—which took effect in July 2024—is among the broadest comprehensive state privacy laws in the country.
He said it gives Texans the ability to access, correct, obtain, and delete their personal information; opt out of certain data collection and targeted advertising; and obtain additional protections for sensitive information, precise geolocation data, and information involving children younger than 13.
Since the attorney general’s office launched an updated complaint portal in September 2025, it has received approximately 6,300 complaints under the law. Requests to delete personal information are among the most common issues raised by consumers, Stone said. The office has sent nearly 50 notices of alleged violations and uses complaint trends to identify companies whose practices affect the greatest number of Texans.
Stone said enforcement is often slowed by companies claiming Texas courts lack jurisdiction because data is stored, processed, or collected through online systems located outside the state.
He told lawmakers the Legislature could consider clarifying that companies registered to do business or conducting substantial business in Texas consent to Texas jurisdiction.
While witnesses broadly described the Texas Data Privacy and Security Act as an important foundation, testimony centered on whether those protections go far enough—and whether Texas should formally recognize personal data as property owned by the individual.
David Dunmoyer of the Texas Public Policy Foundation summarized the concern bluntly: “Texans do not own their own personal information. Texas has never granted its citizens title to their own data, so ownership ultimately defaults to possession.”
Under that view, consumers must request permission from companies to control the information generated by their own activities, rather than exercising a clear ownership right. Dunmoyer urged lawmakers to “flip the script,” particularly as artificial intelligence creates new ways to analyze, combine, and profit from personal information.
Ron Yokubaitis, co-founder of Texas.net and Data Foundry, likewise told lawmakers privacy should be considered a property-rights issue rather than merely a regulatory one.
“Privacy becomes much less complicated when we stop treating it solely as a regulatory issue and recognize it for what it really is: a property rights issue,” Yokubaitis said.
Yokubaitis argued companies could still collect information necessary to deliver services, but should act as controllers, custodians, or licensees—not as permanent owners of a Texan’s digital identity. He also recounted instances in which government entities sought customer information from his data centers, saying his companies demanded proper legal process before handing over records.
That distinction took on added importance as lawmakers discussed how location data, biometric information, and data gathered by connected devices can reveal intimate details about Texans’ lives.
State Rep. Briscoe Cain (R–Deer Park) raised questions about the effect of a property-rights framework on people who never directly agreed to the collection of their information. He pointed to Ring doorbells, social-media posts, and biometric data involving children or spouses.
“If I consent to them to do it, I guess I’ve consented for myself,” Cain said. “What about my children?”
While the federal Children’s Online Privacy Protection Act (COPPA) requires verifiable parental consent before online services collect personal information from children younger than 13, Dunmoyer argued technology companies frequently use terms-of-service agreements setting a minimum age of 13 to claim they lack “actual knowledge” that younger children are using their services.
The Texas Data Privacy and Security Act requires compliance with COPPA, but the hearing highlighted the difficulty of enforcing that requirement when companies maintain they do not know a user’s age. Lawmakers also discussed Texas’ App Store Accountability Act, which requires age verification at the app-store level and parental approval for minors’ app downloads.
Scott McCollough, an attorney focused on telecommunications and consumer rights, told the committee a property-based approach could offer courts a more straightforward standard than the longstanding “reasonable expectation of privacy” test.
“Property asks the question courts know how to understand,” McCollough said. “Whose is it? Simple question. That’s the virtue of property.”
McCollough noted Texas law already contains pieces of such a framework. State computer-crime statutes define data as property, while the Texas Revised Uniform Fiduciary Access to Digital Assets Act recognizes individual rights and interests in digital assets and describes companies holding those assets as “custodians.”
He also pointed to the U.S. Supreme Court’s recent Chatrie v. United States decision, which held that government acquisition of historical cellphone location information through a geofence warrant constitutes a Fourth Amendment search. In a concurrence, Justice Neil Gorsuch argued for greater use of property principles in digital-privacy cases and cited Texas law’s recognition of computer data as property.
The public comments submitted for the hearing showed that Texans’ privacy concerns extend beyond online platforms.
Most commenters focused on automated license plate reader (ALPR) networks, particularly Flock Safety cameras, warning that the systems allow law enforcement and private entities to track and retain the movements of drivers who are not suspected of crimes.
Several commenters called for ending taxpayer subsidies for automated license plate reader systems, closing exemptions in the Texas Data Privacy and Security Act, requiring warrants to access historical location records, limiting retention periods, and requiring public audit logs.
Institute for Justice attorney Daniel Woislaw urged lawmakers to consider statewide safeguards governing ALPR access, retention, sharing, and auditing.
The debate now is whether lawmakers will turn that principle into enforceable protections during the 2027 legislative session.