Texas Attorney General Ken Paxton issued a 30-day compliance notice to TP-Link, Alibaba, CapCut, and other CCP-affiliated Chinese companies for violating the Texas Data Privacy and Security Act (TDPSA). The companies are accused of failing to disclose consumer data processing activities, allow opt-out of data collection, and enable consumer data deletion as required by Texas law. If the companies do not comply within 30 days, the Attorney General's office will pursue additional legal action.
The named companies must comply with TDPSA requirements within 30 days, including disclosing consumer data processing activities, allowing consumers to opt out of data collection, and enabling consumers to delete their personal data. No monetary penalties or other remedies are imposed unless the companies fail to cure their violations within the 30-day period.
In-house legal teams should review all vendor agreements with technology companies, especially those with CCP affiliations, to ensure compliance with TDPSA requirements. Key clauses to audit include data processing disclosures, consumer opt-out mechanisms, and data deletion rights. Teams should also add provisions for vendor compliance audits, cure periods for privacy breaches, and restrictions on cross-border data transfers to high-risk jurisdictions. Additionally, contracts should include representations that vendors comply with all applicable Texas privacy laws.
Entity
TP-Link, Alibaba, CapCut, and several other CCP-affiliated Chinese companies
Industry
Technology"TP-Link, Alibaba, CapCut, and several other Chinese and Chinese Communist Party (“CCP”) aligned companies"
"Texas Data Privacy and Security Act (“TDPSA”)"
"The law requires companies to disclose whether they process consumer data, allow consumers to opt out of data collection, and enable consumers to delete their personal data entirely."
"given the CCP-affiliated companies thirty days to comply with Texas’s heightened privacy protections."
"Attorney General Ken Paxton"
"If the companies fail to comply with the TDPSA, additional legal action will be taken."
Texas Attorney General Ken Paxton launched an investigation into the American Academy of Pediatrics (AAP) over concerns that the organization may be promoting and recommending childhood vaccines for financial gain. The AAP has been issued a Civil Investigative Demand to determine the basis of its vaccine recommendations and whether they are influenced by financial incentives from pharmaceutical donors.
Texas Attorney General Ken Paxton announced an investigation into major food manufacturers, including Frito Lay, Flora Food Group, and ACH Foods, over misleading 'heart healthy' labeling. The investigation will examine whether their advertising practices violate the Texas Deceptive Trade Practices Act by misrepresenting the health value of their products. Civil Investigative Demands have been issued to these companies.
Texas Attorney General Ken Paxton opened an investigation into Lone Star Pups, LLC for misleading consumers about the origin and veterinary care of puppies sold online. The company allegedly misrepresents breeder certifications and a '10 Year Health Guarantee' with restrictive fine print. The investigation focuses on potential violations of the Texas Deceptive Trade Practices Act.
Texas Attorney General Ken Paxton announced industry-wide investigations into feminine care and cosmetic product brands, including Tampax, Kotex, L., and LOLA, over potential deceptive trade practices related to undisclosed toxic chemicals and heavy metals in their products. The investigations focus on whether consumers were misled about product safety and ingredient composition under the Texas Deceptive Trade Practices Act.
Texas Attorney General Ken Paxton issued a consumer alert warning Texans about scams, fraudulent charities, and illegal price gouging related to severe flooding. The guidance provides resources for verifying charities and reporting suspected fraud or price gouging to the AG's office.
$150.0M
Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.