Court Rules
All enforcement actions
Warning LetterLow Risk

Texas AG Paxton Issues 30-Day TDPSA Compliance Notice to Chinese Companies

TP-Link, Alibaba, CapCut, and several other CCP-affiliated Chinese companiesMay 6, 2025Texas Attorney General

Summary

Texas Attorney General Ken Paxton issued a 30-day compliance notice to TP-Link, Alibaba, CapCut, and other CCP-affiliated Chinese companies for violating the Texas Data Privacy and Security Act (TDPSA). The companies are accused of failing to disclose consumer data processing activities, allow opt-out of data collection, and enable consumer data deletion as required by Texas law. If the companies do not comply within 30 days, the Attorney General's office will pursue additional legal action.

Remedy

The named companies must comply with TDPSA requirements within 30 days, including disclosing consumer data processing activities, allowing consumers to opt out of data collection, and enabling consumers to delete their personal data. No monetary penalties or other remedies are imposed unless the companies fail to cure their violations within the 30-day period.

Corrective Notice

Contract Impact

In-house legal teams should review all vendor agreements with technology companies, especially those with CCP affiliations, to ensure compliance with TDPSA requirements. Key clauses to audit include data processing disclosures, consumer opt-out mechanisms, and data deletion rights. Teams should also add provisions for vendor compliance audits, cure periods for privacy breaches, and restrictions on cross-border data transfers to high-risk jurisdictions. Additionally, contracts should include representations that vendors comply with all applicable Texas privacy laws.

Contract Search Terms

TDPSA complianceopt-out mechanismdata deletion rightsconsumer data processing disclosureGlobal Privacy Controlcross-border data transferCCP-affiliated vendor30-day cure period

Laws Cited

Texas Data Privacy and Security Act (TDPSA)

Violation Types

Entity Details

Entity

TP-Link, Alibaba, CapCut, and several other CCP-affiliated Chinese companies

Industry

Technology

Official Sources

Source Evidence

Entity Name
"TP-Link, Alibaba, CapCut, and several other Chinese and Chinese Communist Party (“CCP”) aligned companies"
Laws Cited
"Texas Data Privacy and Security Act (“TDPSA”)"
Violation Types
"The law requires companies to disclose whether they process consumer data, allow consumers to opt out of data collection, and enable consumers to delete their personal data entirely."
Event Type
"given the CCP-affiliated companies thirty days to comply with Texas’s heightened privacy protections."
Jurisdiction
"Attorney General Ken Paxton"
Remedy Summary
"If the companies fail to comply with the TDPSA, additional legal action will be taken."

Related Enforcement Actions

TX

Tris Pharmaceuticals

$7.5M

Texas Attorney General Ken Paxton announced a $7.5 million settlement with Tris Pharmaceuticals over alleged misrepresentations about the efficacy of Dyanavel XR, an ADHD drug marketed for children. The release says the company overstated the drug’s efficacy and directed sales representatives to make misleading claims to doctors, including Medicaid providers.

TX

Plum Organics

Texas Attorney General Ken Paxton announced an agreement with Plum Organics requiring stronger testing and limits for heavy metals in covered baby food products, along with publicly accessible testing results. The release does not state a monetary penalty; the agreement follows an ongoing investigation into baby food manufacturers.

TX

Health Care Service Corporation (including Blue Cross and Blue Shield of Texas)

Texas Attorney General Ken Paxton opened an investigation into Blue Cross and Blue Shield of Texas, its parent Health Care Service Corporation, and related entities over alleged denials or delays of urgent and medically necessary care and potentially burdensome prior authorization requirements. The investigation is ongoing; the Attorney General issued a Civil Investigative Demand to obtain information and assess potential violations of Texas law.

TX

N/A (consumer alert; no enforcement target)

Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofits about a surge of demand letters alleging California Invasion of Privacy Act (CIPA) violations based on common website technologies such as cookies, pixels, and analytics tools. The AG cautions that some letters may exaggerate or misrepresent violations and may be fraudulent, noting serial CIPA plaintiff Vivek Shah has been declared a vexatious litigant. Recipients are advised not to pay or respond directly, to consult privacy counsel, and to report suspected fraud to the Consumer Protection Division.

TX

TikTok

A Texas state district court (Judge Cory Liu) has found TikTok liable for lying to parents about the safety of its platform and for exposing children to inappropriate and explicit content, making Texas the first state in the nation to hold TikTok liable on these claims. The court found that although TikTok claimed it would remove graphic videos depicting drugs, nudity, alcohol, injuries, and profanity, such videos remained accessible to minors, even under 'Restricted Mode.' No penalty has been imposed yet; Attorney General Paxton will proceed to trial, expected next month, where relief and penalties will be determined.

TX

TriWest Healthcare Alliance Corp.

Texas Attorney General Ken Paxton opened an investigation into TriWest Healthcare Alliance Corp., the U.S. government contractor that administers the VA Community Care Network and the Defense Health Agency's TRICARE West Region, over reports that it wrongfully denied health care claims by falsely treating insureds as having other health insurance (OHI). The OAG has issued Civil Investigative Demands (CIDs) and plans to interview consumers and employees to determine whether TriWest violated the Texas Deceptive Trade Practices Act. No findings or penalties have been imposed yet.