TwinEthosRequest access

Law

Texas Bus. & Com. Code 503.001 (biometric identifiers)

Texas Attorney General · Texas (US-TX) · 2 provisions encoded · verified against the official source as of 2026-09-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

AI-adjacent law General privacy or biometric law, included only where AI data flows trigger it; reported apart from AI-specific law.

Official text: tcss.legis.texas.gov.

Binding law — in force AI-adjacent law

Destroy captured face and voice biometrics within a year after their purpose expires (Texas)

Tex. Bus. & Com. Code 503.001(c) · official text · In force: applies since 1 Apr 2009 · Texas (US-TX)

A person who possesses a biometric identifier captured for a commercial purpose must protect it with reasonable care, may disclose it only in listed cases, and must destroy it within a reasonable time, no later than the first anniversary of the date the purpose for collecting it expires (later only where another law requires keeping a document it is used with). Detect stored face or voice templates with no deletion path tied to the end of their purpose.

Who it applies to

  • Duty falls on: organization
  • Persons possessing biometric identifiers captured for a commercial purpose. In force since 2009-04-01.
  • Not covered:
    • Voiceprint data retained by a financial institution or affiliate (503.001(e)(1))
    • Training, processing or storage of biometric identifiers to develop, train, evaluate, disseminate or offer AI models or systems, unless a system is used or deployed to uniquely identify a specific individual (503.001(e)(2))
    • AI developed or deployed to prevent, detect or respond to security incidents, identity theft, fraud, harassment or other illegal activity, to preserve system integrity or security, or to investigate or prosecute those responsible (503.001(e)(3))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Store each face or voice template with its purpose and an expiry, and run a scheduled job that deletes it from every store when the purpose ends or retention lapses.

Each template row or collection entry carries its purpose, last_interaction_at, and an expires_at computed from the written retention schedule. A scheduled deletion job (cron, Celery beat, EventBridge schedule) removes expired templates from every place they live, including the Rekognition collection (delete_faces with the FaceIds) and any vector index, and account closure or the end of the purpose triggers deletion right away. The retention schedule is published (privacy policy or biometric policy page in the site source) and kept in the repo so code and policy match; deletions are logged.

Where it goes: 1 application source code, 2 data models, 4 infrastructure-as-code, 14 user-facing text.

What this provision adds:

  • Destroy the identifier within a reasonable time and no later than the first anniversary of the date the collection purpose expires, unless another law requires keeping a document it is used with.

Example (AWS Rekognition (boto3)), before:

resp = rekognition.index_faces(CollectionId='members', Image={'Bytes': img}, ExternalImageId=user_id)
db.faces.insert(user_id=user_id, face_id=resp['FaceRecords'][0]['Face']['FaceId'])

After:

resp = rekognition.index_faces(CollectionId='members', Image={'Bytes': img}, ExternalImageId=user_id)
db.faces.insert(user_id=user_id, face_id=resp['FaceRecords'][0]['Face']['FaceId'],
                purpose='door_access', expires_at=retention.expiry_for('door_access', now()))

def purge_expired_faces():   # scheduled daily
    expired = db.faces.expired(before=now())
    for batch in chunks(expired, 1000):
        rekognition.delete_faces(CollectionId='members', FaceIds=[f.face_id for f in batch])
        db.faces.delete_ids([f.id for f in batch])
        deletion_log.record(len(batch), reason='retention_expired')

Control: Biometric templates stored with no retention limit or destruction path. The same guard addresses 2 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Rule id tx-bc-503.biometric-destruction · review status: primary source derived