Glenn Hegar
Texas Comptroller of Public Accounts
Glenn Hegar
Texas Comptroller of Public Accounts
Skip navigation
Glenn Hegar
Texas Comptroller of Public Accounts
Skip navigation
Top navigation skipped


Privacy and Security Policy

The Comptroller of Public Accounts, its divisions, and its associated companies (CPA or "we") values and protects the public's (your) privacy and places strict controls on the gathering and use of sensitive information and confidential information. Sensitive information and confidential information are not disclosed, made available, or otherwise used for purposes other than those specified at the time of collection, except with your consent or as authorized by law or regulation.

As a public agency, some information is required to be made available to the public via our websites, the Texas Data Portal, or in response to an open records request. However, CPA understands the importance of maintaining your privacy and will make every attempt to maintain your trust and confidence regarding the collection and use of your non-public sensitive and confidential information.

Please read this policy carefully to understand our policies and practices regarding your information and how we will treat it. By accessing or using our websites, you agree to this privacy policy. This policy may change from time to time. Your continued use of our websites after we make changes is deemed to be acceptance of those changes, so please check the policy periodically for updates. This policy has been developed and is maintained in accordance with all applicable Texas and federal laws and regulations.

What Information is Collected?
Sensitive or Confidential Information

The voluntary disclosure of sensitive information or confidential information to CPA, whether solicited or unsolicited, via physical or electronic means constitutes your consent to the collection and disclosure of the information by CPA for the purposes for which the information was disclosed to CPA, as was reasonably ascertainable from the nature and terms of the disclosure, including collection and disclosure for the purpose of validating your identity.

Web Analytics Data

CPA's websites collect and store information each time you access them to enable us to measure the total number of visitors, and certain non-personal statistical information. This helps us make our websites more accessible and useful to visitors.

If you browse through our sites reading, printing, or downloading information, no sensitive information and no confidential information about you is collected.

The information we collect when you visit CPA's sites may include:

  • The Internet Protocol (IP) address from which you are accessing the site(s)
  • The name of the Internet Service Provider (ISP) or wireless carrier you are using to access the site(s) (e.g. Comcast, Spectrum, Verizon, or Sprint)
  • The date and time you visited the site(s)
  • The web pages or services you accessed at the site(s)
  • The type, manufacturer, model, operating system, and Media Access Control (MAC) address of the device you are using to access the site(s)
  • Internet browser type and version used to access the site(s)

CPA uses Google Analytics to measure traffic on our websites. Review the Google Analytics Terms of Use or learn more about how Google uses, collects, and processes analytics data. To prevent Google Analytics from recognizing return visits to our websites you may disable cookies in your Web browser.

Some CPA sites may also use JavaScript to collect site traffic and activity, as well as to measure the performance of our servers and network. These scripts do not collect sensitive information or confidential information about you.

Multifactor Authentication to Access CPA Sites/Applications

To better serve you and protect access to your information, CPA sites may use multifactor authentication (MFA) to enhance the security of your account(s)/information accessed via our sites. By using our MFA service(s), you may be required to supply an email address or phone number in order for us to deliver security verification codes to you. We will not disclose this information to third parties (except permitted by law) without your express written consent.

Biometric and Geolocation Information

When you use our sites and services CPA does not actively collect, maintain, or disseminate biometric or geolocation information obtained from global positioning system technology, individual contact tracing, or biometric identifier collection technology.

Cookies, Pixels, and Other Digital Tracking Technologies

To better serve you, CPA sites may use cookies to enhance or customize your visit to the site(s). Cookies do not contain your sensitive information or confidential information.

We may also use third-party advertising companies to deliver advertisements on our behalf. These companies may use anonymous cookies or other technologies to track information regarding your browsing history on our site(s). Third-party advertising networks, such as Google AdWords and AdRoll, use this information to deliver ads to you on our behalf at other sites throughout the Internet, to track your response to advertisements, report on visitor interaction, and to measure the effectiveness of advertisements. We do not control these third parties' tracking technologies or how they may be used.

Facebook provides certain features and tools, such as pixels, SDKs, and APIs that can send your browsing data to Facebook, including pages you visit and actions you take on our site(s). This tool allows us to personalize our ads based on the content you viewed on our site. We may also use Facebook technology to deliver interest-based ads using lists of email addresses that we have collected on our site(s). We update these lists once a month so that we do not intentionally target our ads to users who have opted out of emails from CPA.


If you communicate with CPA by sending an email, your email address may be retained for further communication with you in connection with processing your request or as provided by law. Do not send any sensitive or confidential information in the body of, or as an attachment to, an electronic mail message unless the data is adequately encrypted. Data sent via email is not inherently secured or encrypted. Any information contained in an email message or attachment may be retained and stored by CPA pursuant to the applicable retention period or as provided by law and may be provided to other state agencies to better serve your needs.

In addition, CPA collects the email addresses of those individuals who voluntarily provide their email address on our site(s) and on other platforms, such as Facebook.

Further, email addresses and other volunteered information may be used to send news, notices, and other information to those who request it on a strictly opt-in basis. Email addresses may also be used to serve interest-based ads on other platforms, such as Facebook.

Social Media

In the spirit of open, transparent government, CPA makes use of social media tools (e.g. Facebook, Twitter, YouTube, etc.) to keep the public informed of news, economic updates, and other announcements.

Any comments or posts made to a social media forum maintained by CPA may be subject to release to the public as required by the Texas Public Information Act (PIA).

Users of these social media services are bound by the terms of service and user agreements for the platform.

How is Information Used or Stored?
Purpose Limitations

CPA gathers your information through lawful means. Any subsequent use of the information is limited to purposes consistent with the purpose(s) given at the time of collection.

Public Disclosure

Texas law provides that all information collected or maintained by CPA is subject to the Texas Public Information Act. CPA is required to disclose information requested by the public under the PIA unless the information is excepted from disclosure by the PIA or other applicable law or regulation.

Disclosure to Third Parties

You are responsible for protecting the confidentiality of any user ID, password, or PIN used to access CPA websites. If you give your user ID, password, or PIN to anyone else, they will be able to access your sensitive and confidential information.

CPA does not sell your information to any third party. CPA does not distribute to or share your information with any non-governmental third party without your consent or as authorized by law or regulation. Employees will only use sensitive and confidential information submitted by you on a need-to-know basis to provide information or services, or carry out the duties of our agency.

Further, we will not disclose information we collect from you to third parties without your permission except to the extent necessary including:

  • To fulfill your requests for services.
  • To protect ourselves from liability.
  • To verify or update information provided.
  • To comply with any law enforcement agency, self-regulatory organizations or a properly authorized civil, criminal, or regulatory investigation.
  • To prevent, detect, mitigate, and investigate actual or potential fraud and unauthorized transactions or claims.
  • To comply with subpoenas or summons or to comply with federal, state or local laws, rules and other legal requirements, or in connection with a merger, acquisition, or liquidation of a company.

It is possible to opt-out of data collection by common third parties by visiting:

Retention and Destruction

Information collected by or provided to CPA will be retained and maintained as required by law or regulation such as Texas Government Code Section 441.180 et seq. Different types of information are required to be kept for different periods of time.

CPA stores or uses sensitive and confidential information submitted by you only for the time necessary. Confidential information is destroyed via purging, magnetic degaussing/erasing, shredding, and/or other means of authorized confidential destruction when no longer required and to prevent unauthorized access or use of the data. Regularly scheduled archiving, purging, and proper disposal of records and information is a standard practice throughout CPA.

Read details on CPA's Records Retention Schedule as published on the Texas State Library and Archives Commission site (PDF).

How is Information Protected?

CPA's public facing websites and systems, as well as internal systems, have reasonable security measures in place to protect against the loss, misuse, and alteration of your data and information that is under our control. Interactive applications and forms that collect transaction payments, sensitive or confidential information are encrypted using privacy and security safeguards such as Transport Layer Security (TLS) or similar technology.

Appropriate computer, network, and Internet technical security controls at the employee and departmental level prevent unauthorized access to information voluntarily provided by you. Some of these security controls are password and user identification verification, data encryption, confidential transmissions, secure storage areas, and audit trails. CPA employees are educated regarding the requirements of working with sensitive and confidential information as well as the consequences of misuse.

What Can I Do With My Information?

With few exceptions, you have the right to request, receive, and review your information with CPA. You are also entitled to have us correct any information about you in our possession that may be incorrect.

To request your information from CPA for review, please submit your request via one of the methods listed below and ensure your request includes enough description and detail so we may accurately identify and locate your information.

By email:
Open Records.
FYI Open Records Tool
By mail:
Open Records Section
Comptroller of Public Accounts
P.O. Box 13528
Austin, TX 78711-3528
In person:
Open Records Section
Comptroller of Public Accounts
111 E. 17th St.
LBJ State Office Bldg., Ste. 210
Austin, TX 78701
Request a Correction

To request a correction of incorrect information about yourself, submit your request via one of the methods listed above or directly via our site for common changes listed below.

For filing taxes:

Non-CPA Website Links Disclaimer

CPA's websites contain links to other websites for your information and convenience. CPA has no control over the privacy practices or the content of such other websites. Please review the privacy information provided by these sites.

The responsibility for the content and accuracy of information on sites accessed by linking from our websites rests with the entities providing the information. This includes any responsibility for updating information upon which visitors may rely.

The inclusion of links from our sites to others does not imply any endorsement by CPA of any product, service, or vendor. Any mention of products, services, or vendors is for informational purposes only.

Read details on CPA's Link Policy.

Policy Disclaimer and Limitation of Liability

The information provided in this privacy policy should not be construed as giving business, legal, or other advice, or warranting as fail proof the security of information provided through our websites.

Information on CPA's sites is public domain and may be copied and used as permitted by law, with the exception of pictures, official symbols, and registered service marked names and logos. While CPA attempts to maintain a high degree of accuracy, we will not be held liable for errors or omissions that may occur.

CPA is not an operator of websites or online services directed at children under 13 years of age and does not knowingly collect sensitive and confidential information from children without parental consent. Users are cautioned, however, that the collection of sensitive and confidential information via an interactive application or email will be treated as though it was submitted by an adult, and may, unless exempted from access by federal or state law, be subject to public access. CPA strongly encourages parents and teachers to be involved in children's Internet activities, and to provide guidance whenever children are asked to provide sensitive and confidential information online.

Application Programming Interface (API)
A set of subroutine definitions, protocols, and tools for building application software. In general terms, it is a set of clearly defined methods of communication between various software components.
Confidential Information
Information typically excepted from public disclosure, whether specified in law or through a decision by the Open Records division of the Texas Attorney General's office. This includes Sensitive Personal Information (SPI), as defined by Texas Business and Commerce Code Section 521.
A small piece of data sent from a website and stored in the user's web browser while the user is browsing it. Cookies can be disabled by adjusting the browser settings. If the cookies are disabled in the browser, certain parts of our website might not be accessible.
Internet Protocol (IP) Address
A unique string of numbers separated by periods that identifies each computer using the Internet Protocol to communicate over a network.
Internet Service Provider (ISP)
An organization that provides services for accessing, using, or participating in the Internet.
An object-oriented computer programming language commonly used to create interactive effects within web browsers.
Multifactor Authentication (MFA)
More than one factor of authentication i.e., something you know (e.g., a User ID in combination with a password), something you have (e.g., an ID badge or a cryptographic key), something you are (e.g., a fingerprint or other biometric data).
Public Information
Information available to the public freely and without reservation. Such information requires no authentication and is freely distributable by all agency personnel.
Regulated Information
Information typically controlled by federal or state regulation or other third-party agreement. This information may be confidential, sensitive, or public, but is subject to additional controls regarding its protection or disclosure.
Sensitive Information
Information that may be subject to public release under an open records request. The information should be vetted and verified before release. This includes Personal Identifying Information (PII), as defined by Texas Business and Commerce Code Section 521.
Short Message Service (SMS)
A text messaging service component of most telephone, Internet, and mobile device systems, which uses standardized communication protocols that let mobile devices exchange short text messages.
Software Development Kit (SDK)
A set of software development tools that allows the creation of applications for a certain software package, software framework, hardware platform, computer system, video game console, operating system, or similar development platform.
Transport Layer Security (TLS)
The standard security technology for establishing an encrypted link between two or more communicating computer applications such as web browsers and servers, email, instant messaging, and voice over IP (VoIP). This link ensures the privacy and integrity of all data passed between the computer applications.

Contact Us

If you have questions, comments, or concerns about CPA's Privacy and Security Policy, please email Information Security's Privacy Office

Or mail us at:

Information Security
Comptroller of Public Accounts
P.O. Box 13528, Capital Station
Austin, TX 78711-3528

If you require special accommodation pursuant to the Americans with Disabilities Act, please contact our Workplace Accommodations Coordinator at 512-475-3560.