Texas Data Privacy and Security Act

Texas uses a broad coverage test for consumer privacy. The Texas Data Privacy and Security Act applies without a $26.625 million revenue threshold, a 100,000 consumer threshold, or a requirement that data sales generate half of a business's revenue.

The TDPSA applies to a person that conducts business in Texas, or produces a product or service consumed by Texas residents, and processes or sells personal data. A person that qualifies as a small business under U.S. Small Business Administration standards is generally exempt, but even a small business must obtain prior consumer consent before selling sensitive personal data.

California's thresholds don't control the Texas analysis. A company below those thresholds may have to provide a Texas privacy notice, establish a consumer request process, honor qualifying opt out signals, use processor contracts, conduct data protection assessments, and obtain consent before processing sensitive data.

Who Counts as a Consumer

A consumer is a Texas resident acting in an individual or household context. The definition excludes a person acting in a commercial or employment context.

This distinction affects the first compliance question. Website data from Texas customers may qualify as consumer personal data, while employee, applicant, contractor, vendor, and business contact data may qualify for separate exclusions based on the context in which the business collected and used it.

Who the TDPSA Covers

Coverage depends on three conditions. You conduct business in Texas or provide a product or service consumed by Texas residents, you process or sell personal data, and you don't qualify as a small business under SBA standards.

The sensitive data sale rule applies even when a business qualifies for the small business exemption. A small business must obtain prior consent before selling personal data that qualifies as sensitive data.

SBA size standards vary by industry. Some use employee headcount, while others use annual receipts, so a software company, retailer, construction business, professional services firm, and manufacturer may face different tests.

Several entity exemptions also apply. Chapter 541 excludes state agencies and political subdivisions, financial institutions and data subject to the Gramm-Leach-Bliley Act, covered entities and business associates governed by HIPAA, nonprofit organizations, institutions of higher education, electric utilities, power generation companies, and retail electric providers.

Separate data exemptions cover categories that include information governed by the Fair Credit Reporting Act, the Family Educational Rights and Privacy Act, and the Driver's Privacy Protection Act. The statute also exempts specified health information, employment data, emergency contact data, benefits administration data, and personal data processed during a personal or household activity.

Personal Data and Sensitive Data

Personal data means information linked or reasonably linkable to an identified or identifiable individual. The definition includes pseudonymous data when a controller or processor combines it with other information that reasonably links the data to an individual, while publicly available information and deidentified data are excluded.

Additional rules apply to sensitive data. It includes personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexuality, citizenship, or immigration status.

The definition also includes genetic data, biometric data processed to identify a specific person uniquely, personal data collected from a known child, and precise geolocation data. A known child is a child whose age the controller knows or willfully disregards.

Texas defines precise geolocation data by radius. The term covers technology derived information that directly identifies an individual's location within 1,750 feet, but it excludes communication content and specified utility data.

Sale and Targeted Advertising

A sale means sharing, disclosing, or transferring personal data to a third party for money or other valuable consideration. This definition covers an exchange of data for value even when the parties don't use a conventional purchase price.

The statute excludes disclosures to a processor, disclosures needed to provide a product or service requested by the consumer, and affiliate disclosures. It also excludes information the consumer intentionally made available to the general public through a mass media channel without restricting the audience, along with transfers made as part of a merger or acquisition. Each exclusion depends on the facts of the transfer.

Targeted advertising means displaying an advertisement selected from personal data obtained through a consumer's activity over time and across nonaffiliated websites or applications to predict that consumer's preferences or interests. The definition excludes advertisements based on activity within your website or application, the context of a current search or visit, a response to the consumer's request, and processing used only to measure advertising performance, reach, or frequency.

Those distinctions affect website design. First party analytics and contextual advertising may fall outside the targeted advertising definition, while cross site behavioral advertising, retargeting pixels, and advertising network disclosures may trigger an opt out right.

Consumer Rights

Texas consumers may ask whether you process their personal data and request access to that data. They may also request correction of inaccuracies, deletion of personal data provided by or obtained about them, and a portable copy of personal data they previously provided when it is available in digital form.

Consumers may opt out of processing for targeted advertising, sale of personal data, and profiling used for decisions that produce legal or similarly significant effects. Those decisions concern access to financial and lending services, housing, insurance, health care, education enrollment, employment opportunities, criminal justice, and basic necessities such as food and water.

A parent or legal guardian may exercise these rights for a known child. Online data collected with verifiable parental consent that complies with COPPA also satisfies the TDPSA's parental consent requirement.

Consumer Request Mechanics

You must establish at least two secure and reliable methods for consumer requests. The methods must account for how consumers normally interact with you, the need for secure and reliable communications, and your ability to authenticate the person submitting the request.

If you maintain a website, you must provide a website mechanism for requests covered by Chapter 541. A controller that operates exclusively online and has a direct relationship with the consumer from whom it collects personal information may use an email address for that website mechanism.

You can't require a consumer to create a new account to exercise TDPSA rights, although you may require use of an existing account. When you decline a request, you must explain the decision and provide appeal instructions.

You must respond without undue delay and no later than 45 days after receiving a request. You may extend that period once for another 45 days when reasonably necessary because of the request's complexity or volume, but you must notify the consumer and give the reason within the initial response period.

You must provide information in response to a request without charge at least twice each year for each consumer. You may charge a reasonable administrative fee or decline to act when you can establish that a request is manifestly unfounded, excessive, or repetitive.

Appeals

Chapter 541 requires an appeal process when you refuse to act on a consumer request. You must make that process conspicuously available and similar to the process for submitting the original request.

You must respond to an appeal in writing within 60 days after receiving it. If you deny the appeal, you must provide the Attorney General's online complaint mechanism.

Your privacy notice and operating procedures should account for both stages. The request intake, denial notice, appeal channel, response calendar, and Attorney General complaint link should use the same documented workflow.

Universal Opt Out Signals

Since January 1, 2025, a Texas consumer has been able to designate an authorized agent to opt out of targeted advertising and the sale of personal data. The consumer may designate the agent through a website link, browser setting or extension, device setting, or other technology that communicates the consumer's choice.

The TDPSA doesn't designate Global Privacy Control as the exclusive technology. An authorized agent must communicate the request in a clear and unambiguous manner, and the technology can't unfairly disadvantage another controller or rely on a default setting that the consumer didn't affirmatively choose.

The technology must also be consumer friendly and easy for the average consumer to use. These requirements make the consumer's affirmative choice and the signal's operation more important than its product name.

You must honor an authorized agent's request when you can verify the consumer's identity and the agent's authority with commercially reasonable effort. You may refuse the request when you can't verify Texas residency, don't have the ability to process it, or don't process similar requests under similar laws of another state.

Your website should detect and process qualifying opt out signals. Your internal procedure should identify the signals you accept, the verification you perform, and how each opt out applies to sales and targeted advertising.

Privacy Notice Requirements

A covered controller must provide a reasonably accessible privacy notice. The notice must identify the categories of personal data processed, including sensitive data when applicable, and the purposes for processing.

The notice must explain how consumers may exercise their rights and appeal a denied request. It must also identify the available request methods, the categories of personal data shared with third parties, and the categories of third parties that receive the data.

If you sell personal data or process it for targeted advertising, you must disclose that activity clearly and conspicuously and explain how consumers may opt out. A business that sells sensitive personal data or biometric personal data must also post the additional sale notice prescribed by Section 541.102 in the same location and manner as its privacy notice.

Controller Duties

You must limit personal data collection to information that is adequate, relevant, and reasonably necessary for the disclosed purposes. A checkout process that needs a shipping address, payment details, and an email address for the receipt shouldn't collect precise geolocation, birthdate, or demographic attributes by default.

You must establish, implement, and maintain reasonable administrative, technical, and physical security practices. Those practices must reflect the volume and nature of the personal data you process.

You must obtain consent before processing sensitive data. Consent requires a freely given, specific, informed, and unambiguous affirmative act, and it doesn't include acceptance of broad terms, hovering over content, muting or pausing content, closing content, or agreement obtained through a dark pattern.

You must process personal data collected from a known child in accordance with COPPA. Compliance with COPPA's verifiable parental consent requirements for data collected online satisfies the corresponding TDPSA consent requirement.

Data Protection Assessments

You must conduct and document data protection assessments for processing that presents a heightened risk of harm to consumers. Chapter 541 specifically identifies targeted advertising, sale of personal data, certain profiling, and sensitive data processing.

An assessment must weigh the direct and indirect benefits of the processing against the potential risks to consumer rights after accounting for available safeguards. It must also consider deidentified data, reasonable consumer expectations, the context of the processing, and the relationship between the controller and consumer.

The Attorney General may request a relevant assessment through a civil investigative demand. An assessment submitted in response remains confidential and exempt from public inspection, and the disclosure doesn't waive the privilege between attorney and client or work product protection.

One assessment may address a comparable set of similar processing operations. An assessment prepared under another law may satisfy the TDPSA when it has a reasonably comparable scope and effect.

Processor Contracts

A controller and processor must use a written contract that governs processing performed for the controller. The contract must state the processing instructions, nature and purpose of processing, type of data, processing duration, and rights and obligations of both parties.

The contract must require confidentiality for each person who processes personal data. It must also address deletion or return of personal data after services end, compliance information, reasonable assessments, and written terms requiring each subcontractor to satisfy the processor's obligations for the data.

An amendment effective January 1, 2026 expanded Section 541.104. A processor must now assist the controller with security requirements for personal data collected, stored, and processed by an artificial intelligence system when applicable, as well as notification duties for a breach of the processor's system under Chapter 521.

Processor contracts should address vendor use of artificial intelligence systems on customer data. The contract should also require the information and cooperation needed for security compliance and breach notification.

Enforcement

The Texas Attorney General has exclusive authority to enforce the TDPSA. Chapter 541 provides no private right of action.

Before filing an enforcement action, the Attorney General must provide written notice that identifies the alleged violations and allow 30 days to cure them. The Attorney General can't file the action if the business cures within that period and provides the required written statement.

That statement must confirm the cure, state that the business notified each affected consumer when contact information was available, include supporting documentation, and identify any necessary policy changes made to prevent another violation. The cure provision has no expiration date.

A person that fails to cure or breaches its written statement may face a civil penalty of up to $7,500 for each violation. The Attorney General may also seek an injunction and recover reasonable attorney's fees and investigation expenses.

Texas has used the statute since it took effect. The Attorney General launched a privacy enforcement initiative in June 2024 and sued Allstate and Arity in January 2025 over alleged collection, use, and sale of precise geolocation and driving data.

The Attorney General also notified DeepSeek of alleged TDPSA violations in February 2025 and sent violation notices to TP-Link, Alibaba, CapCut, and other companies in May 2025. By July 2025, the office reported privacy investigations into more than 200 companies, dozens of TDPSA violation notices, and more than 2,000 consumer complaints submitted through its privacy portal.

How Texas Differs From California

California uses revenue, data volume, and sale or sharing revenue thresholds to define covered businesses. Its inflation adjusted annual gross revenue threshold has been $26.625 million since January 1, 2025.

Texas applies a different coverage test. A business that operates in Texas or serves Texas residents, processes or sells consumer personal data, and doesn't qualify for an entity or small business exemption may need a TDPSA compliance program.

The enforcement structures also differ. California permits enforcement by the California Attorney General and the California Privacy Protection Agency and provides a limited private claim for specified data breaches, while Texas assigns TDPSA enforcement exclusively to the Attorney General and provides a permanent 30 day cure period.

A privacy program designed only for California may omit Texas requirements. Common omissions include the SBA small business analysis, sensitive data sale notices, authorized agent signals, processor contracts, data protection assessments, and the appeal process.

What You Should Build

You should begin with a data map for Texas residents. List the personal data you collect, each purpose for collection, each source, each vendor recipient, and every use involving targeted advertising, sale, or sensitive data.

You should then test the small business exemption under the SBA size standard for your industry. If the exemption applies, you should determine whether you sell sensitive personal data because that sale requires prior consent.

Your privacy notice should match the actual data flow. It should explain the categories and purposes of processing, consumer and appeal rights, request methods, third party disclosures, targeted advertising, sales, and any sale of sensitive or biometric data.

Your systems should authenticate consumer requests and account for the 45 day response period, appeal procedures, and the 60 day appeal deadline. If you sell personal data or use it for targeted advertising, your website should also process qualifying opt out signals.

You should complete processor contracts, sensitive data consent procedures, data protection assessments, and deletion workflows before receiving an Attorney General notice. The statutory cure process requires supporting documentation, and an established compliance system produces that record.

This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.

Need advice tied to your business issue?

Share the issue. Get direct attorney review. Receive a concrete recommendation.

Submit an Inquiry