Texas Data Privacy and Security Act

Texas doesn't use the California model for consumer privacy coverage. The Texas Data Privacy and Security Act applies without a $26.625 million revenue trigger, a 100,000 consumer threshold, or a requirement that data sales drive half the business.

The TDPSA applies to a person that conducts business in Texas, or produces a product or service consumed by Texas residents, and processes or sells personal data. The main statutory limit is the small business exemption, tied to U.S. Small Business Administration size standards. Even that exemption has a sharp edge. A small business may not sell sensitive personal data without prior consumer consent.

California's thresholds don't control the Texas analysis. A company below California's thresholds may need a Texas privacy notice, consumer request process, opt out mechanism, processor contracts, data protection assessments, and consent workflow for sensitive data.

Who Counts as a Consumer

A consumer is a Texas resident acting in an individual or household context. Employees, job applicants, contractors, and business contacts acting in a commercial or employment context fall outside that definition.

That distinction affects the first compliance question. If your website collects customer account data, purchase history, geolocation data, analytics identifiers, advertising identifiers, or app usage data from Texas residents, you may be processing consumer personal data. If the same system stores employee payroll files, vendor contacts, or business prospect records, those records may require separate analysis under other laws, but they don't become TDPSA consumer data just because the person lives in Texas.

Who the TDPSA Covers

Coverage turns on three conditions. You conduct business in Texas or provide a product or service consumed by Texas residents. You process or sell personal data. You don't qualify as a small business under SBA standards, except for the sensitive data sale rule.

SBA size standards vary by industry. Some use employee headcount. Others use annual receipts. A software company, retailer, construction business, professional services firm, and manufacturer may face different size tests, so "small business" under the TDPSA isn't a casual label.

Several entity exemptions also apply. The TDPSA excludes state agencies and political subdivisions, financial institutions and data subject to the Gramm Leach Bliley Act, covered entities and business associates governed by HIPAA, nonprofit organizations, institutions of higher education, electric utilities, power generation companies, and retail electric providers. Separate data level exemptions cover categories such as FCRA, FERPA, the Driver's Privacy Protection Act, health records, employment data, emergency contact data, and personal data processed for personal or household activity.

Personal Data and Sensitive Data

Personal data means information linked or reasonably linkable to an identified or identifiable individual. That includes pseudonymous data when you use it with other information that can reasonably connect it to a person. Publicly available information and deidentified data fall outside the definition.

Sensitive data has higher stakes. It includes personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, citizenship, or immigration status. It also includes genetic data, biometric data processed to uniquely identify an individual, personal data collected from a known child, and precise geolocation data.

Texas defines precise geolocation data by radius. The term covers location information derived from technology, including GPS level latitude and longitude coordinates, that identifies an individual's location with precision and accuracy within 1,750 feet. That definition covers apps, vehicles, fitness tools, delivery platforms, retail beacons, connected devices, and SDKs that collect location data in the background.

Sale and Targeted Advertising

A sale means sharing, disclosing, or transferring personal data for monetary or other valuable consideration. That definition reaches arrangements without a conventional invoice when the data transfer provides value. It excludes processor disclosures, affiliate disclosures, disclosures needed to provide a product or service requested by the consumer, information the consumer intentionally made public without restricting the audience, and transfers as part of a merger or acquisition.

Targeted advertising means displaying an ad selected from personal data obtained from a consumer's activity over time and across nonaffiliated websites or apps to predict preferences or interests. It doesn't include ads based on activity within your own website or app, the context of a current search or visit, a response to the consumer's request, or processing used only to measure ad performance, reach, or frequency.

That line drives website design. First party analytics and contextual advertising may avoid opt out treatment. Cross site behavioral advertising, retargeting pixels, and ad network data sharing may require it.

Consumer Rights

Texas consumers can ask whether you process their personal data and access that data. They can request correction of inaccuracies, deletion of personal data provided by or obtained about them, and a portable copy of personal data they previously provided if the data is available in digital form.

Consumers can also opt out of processing for targeted advertising, sale of personal data, and profiling tied to decisions that produce legal or similarly significant effects. Those decisions include access to financial and lending services, housing, insurance, health care, education enrollment, employment opportunities, criminal justice, and basic necessities such as food and water.

Parents and legal guardians can exercise rights for a known child. A known child means a child under circumstances where the controller has actual knowledge of, or willfully disregards, the child's age.

Consumer Request Mechanics

You must establish at least two secure and reliable methods for consumer requests. Those methods should match how consumers normally interact with you, protect request communications, and let you authenticate the person making the request.

A controller that operates only online and has a direct relationship with the consumer only has to provide an email address for requests through the website mechanism. That exception is narrow. If your business operates offline, uses multiple consumer channels, or lacks a direct relationship with the consumer, an email only process may not be enough.

You can't require a consumer to create a new account to exercise TDPSA rights. You may require use of an existing account. If you decline a request, you must explain why and provide appeal instructions.

Responses are due within 45 days. You get one additional 45 day extension when reasonably necessary based on complexity or request volume, but you must notify the consumer within the first 45 days and give the reason. You must provide request responses free of charge at least twice each year per consumer, unless the request is manifestly unfounded, excessive, or repetitive.

Appeals

Chapter 541 requires an appeal process when you refuse to act on a consumer request. That appeal process must be conspicuously available and similar to the request process.

You must respond to an appeal in writing within 60 days after receiving it. If you deny the appeal, you must tell the consumer how to submit a complaint to the Texas Attorney General.

This means the privacy policy can't stop at listing rights. Your request intake, denial templates, appeal channel, response calendar, and complaint instructions all need to work together.

Universal Opt Out Signals

As of January 1, 2025, Texas consumers can use an authorized agent to opt out of targeted advertising and sale of personal data. The agent may use a browser setting, browser extension, device level setting, website link, or other technology that communicates the opt out.

Nothing in the TDPSA names Global Privacy Control as the only method. A signal has to meet the statutory conditions. It must communicate the request in a direct and unambiguous way, avoid unfairly disadvantaging another controller, avoid default settings that weren't affirmatively chosen by the consumer, and be consumer friendly and easy for the average consumer to use.

Controllers also have statutory limits on when they must honor an agent request. They must be able to verify the consumer's identity and the agent's authority with commercially reasonable effort. They may refuse when they can't verify Texas residency, lack the ability to process the request, or don't process similar requests under similar state laws.

Your site should be able to detect and process qualifying opt out signals, and your internal rule should describe what signals qualify, what verification you perform, and how the opt out maps to sale and targeted advertising.

Privacy Notice Requirements

A covered controller must provide a reasonably accessible privacy notice. The notice must identify categories of personal data processed, including sensitive data if applicable, and the purposes for processing.

It must explain how consumers can exercise TDPSA rights, how they can appeal a denied request, what request methods they can use, what categories of personal data you share with third parties, and what categories of third parties receive that data.

If you sell personal data or process personal data for targeted advertising, you must make a prominent disclosure and explain how consumers can opt out. If you sell sensitive personal data or biometric personal data, the TDPSA requires an additional statutory sale notice in the same location and manner as the privacy notice.

Controller Duties

You must limit personal data collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes. If your checkout process needs a shipping address, payment details, and email receipt address, it shouldn't collect precise geolocation, birthdate, and demographic attributes by default.

You must maintain reasonable administrative, technical, and physical security practices. Those practices should fit the volume and nature of the personal data you process.

You must obtain consent before processing sensitive data. Consent means a freely given, specific, informed, and unambiguous affirmative act. It doesn't include acceptance of broad terms of use, hovering over content, muting content, pausing content, closing content, or agreement obtained through dark patterns.

For personal data collected from a known child, you must process that data in accordance with COPPA.

Data Protection Assessments

You must conduct and document data protection assessments for processing that creates heightened consumer risk. The TDPSA specifically names targeted advertising, sale of personal data, certain profiling, sensitive data processing, and other processing that presents heightened risk of harm.

A proper assessment weighs benefits to the controller, consumer, other stakeholders, and the public against risks to consumer rights. It also considers safeguards, deidentified data, reasonable consumer expectations, processing context, and the relationship between controller and consumer.

The Attorney General can request assessments through a civil investigative demand. The assessment is confidential and exempt from public disclosure, and disclosure to the Attorney General doesn't waive attorney client privilege or work product protection. A comparable assessment prepared for another law can satisfy the TDPSA if the scope and effect are reasonably comparable.

Processor Contracts

A controller and processor need a written contract governing the processing. The contract must state processing instructions, the nature and purpose of processing, the type of data processed, the duration of processing, and the rights and obligations of both parties.

Processor duties need teeth. The contract must require confidentiality, deletion or return of personal data after services end unless retention is legally required, information needed to demonstrate compliance, cooperation with reasonable assessments, and written flow down terms for subcontractors.

Effective January 1, 2026, the Texas Responsible Artificial Intelligence Governance Act amended section 541.104 to require processors to assist controllers with security obligations for personal data collected, stored, and processed by an artificial intelligence system, if applicable, and with breach notification obligations under Chapter 521. If your vendors use artificial intelligence tools on customer data, the processor contract should address that use directly.

Enforcement

Only the Texas Attorney General can enforce the TDPSA. Consumers don't have a private lawsuit under Chapter 541.

Before filing an enforcement action, the Attorney General must send written notice identifying the alleged violations and give the business 30 days to cure. To preserve the cure, the business must fix the violation and provide a written statement saying it cured the violation, notified affected consumers if contact information was available, provided supporting documentation, and changed internal policies if needed to prevent the issue from recurring.

That cure period doesn't sunset. Texas made it permanent.

If the business fails to cure or breaches the written cure statement, the Attorney General may seek up to $7,500 per violation, injunctive relief, attorney fees, and investigation costs.

Texas enforcement is active. The Attorney General launched a data privacy and security initiative on June 4, 2024. In January 2025, the Attorney General sued Allstate and Arity over alleged collection, use, and sale of precise geolocation and driving behavior data, calling it the first state attorney general enforcement action under a comprehensive state privacy law. In February 2025, the Attorney General announced an investigation into DeepSeek and notified the company of alleged TDPSA violations. In May 2025, the Attorney General announced TDPSA notices to TP Link, Alibaba, CapCut, and other Chinese and CCP affiliated companies. As of the date of this article, those public materials show ongoing enforcement activity and contested litigation rather than final merits rulings under the TDPSA.

How Texas Differs From California

California uses threshold tests. The CCPA applies to covered for profit businesses that meet revenue, data volume, or sale and sharing revenue thresholds, including the inflation adjusted $26.625 million annual gross revenue threshold effective January 1, 2025.

Texas uses a broader entry point. If you conduct business in Texas, process or sell consumer personal data, and don't qualify for the small business exemption or another statutory exemption, you may need a TDPSA compliance program.

Enforcement also differs. California has the California Attorney General, the California Privacy Protection Agency, and a limited private right of action for certain data breaches. Texas puts TDPSA enforcement in the Attorney General's office and keeps the 30 day cure period.

A privacy policy built only around California often misses Texas. The most common Texas misses are the SBA small business analysis, sensitive data sale notices, universal opt out signal handling, processor contracts, data protection assessments, and appeal workflow.

What You Should Build

You should start with a data map tied to Texas residents. List the personal data you collect, why you collect it, where it comes from, which vendors receive it, whether it supports targeted advertising, whether it's sold, and whether any category qualifies as sensitive data.

Then test the small business exemption against the SBA size standard for your industry. If the exemption applies, you should confirm whether you sell sensitive personal data because that sale needs prior consent.

Your privacy notice should match the real data flow. It should explain categories, purposes, consumer rights, appeal rights, request methods, third party sharing, targeted advertising, sale, sensitive data, and biometric data sales if applicable.

Your site should accept consumer requests, verify identity, track 45 day and 60 day deadlines, process appeals, and send consumers to the Attorney General complaint process when an appeal is denied. If you sell personal data or process personal data for targeted advertising, your site should also process qualifying universal opt out signals.

Processor contracts, sensitive data consent, data protection assessments, and deletion workflows should be finished before the Attorney General sends a notice letter. The TDPSA provides 30 days to cure, but the cure statement requires evidence. Evidence is easier to produce when the system already exists.

This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.

Need advice tied to your business issue?

Share the issue. Get direct attorney review. Receive a concrete recommendation.

Submit an Inquiry