The Texas Data Privacy and Security Act (TDPSA) took effect July 1, 2024. It covers businesses that operate in Texas, process personal data, and are not SBA-defined small businesses. The law grants consumers six privacy rights, requires opt-in consent for sensitive data, and lets the Texas Attorney General fine violators up to $7,500 per violation.
The Texas Data Privacy and Security Act is now the rulebook for how any business handles the personal data of Texans, and it carries real teeth. Texas moved from passing the law to suing over it in less than a year, filing the first enforcement action of any state comprehensive privacy law in January 2025. This guide explains what the TDPSA requires, whether your business is covered, the rights it gives your customers, and the concrete steps that keep you off the Attorney General's list. Every figure below comes from the Texas Attorney General, the Texas Department of Information Resources, and named federal sources, with links to each.
The TDPSA is a comprehensive consumer privacy law that regulates how businesses collect, use, process, and sell the personal data of Texas residents. Signed as House Bill 4 and effective July 1, 2024, it gives Texans a defined set of rights over their data and puts matching obligations on the companies that hold it. The requirement to honor universal opt-out signals, such as the Global Privacy Control browser setting, followed on January 1, 2025.
The law sits alongside similar statutes in a growing group of states, but Texas wrote it with two features that make it broader than most. It sets no minimum threshold for the number of consumers whose data you process, and it defines who is exempt by business size rather than data volume. That combination pulls far more Texas companies into scope than a California-style law would, which is exactly why understanding applicability comes first.
The TDPSA applies to your business if it meets all three of the following conditions. Most state privacy laws add a numeric trigger, such as processing data on 100,000 consumers, but Texas deliberately left that out, so a small volume of data does not put you in the clear.
The small business exemption is where most owners stop reading, and that is a mistake. The carve-out is not total. Even a business that qualifies as an SBA small business must obtain a consumer's consent before it sells sensitive personal data, so the exemption never lets you trade in health, geolocation, or biometric data quietly. If you sit near the 500-employee line, treat compliance as the safer default, because the SBA definition varies by industry and the Attorney General reads it strictly.
The TDPSA grants Texas consumers six rights over their personal data, and your business has to build a process to honor each one. A consumer submits a request, and you have 45 days to respond, with one 45-day extension allowed when reasonably necessary. The six rights are listed below.
You also have to give consumers a way to appeal a refused request and respond to that appeal within 60 days. The practical takeaway is that these rights are operational, not theoretical. Someone in your business has to receive the request, verify the person, pull the data across every system that holds it, and act within the deadline. That workflow is the part most companies have never built.
Beyond honoring consumer requests, the TDPSA imposes duties on how you handle data day to day. These are the obligations the Attorney General checks first, because they are visible from the outside without an investigation.
That last duty is where privacy law and cybersecurity meet. The TDPSA requires reasonable data security practices, so a breach caused by weak controls can become a privacy violation, not just an IT incident. Meeting the standard means the same fundamentals a good provider delivers through its cybersecurity services, including access controls, encryption, monitoring, and a tested incident response plan.
The Texas Attorney General has exclusive authority to enforce the TDPSA, and there is no private right of action, so consumers cannot sue you directly. What they can do is file a complaint, and that complaint can start an investigation. Before filing suit, the Attorney General must send written notice of the violation and give your business 30 days to cure it. Fix the problem and document the fix inside that window, and no penalty follows. Miss it, and the numbers climb fast.
The word "per violation" is what makes the penalty serious. A single flawed practice, applied across thousands of consumer records, multiplies the exposure well beyond one $7,500 line. Texas made the point in its first case. On January 13, 2025, the Attorney General sued Allstate and its analytics subsidiary Arity, alleging they collected and sold the driving and geolocation data of Texans without consent, part of a database drawn from more than 45 million consumers nationwide. It was the first enforcement action ever brought under a state comprehensive privacy law.
The $7,500 penalty is the smallest number in this story. The larger cost is the breach the law is trying to prevent, and the data on that is unambiguous. IBM's 2025 Cost of a Data Breach Report put the United States average breach at $10.22 million, the highest of any country, even as the global average fell to $4.44 million. A privacy violation and a data breach often ride together, because the weak controls that expose data also fail the TDPSA's reasonable-security duty.
The threat volume driving those costs is climbing, and Texas is squarely in it. The FBI's Internet Crime Complaint Center logged 859,532 complaints in 2024 with reported losses topping $16.6 billion, a 33 percent jump over 2023, and Texas ranked among the top three states for complaints filed. For a Texas business, the takeaway is that TDPSA compliance and cybersecurity are the same project. The controls that satisfy the Attorney General are the controls that keep you out of the breach statistics.
Turn the law into a short list of actions and work it top to bottom. Each step below starts with a verb so you can assign it and track it. None of it requires a law firm on retainer, but all of it requires someone who owns the work.
Work this list once, then review it whenever you add a new tool, vendor, or data source, because scope creeps quietly. A business that can show a data map, a live privacy notice, a working request process, and documented security controls has answered most of what the Attorney General would ask.
Several categories of business and data sit outside the TDPSA even when they touch Texas residents. The exemptions fall into two groups, entity-level and data-level, and knowing which one covers you saves the cost of building a program you do not need. Exempt entities include state agencies and political subdivisions, financial institutions governed by the Gramm-Leach-Bliley Act, covered entities and business associates under HIPAA and the HITECH Act, nonprofit organizations, institutions of higher education, and electric utilities and power generation companies. Exempt data includes protected health information already covered by HIPAA, consumer credit information handled under the Fair Credit Reporting Act, education records under FERPA, and driver data under the Driver's Privacy Protection Act.
One carve-out catches many owners by surprise. The TDPSA does not cover personal data processed in an employment or business-to-business context, because it excludes any individual acting in a commercial or employment context. Job applicant, employee, and independent contractor records fall outside the law, as does data tied to a business contact acting for their company. The exemption is read narrowly, so information that leaves that context and reaches a Texas resident as a consumer still counts. When in doubt, treat the data as covered and document why an exemption applies.
The TDPSA splits every covered business into one of two roles, and your role sets your duties. A controller decides why and how personal data is processed. A processor handles that data on a controller's behalf and under its instructions. Most businesses act as a controller for their own customer data and as a processor when they handle data for a client, so many companies wear both hats at once.
A written contract binds the two roles together, and the TDPSA lists what that contract must contain. A data processing agreement sets the processing instructions, nature, and purpose, names the categories of data and the duration, and imposes a duty of confidentiality on everyone who touches the data. It requires the processor to delete or return the data when the work ends, to cooperate with the controller's assessments, and to bind any subcontractor to the same terms. Controllers also run and document a data protection assessment before higher-risk processing, including targeted advertising, the sale of data, certain profiling, and all processing of sensitive data.
A TDPSA privacy notice has to be clear, accessible, and specific, so generic boilerplate does not meet the standard. The notice lists the categories of personal data you process, your purpose for processing them, the categories of data you share, the categories of third parties you share with, and the exact methods a consumer uses to exercise their rights and appeal a refusal.
Selling certain data triggers extra, word-for-word disclosures. A business that sells sensitive personal data must post the statement "NOTICE: We may sell your sensitive personal data" in the same location and manner as its privacy notice. A business that sells biometric data must post "NOTICE: We may sell your biometric personal data" the same way. Any controller that sells personal data to third parties or processes it for targeted advertising also has to disclose that clearly and give consumers a plain way to opt out. These notices are visible from outside without an investigation, so a missing line is an easy target for a complaint to the Attorney General.
The TDPSA follows the Virginia model more than the California one, yet its scope reaches further than either. Texas was the tenth state to pass a comprehensive privacy law, and it borrowed the structure of the Virginia Consumer Data Protection Act. Where it breaks from the pack is applicability. Most state laws switch on only above a revenue or data-volume line, and Texas set neither.
That single choice pulls far more businesses into scope. California's CCPA and CPRA apply once a business clears $25 million in annual revenue or hits other data thresholds, and Florida's law targets companies above $1 billion in revenue. Texas ties coverage to business size through the U.S. Small Business Administration definition instead, so a company with modest revenue and a small database can still be fully covered. Texas also swapped the phrase "targeted to" for "consumed by," a broader trigger meant to stop out-of-state sellers from arguing the law does not reach them.
Most of the TDPSA is a technology problem wearing a legal label. Knowing your rights and duties is one thing; producing a data map, honoring opt-out signals in code, verifying request identities, and proving reasonable security is where compliance actually lives. Tuminto handles that layer for Texas businesses by combining managed IT with the security controls the law expects, so privacy obligations map to systems you already run rather than a binder nobody opens. We help you inventory data across your environment, stand up the safeguards that satisfy the reasonable-security standard, and keep the whole thing documented so a complaint never becomes a crisis. Compliance is not a one-time cleanup, it is a standard you hold, and holding it is easier with one accountable partner.
The Texas Data Privacy and Security Act took effect on July 1, 2024. The requirement to recognize universal opt-out preference signals, such as the Global Privacy Control, followed on January 1, 2025. The law regulates how businesses collect, use, process, and sell the personal data of Texas residents.
The TDPSA applies to any person or business that conducts business in Texas or produces products or services consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration. Unlike most state privacy laws, the TDPSA sets no minimum threshold for the number of consumers whose data you process.
Most small businesses are exempt, because the TDPSA excludes businesses that meet the U.S. Small Business Administration definition, generally an independent for-profit entity with fewer than 500 employees. The exemption is not total. A small business must still obtain a consumer's consent before it sells sensitive personal data.
The Texas Attorney General can seek civil penalties of up to $7,500 for each violation of the TDPSA, plus injunctive relief, attorney fees, and investigative costs. Before suing, the Attorney General must send written notice and give the business 30 days to cure the violation. That cure period does not expire.
No. The TDPSA gives the Texas Attorney General exclusive authority to enforce the law. Consumers cannot sue a business directly for a violation, but they can file a complaint with the Attorney General's office, which can trigger an investigation and, if the violation is not cured, a lawsuit.
Sensitive data under the TDPSA includes data revealing racial or ethnic origin, religious beliefs, health conditions, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify a person, precise geolocation, and personal data of a known child. A business must get opt-in consent before processing any of these categories.
No. The TDPSA excludes personal data tied to an individual acting in a commercial or employment context, so job applicant, employee, and independent contractor records and most business-to-business contact data fall outside the law. The Act protects Texas residents acting in an individual or household context, not people acting on behalf of a business.
A controller decides why and how personal data is processed, while a processor handles that data on the controller's behalf and under its instructions. The TDPSA requires a written data processing agreement between them that sets confidentiality duties, data-deletion terms, cooperation with assessments, and the same obligations for any subcontractor.
A business that sells sensitive personal data must post the exact statement "NOTICE: We may sell your sensitive personal data" in the same location and manner as its privacy notice. A business that sells biometric data must post "NOTICE: We may sell your biometric personal data" the same way, and it must give consumers a clear way to opt out.
The TDPSA is modeled on Virginia's privacy law, not California's, and unlike the CCPA it sets no revenue or data-volume threshold. California's CCPA applies once a business reaches $25 million in annual revenue or other data thresholds, while Texas ties coverage to the U.S. Small Business Administration small-business definition, pulling far smaller companies into scope.
Privacy and security, one accountable team
We will map your data, test your safeguards, and show you exactly what the Texas Data Privacy and Security Act expects, with no obligation.
Book Your Assessment