Compliance

Texas Data Privacy and Security Act: What Businesses Need to Know

In brief

The Texas Data Privacy and Security Act (TDPSA) took effect July 1, 2024. It covers businesses that operate in Texas, process personal data, and are not SBA-defined small businesses. The law grants consumers six privacy rights, requires opt-in consent for sensitive data, and lets the Texas Attorney General fine violators up to $7,500 per violation.

The Texas Data Privacy and Security Act is now the rulebook for how any business handles the personal data of Texans, and it carries real teeth. Texas moved from passing the law to suing over it in less than a year, filing the first enforcement action of any state comprehensive privacy law in January 2025. This guide explains what the TDPSA requires, whether your business is covered, the rights it gives your customers, and the concrete steps that keep you off the Attorney General's list. Every figure below comes from the Texas Attorney General, the Texas Department of Information Resources, and named federal sources, with links to each.

What is the Texas Data Privacy and Security Act?

The TDPSA is a comprehensive consumer privacy law that regulates how businesses collect, use, process, and sell the personal data of Texas residents. Signed as House Bill 4 and effective July 1, 2024, it gives Texans a defined set of rights over their data and puts matching obligations on the companies that hold it. The requirement to honor universal opt-out signals, such as the Global Privacy Control browser setting, followed on January 1, 2025.

The law sits alongside similar statutes in a growing group of states, but Texas wrote it with two features that make it broader than most. It sets no minimum threshold for the number of consumers whose data you process, and it defines who is exempt by business size rather than data volume. That combination pulls far more Texas companies into scope than a California-style law would, which is exactly why understanding applicability comes first.

Does the TDPSA apply to your business?

The TDPSA applies to your business if it meets all three of the following conditions. Most state privacy laws add a numeric trigger, such as processing data on 100,000 consumers, but Texas deliberately left that out, so a small volume of data does not put you in the clear.

  • You conduct business in Texas or produce products or services consumed by Texas residents.
  • You process or engage in the sale of personal data, which covers almost any customer, lead, or employee record tied to an identifiable person.
  • You are not a small business as defined by the U.S. Small Business Administration, generally an independent for-profit entity with fewer than 500 employees.

The small business exemption is where most owners stop reading, and that is a mistake. The carve-out is not total. Even a business that qualifies as an SBA small business must obtain a consumer's consent before it sells sensitive personal data, so the exemption never lets you trade in health, geolocation, or biometric data quietly. If you sit near the 500-employee line, treat compliance as the safer default, because the SBA definition varies by industry and the Attorney General reads it strictly.

What rights does the TDPSA give Texas consumers?

The TDPSA grants Texas consumers six rights over their personal data, and your business has to build a process to honor each one. A consumer submits a request, and you have 45 days to respond, with one 45-day extension allowed when reasonably necessary. The six rights are listed below.

  • Access to confirm whether you process their data and to obtain a copy of it.
  • Correction of inaccurate personal data you hold about them.
  • Deletion of personal data you have collected or obtained.
  • Portability to receive their data in a usable, portable format.
  • Non-discrimination so you cannot punish them for exercising a right.
  • Opt-out of the sale of their data, targeted advertising, and profiling that produces legal or similarly significant effects.

You also have to give consumers a way to appeal a refused request and respond to that appeal within 60 days. The practical takeaway is that these rights are operational, not theoretical. Someone in your business has to receive the request, verify the person, pull the data across every system that holds it, and act within the deadline. That workflow is the part most companies have never built.

What the TDPSA requires businesses to do

Beyond honoring consumer requests, the TDPSA imposes duties on how you handle data day to day. These are the obligations the Attorney General checks first, because they are visible from the outside without an investigation.

  • Publish a clear privacy notice that lists the categories of data you process, why you process them, the categories you share, and how consumers exercise their rights.
  • Get opt-in consent for sensitive data before you process it, and disclose plainly if you sell it.
  • Recognize universal opt-out signals, a requirement live since January 1, 2025, so a consumer's browser-level Global Privacy Control setting counts as a valid opt-out.
  • Sign data processing agreements with every vendor that processes data on your behalf, binding them to the same duties.
  • Run data protection assessments for higher-risk processing, including targeted advertising, the sale of data, certain profiling, and all processing of sensitive data.
  • Practice data minimization and security, limiting collection to what is adequate and relevant and protecting it with reasonable administrative, technical, and physical safeguards.

That last duty is where privacy law and cybersecurity meet. The TDPSA requires reasonable data security practices, so a breach caused by weak controls can become a privacy violation, not just an IT incident. Meeting the standard means the same fundamentals a good provider delivers through its cybersecurity services, including access controls, encryption, monitoring, and a tested incident response plan.

Penalties and enforcement: what happens if you get it wrong

The Texas Attorney General has exclusive authority to enforce the TDPSA, and there is no private right of action, so consumers cannot sue you directly. What they can do is file a complaint, and that complaint can start an investigation. Before filing suit, the Attorney General must send written notice of the violation and give your business 30 days to cure it. Fix the problem and document the fix inside that window, and no penalty follows. Miss it, and the numbers climb fast.

$7,500 Maximum civil penalty per violation under the TDPSA, on top of injunctive relief, attorney fees, and investigative costs. The Texas Attorney General enforces the law exclusively, after a written notice and a 30-day cure period. Texas Office of the Attorney General, 2025

The word "per violation" is what makes the penalty serious. A single flawed practice, applied across thousands of consumer records, multiplies the exposure well beyond one $7,500 line. Texas made the point in its first case. On January 13, 2025, the Attorney General sued Allstate and its analytics subsidiary Arity, alleging they collected and sold the driving and geolocation data of Texans without consent, part of a database drawn from more than 45 million consumers nationwide. It was the first enforcement action ever brought under a state comprehensive privacy law.

45M+ Consumers whose driving and location data was allegedly collected and sold without consent in the Texas Attorney General's first TDPSA lawsuit, filed against Allstate and Arity in January 2025, the first enforcement of any state comprehensive privacy law. Texas Office of the Attorney General, 2025

Why the stakes are higher than the fine

The $7,500 penalty is the smallest number in this story. The larger cost is the breach the law is trying to prevent, and the data on that is unambiguous. IBM's 2025 Cost of a Data Breach Report put the United States average breach at $10.22 million, the highest of any country, even as the global average fell to $4.44 million. A privacy violation and a data breach often ride together, because the weak controls that expose data also fail the TDPSA's reasonable-security duty.

$10.22M Average cost of a data breach for United States organizations in 2025, the highest of any country and an all-time high, while the global average was $4.44 million. IBM Cost of a Data Breach Report, 2025

The threat volume driving those costs is climbing, and Texas is squarely in it. The FBI's Internet Crime Complaint Center logged 859,532 complaints in 2024 with reported losses topping $16.6 billion, a 33 percent jump over 2023, and Texas ranked among the top three states for complaints filed. For a Texas business, the takeaway is that TDPSA compliance and cybersecurity are the same project. The controls that satisfy the Attorney General are the controls that keep you out of the breach statistics.

$16.6B Reported losses to internet crime in the United States in 2024, up 33 percent from 2023 across 859,532 complaints, with Texas among the top three states by complaint volume. FBI Internet Crime Report, 2024

A TDPSA compliance checklist for Texas businesses

Turn the law into a short list of actions and work it top to bottom. Each step below starts with a verb so you can assign it and track it. None of it requires a law firm on retainer, but all of it requires someone who owns the work.

  • Confirm whether you are covered, using the three applicability tests, and remember the sensitive-data consent rule applies even to exempt small businesses.
  • Map the personal data you hold, where it lives, why you collect it, and who you share it with, since you cannot protect or produce data you have not inventoried.
  • Publish a compliant privacy notice that names your data categories, purposes, sharing, and the exact process for exercising rights.
  • Build a request workflow that verifies the consumer, answers within 45 days, and offers an appeal path.
  • Configure your website to detect and honor universal opt-out signals for sale and targeted advertising.
  • Collect opt-in consent before processing any sensitive data, and record that consent.
  • Sign data processing agreements with vendors and run data protection assessments for higher-risk processing.
  • Harden your security so the reasonable-safeguards duty is met, then rehearse an incident response plan.

Work this list once, then review it whenever you add a new tool, vendor, or data source, because scope creeps quietly. A business that can show a data map, a live privacy notice, a working request process, and documented security controls has answered most of what the Attorney General would ask.

Which businesses and data are exempt from the TDPSA?

Several categories of business and data sit outside the TDPSA even when they touch Texas residents. The exemptions fall into two groups, entity-level and data-level, and knowing which one covers you saves the cost of building a program you do not need. Exempt entities include state agencies and political subdivisions, financial institutions governed by the Gramm-Leach-Bliley Act, covered entities and business associates under HIPAA and the HITECH Act, nonprofit organizations, institutions of higher education, and electric utilities and power generation companies. Exempt data includes protected health information already covered by HIPAA, consumer credit information handled under the Fair Credit Reporting Act, education records under FERPA, and driver data under the Driver's Privacy Protection Act.

One carve-out catches many owners by surprise. The TDPSA does not cover personal data processed in an employment or business-to-business context, because it excludes any individual acting in a commercial or employment context. Job applicant, employee, and independent contractor records fall outside the law, as does data tied to a business contact acting for their company. The exemption is read narrowly, so information that leaves that context and reaches a Texas resident as a consumer still counts. When in doubt, treat the data as covered and document why an exemption applies.

Controller or processor: what the TDPSA asks of each

The TDPSA splits every covered business into one of two roles, and your role sets your duties. A controller decides why and how personal data is processed. A processor handles that data on a controller's behalf and under its instructions. Most businesses act as a controller for their own customer data and as a processor when they handle data for a client, so many companies wear both hats at once.

A written contract binds the two roles together, and the TDPSA lists what that contract must contain. A data processing agreement sets the processing instructions, nature, and purpose, names the categories of data and the duration, and imposes a duty of confidentiality on everyone who touches the data. It requires the processor to delete or return the data when the work ends, to cooperate with the controller's assessments, and to bind any subcontractor to the same terms. Controllers also run and document a data protection assessment before higher-risk processing, including targeted advertising, the sale of data, certain profiling, and all processing of sensitive data.

What a TDPSA privacy notice and sale disclosures must say

A TDPSA privacy notice has to be clear, accessible, and specific, so generic boilerplate does not meet the standard. The notice lists the categories of personal data you process, your purpose for processing them, the categories of data you share, the categories of third parties you share with, and the exact methods a consumer uses to exercise their rights and appeal a refusal.

Selling certain data triggers extra, word-for-word disclosures. A business that sells sensitive personal data must post the statement "NOTICE: We may sell your sensitive personal data" in the same location and manner as its privacy notice. A business that sells biometric data must post "NOTICE: We may sell your biometric personal data" the same way. Any controller that sells personal data to third parties or processes it for targeted advertising also has to disclose that clearly and give consumers a plain way to opt out. These notices are visible from outside without an investigation, so a missing line is an easy target for a complaint to the Attorney General.

How the TDPSA compares to California and other state privacy laws

The TDPSA follows the Virginia model more than the California one, yet its scope reaches further than either. Texas was the tenth state to pass a comprehensive privacy law, and it borrowed the structure of the Virginia Consumer Data Protection Act. Where it breaks from the pack is applicability. Most state laws switch on only above a revenue or data-volume line, and Texas set neither.

That single choice pulls far more businesses into scope. California's CCPA and CPRA apply once a business clears $25 million in annual revenue or hits other data thresholds, and Florida's law targets companies above $1 billion in revenue. Texas ties coverage to business size through the U.S. Small Business Administration definition instead, so a company with modest revenue and a small database can still be fully covered. Texas also swapped the phrase "targeted to" for "consumed by," a broader trigger meant to stop out-of-state sellers from arguing the law does not reach them.

$25M Annual revenue that triggers California's CCPA and CPRA. The TDPSA sets no revenue or data-volume threshold at all, so far smaller Texas businesses fall within its scope. California Office of the Attorney General, CCPA

How Tuminto helps Texas businesses comply

Most of the TDPSA is a technology problem wearing a legal label. Knowing your rights and duties is one thing; producing a data map, honoring opt-out signals in code, verifying request identities, and proving reasonable security is where compliance actually lives. Tuminto handles that layer for Texas businesses by combining managed IT with the security controls the law expects, so privacy obligations map to systems you already run rather than a binder nobody opens. We help you inventory data across your environment, stand up the safeguards that satisfy the reasonable-security standard, and keep the whole thing documented so a complaint never becomes a crisis. Compliance is not a one-time cleanup, it is a standard you hold, and holding it is easier with one accountable partner.

Related reading

FAQ

When did the Texas Data Privacy and Security Act take effect?

The Texas Data Privacy and Security Act took effect on July 1, 2024. The requirement to recognize universal opt-out preference signals, such as the Global Privacy Control, followed on January 1, 2025. The law regulates how businesses collect, use, process, and sell the personal data of Texas residents.

Who has to comply with the TDPSA?

The TDPSA applies to any person or business that conducts business in Texas or produces products or services consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration. Unlike most state privacy laws, the TDPSA sets no minimum threshold for the number of consumers whose data you process.

Does the TDPSA apply to small businesses?

Most small businesses are exempt, because the TDPSA excludes businesses that meet the U.S. Small Business Administration definition, generally an independent for-profit entity with fewer than 500 employees. The exemption is not total. A small business must still obtain a consumer's consent before it sells sensitive personal data.

What are the penalties for violating the TDPSA?

The Texas Attorney General can seek civil penalties of up to $7,500 for each violation of the TDPSA, plus injunctive relief, attorney fees, and investigative costs. Before suing, the Attorney General must send written notice and give the business 30 days to cure the violation. That cure period does not expire.

Is there a private right of action under the TDPSA?

No. The TDPSA gives the Texas Attorney General exclusive authority to enforce the law. Consumers cannot sue a business directly for a violation, but they can file a complaint with the Attorney General's office, which can trigger an investigation and, if the violation is not cured, a lawsuit.

What is sensitive data under the TDPSA?

Sensitive data under the TDPSA includes data revealing racial or ethnic origin, religious beliefs, health conditions, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify a person, precise geolocation, and personal data of a known child. A business must get opt-in consent before processing any of these categories.

Does the TDPSA apply to employee or business-to-business data?

No. The TDPSA excludes personal data tied to an individual acting in a commercial or employment context, so job applicant, employee, and independent contractor records and most business-to-business contact data fall outside the law. The Act protects Texas residents acting in an individual or household context, not people acting on behalf of a business.

What is the difference between a controller and a processor under the TDPSA?

A controller decides why and how personal data is processed, while a processor handles that data on the controller's behalf and under its instructions. The TDPSA requires a written data processing agreement between them that sets confidentiality duties, data-deletion terms, cooperation with assessments, and the same obligations for any subcontractor.

What notice must a business post if it sells sensitive data under the TDPSA?

A business that sells sensitive personal data must post the exact statement "NOTICE: We may sell your sensitive personal data" in the same location and manner as its privacy notice. A business that sells biometric data must post "NOTICE: We may sell your biometric personal data" the same way, and it must give consumers a clear way to opt out.

How is the TDPSA different from California's CCPA?

The TDPSA is modeled on Virginia's privacy law, not California's, and unlike the CCPA it sets no revenue or data-volume threshold. California's CCPA applies once a business reaches $25 million in annual revenue or other data thresholds, while Texas ties coverage to the U.S. Small Business Administration small-business definition, pulling far smaller companies into scope.

Privacy and security, one accountable team

Get a free TDPSA readiness assessment

We will map your data, test your safeguards, and show you exactly what the Texas Data Privacy and Security Act expects, with no obligation.

Book Your Assessment