All Blog Posts

Texas Data Privacy and Security Act (TDPSA): U.S. Business Overview

Close
Read time
9 mins
Updated
Sep 1, 2026
Share
  • The TDPSA has applied to covered businesses in Texas since July 1, 2024.
  • It covers any business operating in Texas or serving Texas residents, unless the business qualifies as a small business under SBA size standards.
  • Consumers can access, correct, delete, and port their personal data, and opt out of its sale, targeted advertising, or profiling.
  • Businesses have recognized universal opt-out signals such as Global Privacy Control since January 1, 2025.
  • A 2026 amendment (TRAIGA) added a new duty for processors handling personal data through AI systems.
  • Only the Texas Attorney General can enforce the TDPSA, with a 30-day cure period and civil penalties of up to $7,500 per violation.

If your business has customers in Texas, even a handful, you're probably already inside the reach of the Texas Data Privacy and Security Act. Unlike most state privacy laws, the TDPSA doesn't care how much revenue you make or how much data you handle. It cares whether you're doing business with Texans at all.

Here's what the law requires, what changed in 2026, and what happens if you get it wrong.

What Is the TDPSA?

The TDPSA is a state law that gives Texas residents control over their personal data. It sets rules for how businesses collect, use, and sell that data, and it applies whether or not your company is based in Texas.

If a Texan can buy from your website, sign up for your app, or interact with your business online, the law likely reaches you. Like most U.S. state privacy laws, it only protects people acting in their personal capacity, not employees or business contacts acting on the job. The law calls these protected individuals "consumers."

Texas uses an opt-out model, which is the norm across U.S. state privacy laws. That means you generally don't need permission before collecting or processing someone's data. What you do need is transparency: you have to tell people what you're collecting, why, who else might get access to it, and how they can opt out.

Who Actually Has to Comply?

You're covered by the TDPSA if all three of these apply:

  • You do business in Texas, or your product or service reaches Texas residents
  • You process personal data, or sell it
  • You don't qualify as a small business under U.S. Small Business Administration standards (generally, an independent for-profit business with fewer than 500 employees)

There's no revenue threshold and no data-volume threshold here. That's unusual. Most other state privacy laws exempt smaller companies based on how much money they make or how many residents' data they touch. Texas doesn't, so size, not revenue, is what determines whether you're in scope.

Who Is Exempt

A handful of entity types sit outside the law entirely:

  • State government agencies
  • Financial institutions covered by the Gramm-Leach-Bliley Act (GLBA)
  • Entities covered by HIPAA and related health data laws
  • Nonprofits
  • Higher education institutions
  • Electric utilities

Certain categories of data are also carved out, including healthcare records, research data, and information already governed by federal laws like HIPAA, FCRA, FERPA, and the Driver's Privacy Protection Act.

The Terms You Need to Know

A few definitions do a lot of work in this law. Here's what they mean in plain terms.

Personal Data

The TDPSA defines personal data as "any information, including sensitive data, that is linked or reasonably linkable to an identified or identifiable individual." Pseudonymous data counts too, if it can be tied back to a person using other information you hold.

Public information and properly de-identified data don't count. Unlike some other state laws, the TDPSA doesn't spell out examples, but in practice this usually means names, phone numbers, emails, Social Security numbers, and driver's license numbers.

Sensitive Data

This is personal data that could cause real harm if it got out. It includes information revealing:

  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health diagnoses
  • Sexuality
  • Citizenship or immigration status
  • Genetic or biometric data used to identify someone
  • Data from a known child under 13
  • Precise geolocation

Consent under the TDPSA means a "clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement." That's GDPR-influenced language, and it comes with real limits. Accepting a broad terms-of-use page doesn't count as consent. Neither does hovering, muting, or closing a pop-up, or agreeing to something through a dark pattern.

One notable gap: Texas doesn't require you to offer a way to withdraw consent once it's given.

Controller and Processor

A controller decides why and how personal data gets processed. That's the party carrying the legal weight, as protecting the data and honoring consumer rights sits with them.

A processor handles data on the controller's behalf, following instructions set out in a contract. If something goes wrong with how a processor handles data, the controller is still on the hook. That's why the contract terms matter.

Sale, and What Doesn't Count

"Sale" means sharing, disclosing, or transferring personal data for money or other value. It does not include disclosures:

  • To a processor doing work for the controller
  • To fulfill a product or service the consumer asked for
  • To an affiliate
  • Of data the consumer already made public through mass media
  • As part of a merger or acquisition

Targeted Advertising, and What Doesn't Count

Targeted advertising means using someone's activity across unrelated sites and apps to predict what they'll want and show them an ad for it. It doesn't include ads based on your own site's activity, ads tied to a current search, ads someone specifically asked for, or measuring ad performance.

What Rights Do Texans Have?

Texas residents get five core rights under the law:

  • Access: confirm whether a business is processing their data, and see it
  • Correction: fix inaccurate or outdated data
  • Deletion: request removal of their data, with some exceptions
  • Portability: get a copy of their data in a usable, transferable format
  • Opt-out: stop the sale of their data, targeted advertising, or profiling with legal or similarly significant effects

Parents can exercise these rights for their kids. One thing the TDPSA doesn't give consumers, unlike the California Consumer Privacy Act (CCPA), is the right to sue directly.

What You're Required to Do as a Business

The TDPSA places a set of concrete obligations on controllers, covering everything from how you respond to a consumer request to how you write your privacy notice. Here's what each one looks like in practice.

Handle Consumer Requests Properly

You need to tell consumers what their rights are, how to use them, and how to appeal if you say no. You also need at least two accessible ways for people to submit these requests. You can ask them to log in to verify identity, but you can't force them to create a new account just to exercise a right.

You have 45 days to respond, with one 45-day extension available if you notify the consumer before the first period ends. You can decline a request if you can't reasonably verify who's asking. And you have to handle up to two of these requests per consumer per year for free.

If you deny a request, consumers can appeal, and you have 60 days to respond to that appeal.

Limit What You Collect

You can only collect what's "adequate, relevant, and reasonably necessary" for the purpose you disclosed. Collecting extra data "just in case" isn't compliant.

Keep Data Secure

You need administrative, technical, and physical safeguards appropriate to the volume and sensitivity of the data you handle. There's no one-size-fits-all standard here. It scales with your risk.

Assess Higher-Risk Processing

You're required to document a data protection assessment when you process data for targeted advertising, sale, certain kinds of profiling, sensitive categories, or anything that presents heightened risk. The Attorney General can ask to see these during an investigation.

The opt-out model covers most processing, but sensitive data is the exception. You need consent before handling it. Children's data under 13 gets extra protection: the law treats it all as sensitive and requires parental consent before you process it, aligning with COPPA.

Don't Penalize People for Exercising Their Rights

You can't charge someone more, give them lesser service, or deny them access because they opted out or asked you to delete their data. A site not working fully because someone declined non-essential cookies isn't considered discrimination. Offering a discount for voluntary participation in a loyalty program is also fine, as long as it's not so steep it starts to feel coercive.

Publish a Clear Privacy Notice

Your notice needs to cover what categories of data you collect, why, who you share it with, and how consumers can opt out. If you sell sensitive or biometric data, you're required to include a specific disclosure: "NOTICE: We may sell your sensitive personal data" (or "biometric personal data," as applicable).

Recognize Universal Opt-Out Signals

Since January 1, 2025, businesses have had to recognize universal opt-out signals like Global Privacy Control (GPC). It lets a consumer set their privacy preference once, through their browser, and have it respected everywhere they go. This is no longer a forward-looking requirement. It's active now, and it's one of the areas the Attorney General has flagged as an enforcement priority.

Put It in Writing With Your Processors

Your contracts with processors need to spell out processing instructions, the nature and purpose of the work, what data types are involved, how long processing lasts, confidentiality requirements, and what happens to the data once the work is done.

What Changed in 2026: The TRAIGA Amendment

Texas has already updated this law once. The Texas Responsible AI Governance Act (TRAIGA), effective January 1, 2026, amended the TDPSA to add a specific processor duty: if a processor handles personal data through an AI system, it now has to help the controller protect that data, in addition to the general security-assistance duty that already existed.

If your business uses AI tools anywhere in your data pipeline, whether that's a chatbot, an analytics tool, or something further upstream, this amendment is worth a closer look with whoever manages your processor contracts.

How the State Enforces This

The Texas Attorney General has exclusive enforcement authority. Consumers can't sue you directly, but they can file complaints, and the AG's office follows up on them. Before any enforcement action, the AG has to send written notice detailing the alleged violations, and you get 30 days to fix the problem. Unusually, that cure period never expires. Most states have phased theirs out or set them to sunset; Texas hasn't.

If you do cure a violation, you also have to tell the AG in writing what you fixed and confirm it won't happen again.

In January 2025, the Texas AG filed the law's first enforcement action, against insurance company Allstate and its subsidiary Arity, over the collection and sale of geolocation and driving data without proper notice or an opt-out mechanism. It was the first time any state attorney general brought a case under a comprehensive privacy law. Texas has shown it will use this authority.

What a Violation Costs

If you don't cure in time, or you violate the corrective statement you gave the AG, you're looking at civil penalties of up to USD 7,500 per violation, plus the state's costs to investigate. With enough affected consumers, that adds up fast.

TDPSA Support for Your Website

A consent management platform like Cookiebot™ CMP handles a lot of this groundwork for you. It can scan your site for cookies and trackers, categorize them, block anything non-essential until a visitor has made a choice where required, and keep a record of that choice in case you're ever asked to produce one.

You will need to write your data processing agreements and run your data protection assessments separately. But for the visitor-facing side of the law, especially the opt-out and consent-signal requirements, it's the tool most businesses lean on.

Cookiebot does not provide legal advice, and this article is for informational purposes only. Talk to qualified legal counsel about your specific business operations, privacy compliance, and how the TDPSA applies to your specific situation.

Frequently asked questions

No. Only the Texas Attorney General can enforce the TDPSA. Consumers can file complaints with the Attorney General's office but cannot bring a private lawsuit under the law.

Yes. In January 2025, the Texas Attorney General brought the law's first enforcement action, against Allstate and its subsidiary Arity, over the collection and sale of geolocation and driving data without adequate notice or an opt-out option.

Yes. The Texas Responsible AI Governance Act (TRAIGA), effective January 1, 2026, amended the TDPSA to require processors to help controllers protect personal data that's processed through AI systems, alongside their existing security obligations.

Businesses get a 30-day cure period, with no expiration date on that right, after receiving written notice from the Attorney General. Violations that go uncured can carry civil penalties of up to $7,500 each, plus the state's investigation costs.

The TDPSA took effect on July 1, 2024. The requirement to recognize universal opt-out signals, such as Global Privacy Control, took effect separately on January 1, 2025.

Any business that conducts business in Texas or offers products or services to Texas residents, processes personal data, and doesn't qualify as a small business under U.S. Small Business Administration size standards. There's no revenue or data-volume threshold, which sets Texas apart from several other state privacy laws.