The Texas Data Privacy and Security Act covers any business that sells products or services to Texas residents, processes their personal data, and does not qualify as a small business under U.S. Small Business Administration size standards. The attorney general enforces it alone, at up to $7,500 per violation, after a 30 day window to cure.
This overview is published by Uprite Services, a Texas-based managed IT and cybersecurity provider serving Houston, San Antonio and Dallas-Fort Worth since 1999. The law took effect on July 1, 2024 under HB 4 of the 88th Legislature. Three later bills have amended the rules around it, the most recent on January 1, 2026. This guide covers who is in scope, what the law requires, where the deadlines stand now, and what enforcement has actually looked like.
What is the Texas Data Privacy Law?
The TDPSA regulates how companies collect, process, and share personal information about Texas residents. It sets rules for handling that data, grants consumers rights over it, and requires you to say in plain language what you are doing. That gives Texas consumers a set of rights over their own data. The state enforces them.
Texas adds a second layer. Businesses that document a recognized cybersecurity program get a liability safe harbor under SB 2610, which is covered further down this page.
Consumers get four core rights under the TDPSA.
- Right to access. Consumers can request disclosure of the personal data you hold about them.
- Right to delete. Consumers can require you to delete their data.
- Opt-out rights. Consumers can require you to stop selling their personal data, stop using it for targeted advertising, and stop profiling that carries legal or similarly significant effects.
- Right of consent. Companies must obtain permission before collecting sensitive information.
Enforcement dates. The TDPSA took effect July 1, 2024. On January 1, 2025 a second obligation switched on under Section 541.055(e), which requires controllers to honor universal opt-out signals sent by a browser setting or a device-level control. The 30 day cure period did not expire. Texas is the outlier here. Colorado, Connecticut and Montana wrote sunset dates into their cure provisions, and Texas did not, so Section 541.154 gives you 30 days to fix a noticed violation for as long as the statute stands.
Why it matters. Legal compliance ensures transparency, builds trust with Texas consumers, and avoids fines.
Where the Texas Privacy Rules Stand in 2026
Four separate bills have moved the ground under the TDPSA since it took effect. None of them replaced it. Each one added a duty, a defense, or a definition that sits next to it. All four are in force.

| Effective | What changed | Bill |
|---|---|---|
| July 1, 2024 | TDPSA takes effect | HB 4, 88th Legislature |
| January 1, 2025 | Controllers must honor universal opt-out signals from browsers and devices | HB 4, Sec. 541.055(e) |
| September 1, 2025 | Safe harbor from exemplary damages for businesses under 250 employees that run a recognized cybersecurity program | SB 2610 |
| September 1, 2025 | Data broker definition narrowed to revenue and volume thresholds, and brokers must publish how to exercise TDPSA rights | SB 2121, SB 1343 |
| January 1, 2026 | Processors must assist controllers with security obligations for personal data handled by AI systems | HB 149, TRAIGA |
Nothing changes by statute during 2026. The Texas Legislature meets in regular session every two years, in odd-numbered years, and the 90th Legislature convenes January 12, 2027. That makes this a two-year window where the only moving part is enforcement. Enforcement is the variable now. That’s where the attorney general has been spending attention.
The AI amendment most Texas businesses missed
The Texas Responsible Artificial Intelligence Governance Act took effect January 1, 2026, and most coverage of it focused on the restrictions that apply to government agencies. The part that touches ordinary businesses is smaller and easier to miss. TRAIGA amended the TDPSA to make clear that a processor’s duty to help a controller meet its security obligations extends to personal data collected, stored, and processed by an AI system. It’s a contract problem, not an AI problem. If you added an AI support agent, a call summarizer, or a document tool in the last two years, your data processing agreement with that vendor now has to reach it. We cover what TRAIGA requires of Texas SMBs in full, and the wider framework on our AI governance and compliance page.

The safe harbor that rewards work you may already be doing
SB 2610 took effect September 1, 2025. It gives a business under 250 employees a defense against exemplary damages in a data breach suit, provided it maintains a written cybersecurity program scaled to its size. The tiers are specific.
- Under 20 employees. Basic practices, including a password policy and security awareness training.
- 20 to 99 employees. CIS Controls Implementation Group 1.
- 100 to 249 employees. Full conformance to a recognized framework such as NIST CSF, NIST SP 800-171, CIS Controls, or ISO 27001.
The safe harbor does not stop a breach notification, a regulatory investigation, or a claim for actual damages. It caps the worst outcome. Our SB 2610 compliance guide walks the tiers in detail.
What Do the Key TDPSA Terms Mean?
The TDPSA uses specific terms that companies have to understand to comply correctly. Definitions do real work here. Getting them right keeps your processing defensible and reduces risk. It also helps employees, vendors, and partners avoid the common misreadings of personal data and sensitive data.
- Personal data. A name, an address, an IP address, and any other information linked to an identifiable person.
- Sensitive data. Data revealing racial or ethnic origin, religious belief, mental or physical health diagnosis, sexuality, or citizenship and immigration status, plus genetic or biometric data processed to identify an individual, data collected from a known child, and precise geolocation data.
- Biometric data. Fingerprints, voiceprints, and retina or iris scans.
- Controller and processor. The controller decides why and how personal data is used. The processor handles that data on the controller’s behalf.
- Processing. Every operation performed on personal data, from collection and storage through use and disclosure.
Who Must Comply?
Not every company in the United States has to comply with the TDPSA, but many do, including plenty that have never set foot in the state. Location is not the test. The applicability test has to do with whose data you hold, not where you sit.
The test has three parts.
- You conduct business in Texas, or you produce products or services consumed by Texas residents.
- You process or sell personal data.
- You are not a small business as defined by the U.S. Small Business Administration.
Texas took an unusual route on that third part. Most state privacy laws draw the line at a record count or a revenue figure, and Texas instead points at the U.S. Small Business Administration size standards, which vary by industry code. Size is not decisive on its own. One duty still reaches a small business, because Section 541.107 requires consent before selling sensitive personal data no matter how small the company is.
TDPSA coverage is broader than most state laws in one more way. An online retailer can be pulled in without ever targeting Texas specifically, simply because Texans buy from it.
Who Is Exempt From the Texas Privacy Law?
The TDPSA does not cover all data activity. Certain entities and certain categories of data sit outside it entirely. Knowing which ones apply to you saves real time, because it narrows the work to the systems that actually carry consumer data.
Exclusions include the following.
- Personal or household activity.
- Data about individuals acting in a commercial or employment context, which covers most business-to-business contact records and your own employee files.
- State agencies and political subdivisions.
- Entities regulated by HIPAA or the Gramm-Leach-Bliley Act.
- Electric utilities, power generation companies, and retail electric providers.
- Nonprofit organizations and institutions of higher education.
One caution on those. An exemption for an entity is not the same as an exemption for a data set, and a company that qualifies under one heading often still processes consumer data that falls outside it. Verify it first.
What Does the TDPSA Require You to Do?
Businesses have to follow specific rules to comply with the TDPSA. They cover consent, data sales, advertising, privacy notices, contracts with processors, consumer requests, and risk assessments. Seven obligations carry most of the weight.
1. Opt-in for Sensitive Data
Companies must obtain explicit consent before processing sensitive data. Consent cannot be implied. It also cannot be buried in a terms-of-service acceptance. For a known child, you need consent under the federal Children’s Online Privacy Protection Act instead.
2. Opt-out for Sale of Personal Data
Consumers have the right to stop the sale of their personal data. The TDPSA defines a sale broadly, covering exchanges for money or for other valuable consideration, which sweeps in arrangements most companies would never call a sale. Check your ad tech. You have to provide a clear and easy way to opt out. Since January 1, 2025 you also have to honor a universal opt-out signal that arrives from the consumer’s browser or device.
3. Opt-out for Targeted Advertising
Consumers can opt out of targeted advertising built on their personal data. Contextual advertising is excluded. If you sell personal data or run targeted ads, the law also requires a specific notice saying so, in those words, on your website.
4. Drafting a Privacy Notice
The controller has to publish a reasonably accessible privacy notice covering the following.
- The categories of personal data processed, including sensitive data.
- The purpose for processing it.
- The categories shared with third parties, and the categories of those third parties.
- How a consumer exercises their rights, including how to appeal a refusal.
Write it in plain language. A notice a consumer cannot follow does not do the job the statute asks of it.
5. Data Processing Agreements
A controller has to have a written contract with every processor that handles personal data on its behalf. The contract has to set out the processing instructions, the nature and purpose of the processing, the type of data involved, the duration, and the duties of both sides. It also has to require the processor to delete or return the data when the service ends. This is the requirement companies discover last. Auditing the vendor list is part of the job.
6. Handling Consumer Rights Requests
Texas consumers can ask you to confirm whether you are processing their personal data, give them access to it, correct errors in it, delete it, or hand over a portable copy in a readily usable format. They can also opt out of sale, targeted advertising, and profiling that produces legal or similarly significant effects. You have 45 days to respond, with one 45 day extension where the request is genuinely complex. The clock starts on receipt. A slow identity check eats your own window.
7. Conducting Data Protection Assessments
Businesses must conduct and document a data protection assessment before doing any of the following.
- Processing sensitive data.
- Selling personal data.
- Processing personal data for targeted advertising.
- Profiling that carries a reasonably foreseeable risk of unfair or deceptive treatment, financial or physical injury, or intrusion on solitude.
Keep them on file. The attorney general can request them, and an assessment you cannot produce is an assessment you did not do.
How Is the TDPSA Enforced, and What Are the Penalties?
The Texas attorney general enforces the TDPSA exclusively. Consumers have no private right of action, which means the risk on this statute is regulatory rather than class action. It arrives as a letter. Not a lawsuit.
- Civil penalty. Up to $7,500 for each violation, under Section 541.155.
- Notice first. The attorney general must give written notice identifying the specific provisions alleged to be violated, at least 30 days before filing.
- The cure. Fixing the violation inside 30 days blocks the action, but you have to certify it in writing, notify affected consumers where you hold their contact details, produce documentation showing how the violation was cured, and revise internal policy so it does not recur.
- Investigative demands. The attorney general can issue civil investigative demands before any of this starts.
What enforcement has actually looked like
Texas filed the first enforcement action ever brought by any state under a comprehensive privacy law. On January 13, 2025 the attorney general sued Allstate and its Arity subsidiaries over driving data collected through software embedded in third-party mobile apps, covering roughly 45 million consumers. The case is still live. A court dismissed Arity in 2026 for insufficient Texas contacts, and the state is appealing that ruling.

The broader pattern matters more than the single case. Since launching its Data Privacy and Security Initiative in June 2024, the attorney general’s office has opened investigations into more than 200 companies, concentrated on data brokers, connected vehicles, and platforms handling data from minors. A 30 day cure period is a real shield. It’s only useful if you can answer a notice inside 30 days with documentation, and that is an operational capability rather than a legal one.
Can your team answer a 30 day cure notice? That means producing a data inventory, your processing agreements, and evidence of what you fixed, inside a month. Most Texas businesses find out they cannot when the letter arrives. Book a compliance and regulatory assessment and find out before then.
TDPSA Compliance Checklist
Every obligation above depends on one thing you probably have not finished. You need to know what personal data you hold and where it lives. That’s the foundation of everything below. Start there. Then work down this list.

| Step | What it takes | Where it usually breaks |
|---|---|---|
| Inventory your personal data | Map every system, app and vendor that touches data about Texas residents | Marketing tools and support platforms nobody put on the list |
| Confirm scope | Check the SBA size standard for your industry code, then check what data you hold | Assuming a B2B model or a small headcount ends the analysis |
| Publish a compliant privacy notice | Categories, purposes, third parties, rights, and the appeal route | A notice written for a different state’s law |
| Post the sale and targeted advertising notices | The specific statutory wording, on your website | Companies that do sell data but never call it that |
| Build the consumer request process | Two intake methods, identity verification, a 45 day clock, and an appeal path | No log, so you cannot prove what you did |
| Honor universal opt-out signals | Recognize and act on browser and device-level opt-out preference signals | Consent tools that were never configured for it |
| Paper every processor | A data processing agreement with each vendor, now reaching AI tools under TRAIGA | Vendors added after the last contract review |
| Run and file assessments | Documented assessments for sensitive data, sale, targeted ads and profiling | Done informally, never written down |
| Document the security program | Scale it to headcount under SB 2610 to hold the safe harbor | Controls exist but no written program describes them |
Simplify Texas Privacy Law Compliance with Expert Help
Meeting the requirements of the TDPSA is a real project for most companies. From capturing consent to answering consumer requests inside 45 days, each stage needs someone who owns it. Uprite Services builds and runs that work for Texas businesses, including the privacy notice, the opt-in and opt-out mechanics, the processor agreements, and the data protection assessments. The point is to keep the program defensible while your team stays on the work that makes money.
Why Choose Uprite
- Texas-specific knowledge. We track the TDPSA, SB 2610, and TRAIGA as they move, not as they were written.
- Tailored solutions. IT compliance solutions scaled to your headcount and your industry.
- Full coverage. From privacy notices through data protection assessments and the evidence file behind them.
- Risk reduction. Answer a cure notice on time and keep the SB 2610 safe harbor intact.
Our Takeaway
The TDPSA is not the hardest privacy law in the country, and that’s exactly why companies get caught by it. The obligations are readable, the penalties are capped, and the 30 day cure period is permanent, so nothing about it feels urgent until a notice arrives. Then it’s very urgent. The businesses that handle that moment well are the ones that did the inventory first and kept the paperwork current, and the ones that struggle are almost always the ones that could not say where their data lived. Start with the inventory. Talk to us when you want help building the rest.
What Texas Businesses Ask About the TDPSA
Does this law apply to a company our size?
It turns on whether you qualify as a small business under U.S. Small Business Administration size standards, not on a revenue or record-count threshold, which is what makes the Texas law different from most state privacy statutes. Read the exemption test. Size is not decisive on its own, because a small business still needs consent before selling sensitive data.
We only sell to other businesses. Are we still covered?
Often not, and Texas is clearer about this than most states. The statute defines a consumer as a resident acting only in an individual or household context, and it explicitly excludes anyone acting in a commercial or employment context. So your buyer contacts at client companies and your own employee records fall outside the TDPSA. Check what else you hold before relying on that. Most B2B companies still run a website, a marketing list, or a support portal that collects data from individuals, and those records are in scope even when the core business is not.
What is the difference between opt-in and opt-out here?
Sensitive data requires permission first, everything else requires a way to say no. That split is the practical core of the law, and getting it backwards is one of the more common mistakes. Ask which category applies.
How quickly do we have to answer a consumer request?
Within 45 days, with one 45 day extension available when the request is complex and you tell the consumer why. The clock starts on receipt, not on verification, so a slow identity check eats your own window. Build the process now. You also have to log what you did and be able to produce that record later.
Did the 30 day cure period expire?
No, and this is the most common misreading of the Texas law. Colorado, Connecticut and Montana wrote sunset dates into their cure provisions, and Texas did not, so the attorney general still has to give you 30 days to fix a noticed violation before filing. What changed on January 1, 2025 was something else entirely, the duty to honor universal opt-out signals from a consumer’s browser or device.
Do we need agreements with our vendors?
You do, and this is the requirement most often discovered late. Any processor handling personal data on your behalf needs a data processing agreement defining what they can do with it, which means auditing your vendor list is part of compliance rather than a separate exercise. As of January 1, 2026 that reach extends to AI tools, because TRAIGA amended the TDPSA to cover personal data processed by an AI system.
Where does a Texas business start with all this?
Start with an inventory of what personal data you hold and where it lives, because every other obligation depends on knowing that. Privacy notices, consumer requests, vendor agreements, and assessments all become straightforward once the inventory exists and nearly impossible while it does not. An IT assessment will map the systems holding it.










