The Texas Data Privacy and Security Act gives Texas residents named rights over their personal data and creates specific duties for businesses that process Texans’ data. Most of the law took effect July 1, 2024, with a handful of provisions following on January 1, 2025. The highest-stakes pieces are the opt-out rights for targeted ads, data sales, and profiling, the requirement to document data protection assessments, and the Attorney General’s broad enforcement power.
TL;DR:
- Small businesses selling sensitive personal data must obtain consumer opt-in consent, regardless of size, while exemptions include regulated sectors like healthcare and education.
- Businesses must conduct data protection assessments for high-risk processing, which are confidential and serve as both compliance records and shields during investigations.
- Texas’ enforcement relies solely on the Attorney General, with violations costing up to 7,500 dollars per breach and a 30-day cure period based on documented remediation.
- Companies should inventory data flows, update privacy notices, establish secure request processes, and document assessments to prepare for compliance and enforcement actions.
- Handling AI tools used in profiling or automated decisions requires model bias review, thorough documentation, and oversight to meet the law’s transparency and risk mitigation standards.
Table of Contents
- What the TDPSA Covers: Definitions, Scope, and Timeline
- Who Must Comply and Who Is Exempt
- What Rights Texans Have and How to Use Them
- Controller and Processor Duties Under the TDPSA
- How the Attorney General Enforces the TDPSA
- Your Compliance Checklist: What to Do Now
- Why Texas’s Enforcement Posture Changes the Math
- Getting TDPSA-Ready Without the Guesswork
- FAQ
- Sources
What the TDPSA Covers: Definitions, Scope, and Timeline
The law separates personal data from sensitive data, and that distinction drives almost every obligation that follows. Personal data is information linked or reasonably linkable to an identified or identifiable person. Sensitive data gets extra protection and includes:
- Precise geolocation information
- Biometric data used to identify a person
- Data from a known child under 13
- Information revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship status
The statute, found in Chapter 541 of the Texas Business and Commerce Code, became effective July 1, 2024, with select provisions, including authorized-agent opt-out mechanics, following on January 1, 2025. It sits alongside the separate Texas Data Broker Act, which covers companies whose main business is selling personal data, and it carves out exemptions we will cover next.
Who Must Comply and Who Is Exempt
Figuring out whether the TDPSA applies to your business comes down to three tests, and you need to clear all three:
- You conduct business in Texas or produce a product or service consumed by Texas residents.
- You process or sell personal data as part of that business.
- You do not qualify as a small business under the federal Small Business Administration size standards, with one important exception noted below.
Small businesses get relief from most TDPSA duties, but that exception has a hard limit: a small business that sells sensitive personal data still needs consumer opt-in consent before the sale happens, regardless of size. The law also exempts several categories outright, including data already regulated under the Gramm-Leach-Bliley Act, HIPAA-covered entities and their business associates, state agencies and political subdivisions, nonprofits, institutions of higher education, and certain employment-related records. If your business touches one of those categories, read the relevant exemption closely. Partial exemptions are common, and they rarely cover every type of data you handle.
What Rights Texans Have and How to Use Them
Texas residents get a defined set of controls over their personal data, and businesses have to make those controls usable, not just theoretical. Under the law, you can:
- Confirm whether a business is processing your data and access that data
- Correct inaccuracies in your personal data
- Delete personal data a business holds about you
- Get a portable copy of your data in a format you can actually use elsewhere
- Opt out of targeted advertising, the sale of your personal data, and profiling that leads to a legal or similarly significant decision about you
The Texas Attorney General’s consumer guidance confirms these rights and requires that businesses offer at least two secure, reliable methods for submitting a request, such as a toll-free number and an online form. Businesses also have to authenticate the request reasonably before acting on it, which protects you from someone else deleting or accessing your data by pretending to be you.
Pro Tip: Save a copy of every data request you submit and the business’s response. If a company stalls or ignores you, that record is exactly what the Attorney General’s office will want to see.
Controller and Processor Duties Under the TDPSA
Businesses that control personal data, and the processors working on their behalf, carry obligations that go well beyond posting a privacy policy and calling it done. A compliant privacy notice needs to spell out the categories of data collected, the purposes for processing, how consumers exercise their rights, and whether data is sold or used for targeted advertising, with a conspicuous disclosure whenever sensitive data is part of that sale. Businesses also have to:
- Minimize collection to what is reasonably necessary for the stated purpose
- Maintain administrative, technical, and physical safeguards sized to the volume and sensitivity of the data involved
- Put processor relationships in writing, with contracts that flow security and confidentiality duties down to subprocessors
- Get affirmative, opt-in consent before processing sensitive data, since the TDPSA treats passive behavior or pre-checked boxes as invalid consent
One of the more overlooked protections in the law: data protection assessments submitted to the Attorney General’s office during an investigation are not disclosable under the Texas Public Information Act. That matters because it means a well-documented assessment functions as both a compliance record and a shield, not a public liability. Assessments are required for targeted advertising, data sales, profiling that carries foreseeable risk, and any processing of sensitive data, and they need to be specific enough to show you actually weighed the risk against the benefit.
How the Attorney General Enforces the TDPSA
Enforcement runs through one office, and that concentration changes how businesses should prepare. The Texas Attorney General holds exclusive enforcement authority under the TDPSA, there is no private right of action, and the consequences for an uncured violation include:
- Civil penalties of up to $7,500 per violation
- Injunctive relief ordering the business to stop the violating practice
- Recovery of attorney’s fees and investigation costs by the state
Before any of that lands, the law requires the Attorney General to send written notice of the violation and give the business 30 days to cure it, under Section 541.154. That cure window is a real opportunity, not a formality, but only if you can show documented remediation rather than a verbal promise to do better. Recent enforcement activity gives a sense of where the office is focused: the Attorney General has pursued significant settlements and actions tied to biometric data, precise geolocation tracking, and data broker practices, which tells you exactly where to prioritize your own review.
Your Compliance Checklist: What to Do Now
If you run a Texas business handling consumer data, work through these steps in order rather than trying to fix everything at once:
- Inventory the personal and sensitive data you collect, where it lives, and who touches it.
- Rewrite your privacy notice to disclose categories of data, purposes, and any sale or targeted advertising use.
- Build a request intake process with at least two methods and a reasonable authentication step.
- Flag any processing that triggers a data protection assessment, sensitive data, targeted ads, sales, or high-risk profiling.
- Document each assessment in writing, including the benefit weighed against the risk.
- Update contracts with every processor and subprocessor to require matching security obligations.
- Confirm technical controls are actually in place: access restrictions, encryption, and activity logging.
- Set retention limits and a disposal schedule so you are not holding data past its purpose.
If you use AI tools for profiling, scoring, or any automated decision that affects a consumer’s access to credit, employment, housing, or similar outcomes, document the model’s inputs and review it for bias before it ever touches a legal or similarly significant decision. A risk-based AI governance roadmap is a useful reference for structuring that review.
Pro Tip: Keep every piece of remediation evidence in one folder labeled by date. If the Attorney General’s office sends a 30-day cure notice, you want to hand over a timeline, not scramble to build one.
Why Texas’s Enforcement Posture Changes the Math
Texas chose centralized Attorney General enforcement over private lawsuits, which sounds like less exposure until you look at the settlements already on the board. A policy sitting in a drawer does not help you during a 30-day cure window. What helps is a documented, repeatable process you can point to the moment a notice arrives, not one you build after the fact.
— Randy Bryan
Getting TDPSA-Ready Without the Guesswork
Mapping your data flows, flagging high-risk AI use, and documenting assessments is real work, and most Texas businesses are already stretched thin running their core operations. We built the AI Profit and Growth Assessment to map where AI creates efficiency in your business while flagging the privacy and security risks the TDPSA expects you to document, so compliance work and AI strategy happen together instead of as two separate projects.

As an AI partner rather than a traditional consultant, we ground every recommendation in active cybersecurity practice, not theory, and for businesses that need ongoing support we also offer Managed AI Security to keep technical controls monitored over time. If you are ready to understand your business’s position, start with a thorough AI assessment.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ
Can someone record me without my consent in Texas?
Texas is a one-party consent state for recording conversations, meaning you can record a conversation you are part of without the other person’s permission. This is governed by Texas wiretapping law separate from the TDPSA, which deals with how businesses collect and process personal data rather than audio recording consent.
Is it illegal to collect data without consent?
It depends on the type of data and how it is used. Under the TDPSA, businesses need your opt-in consent specifically before processing sensitive data like biometric information or precise geolocation, and you can opt out of having your general personal data sold or used for targeted advertising at any time, as outlined by the Texas Attorney General’s office.
Which state has the strictest data privacy laws?
There is no single agreed-upon ranking, since states like California, Virginia, Colorado, and Texas each structure consumer rights, enforcement mechanisms, and penalties differently. Texas stands out for its lack of a private right of action combined with an active Attorney General enforcement record, which shifts risk toward regulatory penalties rather than consumer lawsuits.
Can you refuse to show ID in Texas?
Generally yes, Texas does not have a blanket law requiring you to show identification to just anyone who asks, though specific situations like traffic stops or certain business transactions carry their own rules. This question falls outside the TDPSA, which governs data privacy practices rather than identification requirements.
When do I need to complete a data protection assessment under the TDPSA?
You need one whenever your processing involves targeted advertising, the sale of personal data, profiling that carries a foreseeable risk of harm, or any use of sensitive data, according to Texas Business and Commerce Code Chapter 541. These assessments should be documented in writing and kept current as your data practices change.