EnglishEspañol
Texas flag

Texas

TDPSA Compliance Checklist for Businesses (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

TDPSA Compliance Checklist for Businesses (2026)

Frequently Asked Questions

Does the TDPSA apply to my small business?

If your business qualifies as an SBA small business under 13 C.F.R. Part 121 for your specific NAICS industry code, most TDPSA controller obligations do not apply. However, even SBA small businesses are prohibited from selling sensitive personal data without prior consumer consent under Tex. Bus. & Com. Code § 541.107. To determine your threshold, look up your NAICS code at sba.gov/size-standards and calculate size including all affiliates.

What is the difference between opt-in and opt-out under the TDPSA?

The TDPSA requires affirmative opt-IN consent before processing sensitive data. You need a clear, informed yes before any collection or processing of sensitive categories begins. For non-sensitive personal data used in targeted advertising or sold to third parties, the standard is opt-OUT: you may process the data unless and until the consumer objects. Understanding this distinction is critical because the wrong standard applied to sensitive data is precisely the type of violation the Allstate enforcement action targets.

What exactly must the mandatory sale notices say?

The statute specifies verbatim text that cannot be paraphrased. If you sell sensitive personal data, the notice must read exactly: 'NOTICE: We may sell your sensitive personal data.' If you separately sell biometric personal data, the notice must read exactly: 'NOTICE: We may sell your biometric personal data.' Under Tex. Bus. & Com. Code §§ 541.102(b) and 541.102(c), each notice must be posted in the same location and in the same manner as the privacy notice required by § 541.102(a).

Are nonprofits subject to the TDPSA?

No. Nonprofit organizations are categorically exempt from the TDPSA under Tex. Bus. & Com. Code § 541.002(b)(4). A nonprofit that processes personal data of millions of Texas residents has no TDPSA controller obligations. The nonprofit may still have obligations under HIPAA, COPPA, or other federal or state laws depending on the nature of the data it processes.

Does the TDPSA have a private right of action?

No. Tex. Bus. & Com. Code § 541.156 expressly states the TDPSA may not be construed as providing a basis for a private right of action. Only the Texas Attorney General can enforce the law. This is a meaningful structural protection compared to state biometric laws like Illinois BIPA, which allows individual lawsuits and has generated substantial class action liability.

How long is the TDPSA cure period, and does it sunset?

The cure period is 30 days after the AG's written notice identifying specific violations. If you cure successfully and provide written confirmation of the remediation, the AG may not bring an enforcement action for that violation. Unlike some other state privacy laws, the TDPSA cure period does not have a scheduled sunset date under the current text of Tex. Bus. & Com. Code § 541.154.

What is the maximum penalty for a TDPSA violation?

Civil penalties of up to $7,500 per violation. The AG may also seek injunctive relief and recover reasonable attorney fees and court costs under Tex. Bus. & Com. Code § 541.155. Because the penalty applies per violation rather than per enforcement action, the aggregate exposure for mass-scale processing violations can be enormous, as illustrated by the Allstate lawsuit alleging violations affecting 45 million consumers.

Do I need a data protection assessment for all of my data processing?

No. DPAs are required only for processing activities that present a heightened risk: targeted advertising, selling personal data, risky profiling, sensitive data processing, and any other high-risk processing under Tex. Bus. & Com. Code § 541.105(a). Routine business processing that falls outside those five categories does not require a formal DPA. However, maintaining a brief written record of your threshold analysis for borderline activities is a best practice, since the AG can demand DPAs during an investigation.

Updates

Corrected the SBA size-standard measurement periods in the applicability self-test, the citation for the data-sale and targeted-advertising opt-out disclosure, the placement rule and account requirements for opt-out and sale notices, the 60-day deadline for deciding a consumer appeal, and the statutory structure of the sensitive-data definition.

Corrected the number of processor-contract operational duties in Step 8 from six to five, and added the January 2026 update (House Bill 149) that extends processor data-security assistance duties to personal data used in AI systems.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Tex. Bus. & Com. Code ch. 541 (TDPSA full text)(statutes.capitol.texas.gov).gov
  2. Texas H.B. 4 (88th Legislature, enrolled) — TDPSA original bill text(capitol.texas.gov).gov
  3. Texas Attorney General — Texas Data Privacy and Security Act consumer information page(texasattorneygeneral.gov).gov
  4. Texas AG Press Release: Paxton Sues Allstate and Arity for Unlawfully Collecting, Using, and Selling Over 45 Million Americans' Driving Data(texasattorneygeneral.gov).gov
  5. Texas Department of Information Resources — TDPSA implementation page(dir.texas.gov).gov
  6. Texas State Law Library — Texas Data Privacy and Security Act spotlight (July 2024)(sll.texas.gov).gov
  7. U.S. Small Business Administration — Size Standards overview (SBA small-business definition used in § 541.002)(sba.gov).gov
  8. U.S. SBA — Table of Small Business Size Standards (13 C.F.R. Part 121)(sba.gov).gov
  9. Tex. Bus. & Com. Code ch. 510 — Texas Data Broker Registration Law (formerly ch. 509, redesignated eff. Sept. 1, 2025)(statutes.capitol.texas.gov).gov
  10. 13 C.F.R. 121.104 - Calculation of annual receipts for SBA size standards (5-fiscal-year averaging rule)(govinfo.gov)
  11. 13 C.F.R. 121.106 - Calculation of number of employees for SBA size standards (24-calendar-month averaging rule)(govinfo.gov)
Share: