EnglishEspañol
Texas flag

Texas

What Is the TDPSA? Texas Data Privacy and Security Act

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 13 primary sources cited on this page. How we verify our legal content

What Is the TDPSA? Texas Data Privacy and Security Act

Frequently Asked Questions

What is the TDPSA?

The TDPSA, or Texas Data Privacy and Security Act, is Texas's comprehensive consumer data privacy law codified at Texas Business and Commerce Code Chapter 541 (Sections 541.001 through 541.204). Governor Greg Abbott signed HB 4 into law on June 18, 2023, and the statute took effect July 1, 2024. It gives Texas residents five data rights and requires covered businesses to be transparent about how they collect, use, and sell personal data. One provision governing universal opt-out signals became effective January 1, 2025.

Who does the TDPSA apply to?

The TDPSA applies to any person or business that (1) conducts business in Texas or produces products or services consumed by Texas residents, (2) processes or sells personal data, and (3) is not a small business as defined by the U.S. Small Business Administration. There is no minimum revenue threshold and no consumer data-volume floor. SBA size standards vary by industry code, so whether a company qualifies as an SBA small business depends on its primary NAICS classification and either its employee count or annual receipts.

Does the TDPSA apply to small businesses?

Mostly no. SBA-defined small businesses are exempt from most TDPSA obligations, including privacy notice requirements, consumer rights response duties, and universal opt-out honoring. However, even small businesses may not sell sensitive personal data (including health data, biometric identifiers, children's data, precise geolocation data, or data revealing race or immigration status) without first obtaining opt-in consent from the affected consumer. That restriction applies to small businesses regardless of their exemption from other TDPSA requirements.

What rights do Texas consumers have under the TDPSA?

Texas residents have five rights under Section 541.051(b): (1) access: confirm whether their data is being processed and get a copy; (2) correct: require a controller to fix inaccurate data; (3) delete: request removal of personal data the consumer provided or that was collected about them; (4) portability: receive a machine-readable copy for transfer to another controller; and (5) opt out: of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects. Controllers must respond within 45 days, with one allowable 45-day extension.

What is the penalty for violating the TDPSA?

Up to $7,500 in civil penalties per violation, plus reasonable expenses, court costs, and attorney fees recoverable by the AG. Before filing suit, the Texas AG must serve written notice identifying the specific statutory provision(s) allegedly violated and allow 30 days to cure. If the business remedies the violation and submits written documentation of compliance within that window, no enforcement action may proceed for that violation. The cure period is permanent; the TDPSA contains no sunset date for the cure provision.

Does the TDPSA have a private right of action?

No. Section 541.156 expressly states the TDPSA 'may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law.' Enforcement is exclusively the Texas Attorney General's authority. Individual consumers cannot sue covered businesses directly under Chapter 541 for any violation, including unauthorized data sales, ignored deletion requests, or processing of sensitive data without consent.

Does the TDPSA require honoring Global Privacy Control (GPC) signals?

Yes, in effect. Section 541.055(e), effective January 1, 2025, requires controllers to honor opt-out signals submitted by a consumer's authorized agent through qualifying technology, including browser settings, browser extensions, and global device-level settings. The statutory description encompasses GPC-type signals, though the statute does not name GPC by brand. The technology must represent an affirmative, unambiguous consumer choice and not a browser default setting. Section 541.055(e) also lists four grounds on which a controller is not required to comply with an agent-submitted request, including that the controller cannot verify Texas residency, does not possess the ability to process the request, or does not process similar requests in order to comply with another state's similar law.

What notice must a controller post if it sells sensitive personal data?

Controllers that sell sensitive personal data must post the exact statutory text: 'NOTICE: We may sell your sensitive personal data.' This notice must appear in the same location and manner as the privacy notice. Controllers that sell biometric personal data specifically must also post a separate notice: 'NOTICE: We may sell your biometric personal data.' Both notices are required in addition to, not instead of, obtaining opt-in consent before processing sensitive data.

How is the TDPSA different from the CCPA?

Three key differences: (1) Coverage threshold: the CCPA uses revenue and data-volume minimums ($25M/100K consumers); the TDPSA uses SBA small-business status as its only size filter, meaning many mid-size companies covered by the TDPSA are not covered by the CCPA, and vice versa. (2) Universal opt-out: both now require honoring browser opt-out signals, but Texas's requirement is a direct statutory command in Section 541.055(e) while California's is grounded in regulatory interpretation. (3) Private right of action: the CCPA includes a limited private right of action for data breach victims; the TDPSA has none.

Updates

Corrected the statutory subsection cited for the five consumer rights, restored the enacted wording of three statutory quotations, added the four grounds on which a controller may decline an agent-submitted opt-out signal, and narrowed the Gramm-Leach-Bliley exemption description to match the enacted text.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Tex. Bus. & Com. Code ch. 541:Texas Data Privacy and Security Act (Full Text)(statutes.capitol.texas.gov).gov
  2. Texas HB 4, 88th Legislature (2023):Enrolled Bill Text(capitol.texas.gov).gov
  3. Texas HB 4:Legislative History (88th Regular Session)(capitol.texas.gov).gov
  4. Tex. Bus. & Com. Code § 541.002:Applicability(statutes.capitol.texas.gov).gov
  5. Tex. Bus. & Com. Code § 541.051:Consumer Rights(statutes.capitol.texas.gov).gov
  6. Tex. Bus. & Com. Code § 541.055:Consumer Opt-Out Rights and Universal Opt-Out Signals(statutes.capitol.texas.gov).gov
  7. Tex. Bus. & Com. Code § 541.101:Controller Responsibilities(statutes.capitol.texas.gov).gov
  8. Tex. Bus. & Com. Code § 541.102:Privacy Notice and Sensitive Data Sale Notices(statutes.capitol.texas.gov).gov
  9. Tex. Bus. & Com. Code § 541.105:Data Protection Assessments(statutes.capitol.texas.gov).gov
  10. Tex. Bus. & Com. Code § 541.107:Small Business Sensitive Data Restriction(statutes.capitol.texas.gov).gov
  11. Tex. Bus. & Com. Code § 541.154:30-Day Cure Period(statutes.capitol.texas.gov).gov
  12. Tex. Bus. & Com. Code § 541.155:Civil Penalty; Injunction(statutes.capitol.texas.gov).gov
  13. Tex. Bus. & Com. Code § 541.156:No Private Right of Action(statutes.capitol.texas.gov).gov
Share: