US Privacy Law Texas, USA

Texas TDPSA: Data Privacy and Security Act Guide

The Texas Data Privacy and Security Act: near-universal applicability, sensitive-data consent, GPC recognition, the AG's aggressive enforcement, and $7,500 penalties.

Regulation

Texas Data Privacy and Security Act (HB 4, 2023), Tex. Bus. & Com. Code ch. 541, effective July 1, 2024

Max Penalty

Up to $7,500 per violation, plus injunctive relief; the AG has sued at nine-figure exposure levels

Enforcing Authority

Texas Attorney General

Official Source

www.texasattorneygeneral.gov

Executive Summary

  • The TDPSA (effective July 1, 2024) abandons numeric thresholds: it applies to any entity conducting business in Texas or targeting Texans that processes or sells personal data and is not a small business under SBA definitions.
  • Even exempt small businesses need consumer consent before selling sensitive personal data, a provision with no counterpart elsewhere.
  • The rights set follows Virginia (access, correction, deletion, portability, opt-outs of targeted advertising, sale, and profiling) with opt-in consent for sensitive data and mandatory recognition of universal opt-out signals since January 1, 2025.
  • Unique disclosure rules: businesses selling sensitive or biometric data must post prescribed notices verbatim ('NOTICE: We may sell your sensitive personal data.').
  • The Texas AG runs the most aggressive state privacy enforcement outside California: a dedicated privacy unit, sweep letters to over a hundred companies, the $1.4B Meta biometrics settlement (under CUBI), a landmark suit against General Motors over driving-data sales, and a 2025 action against Allstate/Arity over location data.

Texas built the widest and most enforced privacy law in the Virginia family. No thresholds worth planning around, verbatim warning notices, biometric rules with a nine-zero settlement behind them, and an Attorney General who sued two of America’s largest companies over data practices within the law’s first year. For most national businesses the TDPSA is not one more state law; it is the state law that finally applies to them.

LawTDPSA, Tex. Bus. & Com. Code ch. 541
EffectiveJuly 1, 2024 (GPC mandate Jan 1, 2025)
Applies toAny non-small-business processing Texans’ data
Max penalty$7,500 per violation (30-day cure, permanent); CUBI up to $25,000
RegulatorTexas AG
StatuteHB 4 (2023)

The Texas-specific exposure map

Applicability is the trap. Companies that dodged Colorado and Connecticut on volume thresholds are covered here. The only outs are SBA small-business status (verify against your NAICS code) and the standard entity exemptions (HIPAA covered entities, GLBA financial institutions, nonprofits, utilities).

Telematics, SDKs, and location are the AG’s docket. GM (driving behavior sold to insurers) and Allstate/Arity (location SDKs embedded in third-party apps) signal the theory: covert collection plus undisclosed sale equals TDPSA and DTPA violations. Audit embedded SDKs, in your apps and in apps carrying your SDK, the way you audit web trackers.

Biometrics are double-regulated. CUBI consent-and-destruction duties plus TDPSA sensitive-data consent plus the verbatim notice if sold. The Meta $1.4B settlement prices the downside.

The cure period is real but conditional. 30 days, permanent, but curing requires a written statement that violations will not recur, and the AG’s suits show it will proceed where conduct is systemic. Sweep letters are the warning shot; answer them with evidence, not promises.

Broker registry. Texas SB 2105 requires data-broker registration with the Secretary of State and a comprehensive security program, part of the national registry stack.

Multistate programs should treat Texas plus Colorado as the joint spec: Texas for breadth, Colorado for depth; the comparison matrix shows the merge. Check your consumer-facing surface, notices, opt-outs, trackers, GPC handling, with a free scan before a sweep letter checks it for you.

Frequently Asked Questions

Why does the TDPSA cover so many more companies than other state laws?

It has no volume or revenue thresholds. Coverage requires only: conducting business in Texas or serving Texas residents, processing or engaging in the sale of personal data, and not qualifying as a small business under the US Small Business Administration's size standards (which vary by industry, commonly around 100-1,500 employees or revenue caps). A ten-person SaaS company exceeding its industry's SBA cap is covered; a large enterprise is covered regardless. Assume coverage unless you have verified SBA small-business status.

What are the verbatim notice requirements?

If you sell sensitive personal data, your privacy notice must include, word for word: 'NOTICE: We may sell your sensitive personal data.' If you sell biometric personal data: 'NOTICE: We may sell your biometric personal data.' The AG's early sweep letters specifically checked for these strings. Selling here uses a monetary-or-other-valuable-consideration definition broader than Virginia's, so ad-tech arrangements can trigger the notices.

What has Texas enforcement actually looked like?

The AG created a dedicated privacy enforcement unit in 2024 and moved fast: hundreds of notice letters (including a data-broker registration sweep), the General Motors lawsuit (2024, alleging unlawful collection and sale of drivers' telematics data to insurers), the Allstate/Arity suit (January 2025, alleging covert collection of location data from millions of phones via embedded SDKs), and, under the separate biometric statute CUBI, the $1.4B Meta settlement in 2024, the largest state privacy recovery in US history. Texas treats privacy as headline enforcement.

How do CUBI and the TDPSA interact?

CUBI (Capture or Use of Biometric Identifier Act, 2009) is a standalone biometric law: informed consent before capturing biometric identifiers, destruction deadlines, no selling, enforced solely by the AG at up to $25,000 per violation, the statute behind the Meta and Google actions. The TDPSA adds biometric data to its sensitive-data consent regime and its verbatim-notice rule. Biometric programs in Texas must satisfy both.

What should a company do first for TDPSA compliance?

Run the SBA test honestly; if covered: update the privacy notice (including verbatim strings if applicable), gate sensitive-data processing behind opt-in consent, stand up the five rights with 45-day responses and an appeal process, honor GPC from the January 2025 mandate, paper processors, and prepare data protection assessments for targeted advertising, sale, sensitive data, and profiling. If you sell data about consumers you have no relationship with, register as a data broker under SB 2105 as well.

Regulatory Crosswalk

Virginia VCDPACCPATexas SB 2105 (broker registry)

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.