The Texas Data Privacy and Security Act skips consumer-count thresholds entirely: it applies to any business that operates in Texas or serves Texas residents and processes or sells personal data, unless it qualifies as a small business under SBA definitions. Even exempt small businesses must get consumer consent before selling sensitive data.
What the Texas Data Privacy and Security Act Requires
Covered businesses must post a privacy notice, honor access, correction, deletion, and portability rights, get consent for sensitive data, and offer opt-outs for targeted advertising, sale, and significant profiling. Sites that sell sensitive or biometric data must post specific statutory notice language. Universal opt-out signals like the Global Privacy Control must be honored since January 1, 2025.
Enforcement and Penalties
The Attorney General enforces aggressively, with a permanent 30-day cure period and penalties up to $7,500 per violation. Texas has been among the most active enforcers of any state, so national sites should treat TDPSA compliance seriously rather than assuming a small-market state will not follow up.
Source: Texas Legislature Online: HB 4, Tex. Bus. & Com. Code Chapter 541
Report a violation: If you believe a business is violating this law, you can file a complaint with the Texas Attorney General Consumer Protection Division.