{
  "type": "practice-guide",
  "canonical": "https://openagreements.org/practice-guides/privacy/us/texas",
  "links": [
    {
      "rel": "self",
      "href": "https://openagreements.org/practice-guides/privacy/us/texas.json",
      "type": "application/json"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/texas",
      "type": "text/html"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/texas/markdown",
      "type": "text/markdown"
    },
    {
      "rel": "alternate",
      "href": "https://openagreements.org/practice-guides/privacy/us/texas/json",
      "type": "application/json"
    }
  ],
  "data": {
    "topic": "privacy",
    "state": "texas",
    "frontmatter": {
      "title": "Texas Consumer Privacy Law (TDPSA)",
      "description": "The Texas Data Privacy and Security Act gives Texas consumers rights over their personal data and imposes notice, consent, contracting, and security duties on businesses that are not small businesses — with no revenue threshold, exclusive Attorney General enforcement, and no private right of action.",
      "state": "Texas",
      "lastReviewed": "2026-06-04",
      "license": "CC BY 4.0",
      "authors": [
        "steven-obiajulu"
      ],
      "summary": {
        "keyLaw": "Tex. Bus. & Com. Code ch. 541 (Texas Data Privacy and Security Act)",
        "appliesTo": "Anyone who does business in Texas (or sells products/services to Texans), processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration — no revenue or data-volume threshold",
        "privacyPolicyRequired": "Yes — a reasonably accessible and clear notice with statutorily fixed contents",
        "privateRightOfAction": "No — the statute bars any private right of action",
        "regulator": "Texas Attorney General (exclusive)",
        "bottomLine": "If you do business in Texas and are not an SBA small business, the TDPSA requires a specific privacy notice, opt-in consent to process sensitive data, and processor contracts — enforced solely by the Attorney General, with no consumer lawsuits.",
        "lawCoverage": "comprehensive",
        "policyMandate": "statutoryContents",
        "consumersCanSue": "no",
        "sensitiveDataConsent": "optIn",
        "universalOptOutSignal": "notRequired"
      },
      "about": [
        "Texas Data Privacy and Security Act TDPSA",
        "Texas privacy policy requirements",
        "Texas privacy notice contents",
        "TDPSA applicability small business threshold",
        "TDPSA sensitive data consent",
        "TDPSA processor contract requirements",
        "Texas Attorney General privacy enforcement",
        "TDPSA no private right of action"
      ],
      "translations": [
        {
          "language": "中文",
          "status": "planned"
        },
        {
          "language": "Español",
          "status": "planned"
        },
        {
          "language": "Português",
          "status": "planned"
        },
        {
          "language": "Deutsch",
          "status": "planned"
        }
      ]
    },
    "questions": [
      {
        "slug": "does-tdpsa-apply",
        "label": "Does the Texas Data Privacy and Security Act apply to your business?",
        "heading": "Does the Texas Data Privacy and Security Act apply to your business?",
        "answerText": "Probably, if you handle Texans' personal data and are not a small business. Unlike California, Texas sets no revenue or data-volume threshold. The TDPSA applies to a person that does business in Texas or produces a product or service consumed by Texas residents, that processes or sells personal data, and that is not a small business as defined by the U.S. Small Business Administration.",
        "sources": [
          {
            "id": "stat-002-apply",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.002",
            "citation": "Tex. Bus. & Com. Code § 541.002(a).",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "The TDPSA applies to a person that does business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration — with no revenue or volume threshold.",
            "verbatimQuote": "This chapter applies only to a person that: (1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-002-apply"
          }
        ]
      },
      {
        "slug": "privacy-policy-contents",
        "label": "What must your Texas privacy policy contain?",
        "heading": "What must your Texas privacy policy contain?",
        "answerText": "The TDPSA prescribes the contents of the privacy notice directly. A controller must provide a reasonably accessible and clear privacy notice that lists the categories of personal data processed (including any sensitive data), the purposes of processing, how consumers exercise and appeal their rights, the categories of personal data shared with third parties and the categories of those third parties, and a description of the methods for submitting requests.",
        "sources": [
          {
            "id": "stat-102-notice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.102",
            "citation": "Tex. Bus. & Com. Code § 541.102(a).",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "A controller must provide a reasonably accessible and clear privacy notice listing the categories of personal data processed (including any sensitive data), the purposes, how to exercise and appeal rights, the categories of personal data shared with third parties, the categories of those third parties, and a description of the methods for submitting requests.",
            "verbatimQuote": "A controller shall provide consumers with a reasonably accessible and clear privacy notice that includes: (1) the categories of personal data processed by the controller, including, if applicable, any sensitive data processed by the controller; (2) the purpose for processing personal data; (3) how consumers may exercise their consumer rights under Subchapter B, including the process by which a consumer may appeal a controller's decision with regard to the consumer's request; (4) if applicable, the categories of personal data that the controller shares with third parties; (5) if applicable, the categories of third parties with whom the controller shares personal data; and (6) a description of the methods required under Section 541.055 through which consumers can submit requests to exercise their consumer rights under this chapter.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-102-notice"
          },
          {
            "id": "stat-103-optout",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.103",
            "citation": "Tex. Bus. & Com. Code § 541.103.",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "A controller that sells personal data or processes it for targeted advertising must clearly and conspicuously disclose that processing and how a consumer may opt out.",
            "verbatimQuote": "If a controller sells personal data to third parties or processes personal data for targeted advertising, the controller shall clearly and conspicuously disclose that process and the manner in which a consumer may exercise the right to opt out of that process.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-103-optout"
          }
        ]
      },
      {
        "slug": "vendor-contracts",
        "label": "What must your contracts with processors say?",
        "heading": "What must your contracts with processors say?",
        "answerText": "Whenever a processor handles personal data on your behalf, the TDPSA requires a written contract that governs the processing — making a data processing agreement a statutory requirement, not a best practice.",
        "sources": [
          {
            "id": "stat-104-contract",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.104",
            "citation": "Tex. Bus. & Com. Code § 541.104(b).",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "Processing carried out by a processor must be governed by a written contract between the controller and the processor.",
            "verbatimQuote": "A contract between a controller and a processor shall govern the processor's data processing procedures with respect to processing performed on behalf of the controller.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-104-contract"
          },
          {
            "id": "stat-104-terms",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.104",
            "citation": "Tex. Bus. & Com. Code § 541.104(b).",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "The controller-processor contract must include clear processing instructions, the nature and purpose of processing, the type of data, the duration, the parties' rights and obligations, and a requirement that the processor maintain confidentiality, delete or return data at the controller's direction, make compliance information available, cooperate with assessments, and bind subcontractors by written contract.",
            "verbatimQuote": "The contract must include: (1) clear instructions for processing data; (2) the nature and purpose of processing; (3) the type of data subject to processing; (4) the duration of processing; (5) the rights and obligations of both parties; and (6) a requirement that the processor shall: (A) ensure that each person processing personal data is subject to a duty of confidentiality with respect to the data; (B) at the controller's direction, delete or return all personal data to the controller as requested after the provision of the service is completed, unless retention of the personal data is required by law; (C) make available to the controller, on reasonable request, all information in the processor's possession necessary to demonstrate the processor's compliance with the requirements of this chapter; (D) allow, and cooperate with, reasonable assessments by the controller or the controller's designated assessor; and (E) engage any subcontractor pursuant to a written contract that requires the subcontractor to meet the requirements of the processor with respect to the personal data.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-104-terms"
          }
        ]
      },
      {
        "slug": "sensitive-data-consent",
        "label": "Do you need consent to process sensitive data?",
        "heading": "Do you need consent to process sensitive data?",
        "answerText": "Yes. The TDPSA requires opt-in consent before processing a consumer's sensitive data, and for a known child it requires handling the data in accordance with the federal Children's Online Privacy Protection Act. Sensitive data includes data revealing race or ethnicity, religion, health diagnoses, sexuality, or immigration status; genetic or biometric data used to identify a person; data from a known child; and precise geolocation.",
        "sources": [
          {
            "id": "stat-101-consent",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.101",
            "citation": "Tex. Bus. & Com. Code § 541.101(b)(4).",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "A controller may not process a consumer's sensitive data without consent, and must handle a known child's data in accordance with COPPA.",
            "verbatimQuote": "process the sensitive data of a consumer without obtaining the consumer's consent, or, in the case of processing the sensitive data of a known child, without processing that data in accordance with the Children's Online Privacy Protection Act of 1998 (15 U.S.C. Section 6501 et seq.).",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-101-consent"
          },
          {
            "id": "stat-102-salenotice",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.102(b)",
            "citation": "Tex. Bus. & Com. Code § 541.102(b).",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "A controller that sells sensitive personal data must include a fixed statutory notice to that effect in its privacy notice.",
            "verbatimQuote": "If a controller engages in the sale of personal data that is sensitive data, the controller shall include the following notice",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-102-salenotice"
          }
        ]
      },
      {
        "slug": "consumer-lawsuit",
        "label": "Can a consumer sue your business under the TDPSA?",
        "heading": "Can a consumer sue your business under the TDPSA?",
        "answerText": "No. The TDPSA expressly provides that it may not be construed as a basis for, or as being subject to, a private right of action — so consumers cannot sue under it. Enforcement is exclusively the Texas Attorney General's, who may seek civil penalties of up to $7,500 per violation after a 30-day cure period.",
        "sources": [
          {
            "id": "stat-156-nopra",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.156",
            "citation": "Tex. Bus. & Com. Code § 541.156.",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "The TDPSA bars any private right of action; only the Attorney General may enforce it.",
            "verbatimQuote": "This chapter may not be construed as providing a basis for, or being subject to, a private right of action for a violation of this chapter or any other law.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-156-nopra"
          },
          {
            "id": "stat-155-penalty",
            "authorityType": "primary-law",
            "tier": "primary-source-backed",
            "title": "Tex. Bus. & Com. Code § 541.155",
            "citation": "Tex. Bus. & Com. Code § 541.155(a).",
            "url": "https://statutes.capitol.texas.gov/Docs/BC/htm/BC.541.htm",
            "proposition": "After the cure period, a violator is liable for a civil penalty of up to $7,500 per violation, recoverable by the Attorney General.",
            "verbatimQuote": "A person who violates this chapter following the cure period described by Section 541.154 or who breaches a written statement provided to the attorney general under that section is liable for a civil penalty in an amount not to exceed $7,500 for each violation.",
            "anchor": "https://openagreements.org/practice-guides/privacy/us/texas#src-stat-155-penalty"
          }
        ]
      }
    ]
  }
}
