TDPSA Compliance for Texas Startups: What the Texas Data Privacy and Security Act Requires

The Texas Data Privacy and Security Act (TDPSA) took effect July 1, 2024 with no revenue threshold. Here is what Texas startups must do: personal data scope, consumer rights, 45-day response deadline, DPA requirements, AG enforcement, and TRAIGA overlap.

Abstract digital fresco: a translucent teal faceted enclosure on deep navy holds a dark crystal cluster with cream glints, its perimeter traced by thin copper lattice lines and nodes.
Loading AudioNative Player...

On July 1, 2024, Texas became one of the largest states in the nation to enact a comprehensive consumer privacy law. The Texas Data Privacy and Security Act (TDPSA), codified at Chapter 541 of the Texas Business and Commerce Code, governs how companies collect, use, store, sell, and process the personal data of Texas residents. For startups based in Texas — or any startup whose product or service touches Texas consumers — the TDPSA creates compliance obligations that most founders have not yet mapped.

The urgency is real. The Texas Attorney General has exclusive enforcement authority under the TDPSA, and his office has already established a dedicated privacy enforcement task force within the Consumer Protection Division. In June 2024, Attorney General Ken Paxton announced that the new team would focus on "aggressive enforcement" of the state's privacy laws, with a stated focus on companies that "collect and sell data in an unauthorized manner, harm consumers financially, or use artificial intelligence irresponsibly." The AG's first TDPSA enforcement action followed in early 2025.

Meanwhile, the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective January 1, 2026, layers additional data-related obligations on any company developing or deploying AI systems in Texas. For startups building AI products that process consumer data, TDPSA and TRAIGA create overlapping compliance frameworks that must be addressed together. We cover TRAIGA's requirements in detail in our TRAIGA compliance guide.

This guide walks through what the TDPSA requires of Texas startups: who must comply, what counts as personal data, the consumer rights you must honor, the response deadlines that apply, data processing agreement requirements, and the enforcement risk you face if you get it wrong.

What Is the TDPSA and Why Texas Startups Should Care

The TDPSA was passed as House Bill 4 during the 88th Texas Legislature and signed into law in 2023. It took effect on July 1, 2024, making Texas the largest state by population to enact a comprehensive consumer privacy statute at that time.

What makes the TDPSA different from other state privacy laws — and particularly significant for startups — is its broad applicability. Unlike California's CCPA, Virginia's VCDPA, or Colorado's CPA, the TDPSA does not include revenue thresholds or minimum consumer-data-volume triggers. There is no "you only comply if you process data from 100,000+ consumers" cutoff. Instead, the law applies to any entity that conducts business in Texas or produces a product or service consumed by Texas residents and that processes personal data — subject only to a narrow set of exemptions.

For a Texas-based startup collecting email addresses, names, payment information, or behavioral data from users, the TDPSA applies. For a SaaS company headquartered in another state but serving Texas customers, the TDPSA applies. For an e-commerce platform that ships to Texas residents, the TDPSA applies. The only meaningful safe harbor for early-stage companies is the small business exemption, which we discuss below.

Who Must Comply Under the TDPSA

The TDPSA applies to controllers — entities that, alone or jointly with others, determine the purpose and means of processing personal data — and processors — entities that process personal data on behalf of a controller. The key applicability language covers entities that "conduct business in" Texas or "produce a product or service consumed by residents of" Texas, and that collect, use, store, sell, share, analyze, or process consumers' personal data.

The law defines a consumer as an individual who is a Texas resident acting only in an individual or household context. Critically, the TDPSA does not apply to individuals acting in a commercial or employment context — meaning B2B data and employee data are outside its scope. This is a significant distinction from California's CCPA, which has been expanded to cover employee data.

The Small Business Exemption

The TDPSA's primary exemption for startups is the small business exemption. Small businesses, as defined by the U.S. Small Business Administration (SBA), are generally exempt from most TDPSA requirements. The SBA's size standards vary by industry, using either revenue-based or employee-count thresholds — for example, a software company with fewer than 500 employees may qualify, while a retail business may qualify with under $8 million in average annual receipts.

But the exemption is not absolute. Even if your startup qualifies as a small business, you must still obtain consumer consent before selling sensitive personal data. This means that if your startup sells or shares sensitive data categories — health information, precise geolocation data, biometric identifiers, or children's data — the consent requirement applies regardless of your size.

Other Exemptions

The TDPSA also exempts several categories of entities entirely, including state government agencies, nonprofit organizations, public and private institutions of higher education, and entities regulated by federal data laws such as the Gramm-Leach-Bliley Act (GLBA) for financial institutions and HIPAA for healthcare providers. Data governed by the Fair Credit Reporting Act (FCRA), FERPA, and the Farm Credit Act is also outside the TDPSA's scope.

What Counts as Personal Data (and Sensitive Data)

Under Section 541.001(19) of the Texas Business and Commerce Code, "personal data" means any information — including sensitive data — that is linked or reasonably linkable to an identified or identifiable individual. The definition includes pseudonymous data when used in conjunction with additional information that links it to a specific person, but excludes deidentified data and publicly available information.

This is a broad definition. For a startup, the following categories of user data are personal data under the TDPSA: names, email addresses, physical addresses, phone numbers, IP addresses, cookie identifiers, device IDs, purchase histories, browsing behavior tied to a user account, and any other data that can be traced back to a specific Texas resident.

The TDPSA creates a subcategory called sensitive data that triggers additional obligations. Sensitive data includes:

  • Personal data revealing racial or ethnic origin, religious beliefs, or mental or physical health diagnosis
  • A consumer's citizenship or immigration status
  • Genetic data
  • Biometric data — fingerprint, voiceprint, eye retina or iris, or other unique biological characteristics used to identify a specific individual
  • Precise geolocation data — location within a radius of 1,750 feet
  • Personal data of a known child (under 13 years of age)

Controllers must obtain a consumer's consent before processing sensitive data. For children's data, parental consent is required. Consent means a "clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement" — not a pre-checked box or acceptance of a general terms-of-use document. If your startup collects precise geolocation data through a mobile app, health information through a wellness platform, or biometric identifiers for authentication, you need an affirmative, documented consent mechanism before processing begins.

For startups using biometric data for identity verification or authentication, the TDPSA's sensitive data requirements overlap with Texas's separate biometric privacy law — CUBI (the Capture or Use of Biometric Identifier Act). We cover CUBI's consent, retention, and destruction requirements in our Texas CUBI biometric privacy compliance guide.

Consumer Rights You Must Honor

The TDPSA grants Texas consumers seven specific rights over their personal data. As a controller, your startup must establish processes to receive and respond to requests to exercise each of these rights:

  1. Right to know: Consumers can confirm whether you are processing their personal data and obtain a copy of that data in a readable format.
  2. Right to correct: Consumers can request correction of inaccuracies in their personal data, taking into account the nature of the data and the purposes of processing.
  3. Right to delete: Consumers can request deletion of personal data they provided or that was obtained about them.
  4. Right to data portability: Consumers can obtain a copy of their personal data in a readily usable format that allows transfer to another entity.
  5. Right to opt out: Consumers can opt out of the processing of their personal data for purposes of (a) targeted advertising, (b) the sale of personal data, or (c) profiling in furtherance of decisions that produce legal or similarly significant effects — such as decisions about financial services, housing, insurance, healthcare, education, employment, or access to basic necessities.
  6. Right to appeal: If you decline a consumer's request, you must provide a process for the consumer to appeal your decision. If the appeal is denied, you must inform the consumer how to submit a complaint to the Texas Attorney General.
  7. Right against retaliation: You may not discriminate against a consumer for exercising their rights — including by charging different prices, denying goods or services, or providing a different quality of service.

You must establish two or more secure and reliable methods for consumers to submit requests. If your startup operates exclusively online and has a direct relationship with the consumer, an email address satisfies this requirement. You also may not require consumers to create a new account to submit a rights request.

The Universal Opt-Out Requirement

As of January 1, 2025, controllers must recognize and honor universal opt-out mechanisms — such as the Global Privacy Control (GPC) browser signal — that allow consumers to opt out of the sale of their personal data and targeted advertising through a single browser or device setting. If your startup sells personal data or engages in targeted advertising, your website and applications must be configured to detect and respond to these signals automatically.

The Response Deadline: What the Clock Really Says

One of the most common compliance questions we hear from founders is about the TDPSA's response deadline. The statute sets a clear timeline, but the details matter.

Controllers must respond to an authenticated consumer's request to exercise any right without undue delay and no later than 45 days after receiving the request. The response period may be extended by an additional 45 days when reasonably necessary — but only if the controller responds within the initial 45-day window and provides the consumer with a reason for the extension.

Responses to consumer requests must be free of charge, up to twice annually per consumer. If a request is unfounded, excessive, or repetitive, you may charge a reasonable administrative fee — but you must explain the basis for the charge.

If you decline a consumer's request, you must provide the consumer with notice of that decision, including a justification for the declination and instructions on how to appeal.

It is important to distinguish this 45-day consumer response deadline from the 30-day cure period that applies to TDPSA enforcement. Before the Texas AG can file an enforcement action, the AG must provide a written notice of violation and allow the company 30 days to cure the noticed violations. The company must provide a written statement and supporting documentation evidencing that the violations were cured, including whether internal policy changes were necessary to prevent future violations. A company that fails to cure within 30 days — or that breaches a written statement provided to the AG — faces civil penalties of up to $7,500 per violation.

For startups, the practical takeaway is that you need two separate timelines mapped: a 45-day clock for responding to individual consumer rights requests, and a 30-day clock for curing AG-noticed violations. Both must be built into your compliance workflow before either is triggered.

Data Processing Agreement (DPA) Requirements

If your startup uses third-party vendors to process personal data on your behalf — cloud hosting providers, analytics platforms, email service providers, AI model APIs — you are a controller and those vendors are your processors. The TDPSA requires controllers to enter into data processing contracts with their processors that include all elements required by the Act.

At a minimum, a TDPSA-compliant data processing agreement must:

  • Set out instructions for processing personal data, consistent with the controller's documented purposes
  • Require the processor to adhere to the controller's instructions and assist the controller in meeting its TDPSA obligations
  • Ensure the processor imposes the same data protection obligations on any sub-processors it engages, and that the controller has the right to object to sub-processors
  • Require the processor to assist the controller in responding to consumer rights requests
  • Require the processor to assist with data protection assessments
  • Require the processor to maintain appropriate security measures
  • Address deletion or return of personal data at the end of the contract term

Most standard vendor DPAs you receive from major SaaS providers (AWS, Google Cloud, Stripe, etc.) will include provisions that map to these requirements, but you should verify that each contract covers the TDPSA's specific obligations — not just GDPR or CCPA requirements. If a vendor's DPA is silent on TDPSA-specific terms, request an amendment or addendum.

Data Protection Assessments

The TDPSA requires controllers to conduct data protection assessments for certain processing activities that present a heightened risk of harm to consumers. These assessments are mandatory for processing that involves:

  • Targeted advertising
  • The sale of personal data
  • Profiling that presents reasonably foreseeable risks of unfair or deceptive treatment, financial or physical harm, or intrusion on private affairs
  • Processing of sensitive data
  • Any processing that presents a heightened risk of harm to consumers

Data protection assessments must be made available to the Texas AG upon request and are exempt from disclosure under the Texas Public Information Act. Importantly, providing an assessment to the AG does not waive attorney-client or work product privilege.

Texas AG Enforcement and Penalties

The Texas Attorney General has exclusive enforcement authority under the TDPSA. There is no private right of action — consumers cannot sue you directly for TDPSA violations. But the AG's enforcement powers are substantial:

  • The AG can issue civil investigative demands to investigate potential violations
  • Before filing an enforcement action, the AG must provide a written notice of violation and a 30-day cure period
  • After the cure period, the AG can file enforcement actions seeking civil penalties, injunctive relief, attorney's fees, and costs
  • Civil penalties reach up to $7,500 per violation

The AG's privacy enforcement team is not waiting for complaints to arrive. As Goodwin reported in June 2024, the AG has already sent notice letters to more than 100 businesses registered as data brokers in other states but not in Texas, and has opened investigations into car manufacturers' data practices under the Texas Deceptive Trade Practices Act. The AG's first TDPSA enforcement action — against Allstate over alleged unlawful collection and sale of geolocation data — was filed in early 2025.

How TRAIGA Overlaps With the TDPSA

For startups building or deploying AI systems, the TDPSA does not exist in isolation. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), enacted as House Bill 149 and effective January 1, 2026, creates an overlapping regulatory framework that compounds your data compliance obligations.

TRAIGA applies to any person who promotes, advertises, or conducts business in Texas, produces a product or service Texas residents use, or develops or deploys an AI system in Texas. It defines an "artificial intelligence system" broadly as "any machine-based system that, for any explicit or implicit objective, infers from the inputs the system receives how to generate outputs, including content, decisions, predictions, or recommendations, that can influence physical or virtual environments."

The overlap is concrete in three areas:

  1. Consumer data used for AI training: If your startup trains AI models on Texas consumers' personal data, the TDPSA's consent requirements for sensitive data apply — and TRAIGA adds prohibitions on using AI to infringe constitutional rights or unlawfully discriminate against protected classes.
  2. AI-driven decisions: The TDPSA's consumer right to opt out of profiling applies when profiling produces legal or similarly significant effects. TRAIGA independently prohibits AI systems from making decisions that violate state or federal civil rights laws. A startup using AI for credit scoring, hiring, or insurance underwriting must comply with both frameworks simultaneously.
  3. Enforcement convergence: Both the TDPSA and TRAIGA are enforced exclusively by the Texas AG. A single AG investigation can examine whether your AI system violates TRAIGA's prohibited-use rules and whether your data processing violates the TDPSA's consent, security, or consumer rights requirements.

TRAIGA also provides a safe harbor for companies that substantially comply with the NIST AI Risk Management Framework or similar recognized standards. While the TDPSA does not offer a comparable safe harbor, aligning your AI governance with the NIST AI RMF can help demonstrate that your data processing practices are reasonable — a factor that may influence the AG's enforcement discretion. For a deeper analysis of TRAIGA's requirements, see our TRAIGA compliance guide.

Privacy Notice and Security Obligations

Under the TDPSA, controllers must provide consumers with a reasonably accessible and clear privacy notice that includes:

  • The categories of personal data processed (including any sensitive data) and the purpose of processing
  • The categories of personal data shared with third parties, if any
  • The categories of third parties with whom personal data is shared
  • How consumers can exercise their rights under the Act, including the methods for submitting requests and how to appeal a controller's decision
  • If the company sells sensitive personal data or biometric data, specific disclosures: "We may sell your sensitive personal data" or "We may sell your biometric data"

Companies that sell personal data to third parties or process such data for targeted advertising must also clearly and conspicuously disclose that fact, along with the manner in which a consumer may exercise their right to opt out.

In addition to privacy notice requirements, controllers must establish, implement, and maintain reasonable data security practices to protect the confidentiality, integrity, and accessibility of personal data — appropriate to the volume and nature of the personal data processed. This is a duty-of-care standard, not a specific technical mandate, but it means that storing sensitive personal data in plaintext databases, failing to encrypt data in transit, or neglecting basic access controls would likely be considered unreasonable under the TDPSA.

Controllers must also limit collection of personal data to what is "adequate, relevant, and reasonably necessary" in relation to the disclosed purposes for processing — a data minimization principle that directly affects product design decisions.

Actionable Next Steps

  1. Determine whether your startup qualifies for the small business exemption. Check the SBA size standards for your industry. If you qualify, you are exempt from most TDPSA requirements — but you must still obtain consent before selling sensitive data. If you do not qualify, the full compliance framework applies.
  2. Inventory your personal data. Map every category of personal data your startup collects, where it is stored, who has access to it, and which vendors process it. Identify any sensitive data categories — health, biometric, geolocation, children's data — that trigger the consent requirement.
  3. Implement a consumer rights request process. Establish at least two methods for consumers to submit requests (email plus a web form is common for online startups). Designate a team member to monitor the intake, authenticate the requester, and track the 45-day response clock.
  4. Publish a TDPSA-compliant privacy notice. Review your existing privacy policy against the TDPSA's required disclosures. If you sell personal data or process for targeted advertising, add the required opt-out disclosures. If you sell sensitive or biometric data, add the specific statutory notices.
  5. Obtain consent for sensitive data processing. If you collect any sensitive data category, implement an affirmative, documented consent mechanism before processing begins. This is required even for small businesses.
  6. Audit your vendor DPAs. Review every data processing agreement with your cloud providers, analytics platforms, and AI vendors. Confirm that each contract includes the TDPSA's required terms — instructions, sub-processor controls, security assistance, and data return/deletion obligations.
  7. Conduct data protection assessments. If you engage in targeted advertising, sell personal data, process sensitive data, or conduct profiling with foreseeable risk, document a written assessment of the processing activity, its risks, and your mitigation measures.
  8. Configure universal opt-out recognition. If your startup sells personal data or engages in targeted advertising, ensure your website and applications detect and honor GPC or equivalent browser opt-out signals — required since January 1, 2025.
  9. Assess TRAIGA overlap if you build AI. If your product incorporates AI systems, evaluate whether TRAIGA's disclosure, prohibited-use, and safe-harbor provisions apply alongside your TDPSA obligations. Consider NIST AI RMF alignment as a compliance investment that satisfies both regimes.
  10. Engage counsel for a TDPSA compliance review. The cost of a proactive privacy compliance assessment is a fraction of the cost of a Texas AG enforcement action — with penalties of up to $7,500 per violation and no private right of action to prepare for. We help Texas startups build privacy compliance programs that satisfy the TDPSA, TRAIGA, and the broader state privacy law landscape simultaneously.

The TDPSA is not a future risk. It has been enforceable since July 1, 2024, the AG's enforcement team is active, and the penalties are real. Texas startups that build privacy compliance into their product architecture — consent flows, data minimization, vendor controls, consumer rights processes — will face the AG's enforcement environment with confidence. Startups that treat the TDPSA as a compliance afterthought will discover the gaps only when a civil investigative demand arrives — when the cost of fixing the problem is measured in penalties, not preparation time.

Need help building a TDPSA compliance program for your Texas startup? We help founders map their data flows, draft privacy notices, implement consumer rights processes, audit vendor agreements, and align TDPSA compliance with TRAIGA — before the AG's enforcement team comes asking.

Book a consultation