Back to the hub

Does the Texas TDPSA apply to your business?

The Texas Data Privacy and Security Act applies to any business that operates in Texas or serves Texas residents, processes or sells personal data, and is not a small business under US Small Business Administration size standards. There is no revenue or consumer-count threshold; the small-business test is the gate.

Applies to: Businesses that operate in Texas or serve Texas residents, process or sell personal data, and are not a small business under SBA size standards.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Texas took a different route from most privacy states. Rather than setting a revenue figure or a consumer count, it borrows a federal definition of small business and uses that as the on-off switch. The practical effect is that many businesses cannot answer "does it apply to me?" by looking at their own dashboards; they have to check a size standard tied to their industry.

Who the TDPSA covers

The law applies to a person that conducts business in Texas or produces a product or service consumed by Texas residents, that processes or engages in the sale of personal data, and that is not a small business as defined by the US Small Business Administration. All three parts must be true. There is no revenue or consumer-count threshold anywhere in the test. If you are above the SBA small-business size standard for your sector and you handle personal data connected to Texas, you are likely covered.

The small-business gate, and its one exception

Because the gate is the SBA definition, the answer depends on which industry code applies to you and the size standard attached to it, whether measured by employee count or annual receipts. That is why two companies with identical revenue can land on opposite sides of the line. There is an important carve-out: even a small business that is otherwise outside the chapter may not sell sensitive data without the consumer's consent. So being a small business does not give you a free pass on sensitive-data sales.

What covered businesses must do

Covered businesses provide and maintain a clear privacy notice, and include the statutory notice if they sell sensitive data or biometric data. They apply data minimization and purpose limitation, obtain consent before processing sensitive data, and honor opt-outs, including a universal opt-out mechanism. They also conduct data protection assessments for high-risk processing and enter processor agreements. Texas consumers hold rights to access and confirm, correct, delete, data portability, opt out of targeted advertising, sale, and profiling for significant decisions, opt-in consent for sensitive data, the universal opt-out mechanism, and appeal.

How Texas compares

The absence of any numeric threshold sets Texas apart from the CCPA, which measures revenue and consumer volume, and from the Colorado Privacy Act, which counts consumers. A business too small for California or Colorado could still be covered in Texas, or exempt there while covered elsewhere. The US state privacy laws hub shows the contrast.

Next step

Working out your SBA size standard and whether the sensitive-data sale rule reaches you is fiddly. The free 2-minute Obligation Scan runs the Texas gate for you and flags the notice and consent duties that follow, so you spend time on real obligations rather than on the classification puzzle.

Compliance checklist

  • Check whether you are a small business under US Small Business Administration size standards for your industry.
  • If you are covered, provide and maintain a clear privacy notice.
  • Include the statutory notice if you sell sensitive data or biometric data, which applies even to small businesses selling sensitive data.
  • Obtain consent before processing sensitive data and honor a universal opt-out mechanism.
  • Conduct data protection assessments for high-risk processing and enter processor agreements.

Sources

Last verified: 2026-07-23

Informational, not legal advice.