When does the Texas TDPSA require a data protection assessment?
Texas Business and Commerce Code section 541.105 requires a controller to conduct and document a data protection assessment for five activities: targeted advertising, the sale of personal data, profiling that carries a reasonably foreseeable risk of listed harms, processing sensitive data, and any processing that presents a heightened risk of harm.
Applies to: Controllers subject to the Texas Data Privacy and Security Act that run targeted advertising, sell personal data, profile consumers, process sensitive data, or carry out other processing that presents a heightened risk of harm to consumers.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanTexas does not ask for an assessment of everything you do with data. It names five processing activities and says: for these, do the analysis and write it down. If you advertise, sell data, profile people, or handle sensitive data, at least one of them is yours.
The five triggers in Section 541.105(a)
A controller must conduct and document a data protection assessment of each of the following: processing personal data for purposes of targeted advertising; the sale of personal data; processing for purposes of profiling, where the profiling presents a reasonably foreseeable risk of unfair or deceptive treatment of or unlawful disparate impact on consumers, financial, physical, or reputational injury to consumers, a physical or other intrusion on the solitude or seclusion, or the private affairs or concerns, of consumers that would be offensive to a reasonable person, or other substantial injury to consumers; the processing of sensitive data; and any processing activities involving personal data that present a heightened risk of harm to consumers.
Three of the five are flat duties. Targeted advertising, the sale of personal data, and sensitive data trigger the requirement on their face, with no risk test to argue about. Profiling is conditional: it only triggers the duty where one of the listed harms is reasonably foreseeable. The fifth is a deliberate catch-all, and it is the one where writing down why you concluded there was no heightened risk is worth as much as the assessment itself.
What the assessment has to contain
Section 541.105(b) sets the substance. The assessment must identify and weigh the direct or indirect benefits that may flow from the processing to the controller, the consumer, other stakeholders, and the public, against the potential risks to the rights of the consumer associated with that processing, as mitigated by safeguards that can be employed by the controller to reduce the risks.
It must also factor in four specific things: the use of deidentified data, the reasonable expectations of consumers, the context of the processing, and the relationship between the controller and the consumer whose personal data will be processed.
That is a balancing exercise rather than a form. A controller that concludes the processing is justified has still done the work the statute asks for, as long as the document shows how it got there.
Who sees it, and when
Section 541.105(c) requires a controller to make an assessment requested under Section 541.153(b) available to the attorney general, pursuant to a civil investigative demand under Section 541.153. The attorney general has exclusive enforcement authority under Section 541.151.
Section 541.105(d) protects the document on the way out. A data protection assessment is confidential and exempt from public inspection and copying under Chapter 552, Government Code. Disclosing one in compliance with an attorney general request does not constitute a waiver of attorney-client privilege or work product protection with respect to the assessment or the information in it.
Two provisions that save real work
Section 541.105(e) allows a single data protection assessment to address a comparable set of processing operations that include similar activities. You are not writing one per campaign.
Section 541.105(f) goes further: an assessment conducted for the purpose of compliance with other laws or regulations may constitute compliance with this section if it has a reasonably comparable scope and effect. If you already run GDPR Article 35 data protection impact assessments, or Virginia assessments under Section 59.1-580, that work is a realistic starting point rather than a parallel project.
Next step
If you are unsure whether the TDPSA reaches you at all, the applicability test is unusual: there is no revenue or consumer-count threshold, only the Small Business Administration size standard. The Texas TDPSA overview covers it. The free 2-minute Obligation Scan checks which state privacy laws apply to your business and which assessments each one expects.
Compliance checklist
- Map your processing against the five triggers in Section 541.105(a) and record which activities require an assessment and which do not.
- For profiling, document the risk analysis either way: the duty only bites where one of the listed harms is reasonably foreseeable, so your reasoning is the evidence.
- Build the balancing required by Section 541.105(b): weigh direct and indirect benefits to the controller, consumer, other stakeholders, and the public against risks to the consumer, as mitigated by your safeguards.
- Factor in the four items the statute names: use of deidentified data, the reasonable expectations of consumers, the context of the processing, and your relationship with the consumer.
- Store assessments so you can produce one on a civil investigative demand under Section 541.153; they are confidential and exempt from disclosure under Chapter 552, Government Code, and producing one does not waive privilege.
Sources
- Tex. Bus. & Com. Code Section 541.105 (data protection assessments), as enacted by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), effective July 1, 2024 - enrolled text, Texas Legislature Online
- Tex. Bus. & Com. Code Ch. 541 (Consumer Data Protection), Texas Constitution and Statutes
Last verified: 2026-08-19
Informational, not legal advice.