Texas TDPSA exemptions: which businesses are exempt?
The Texas Data Privacy and Security Act exempts state agencies, financial institutions or Gramm-Leach-Bliley data, HIPAA covered entities and business associates, nonprofits, higher education institutions, and electric utilities under Section 541.002(b). Section 541.003 exempts seventeen data categories. Small businesses sit outside the Act, except for the sensitive-data consent duty in Section 541.107.
Applies to: Any business deciding whether the Texas Data Privacy and Security Act reaches it, including out-of-state businesses that produce a product or service consumed by Texas residents.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanTexas wrote its applicability test differently from every other state, and that changes which exemption question you should be asking. There is no revenue figure to check and no consumer count to tally. Chapter 541 asks what you do, not how big you are, with one size-based exclusion that has a hole in it.
The applicability test in Section 541.002(a)
Section 541.002(a) says the chapter applies only to a person that meets all three of the following: it conducts business in this state or produces a product or service consumed by residents of this state; it processes or engages in the sale of personal data; and it is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by that subdivision.
The first limb reaches out-of-state businesses directly. You do not need a Texas office, a Texas entity, or Texas employees. Producing a product or service consumed by Texas residents is enough on its own.
The six entity exemptions in Section 541.002(b)
Section 541.002(b) states that the chapter does not apply to:
- a state agency or a political subdivision of this state;
- a financial institution or data subject to Title V, Gramm-Leach-Bliley Act;
- a covered entity or business associate governed by the HIPAA privacy, security, and breach notification rules at 45 C.F.R. Parts 160 and 164, together with the HITECH Act;
- a nonprofit organization;
- an institution of higher education; or
- an electric utility, a power generation company, or a retail electric provider, as those terms are defined by Section 31.002 of the Utilities Code.
These are entity-level exclusions. If one applies, the chapter is switched off for that entity, not merely for particular records. Note the drafting in the second item: it exempts a financial institution or the data subject to Gramm-Leach-Bliley, so Texas gives banks the entity-level version of the carve-out, unlike California, whose exemption at Section 1798.145(e) is data-level.
Section 541.004 adds a further exclusion that sits outside the list: the chapter does not apply to the processing of personal data by a person in the course of a purely personal or household activity.
The seventeen data exemptions in Section 541.003
Section 541.003 is a different kind of provision, and it is regularly mislabeled. It exempts information, not businesses, so a fully covered controller can hold exempt records while remaining subject to the chapter for everything else.
The seventeen categories cover: HIPAA protected health information; health records; patient identifying information under 42 U.S.C. Section 290dd-2; identifiable private information used in human subjects research under 45 C.F.R. Part 46, the ICH good clinical practice guidelines, or 21 C.F.R. Parts 50 and 56, and research personal data used in accordance with the chapter; information created under the Health Care Quality Improvement Act; patient safety work product; deidentified health care information; information intermingled to be indistinguishable with exempt information held by a HIPAA covered entity or business associate; limited data sets under 45 C.F.R. Section 164.514(e); information collected or used only for HIPAA-authorized public health activities; consumer report information to the extent regulated by the Fair Credit Reporting Act; data handled under the Driver's Privacy Protection Act; data regulated by FERPA; data handled under the Farm Credit Act; employment data processed in the course of an individual applying to, being employed by, or acting as an agent or independent contractor of a controller, processor, or third party; emergency contact information used for emergency contact purposes; and benefits-administration data relating to an employed individual.
That employment carve-out at Section 541.003(15) is the one most SaaS companies rely on without noticing. Your own employee and applicant records sit outside the chapter, while your customers' data does not.
The small business exclusion, and what survives it
Section 541.002(a)(3) keeps SBA-defined small businesses outside the chapter, but expressly preserves Section 541.107 against them. Section 541.107(a) provides that a person described by Section 541.002(a)(3) may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. Section 541.107(b) makes a violation subject to the penalty under Section 541.155.
So the accurate statement is not that small businesses are exempt from the TDPSA. It is that they are exempt from everything except the sensitive-data sale consent duty, and that duty carries the same penalty machinery as the rest of the chapter. The small business exemption page covers how the SBA definition works in practice, and sensitive data consent covers what counts as sensitive.
Nebraska built the same structure into its own act, which is worth knowing if you operate in both.
Effective date
Every section discussed here was added by Acts 2023, 88th Legislature, Regular Session, Chapter 995 (H.B. 4), Section 2, effective July 1, 2024. Sections 541.002, 541.003, and 541.107 carry no amendment notes and stand as enacted. For the chapter as a whole, see the Texas TDPSA overview, and compare with Virginia's exemptions, which are structured around thresholds Texas does not use.
Next step
If you serve Texas residents and are not sure whether an exemption reaches you, the free 2-minute Obligation Scan applies the Section 541.002 test to your business and tells you which Texas duties, if any, you owe.
Compliance checklist
- Run the three-part Section 541.002(a) test before anything else, since Texas has no revenue or record-count threshold to fall back on.
- Check whether you fall inside one of the six entity exclusions in Section 541.002(b), which are entity-level and switch off the whole chapter.
- Check separately whether specific data you hold is exempt under one of the seventeen categories in Section 541.003, which exempt data rather than businesses.
- If you qualify as an SBA small business, confirm you still meet Section 541.107 before selling any sensitive data, because that duty survives the exclusion.
- Note the effective date: Chapter 541 was added by H.B. 4 and took effect July 1, 2024.
Sources
- Tex. Bus. & Com. Code ch. 541 (Consumer Data Protection), Sections 541.002, 541.003, 541.004 and 541.107, Texas Statutes
- Tex. Bus. & Com. Code ch. 541, official PDF, Texas Statutes
Last verified: 2026-09-08
Informational, not legal advice.