Back to the hub

What must a Texas TDPSA privacy notice include?

Texas Business and Commerce Code section 541.102 requires a reasonably accessible and clear privacy notice covering six items: the categories of personal data processed, the purpose, how consumers exercise rights and appeal, categories shared with third parties, categories of those third parties, and the request methods under section 541.055.

Applies to: Controllers subject to the Texas Data Privacy and Security Act, and any business that sells sensitive data or biometric data, which must post the statutory sale notices even where the chapter otherwise does not apply.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Texas wrote its privacy notice rule as a list. Six items in the main notice, plus two sentences of mandated wording that only apply if you sell certain data. The list is short enough to audit an existing notice against in an afternoon.

The six items in Section 541.102(a)

A controller shall provide consumers with a reasonably accessible and clear privacy notice that includes:

the categories of personal data processed by the controller, including, if applicable, any sensitive data processed; the purpose for processing personal data; how consumers may exercise their consumer rights under Subchapter B, including the process by which a consumer may appeal a controller's decision with regard to the consumer's request; if applicable, the categories of personal data that the controller shares with third parties; if applicable, the categories of third parties with whom the controller shares personal data; and a description of the methods required under Section 541.055 through which consumers can submit requests to exercise their consumer rights.

Two of those are conditioned on "if applicable." The other four are not. And note what item three actually asks for: not just how to make a request, but how to appeal a refusal. Notices written for other states often stop at the request.

The two sentences Texas puts in your mouth

Most state privacy laws describe what a notice must convey. Texas, in two cases, dictates the words.

Section 541.102(b): if a controller engages in the sale of personal data that is sensitive data, the controller shall include the following notice: "NOTICE: We may sell your sensitive personal data." The notice must be posted in the same location and in the same manner as the privacy notice described by Subsection (a).

Section 541.102(c) does the same for biometric data: "NOTICE: We may sell your biometric personal data."

These are separate obligations. A business selling both owes both sentences. And because the placement requirement is tied to the main privacy notice, burying either in a sub-page does not satisfy the section.

Where the notice sits among your other duties

The notice is the transparency half of a pair. Section 541.101 carries the substantive duties: limit collection to what is adequate, relevant, and reasonably necessary for the disclosed purposes; maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the data; do not process for purposes incompatible with what you disclosed without consent; do not discriminate against a consumer for exercising rights; and do not process sensitive data without consent. That last duty has its own page: Texas TDPSA sensitive data consent.

Section 541.103 adds a further disclosure. If a controller sells personal data to third parties or processes personal data for targeted advertising, it must clearly and conspicuously disclose that processing and the manner in which a consumer may exercise the right to opt out of it. In practice that lives in the same notice, and pairs with the opt-out mechanics covered in Texas TDPSA browser opt-out signals.

One thing worth checking before you rewrite

The TDPSA has no revenue or consumer-count threshold. Applicability under Section 541.002 turns on whether you conduct business in Texas or produce a product or service consumed by Texas residents, process or sell personal data, and are not a small business as defined by the United States Small Business Administration. The Texas TDPSA applicability page walks through that test.

Next step

The free 2-minute Obligation Scan tells you which state privacy laws reach your business and what each one requires in the notice, so you can write one notice that satisfies several states rather than maintaining a page per jurisdiction. The US state privacy laws hub compares those requirements side by side.

Compliance checklist

  • List the categories of personal data you process, and flag any sensitive data among them, as Section 541.102(a)(1) requires.
  • State the purpose for processing personal data, and the categories of personal data you share with third parties along with the categories of those third parties, where applicable.
  • Describe how consumers exercise their rights, including the appeal process, and describe the submission methods required by Section 541.055.
  • If you sell sensitive data, post the exact sentence 'NOTICE: We may sell your sensitive personal data.' in the same place and manner as the privacy notice.
  • If you sell biometric data, post the exact sentence 'NOTICE: We may sell your biometric personal data.' the same way; the two notices are separate duties and you may owe both.

Sources

Last verified: 2026-08-19

Informational, not legal advice.