Does the Texas TDPSA require consent to process sensitive data?
Yes. Texas Business and Commerce Code section 541.101(b)(4) bars a controller from processing a consumer's sensitive data without consent, and for a known child requires COPPA-compliant handling. Even a small business outside the chapter may not sell sensitive data without the consumer's prior consent under section 541.107.
Applies to: Controllers subject to the Texas Data Privacy and Security Act that process sensitive data, and small businesses otherwise outside the chapter that sell sensitive data, which Section 541.107 still reaches.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanTexas treats sensitive data as a consent question, not a disclosure question. You cannot process it and explain yourself afterwards. And the one rule that survives the small-business exemption is the sensitive data rule, which catches businesses that had reasonably concluded the law did not apply to them.
The duty in Section 541.101(b)(4)
A controller may not process the sensitive data of a consumer without obtaining the consumer's consent, or, in the case of processing the sensitive data of a known child, without processing that data in accordance with the Children's Online Privacy Protection Act of 1998.
Note the ordering. This is a prohibition on processing, so consent comes first. An opt-out link, however prominent, does not satisfy a rule written as "may not process without consent."
For a known child the standard changes rather than raising. You are not asking the child for consent under state law; you are handling the data in accordance with COPPA, which routes you to verifiable parental consent and the federal framework.
What Texas counts as sensitive
The Chapter 541 definition names four groups. Sensitive data is a category of personal data, and the term includes:
personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; genetic or biometric data that is processed for the purpose of uniquely identifying an individual; personal data collected from a known child; and precise geolocation data.
Two of these catch businesses out routinely. Precise geolocation sits in ordinary product telemetry and delivery features. And the third group is categorical: anything collected from a known child is sensitive data, whatever the field contains. A shipping address becomes sensitive data when the person it belongs to is a known child.
The biometric limb is narrower than it first reads. It covers genetic or biometric data processed for the purpose of uniquely identifying an individual. Face data used to unlock a device is squarely in. The same data processed only to count how many people walked past a display is a different analysis, though the Texas biometric statute runs alongside Chapter 541 and has its own consent rule.
The small business trap in Section 541.107
The TDPSA has no revenue or consumer-count threshold. Section 541.002(a)(3) applies the chapter to a person that is not a small business as defined by the United States Small Business Administration, "except to the extent that Section 541.107 applies."
Section 541.107(a) is one sentence long: a person described by Section 541.002(a)(3) may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. Section 541.107(b) makes a violation subject to the penalty under Section 541.155.
So a small business that concluded, correctly, that the chapter does not apply to it still has one live obligation the moment it sells sensitive data. The Texas TDPSA applicability page covers the SBA size standard test.
What consent has to look like
Chapter 541's definition of consent is the familiar one across the state laws: a clear affirmative act signifying a freely given, specific, informed, and unambiguous agreement. In practice that rules out pre-ticked boxes, bundling the request into general terms, and inferring agreement from continued use.
If you sell sensitive data, Section 541.102(b) adds a separate disclosure on top of consent: the exact sentence "NOTICE: We may sell your sensitive personal data.", posted in the same location and manner as your privacy notice. The Texas privacy notice requirements page covers the rest of that notice.
Next step
Sensitive data definitions differ by state, and California's sensitive personal information list is broader in some places and narrower in others. The free 2-minute Obligation Scan tells you which state privacy laws reach your business and which of your data categories each one treats as sensitive.
Compliance checklist
- Inventory your data against the four sensitive categories, paying attention to precise geolocation and to biometric or genetic data processed to uniquely identify someone.
- Treat anything collected from a known child as sensitive data by definition, and handle it in accordance with the Children's Online Privacy Protection Act as Section 541.101(b)(4) requires.
- Collect consent before the processing starts, not after; the section prohibits processing without consent rather than requiring a later opt-out.
- If you are a small business under SBA size standards, confirm whether you sell any sensitive data: Section 541.107 reaches you even though the rest of the chapter does not.
- Disclose sensitive data in your privacy notice under Section 541.102(a)(1), and if you sell it, post the required sentence 'NOTICE: We may sell your sensitive personal data.'
Sources
- Tex. Bus. & Com. Code Sections 541.001 (definitions), 541.002 (applicability), 541.101 (controller duties), 541.107 (requirements for small businesses), as enacted by Acts 2023, 88th Leg., R.S., Ch. 995 (H.B. 4), effective July 1, 2024 - enrolled text, Texas Legislature Online
- Tex. Bus. & Com. Code Ch. 541 (Consumer Data Protection), Texas Constitution and Statutes
Last verified: 2026-08-19
Informational, not legal advice.