Back to the hub

Does the Texas TDPSA exempt small businesses?

Mostly, but not completely. Section 541.002(a)(3) applies the Texas law only to a person that is not a small business as defined by the United States Small Business Administration. One obligation survives: section 541.107 bars a small business from selling sensitive personal data without the consumer's prior consent.

Applies to: Businesses that conduct business in Texas or produce a product or service consumed by Texas residents and that process or engage in the sale of personal data; the small business carve-out in section 541.002(a)(3) determines whether the rest of the chapter attaches.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Texas wrote its privacy law without a revenue threshold, which makes it read as though it catches everyone. It does the opposite: it hands the applicability question to a federal agency.

What section 541.002 actually says

Section 541.002(a) of the Business and Commerce Code provides that the chapter "applies only to a person that:

(1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision."

Three conditions, joined by "and." Fail any one of them and the chapter does not attach. Most other state privacy laws set their own numbers, usually 100,000 residents' data or a mix of a smaller count and a revenue share. Texas set none. Whether you are covered turns entirely on the SBA size standard for your industry.

That is a genuinely different test, and it has a practical consequence: the answer is not the same for two companies with identical revenue in different sectors, because the SBA publishes size standards by NAICS code, some measured in employees and some in average annual receipts.

The obligation that survives the carve-out

The closing clause of 541.002(a)(3) points at section 541.107, which reads:

"(a) A person described by Section 541.002(a)(3) may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. (b) A person who violates this section is subject to the penalty under Section 541.155."

So a Texas small business is outside the chapter's notice requirements, consumer rights machinery, assessment duties, and response deadlines, but it may not sell sensitive personal data without prior consent, and the Attorney General's penalty provision applies if it does.

The drafting here is awkward and worth naming plainly. Section 541.002(a)(3) describes a person that is not a small business, yet section 541.107 applies to "a person described by Section 541.002(a)(3)" and is headed "Requirements for Small Businesses." Read with the "except to the extent" clause, the evident purpose is to catch small businesses with the sensitive-data bar. We quote both provisions rather than assert a resolution the text does not cleanly support, and the safe planning assumption is that a small business selling sensitive data needs prior consent.

Checking the 2025 amendments

Chapter 541 was amended in the 2025 session, so a page like this can go stale quietly. According to the Senate Research Center's bill analysis of C.S.H.B. 149, the only change that bill made to chapter 541 was to section 541.104(a), which concerns a processor's duty to assist a controller. Sections 541.002, 541.107 and 541.052 were not touched.

One limitation to state honestly: the Texas statute viewer at statutes.capitol.texas.gov did not return machine-readable text when this page was written, so the provisions above were read verbatim from the enrolled act, and the 2025 session was checked through the official bill analysis rather than the codified text.

If you are near the line

Growing past the SBA size standard does not phase you in. The controller duties, the privacy notice requirements, the response deadlines that apply state by state and the sensitive data consent rules all attach at once. If you are close, build the intake process before you need it, and see the full Texas overview for what the rest of the chapter requires.

Compliance checklist

  • Run the SBA size standard for your primary NAICS code, since Texas incorporates the federal definition rather than writing its own numbers.
  • Re-run it whenever headcount or receipts change materially, because the carve-out is a moving target rather than a one-time determination.
  • If you qualify as a small business, still identify every category of sensitive data you hold, because section 541.107 applies to you regardless.
  • Get prior consumer consent before any sale of sensitive data, and keep the consent records; the prohibition is on the sale, not on the collection.
  • Document the determination in writing, with the size standard used and the date, so you can show why the rest of the chapter did not attach.
  • Watch for growth past the size standard, at which point the full set of controller duties, notices, and response deadlines attaches at once.

Sources

Last verified: 2026-08-27

Informational, not legal advice.