Back to the hub

Texas TDPSA vs CCPA: what's the difference?

The CCPA applies to for-profits meeting a threshold, such as $25 million in revenue or 100,000 California consumers. The Texas TDPSA has no revenue or consumer-count threshold; it applies to any business over the US Small Business Administration size standard that processes or sells personal data connected to Texas.

Applies to: Businesses working out whether the Texas TDPSA, the California CCPA, or both apply, typically companies serving residents of both states.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Texas and California landed on two different ideas of who a privacy law should cover. California draws a line with numbers, revenue and consumer counts. Texas skips numbers entirely and borrows a federal small-business definition as its on-off switch. The result is that a business can be covered in one state and exempt in the other while looking identical on paper, so comparing the two is really about comparing their front doors.

How each law decides who is covered

The CCPA, as amended by the CPRA, applies to a for-profit business that handles California residents' personal information and meets at least one threshold under Cal. Civ. Code Section 1798.140(d): annual gross revenue over $25 million, buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50 percent or more of revenue from selling or sharing that information. The Texas TDPSA, under Tex. Bus. & Com. Code Section 541.002, applies to a person that conducts business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the US Small Business Administration. No revenue or consumer figure appears anywhere in the Texas test.

Where the thresholds diverge

The practical gap shows up with mid-sized companies. A business under all three CCPA thresholds has no California exposure, yet the same business can be covered in Texas the moment it clears the SBA small-business size standard for its industry, which is measured by employee count or annual receipts depending on the sector. That is why two firms with matching revenue can sit on opposite sides of the Texas line, and why the Texas applicability test has to be run against an industry code rather than a dashboard.

What each requires

The obligations rhyme more than the thresholds do. Both give consumers rights to access, correct, delete, and port their data, both require honoring opt-outs for targeted advertising, sale, and certain profiling, and both require opt-in consent before processing sensitive data. The CCPA centers on notice at collection, a Do Not Sell or Share link, and Global Privacy Control handling, detailed on the CCPA applicability page. Texas layers in data protection assessments for high-risk processing and a statutory notice when a business sells sensitive or biometric data. A program built to the stricter of the two on each topic will generally carry both.

When both apply

A SaaS company selling into both states owes each law independently, and neither analysis cancels the other. The move is not to pick one but to map where your users are and meet the higher bar on each requirement. If you also have EU users, the same logic extends to the GDPR, which the CCPA versus GDPR comparison sets out. Running one strong program beats maintaining three thin ones.

Next step

If you serve customers in both Texas and California and are not sure which law reaches you, the free 2-minute Obligation Scan runs the CCPA thresholds and the Texas small-business gate against your business and lists the duties that follow under each. The US state privacy laws hub shows how the two fit with the rest of the enacted state laws.

Compliance checklist

  • List the states whose residents' data you handle, since each law is triggered by a connection to that state.
  • Run the CCPA test: a for-profit handling California residents' data that meets one threshold ($25 million revenue, 100,000 consumers or households, or 50% of revenue from selling or sharing data).
  • Run the TDPSA test: you conduct business in Texas or serve Texas residents, process or sell personal data, and are not a small business under US Small Business Administration size standards.
  • Note that Texas has no numeric threshold, so company size under the SBA standard, not revenue, is the gate.
  • If both apply, build one program to the stricter rule on each topic, and honor a universal opt-out signal and sensitive-data consent, which both laws require.

Sources

Last verified: 2026-08-11

Informational, not legal advice.