Texas: The TDPSA and What It Requires of Advertisers
Texas has no revenue threshold and no consumer-count threshold. California exempts businesses under $25 million in revenue or fewer than 50,000 consumers. Texas exempts almost nobody: if you process personal data and you are not a small business under Small Business Administration size standards, you are likely covered regardless of size — and even an SBA-exempt small business must obtain consent before selling sensitive data. A company too small for California to notice can sit squarely inside Texas — which makes this the state most likely to surprise a growing ecommerce marketing operation.
A state analysis from Digital, Ecommerce & Performance Marketing in the United States. Companion to the California analysis. This is marketing commentary, not legal advice. Applicability depends on your business and data practices — engage qualified counsel. Last reviewed August 2026.
1. The threshold difference that catches people
Most state privacy laws include size thresholds that keep smaller businesses out of scope. Texas does not work that way, and this is the single most consequential thing for a mid-market digital marketing team to understand.
| Test | California | Texas |
|---|---|---|
| Revenue threshold | $25 million | None |
| Consumer-count threshold | 50,000 consumers | None |
| Basis for exemption | Size and activity | SBA small business definition |
| Small business fully exempt? | Generally yes below thresholds | Not if selling sensitive data |
Sources: TDPSA applicability analysis noting no fixed revenue threshold and no fixed consumer-count threshold, with exemption resting on SBA-defined small business status; Texas Attorney General guidance that small businesses must still obtain consent before selling sensitive data. Whether your business is covered is a legal determination.
A business that concluded it was too small for privacy law probably reached that view by reading California. Texas asks a completely different question, and the answer is frequently the opposite.
2. Opt-in, not opt-out, for sensitive data
California operates an opt-out model. Texas follows an opt-out model for general personal data but requires opt-in consent before collecting or processing sensitive personal data, including data from children under 13.
| Sensitive category | Where marketers encounter it |
|---|---|
| Precise geolocation | Store locators, location-based targeting, mobile SDKs |
| Health information | Symptom quizzes, condition-based content, pharmacy flows |
| Biometric data | Face or voice features in apps and try-on tools |
| Racial or ethnic origin | Diversity forms, audience research, some personalisation |
| Religious beliefs | Dietary preferences, faith-based product interest |
| Children under 13 | Any product with young users |
Sensitive categories as reported under the TDPSA, including precise geolocation, biometric data, health information, racial or ethnic origin, religious beliefs and data from children under 13. Marketing contexts are illustrative examples, not legal classification.
The timing requirement is the part that breaks implementations. Consent must appear before collection occurs — the decision point must precede the data flow rather than follow it. A banner that loads after a location SDK has already fired has satisfied nothing, which makes tag sequencing a performance marketing responsibility rather than a legal one.
3. The notice Texas makes you print
This is the most unusual provision in the statute and one that almost no other state replicates. If you sell sensitive personal data, your privacy policy must contain a conspicuous statement in specified wording: NOTICE: We may sell your sensitive personal data. A parallel notice applies to biometric or genetic data.
Source: reported TDPSA requirement that privacy policies of controllers selling sensitive personal data carry a conspicuous notice in prescribed wording, with an analogous notice for biometric or genetic data. Exact statutory wording and placement should be confirmed with counsel.
The strategic reading matters more than the compliance one. A required disclosure written in plain, unflattering language functions as a deterrent rather than a formality. Before designing how to present it, it is worth asking whether the underlying data sale earns its keep.
4. GPC has been mandatory since January 2025
Texas has required controllers engaged in the sale of personal data or targeted advertising to recognise universal opt-out mechanisms such as Global Privacy Control since 1 January 2025, and the Attorney General has indicated that compliance with this requirement is an enforcement priority.
| Requirement | What it means operationally |
|---|---|
| Detect GPC automatically | Server or tag layer must read the signal |
| Treat it as opt-out of sale and targeted advertising | One signal, two effects |
| Add no friction | No confirmation step, no extra clicks |
| Change behaviour in real time | Scripts must stop, not just preferences store |
| Enforce at network and analytics level | Cookie-level blocking alone is insufficient |
Based on published TDPSA guidance that universal opt-out signals must trigger immediate behavioural changes in how scripts operate rather than only preference storage, and that behavioural ad pixels must honour GPC at the network and analytics level rather than the cookie level alone.
That last row is where most implementations fail. Blocking a cookie while the pixel still transmits does not stop the data flow, and Texas frames the opt-out as a real-time instruction rather than a stored preference.
5. Where the Attorney General is looking
Public reporting on the enforcement docket suggests three areas of focus through 2026.
| Focus area | Who it catches |
|---|---|
| Biometric or location data without clear consent | Apps, retail location targeting, try-on tools |
| Data brokers and ad tech failing to honour opt-outs | The programmatic supply chain |
| Targeting children or vulnerable populations | Gaming, edtech, some consumer brands |
Source: public reporting on Texas Attorney General privacy enforcement priorities through 2026. Enforcement focus can change; treat as directional rather than definitive.
If your stack touches any of those three, Texas compliance work should be prioritised ahead of states with more theoretical enforcement records.
6. Cure period and who can sue
Two structural features make Texas a different risk profile from California, and both cut in the defendant’s favour.
| Feature | Texas position | Practical effect |
|---|---|---|
| Cure period | 30 days from notice | Chance to fix before penalties |
| Private right of action | None | Consumers cannot sue directly |
| Enforcement authority | Attorney General exclusively | Single, predictable enforcer |
| Civil penalty | Up to $7,500 per violation | Scales badly with record counts |
| Response deadline | 45 days, one 45-day extension | Operational process required |
| Appeal right | Consumer may appeal a refusal | Needs a documented workflow |
Sources: reported TDPSA enforcement structure — exclusive Attorney General enforcement with no private right of action, 30-day cure period, civil penalties up to $7,500 per violation, 45-day consumer response deadline with one permitted extension, and a right to appeal a controller’s refusal.
The absence of a private right of action matters commercially. It means Texas exposure arrives as a regulator’s letter with a fixed window to respond, not as a class action. That is a meaningfully more manageable risk — but note the penalty is per violation, and violations in data cases tend to be counted per affected record.
7. TRAIGA and processor contracts
Texas has added AI-related data protection obligations to processor contracts through the Texas Responsible AI Governance Act. For marketers this lands in the same place as the rest of vendor management: agreements with ad tech, analytics providers and agencies need reviewing against a moving requirement set rather than signed once.
Separately, businesses that buy, sell or licence personal data may meet the data broker definition and need to register with the Texas Secretary of State — a registration obligation that catches some companies who do not think of themselves as brokers at all.
8. Texas against California, side by side
The two states are frequently treated as interchangeable in compliance planning. They are not, and the differences run in both directions.
| Dimension | California | Texas |
|---|---|---|
| Size thresholds | Revenue and consumer count | None; SBA status only |
| Sensitive data | Right to limit use | Opt-in consent before processing |
| Mandated notice wording | No direct equivalent | Prescribed sensitive-data notice |
| Cure period | Not available in the same form | 30 days |
| Private right of action | Limited, breach-related | None |
| Dedicated privacy agency | Yes | No; Attorney General |
Comparison assembled from published analyses of both statutes. Simplified for marketing planning — the legal position on any specific point requires counsel.
Building to California covers a lot of Texas but not the part that matters most: opt-in consent for sensitive data, and the fact that being small does not get you out.
9. What this page does not cover
| Not covered | Why |
|---|---|
| Whether TDPSA applies to your business | Turns on SBA status and activity |
| Exact statutory notice wording | Must be taken from the statute itself |
| Data broker registration process | Secretary of State procedure |
| TRAIGA obligations in detail | Separate and evolving regime |
| Texas Medical Records Privacy Act | Distinct health data statute |
| Contract drafting | Legal work |
Scope statement. Texas also has sector-specific statutes including a medical records privacy law that reaches marketing uses of health data. This page addresses the TDPSA’s marketing implications only.
10. The compliance sequence
Indicative sequencing. Confirming exemption status comes first because many businesses assume they are out of scope based on California thresholds that Texas does not use.
11. Mistakes to avoid
| Mistake | Why it happens | What it costs |
|---|---|---|
| Assuming you are too small to be covered | California thresholds anchor expectations | Texas uses no such thresholds |
| Treating sensitive data as opt-out | California habit | Texas requires opt-in first |
| Consent banner loading after the SDK | Tag order never audited | Data flowed before the decision |
| Blocking cookies but not pixels | Cookie-level CMP configuration | Transmission continues regardless |
| Adding a confirmation step to opt-out | Seems careful | Friction is itself the problem |
| Ignoring data broker registration | Do not self-identify as a broker | Definition may still catch you |
Recurring errors in TDPSA compliance for marketing teams; illustrative.
12. What changes next
Enforcement ramps through 2026. The Attorney General has signalled increasing activity, with universal opt-out compliance named as a priority and biometric, location and children’s data as focus areas.
AI obligations spread into contracts. TRAIGA has introduced AI-related data protection requirements into processor agreements, which means vendor paperwork signed before 2026 is likely already out of date.
Multi-state coordination continues. With roughly twenty states now operating comprehensive privacy laws and regulators increasingly running joint sweeps, a failure that shows up in one state tends to be visible in several.
Key Takeaways
- Texas has no revenue or consumer-count threshold. If you are not an SBA small business you are likely covered, whatever your size.
- Even exempt small businesses must obtain consent before selling sensitive data. There is no clean escape.
- Sensitive data requires opt-in consent before collection — geolocation, health, biometrics, race, religion, under-13 data.
- Consent must precede the data flow. A banner that loads after the SDK fires has achieved nothing.
- If you sell sensitive data, a prescribed notice must appear in your privacy policy — deliberately blunt wording that functions as a deterrent.
- GPC has been mandatory since January 2025 and must be honoured at network and analytics level, not just cookies.
- No private right of action and a 30-day cure period make Texas exposure more manageable than California’s — but penalties run per violation.
Frequently Asked Questions
We are under California’s thresholds. Are we exempt in Texas too?
Almost certainly not on the same basis. Texas has no revenue or consumer-count threshold; exemption rests on being a small business under SBA size standards, which vary by industry. Many businesses that fall outside California fall inside Texas.
What counts as sensitive data in Texas?
Reported categories include precise geolocation, biometric data, health information, racial or ethnic origin, religious beliefs, and data from children under 13. Processing any of these requires opt-in consent rather than an opt-out opportunity.
Why does consent timing matter so much?
Because Texas requires the decision point to precede the data flow. If a location SDK, biometric tool or health-related form transmits before consent is captured, the requirement has not been met regardless of what the banner says afterwards.
Is honouring GPC in our cookie banner sufficient?
Generally not. Guidance indicates opt-out signals must trigger immediate behavioural change in how scripts operate, enforced at network and analytics level. Blocking a cookie while a pixel continues transmitting does not stop the underlying data flow.
Do we really have to print that notice?
If you sell sensitive personal data, a conspicuous notice in prescribed wording is required, with an analogous notice for biometric or genetic data. Before designing around it, consider whether the data sale is worth having that sentence on your privacy page.
Can Texas consumers sue us?
No. Enforcement rests exclusively with the Attorney General and there is no private right of action, so consumers may complain but cannot bring claims directly. That makes the risk profile more predictable than states allowing private suits.
What does the cure period actually give us?
Thirty days from notice to remediate before enforcement proceeds. It is a genuine advantage over regimes without one, but it only helps if you can identify and fix the problem quickly — which requires knowing your data flows in advance.
Could we be a data broker without realising?
Possibly. Businesses that buy, sell or licence personal data may meet the definition and require registration with the Texas Secretary of State. Companies whose core business is something else often do not check.
What should we do first?
Confirm whether you are genuinely exempt, then inventory every point where sensitive data is collected and check what fires before consent is captured. Those two steps resolve the majority of Texas-specific exposure for a marketing team.
Conclusion
Texas is the state most likely to catch a business that thought it was too small to worry. It sets no revenue or consumer-count threshold, requires opt-in consent before sensitive data is collected rather than an opt-out afterwards, and has required universal opt-out signals to be honoured since the start of 2025 — at network level, not just in a cookie banner.
Against that it offers a thirty-day cure period, a single enforcer and no private right of action, which makes the exposure more manageable than California’s once you know about it. The failure mode is not aggressive enforcement against companies who tried. It is companies who read the California thresholds, concluded privacy law did not apply to them, and never looked at the state where the thresholds do not exist.
Texas sits alongside California and Washington in the US digital, ecommerce and performance marketing cluster. The capability pages on Google Ads and first-party data cover the technical work these obligations imply.
Work With Me
If you concluded you were below the threshold for privacy compliance, it is worth checking which state’s threshold you were reading. Texas does not have one.
