Texas: The TDPSA and What It Requires of Advertisers

Sharing is caring!

Texas has no revenue threshold and no consumer-count threshold. California exempts businesses under $25 million in revenue or fewer than 50,000 consumers. Texas exempts almost nobody: if you process personal data and you are not a small business under Small Business Administration size standards, you are likely covered regardless of size — and even an SBA-exempt small business must obtain consent before selling sensitive data. A company too small for California to notice can sit squarely inside Texas — which makes this the state most likely to surprise a growing ecommerce marketing operation.

A state analysis from Digital, Ecommerce & Performance Marketing in the United States. Companion to the California analysis. This is marketing commentary, not legal advice. Applicability depends on your business and data practices — engage qualified counsel. Last reviewed August 2026.

$0Revenue threshold to be covered
$7,500Civil penalty per violation
Opt-inRequired before sensitive data processing
Jan 2025GPC recognition already mandatory
30 daysCure period, unlike California
1Enforcer: the Attorney General alone

1. The threshold difference that catches people

Most state privacy laws include size thresholds that keep smaller businesses out of scope. Texas does not work that way, and this is the single most consequential thing for a mid-market digital marketing team to understand.

TestCaliforniaTexas
Revenue threshold$25 millionNone
Consumer-count threshold50,000 consumersNone
Basis for exemptionSize and activitySBA small business definition
Small business fully exempt?Generally yes below thresholdsNot if selling sensitive data

Sources: TDPSA applicability analysis noting no fixed revenue threshold and no fixed consumer-count threshold, with exemption resting on SBA-defined small business status; Texas Attorney General guidance that small businesses must still obtain consent before selling sensitive data. Whether your business is covered is a legal determination.

A business that concluded it was too small for privacy law probably reached that view by reading California. Texas asks a completely different question, and the answer is frequently the opposite.

2. Opt-in, not opt-out, for sensitive data

California operates an opt-out model. Texas follows an opt-out model for general personal data but requires opt-in consent before collecting or processing sensitive personal data, including data from children under 13.

Sensitive categoryWhere marketers encounter it
Precise geolocationStore locators, location-based targeting, mobile SDKs
Health informationSymptom quizzes, condition-based content, pharmacy flows
Biometric dataFace or voice features in apps and try-on tools
Racial or ethnic originDiversity forms, audience research, some personalisation
Religious beliefsDietary preferences, faith-based product interest
Children under 13Any product with young users

Sensitive categories as reported under the TDPSA, including precise geolocation, biometric data, health information, racial or ethnic origin, religious beliefs and data from children under 13. Marketing contexts are illustrative examples, not legal classification.

The timing requirement is the part that breaks implementations. Consent must appear before collection occurs — the decision point must precede the data flow rather than follow it. A banner that loads after a location SDK has already fired has satisfied nothing, which makes tag sequencing a performance marketing responsibility rather than a legal one.

3. The notice Texas makes you print

This is the most unusual provision in the statute and one that almost no other state replicates. If you sell sensitive personal data, your privacy policy must contain a conspicuous statement in specified wording: NOTICE: We may sell your sensitive personal data. A parallel notice applies to biometric or genetic data.

A compliance requirement that is also a conversion problem Texas prescribes the wording. There is no softer way to phrase it. NOTICE: We may sell your sensitive personal data. Most businesses reading that sentence decide they would rather not sell it. Which is, in all likelihood, the point of drafting it that way. The practical question is not how to display the notice well. It is whether the data flows behind it are worth the sentence sitting on your privacy page. Source: TDPSA required disclosure for controllers selling sensitive personal data. Confirm exact wording and placement with counsel.

Source: reported TDPSA requirement that privacy policies of controllers selling sensitive personal data carry a conspicuous notice in prescribed wording, with an analogous notice for biometric or genetic data. Exact statutory wording and placement should be confirmed with counsel.

The strategic reading matters more than the compliance one. A required disclosure written in plain, unflattering language functions as a deterrent rather than a formality. Before designing how to present it, it is worth asking whether the underlying data sale earns its keep.

4. GPC has been mandatory since January 2025

Texas has required controllers engaged in the sale of personal data or targeted advertising to recognise universal opt-out mechanisms such as Global Privacy Control since 1 January 2025, and the Attorney General has indicated that compliance with this requirement is an enforcement priority.

RequirementWhat it means operationally
Detect GPC automaticallyServer or tag layer must read the signal
Treat it as opt-out of sale and targeted advertisingOne signal, two effects
Add no frictionNo confirmation step, no extra clicks
Change behaviour in real timeScripts must stop, not just preferences store
Enforce at network and analytics levelCookie-level blocking alone is insufficient

Based on published TDPSA guidance that universal opt-out signals must trigger immediate behavioural changes in how scripts operate rather than only preference storage, and that behavioural ad pixels must honour GPC at the network and analytics level rather than the cookie level alone.

That last row is where most implementations fail. Blocking a cookie while the pixel still transmits does not stop the data flow, and Texas frames the opt-out as a real-time instruction rather than a stored preference.

5. Where the Attorney General is looking

Public reporting on the enforcement docket suggests three areas of focus through 2026.

Focus areaWho it catches
Biometric or location data without clear consentApps, retail location targeting, try-on tools
Data brokers and ad tech failing to honour opt-outsThe programmatic supply chain
Targeting children or vulnerable populationsGaming, edtech, some consumer brands

Source: public reporting on Texas Attorney General privacy enforcement priorities through 2026. Enforcement focus can change; treat as directional rather than definitive.

If your stack touches any of those three, Texas compliance work should be prioritised ahead of states with more theoretical enforcement records.

6. Cure period and who can sue

Two structural features make Texas a different risk profile from California, and both cut in the defendant’s favour.

FeatureTexas positionPractical effect
Cure period30 days from noticeChance to fix before penalties
Private right of actionNoneConsumers cannot sue directly
Enforcement authorityAttorney General exclusivelySingle, predictable enforcer
Civil penaltyUp to $7,500 per violationScales badly with record counts
Response deadline45 days, one 45-day extensionOperational process required
Appeal rightConsumer may appeal a refusalNeeds a documented workflow

Sources: reported TDPSA enforcement structure — exclusive Attorney General enforcement with no private right of action, 30-day cure period, civil penalties up to $7,500 per violation, 45-day consumer response deadline with one permitted extension, and a right to appeal a controller’s refusal.

The absence of a private right of action matters commercially. It means Texas exposure arrives as a regulator’s letter with a fixed window to respond, not as a class action. That is a meaningfully more manageable risk — but note the penalty is per violation, and violations in data cases tend to be counted per affected record.

7. TRAIGA and processor contracts

Texas has added AI-related data protection obligations to processor contracts through the Texas Responsible AI Governance Act. For marketers this lands in the same place as the rest of vendor management: agreements with ad tech, analytics providers and agencies need reviewing against a moving requirement set rather than signed once.

Separately, businesses that buy, sell or licence personal data may meet the data broker definition and need to register with the Texas Secretary of State — a registration obligation that catches some companies who do not think of themselves as brokers at all.

8. Texas against California, side by side

The two states are frequently treated as interchangeable in compliance planning. They are not, and the differences run in both directions.

DimensionCaliforniaTexas
Size thresholdsRevenue and consumer countNone; SBA status only
Sensitive dataRight to limit useOpt-in consent before processing
Mandated notice wordingNo direct equivalentPrescribed sensitive-data notice
Cure periodNot available in the same form30 days
Private right of actionLimited, breach-relatedNone
Dedicated privacy agencyYesNo; Attorney General

Comparison assembled from published analyses of both statutes. Simplified for marketing planning — the legal position on any specific point requires counsel.

Building to California covers a lot of Texas but not the part that matters most: opt-in consent for sensitive data, and the fact that being small does not get you out.

9. What this page does not cover

Not coveredWhy
Whether TDPSA applies to your businessTurns on SBA status and activity
Exact statutory notice wordingMust be taken from the statute itself
Data broker registration processSecretary of State procedure
TRAIGA obligations in detailSeparate and evolving regime
Texas Medical Records Privacy ActDistinct health data statute
Contract draftingLegal work

Scope statement. Texas also has sector-specific statutes including a medical records privacy law that reaches marketing uses of health data. This page addresses the TDPSA’s marketing implications only.

10. The compliance sequence

Consent before collection, not after: 12 weeks Week 0 Week 4 Week 8 Week 12 Confirm whether you are actually exempt Inventory sensitive data collection points Move consent ahead of the data flow Test GPC at network level Rights request and appeal workflow Processor contracts inc. TRAIGA Red = scope and inventory, amber = technical, green = process, grey = contracts. Indicative; run alongside counsel.

Indicative sequencing. Confirming exemption status comes first because many businesses assume they are out of scope based on California thresholds that Texas does not use.

11. Mistakes to avoid

MistakeWhy it happensWhat it costs
Assuming you are too small to be coveredCalifornia thresholds anchor expectationsTexas uses no such thresholds
Treating sensitive data as opt-outCalifornia habitTexas requires opt-in first
Consent banner loading after the SDKTag order never auditedData flowed before the decision
Blocking cookies but not pixelsCookie-level CMP configurationTransmission continues regardless
Adding a confirmation step to opt-outSeems carefulFriction is itself the problem
Ignoring data broker registrationDo not self-identify as a brokerDefinition may still catch you

Recurring errors in TDPSA compliance for marketing teams; illustrative.

12. What changes next

Enforcement ramps through 2026. The Attorney General has signalled increasing activity, with universal opt-out compliance named as a priority and biometric, location and children’s data as focus areas.

AI obligations spread into contracts. TRAIGA has introduced AI-related data protection requirements into processor agreements, which means vendor paperwork signed before 2026 is likely already out of date.

Multi-state coordination continues. With roughly twenty states now operating comprehensive privacy laws and regulators increasingly running joint sweeps, a failure that shows up in one state tends to be visible in several.

Key Takeaways

  • Texas has no revenue or consumer-count threshold. If you are not an SBA small business you are likely covered, whatever your size.
  • Even exempt small businesses must obtain consent before selling sensitive data. There is no clean escape.
  • Sensitive data requires opt-in consent before collection — geolocation, health, biometrics, race, religion, under-13 data.
  • Consent must precede the data flow. A banner that loads after the SDK fires has achieved nothing.
  • If you sell sensitive data, a prescribed notice must appear in your privacy policy — deliberately blunt wording that functions as a deterrent.
  • GPC has been mandatory since January 2025 and must be honoured at network and analytics level, not just cookies.
  • No private right of action and a 30-day cure period make Texas exposure more manageable than California’s — but penalties run per violation.

Frequently Asked Questions

We are under California’s thresholds. Are we exempt in Texas too?

Almost certainly not on the same basis. Texas has no revenue or consumer-count threshold; exemption rests on being a small business under SBA size standards, which vary by industry. Many businesses that fall outside California fall inside Texas.

What counts as sensitive data in Texas?

Reported categories include precise geolocation, biometric data, health information, racial or ethnic origin, religious beliefs, and data from children under 13. Processing any of these requires opt-in consent rather than an opt-out opportunity.

Why does consent timing matter so much?

Because Texas requires the decision point to precede the data flow. If a location SDK, biometric tool or health-related form transmits before consent is captured, the requirement has not been met regardless of what the banner says afterwards.

Is honouring GPC in our cookie banner sufficient?

Generally not. Guidance indicates opt-out signals must trigger immediate behavioural change in how scripts operate, enforced at network and analytics level. Blocking a cookie while a pixel continues transmitting does not stop the underlying data flow.

Do we really have to print that notice?

If you sell sensitive personal data, a conspicuous notice in prescribed wording is required, with an analogous notice for biometric or genetic data. Before designing around it, consider whether the data sale is worth having that sentence on your privacy page.

Can Texas consumers sue us?

No. Enforcement rests exclusively with the Attorney General and there is no private right of action, so consumers may complain but cannot bring claims directly. That makes the risk profile more predictable than states allowing private suits.

What does the cure period actually give us?

Thirty days from notice to remediate before enforcement proceeds. It is a genuine advantage over regimes without one, but it only helps if you can identify and fix the problem quickly — which requires knowing your data flows in advance.

Could we be a data broker without realising?

Possibly. Businesses that buy, sell or licence personal data may meet the definition and require registration with the Texas Secretary of State. Companies whose core business is something else often do not check.

What should we do first?

Confirm whether you are genuinely exempt, then inventory every point where sensitive data is collected and check what fires before consent is captured. Those two steps resolve the majority of Texas-specific exposure for a marketing team.

Conclusion

Texas is the state most likely to catch a business that thought it was too small to worry. It sets no revenue or consumer-count threshold, requires opt-in consent before sensitive data is collected rather than an opt-out afterwards, and has required universal opt-out signals to be honoured since the start of 2025 — at network level, not just in a cookie banner.

Against that it offers a thirty-day cure period, a single enforcer and no private right of action, which makes the exposure more manageable than California’s once you know about it. The failure mode is not aggressive enforcement against companies who tried. It is companies who read the California thresholds, concluded privacy law did not apply to them, and never looked at the state where the thresholds do not exist.

Texas sits alongside California and Washington in the US digital, ecommerce and performance marketing cluster. The capability pages on Google Ads and first-party data cover the technical work these obligations imply.

Work With Me

If you concluded you were below the threshold for privacy compliance, it is worth checking which state’s threshold you were reading. Texas does not have one.

Comments

comments

Sharing is caring!

Leave a Reply