Everything you need to know about TDPSA compliance, data security requirements, and secure data disposal.
The Texas Data Privacy and Security Act (TDPSA) is one of the broadest comprehensive state privacy laws in the United States, notable for applying to businesses of nearly any size, unlike many comparable state laws that carve out small businesses through revenue or data-volume thresholds. It took effect on July 1, 2024, giving Texas residents meaningful rights over their personal data.
Background
The TDPSA was signed into law in June 2023 and became effective on July 1, 2024. It joined a growing wave of comprehensive US state privacy laws that followed California's lead, drawing structural similarities to laws like Virginia's VCDPA and Colorado's CPA, while introducing some distinctly Texas-specific features.
Who Must Comply
The TDPSA applies to any entity that conducts business in Texas or produces a product or service consumed by Texas residents, processes or engages in the sale of personal data, and is not classified as a "small business" under the federal Small Business Administration's size standards — but notably, small businesses are still subject to certain provisions, including the requirement to obtain consumer consent before selling sensitive personal data. This makes the TDPSA's practical reach broader than laws that fully exempt small businesses, since even small businesses cannot freely sell sensitive data without consent.
Consumer Rights
Texas residents have rights under the TDPSA including:
- The right to confirm whether a controller is processing their personal data and to access that data
- The right to correct inaccuracies in personal data
- The right to delete personal data
- The right to obtain a copy of personal data in a portable format
- The right to opt out of the processing of personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects
Controller Obligations
Businesses classified as "controllers" under the TDPSA must:
- Limit data collection to what is adequate, relevant, and reasonably necessary for the disclosed purpose
- Establish, implement, and maintain reasonable administrative, technical, and physical data security practices
- Not process sensitive data without obtaining the consumer's consent
- Provide a reasonably accessible and clear privacy notice
- Conduct data protection assessments for certain higher-risk processing activities, including targeted advertising, sale of personal data, and profiling
Universal Opt-Out Mechanisms
Following an amendment, the TDPSA requires businesses to recognize universal opt-out mechanisms (such as browser-based signals) starting January 1, 2025, allowing consumers to exercise their opt-out rights for targeted advertising and data sales across multiple websites without needing to submit individual requests to each business.
Enforcement and Penalties
Unlike some state privacy laws, the TDPSA does not provide a private right of action for consumers. Enforcement authority rests exclusively with the Texas Attorney General, who can pursue civil penalties of up to $7,500 per violation. The law includes a cure period, requiring the Attorney General to provide written notice of a suspected violation and allow the business 30 days to cure the violation before an enforcement action can proceed, though this cure period provision has a scheduled expiration under the statute's original terms.
Special Provisions
The TDPSA includes some notable additional features not found in every comparable state law, including specific provisions addressing the sale of biometric data and requirements for "small businesses" to obtain consent before selling sensitive personal data — a meaningful departure from laws that exempt small businesses entirely.
Secure Data Deletion
The TDPSA's deletion right requires that when a consumer requests deletion, the personal data be permanently removed — not merely marked inactive or logically deleted while remaining recoverable. This obligation, combined with the general requirement to maintain reasonable data security practices, means Texas-regulated businesses retiring hardware or storage systems that processed Texas residents' personal data should use standards-based, verifiable data erasure methods and retain proof of destruction, both to fulfill individual deletion requests properly and to reduce exposure in the event of an Attorney General inquiry.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
The TDPSA's broad applicability — extending certain obligations even to small businesses — makes it one of the more far-reaching state privacy laws in the US. Organizations serving Texas consumers need clear consent mechanisms for sensitive and biometric data, support for universal opt-out signals, and verifiable, secure data disposal practices to meet the law's requirements.
No comments yet. Be the first to comment.