Texas Privacy Implementation Changes: New Requirements Now in Effect for Houston Businesses
Stay compliant with Texas’s comprehensive data privacy law as new opt-out requirements take effect January 1, 2025 understanding your obligations and consumer rights under TDPSA
Unlike California's law, the TDPSA does not wait for you to hit a dollar figure. Here is what a Houston SMB has to do now, and where the small-business exemption stops.
The Texas Data Privacy and Security Act is the state's consumer privacy law, and its defining feature is what it left out: a revenue threshold. Most privacy laws let a small company assume it is too small to be covered. The TDPSA does not offer that comfort.
The law took effect July 1, 2024. A second phase, requiring businesses to honor universal opt-out signals from a browser or device, took effect January 1, 2025. If your Houston business collects email addresses, runs a customer database, or lets a marketing tool track visitors, the TDPSA is already the rule you operate under. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and this is the plain-language version of what the law asks.
The TDPSA Applies With No Revenue Threshold, Unlike California
The trigger is what you do with data, not how much money you make.
The TDPSA covers any person or company that conducts business in Texas or sells products and services to Texas residents, processes or sells personal data, and does not qualify as a small business under U.S. Small Business Administration size standards. There is no annual-revenue or record-count trigger.
This is the part that separates Texas from California. The CCPA reaches a business only once it clears a revenue or data-volume bar. Texas removed that bar. The line that decides coverage is the SBA small-business definition, which is set by industry rather than one flat number. For many industries the SBA line falls near 500 employees, but retail, services, construction, and agriculture use annual-receipts figures instead, so the answer is genuinely industry-specific.
- Employee-count industries. Manufacturing and wholesale trade use headcount, often 500 or more, calculated as the average over the trailing 24 months including affiliates.
- Annual-receipts industries. Retail and professional services generally use receipts thresholds in the millions, averaged over the last several years, again counting affiliate revenue.
- The exemption is not automatic. Even an exempt small business must get consent before selling sensitive data such as health, precise location, or biometric information.
For a Houston SMB, the honest read is this: your size might exempt you from the bulk of the obligations, but it does not exempt the one that carries the most legal risk. If a form on your site drops a visitor into a third-party advertising pixel that resells the data, you may have triggered the sensitive-data consent rule without ever deciding to "sell" anything. That is the gap we see most often when a law firm or CPA practice assumes it is out of scope.
The TDPSA Grants Texans Five Rights You Have to Honor
Each right comes with a deadline, and the clock is short.
Under the TDPSA, Texas residents can access their personal data, correct it, delete it, obtain a portable copy, and opt out of its sale, of targeted advertising, and of profiling. A covered business must respond within 45 days, with one 45-day extension allowed when reasonably necessary.
These are not aspirational. They are obligations with a response window. A consumer emails to ask what you hold on them, you have 45 days. They ask you to delete it, same clock. And since January 1, 2025, you also have to recognize a universal opt-out signal, meaning a browser or extension that broadcasts "do not sell or share" has to be treated as a valid opt-out without the person filling out a form.
Owners keep telling me they are too small for the privacy law. Texas wrote the one law where that is the wrong answer. There is no revenue line to hide behind, and the piece that bites is the sensitive-data consent rule that stays on even when the rest of the exemption is off. Read your own website before the Attorney General does.
Find Out What Your Website Is Actually Collecting
Most TDPSA exposure hides in the trackers and forms a business never audited. CinchOps maps what your systems collect and share, then closes the gaps, as part of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →What a Houston SMB Should Do Now to Comply
Six concrete moves, none of which require an enterprise legal team.
TDPSA compliance for a small business is mostly documentation and process: a clear privacy notice, a working way to receive and answer consumer requests, consent before selling sensitive data, honoring universal opt-out signals, a data map, and vendor contracts that meet the law's controller-processor terms.
Enforcement sits with the Texas Attorney General alone. There is no private lawsuit under this law, but the AG can issue civil investigative demands, and the office has been aggressive on privacy, securing over a billion dollars in privacy-related settlements against large technology firms across 2024 and 2025. Before the AG files, it must give you written notice and a 30-day window to cure. That window is the difference between a fixable letter and a $7,500-per-violation penalty.
- Publish a real privacy notice. State what data you collect, why, who you share it with, and how a consumer exercises their rights. A generic template that does not match your actual practices is worse than none.
- Build a request intake. A monitored email or web form that logs access, correction, deletion, and opt-out requests, plus a calendar so you hit the 45-day deadline.
- Handle sensitive data with consent. If any form or embedded tool collects health, precise geolocation, or biometric data, get opt-in consent before collection and before any sale.
- Honor universal opt-out. Configure your site to recognize Global Privacy Control and similar signals, required since January 1, 2025.
- Map your data and vendors. Know what you hold and which processors touch it. The TDPSA requires data-processing agreements with your vendors that spell out security duties.
- Watch the AI angle. A 2025 amendment tied to the Texas Responsible AI Governance Act extended processor security duties to data handled by AI systems, so any AI tool touching customer data is in scope too.
None of this is exotic. It is the same discipline that good IT hygiene already asks for: know your data, control who touches it, and prove it. A business in Houston or Katy that already runs a tight ship is most of the way there.
How CinchOps Helps Houston Businesses Meet the TDPSA
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.
TDPSA compliance is a technical problem as much as a legal one. The rights are only real if your systems can find, correct, delete, and export a person's data, and if your site can recognize an opt-out signal. That is where a managed IT partner fits:
- Through cybersecurity services, we map what your systems collect, tighten access, and build the security practices the law expects of a data controller.
- Through managed IT support, we stand up the request-intake and data-mapping process so a consumer request does not blow past the 45-day deadline.
- We support Houston-area firms across law, accounting, and construction, where customer data volume makes the exemption line worth checking carefully.
The businesses that get burned are the ones that assumed size kept them out. If you are not sure whether the TDPSA reaches your Houston business, or whether your website is quietly selling data you never meant to, do not wait for a notice from the Attorney General to find out. Talk to CinchOps and we will help you get a straight answer.
Frequently Asked Questions
What is the Texas Data Privacy and Security Act?
The Texas Data Privacy and Security Act (TDPSA) is the state's consumer privacy law, effective July 1, 2024. It gives Texas residents rights over their personal data and requires covered businesses to provide notice, honor opt-outs, and secure the data they hold. The Texas Attorney General enforces it.
Does the TDPSA have a revenue threshold?
No. Unlike California's CCPA, the TDPSA has no revenue or data-volume threshold. It applies to any business that conducts business in Texas or sells to Texas residents, processes or sells personal data, and is not a small business under U.S. Small Business Administration size standards.
Are small businesses exempt from the TDPSA?
Mostly, but not fully. A business that qualifies as small under SBA size standards is exempt from most obligations. The exception is significant: even an exempt small business must obtain a consumer's consent before selling that person's sensitive data, such as health or precise-location information.
How does the Texas Attorney General enforce the TDPSA?
The Texas Attorney General has exclusive enforcement authority; there is no private right of action. Before filing, the office must give written notice and a 30-day period to cure the violation. A business that fails to cure faces a civil penalty of up to $7,500 per violation.
What is the universal opt-out requirement?
Since January 1, 2025, covered businesses must recognize universal opt-out signals, such as Global Privacy Control, that a browser or device broadcasts. When a Houston consumer's browser signals "do not sell or share," the business must treat it as a valid opt-out without requiring a separate form.
Discover More
Sources
- Office of the Texas Attorney General, Texas Data Privacy and Security Act
- Texas Department of Information Resources, Texas Data Privacy and Security Act
- Holland & Knight, Privacy and Cybersecurity Legislation in Texas: What Happened in 2025
- Goodwin, Texas's New Privacy Law Goes Into Effect and the AG Builds an Enforcement Team
