CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise Scale
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Manage IT Compliance Houston
Shane
Shane January 1st, 2025

Texas Privacy Implementation Changes: New Requirements Now in Effect for Houston Businesses

Stay compliant with Texas’s comprehensive data privacy law as new opt-out requirements take effect January 1, 2025 understanding your obligations and consumer rights under TDPSA

Compliance Alert
The Texas Data Privacy and Security Act Has No Revenue Threshold. If You Process Texas Residents' Data, It Reaches You.

Unlike California's law, the TDPSA does not wait for you to hit a dollar figure. Here is what a Houston SMB has to do now, and where the small-business exemption stops.

TL;DR
The Texas Data Privacy and Security Act took effect July 1, 2024, with universal opt-out recognition required since January 1, 2025. It applies to businesses that process or sell Texas residents' personal data and are not SBA-defined small businesses, with no revenue threshold. The Texas Attorney General enforces it, gives a 30-day cure window, and can fine up to $7,500 per violation.
⚖️ Who It Applies To 🔓 The Rights You Must Honor ✅ What To Do Now 🚀 How CinchOps Helps

The Texas Data Privacy and Security Act is the state's consumer privacy law, and its defining feature is what it left out: a revenue threshold. Most privacy laws let a small company assume it is too small to be covered. The TDPSA does not offer that comfort.

The law took effect July 1, 2024. A second phase, requiring businesses to honor universal opt-out signals from a browser or device, took effect January 1, 2025. If your Houston business collects email addresses, runs a customer database, or lets a marketing tool track visitors, the TDPSA is already the rule you operate under. CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, and this is the plain-language version of what the law asks.

The catch that trips people up: the small-business exemption sounds like a free pass, but it is narrow. A small business is still barred from selling a consumer's sensitive data without that person's consent. Sharing data with an ad network can count as a sale, so "we are too small" is not the shield most owners think it is.

The TDPSA Applies With No Revenue Threshold, Unlike California

The trigger is what you do with data, not how much money you make.

The TDPSA covers any person or company that conducts business in Texas or sells products and services to Texas residents, processes or sells personal data, and does not qualify as a small business under U.S. Small Business Administration size standards. There is no annual-revenue or record-count trigger.

This is the part that separates Texas from California. The CCPA reaches a business only once it clears a revenue or data-volume bar. Texas removed that bar. The line that decides coverage is the SBA small-business definition, which is set by industry rather than one flat number. For many industries the SBA line falls near 500 employees, but retail, services, construction, and agriculture use annual-receipts figures instead, so the answer is genuinely industry-specific.

  • Employee-count industries. Manufacturing and wholesale trade use headcount, often 500 or more, calculated as the average over the trailing 24 months including affiliates.
  • Annual-receipts industries. Retail and professional services generally use receipts thresholds in the millions, averaged over the last several years, again counting affiliate revenue.
  • The exemption is not automatic. Even an exempt small business must get consent before selling sensitive data such as health, precise location, or biometric information.

For a Houston SMB, the honest read is this: your size might exempt you from the bulk of the obligations, but it does not exempt the one that carries the most legal risk. If a form on your site drops a visitor into a third-party advertising pixel that resells the data, you may have triggered the sensitive-data consent rule without ever deciding to "sell" anything. That is the gap we see most often when a law firm or CPA practice assumes it is out of scope.

The TDPSA Grants Texans Five Rights You Have to Honor

Each right comes with a deadline, and the clock is short.

Under the TDPSA, Texas residents can access their personal data, correct it, delete it, obtain a portable copy, and opt out of its sale, of targeted advertising, and of profiling. A covered business must respond within 45 days, with one 45-day extension allowed when reasonably necessary.

These are not aspirational. They are obligations with a response window. A consumer emails to ask what you hold on them, you have 45 days. They ask you to delete it, same clock. And since January 1, 2025, you also have to recognize a universal opt-out signal, meaning a browser or extension that broadcasts "do not sell or share" has to be treated as a valid opt-out without the person filling out a form.

THE TDPSA AT A GLANCE Jul 1 2024 law took effect $0 revenue threshold to apply 45 days to answer a consumer request 30 day cure period before penalties $7,500 max penalty per violation CinchOps · cinchops.com · Source: Texas Attorney General; Texas DIR; TDPSA (Tex. Bus. & Com. Code ch. 541)
The TDPSA at a glance - the dates, deadlines, and penalty a Houston business operates under.
Owners keep telling me they are too small for the privacy law. Texas wrote the one law where that is the wrong answer. There is no revenue line to hide behind, and the piece that bites is the sensitive-data consent rule that stays on even when the rest of the exemption is off. Read your own website before the Attorney General does.
Shane Stevens, CEO, CinchOps - LinkedIn

Find Out What Your Website Is Actually Collecting

Most TDPSA exposure hides in the trackers and forms a business never audited. CinchOps maps what your systems collect and share, then closes the gaps, as part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

What a Houston SMB Should Do Now to Comply

Six concrete moves, none of which require an enterprise legal team.

TDPSA compliance for a small business is mostly documentation and process: a clear privacy notice, a working way to receive and answer consumer requests, consent before selling sensitive data, honoring universal opt-out signals, a data map, and vendor contracts that meet the law's controller-processor terms.

Enforcement sits with the Texas Attorney General alone. There is no private lawsuit under this law, but the AG can issue civil investigative demands, and the office has been aggressive on privacy, securing over a billion dollars in privacy-related settlements against large technology firms across 2024 and 2025. Before the AG files, it must give you written notice and a 30-day window to cure. That window is the difference between a fixable letter and a $7,500-per-violation penalty.

  • Publish a real privacy notice. State what data you collect, why, who you share it with, and how a consumer exercises their rights. A generic template that does not match your actual practices is worse than none.
  • Build a request intake. A monitored email or web form that logs access, correction, deletion, and opt-out requests, plus a calendar so you hit the 45-day deadline.
  • Handle sensitive data with consent. If any form or embedded tool collects health, precise geolocation, or biometric data, get opt-in consent before collection and before any sale.
  • Honor universal opt-out. Configure your site to recognize Global Privacy Control and similar signals, required since January 1, 2025.
  • Map your data and vendors. Know what you hold and which processors touch it. The TDPSA requires data-processing agreements with your vendors that spell out security duties.
  • Watch the AI angle. A 2025 amendment tied to the Texas Responsible AI Governance Act extended processor security duties to data handled by AI systems, so any AI tool touching customer data is in scope too.

None of this is exotic. It is the same discipline that good IT hygiene already asks for: know your data, control who touches it, and prove it. A business in Houston or Katy that already runs a tight ship is most of the way there.

How CinchOps Helps Houston Businesses Meet the TDPSA

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

TDPSA compliance is a technical problem as much as a legal one. The rights are only real if your systems can find, correct, delete, and export a person's data, and if your site can recognize an opt-out signal. That is where a managed IT partner fits:

  • Through cybersecurity services, we map what your systems collect, tighten access, and build the security practices the law expects of a data controller.
  • Through managed IT support, we stand up the request-intake and data-mapping process so a consumer request does not blow past the 45-day deadline.
  • We support Houston-area firms across law, accounting, and construction, where customer data volume makes the exemption line worth checking carefully.

The businesses that get burned are the ones that assumed size kept them out. If you are not sure whether the TDPSA reaches your Houston business, or whether your website is quietly selling data you never meant to, do not wait for a notice from the Attorney General to find out. Talk to CinchOps and we will help you get a straight answer.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is the Texas Data Privacy and Security Act?

The Texas Data Privacy and Security Act (TDPSA) is the state's consumer privacy law, effective July 1, 2024. It gives Texas residents rights over their personal data and requires covered businesses to provide notice, honor opt-outs, and secure the data they hold. The Texas Attorney General enforces it.

Does the TDPSA have a revenue threshold?

No. Unlike California's CCPA, the TDPSA has no revenue or data-volume threshold. It applies to any business that conducts business in Texas or sells to Texas residents, processes or sells personal data, and is not a small business under U.S. Small Business Administration size standards.

Are small businesses exempt from the TDPSA?

Mostly, but not fully. A business that qualifies as small under SBA size standards is exempt from most obligations. The exception is significant: even an exempt small business must obtain a consumer's consent before selling that person's sensitive data, such as health or precise-location information.

How does the Texas Attorney General enforce the TDPSA?

The Texas Attorney General has exclusive enforcement authority; there is no private right of action. Before filing, the office must give written notice and a 30-day period to cure the violation. A business that fails to cure faces a civil penalty of up to $7,500 per violation.

What is the universal opt-out requirement?

Since January 1, 2025, covered businesses must recognize universal opt-out signals, such as Global Privacy Control, that a browser or device broadcasts. When a Houston consumer's browser signals "do not sell or share," the business must treat it as a valid opt-out without requiring a separate form.

Discover More

CinchOps Cybersecurity Services
Why Security Awareness Training Matters Most for Houston SMBs
What Is MDR? Managed Detection and Response Explained
7 Steps for a Smart Business Continuity Checklist for Houston Businesses
CinchOps Managed IT Services

Sources

  • Office of the Texas Attorney General, Texas Data Privacy and Security Act
  • Texas Department of Information Resources, Texas Data Privacy and Security Act
  • Holland & Knight, Privacy and Cybersecurity Legislation in Texas: What Happened in 2025
  • Goodwin, Texas's New Privacy Law Goes Into Effect and the AG Builds an Enforcement Team
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

July 21st, 2026
Choosing an IT provider for a Houston CPA firm
How to Choose an IT Provider That Understands CPA Firms (2026 Guide)

Run Every Provider Through The Same Eight Questions – The One Question That Sorts The Room Fastest

April 1st, 2026
Threat Monitoring
Cybersecurity Houston: Why Real-Time Threat Monitoring Beats Reactive Defense Every Time

Proactive Versus Reactive Cybersecurity for Houston Businesses – Every Hour Without Monitoring Is an Hour Attackers Have the Advantage

July 30th, 2026
Google Reviews (4)
How to Choose an IT Company in Houston (2026): 7 Green and 7 Red Flags

A Vetting Checklist Built From Real Client Reviews – Why Houston Businesses Really Change IT Providers

June 23rd, 2026
Managed IT Houston
Houston Small Business AI Adoption: The 2026 Census Report

Houston Is 18th of 25 Metros on AI – The Head Start Is Still Open

August 6th, 2026
Managed IT Houston
We Audited the “Top Managed IT Providers in Houston” Category

How To Read A “Top Managed IT Providers” Article Before You Trust It – Self-Published Guides, Directories, And The Difference Between Them

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery (BCDR)
  • Cloud Services
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy