Laws
The Texas Data Privacy Act for Consumers (2026 Guide)
The short version
The Texas Data Privacy and Security Act has been in force since July 1, 2024. If you live in Texas, you can make a company tell you what it holds on you, correct it, delete it, hand you a copy, and stop selling it or using it for targeted ads. Companies get 45 days to answer. The law reaches more businesses than California's because it has no revenue threshold, but you cannot sue under it, and it does not touch the public-record data that people-search sites publish.
What the Texas Data Privacy and Security Act is
The Texas Data Privacy and Security Act, usually shortened to TDPSA, is the state's comprehensive consumer privacy law. The legislature passed it as House Bill 4 in 2023 and it took effect on July 1, 2024. It sits in Chapter 541 of the Texas Business and Commerce Code and is enforced only by the Texas Attorney General.
It follows the same shape as the laws in Virginia, Colorado, and Connecticut, but Texas made two choices that work in your favor: it covers far more businesses than most state laws, and it requires your consent before a company touches your most sensitive data. It protects a "consumer", meaning a Texas resident acting in a personal or household context, not as an employee or on behalf of a business.
Which companies have to follow it
The TDPSA applies to any business that operates in Texas or sells to Texans and that processes or sells personal data, unless it is a small business under the US Small Business Administration's definition. There is no revenue floor and no minimum number of customers. That makes it one of the widest-reaching state privacy laws in the country.
Compare that with California, where a company must clear one of three thresholds before the California Consumer Privacy Act applies: more than $25 million in annual revenue, data on 100,000 or more California residents or households, or half its revenue from selling personal data. A mid-sized company that falls under all three California thresholds can still owe a Texan every right on the list below.
The small-business exemption has a catch that many summaries skip. Section 541.107 says a small business still may not sell your sensitive data without your prior consent, and the Attorney General can penalize it if it does. So even a company too small for the main law cannot quietly sell your health, location, or immigration data.
Some data is excluded: health data covered by HIPAA, credit data under the Fair Credit Reporting Act, employment records, and education records, and state agencies are not covered at all. The exclusion that matters most for people-search listings is covered further down.
The five rights you can exercise
Section 541.051 gives you five rights, and you exercise them by sending an "authenticated" request to the company, which means the company can take reasonable steps to confirm you are who you say you are. A parent or guardian can exercise the rights on behalf of a child.
- Access. Confirm whether the company is processing your personal data and see that data.
- Correction. Have inaccurate data fixed, taking into account the nature of the data and why it is processed.
- Deletion. Delete personal data you provided, and also data the company obtained about you from elsewhere.
- Portability. Get a copy of the data you gave the company in a portable and, where feasible, readily usable format.
- Opt out. Stop the company processing your data for targeted advertising, for sale, or for profiling that feeds decisions with legal or similarly significant effects.
The deletion right is broader than it looks. Some earlier state laws, Virginia's among them, limited deletion to data you handed over yourself. Texas also covers data the company "obtained about" you, which is the profile a company bought or assembled without asking. Requests are free at least twice a year; beyond that a company may charge a reasonable fee or refuse one it can show is excessive or repetitive.
Sensitive data needs your consent first
This is the rule that gives Texas real teeth. Under section 541.101, a company may not process your sensitive data at all without your consent. That is an opt-in standard, and it applies before collection, not after. Most other state laws, including California's, let you limit sensitive data use only after the fact.
The statute defines sensitive data as four categories. First, data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexuality, or citizenship or immigration status. Second, genetic or biometric data processed to identify you. Third, any data collected from a known child. Fourth, precise geolocation data, which the law pins down as anything that locates you within a 1,750-foot radius.
That last category is why the state's first lawsuit under the law was about driving data. A phone app that quietly reports your location every few seconds is processing sensitive data, and the state's position is that burying the disclosure inside a third-party app's terms is not consent.
How to file a request and what the deadlines are
Find the company's privacy notice, which the law requires it to publish, and use the method it lists for consumer requests. The company then has 45 days to act. It can extend once, by up to 45 more days, but only if it tells you within the first window and explains why the request is complex.
Write down the date you sent the request. If the company declines, it has to tell you the reason within the same 45 days and explain how to appeal. It must answer the appeal in writing within 60 days. If the appeal is denied too, it has to point you to the Attorney General's complaint mechanism.
| Stage | Deadline | What the company owes you |
|---|---|---|
| Initial request | 45 days | Action, or a reason for refusing plus appeal instructions |
| Extension | Up to 45 more days | Notice within the first 45 days, with a reason |
| Appeal | 60 days | A written decision, and if denied, a route to the Attorney General |
| Cure period before enforcement | 30 days | Applies to the company, after the Attorney General sends notice |
Source: Texas Business and Commerce Code sections 541.052, 541.053, and 541.154.
A missed deadline is not penalized automatically, but it is exactly the documented fact the Attorney General's office needs, so keep the emails. Our guide to what to do when a company ignores your deletion request covers the escalation steps.
The browser signal that opts you out everywhere
Since January 1, 2025, the Texas law has recognized opt-out requests sent through technology rather than by hand. Section 541.055 names a link on a website, a browser setting or extension, or a global setting on a device as valid ways to tell a company you opt out of sales and targeted advertising.
In practice that means a browser-level signal such as Global Privacy Control. Turn it on once, and every covered site you visit receives your opt-out without a form. A company may take reasonable steps to check the signal represents a Texas resident, but it cannot simply ignore it. The same section lets you appoint an "authorized agent" to opt out for you, which is the legal basis on which paid removal services file the same free requests on your behalf.
What a Texan can demand that a Californian cannot
Texas wins on reach and on consent. With no revenue threshold, a Texan can send a binding access or deletion request to mid-sized companies a Californian cannot touch under the CCPA. And a Texan's sensitive data cannot be processed until they agree, where a Californian can only ask a company to limit how it uses that data afterward.
Texas also runs a public data broker registry, and since September 1, 2025 every registered broker must post a notice on its website explaining how to exercise your TDPSA rights. That came from Senate Bill 1343; a companion bill, SB 2121, widened the definition of a data broker to any business handling personal data it did not collect from you directly.
What a Californian can demand that a Texan cannot
California gives its residents four things Texas does not: a dedicated regulator, the California Privacy Protection Agency; a limited right to sue over data breaches, worth up to $750 per incident when unencrypted data is stolen through poor security; a right to limit the use of sensitive personal information; and, the big one, the DROP platform.
DROP, the Delete Request and Opt-out Platform run under the California Delete Act, lets a Californian send one deletion request to more than 500 registered data brokers at once. Registered brokers have been required to process those requests since August 1, 2026. Texas has nothing comparable. A Texan who wants out of data broker listings still has to opt out site by site, or pay a service to do it.
| Feature | Texas (TDPSA) | California (CCPA / Delete Act) |
|---|---|---|
| Who is covered | Any non-small business processing personal data | Businesses over $25M revenue, 100,000+ residents, or 50% revenue from data sales |
| Sensitive data | Opt-in consent required before processing | Right to limit use after the fact |
| Response deadline | 45 days, one 45-day extension | 45 days, one 45-day extension |
| Right to sue | None | Limited, for breaches only, up to $750 per incident |
| One-click broker deletion | No | Yes, via DROP |
| Enforcer | Attorney General only | Privacy Protection Agency and Attorney General |
| Maximum penalty | $7,500 per violation | Varies by violation type |
Sources: Texas Business and Commerce Code Chapter 541; California Attorney General CCPA consumer page; California Privacy Protection Agency on the Delete Act and DROP.
For a state-by-state view of how these rights differ, see your data deletion rights by state. If you are weighing the California model specifically, our Delete Act explainer goes deeper.
How Texas has actually enforced it
Texas has used the law, which is more than most states can say. On January 13, 2025 the Attorney General sued Allstate and its subsidiary Arity, the first lawsuit any state had filed under a comprehensive privacy law. The complaint alleged they collected precise location data from more than 45 million people through code embedded in third-party apps.
The case has not been quick. In April 2025 a Montgomery County district judge ruled the court lacked jurisdiction over the Allstate parent company and one Arity entity because neither is based in Texas, and the litigation against the remaining entities continued through 2025. Whatever the outcome, the filing showed what the state thinks consent looks like, and that phone location data is squarely in scope.
The office's largest privacy wins came under older Texas laws, not the TDPSA: Meta agreed in July 2024 to pay $1.4 billion over facial recognition on Facebook under the state's biometric statute, and Google agreed in May 2025 to a $1.375 billion settlement over location tracking, Incognito mode, and biometric data. They signal how aggressively the office pursues data claims.
The mechanics matter for you. The law says plainly that there is no private right of action, so you cannot sue. Before the Attorney General can sue, it must give a company written notice and a 30-day window to cure. After that, the penalty is up to $7,500 per violation, plus injunctions and the state's legal costs.
Where the law stops: people-search sites and public records
The TDPSA will not, by itself, remove your profile from Spokeo, Whitepages, or TruePeopleSearch. The law excludes "publicly available information", defined as information lawfully available through government records or that a business reasonably believes was made public through widely distributed media. Property deeds, voter files, and court records are exactly that, and they are the raw material of people-search sites.
It also excludes any data regulated by the Fair Credit Reporting Act, which is the law background-check companies say they follow. Our post on what the FCRA means for background checks explains why that exemption is so wide.
There is a partial workaround. Data a broker bought from a marketing firm or inferred from your behavior is not a government record, and a TDPSA deletion request can reach it. But for the listing itself, the reliable path remains the broker's own free opt-out, which we document in dated step-by-step opt-out guides for 57 major brokers.
A practical plan for a Texan
Start by finding out where you are exposed. RedactZero's free exposure scan checks an email against known breaches, a username across public profiles, and lists the data brokers likely to hold a US adult, without storing anything you enter. That gives you a target list before you write a single request.
Then work in this order:
- Turn on a browser opt-out signal. It covers every TDPSA-covered site you visit from then on.
- Opt out of the people-search sites that show your listing, using their free forms. Expect to repeat this every three to six months, because listings reappear as brokers re-ingest public records.
- Send TDPSA deletion requests to companies you know hold data on you but have no listing to remove: apps, retailers, marketing firms. Note the date and set a 45-day reminder.
- Check the Texas Secretary of State's data broker registry for brokers you have not heard of, and use the TDPSA notice each one must now post.
- If a company blows the deadline or denies your appeal, file with the Attorney General. Our guide to where to file a privacy complaint has the specifics.
None of this is a one-time job, but the Texas law turns most of it from a favor you ask into a demand a company has to answer. The rest of our privacy law coverage tracks how the other states compare.
See where you stand first
Run a free exposure scan to see which data brokers likely list you, plus any breaches tied to your email - no account, nothing stored.
Frequently asked questions
What is the Texas Data Privacy and Security Act?
It is the Texas consumer privacy law, passed as House Bill 4 in 2023 and in force since July 1, 2024. It gives Texas residents the right to access, correct, delete, and receive a copy of their personal data, and to opt out of targeted advertising, data sales, and certain profiling.
Does the Texas privacy law apply to small companies?
It applies to any company that does business in Texas and processes or sells personal data, unless the company is a small business under the US Small Business Administration definition. There is no revenue or customer-count threshold. Even exempt small businesses need your consent before selling sensitive data.
How long does a company have to answer a Texas privacy request?
Forty-five days from receiving your request. A company can extend that once by up to 45 more days if it tells you within the first window and explains why. If it refuses, it must give a reason and explain how to appeal, and it must answer your appeal within 60 days.
Can I sue a company under the Texas Data Privacy and Security Act?
No. The law states there is no private right of action. Only the Texas Attorney General can enforce it, with civil penalties of up to $7,500 per violation after a 30-day cure period. Your route is a complaint to the Attorney General's Consumer Protection Division.
Does the Texas law force people-search sites to delete my profile?
Usually not. The law excludes publicly available information such as government records, which is where people-search sites get most of what they publish, and it excludes data covered by the Fair Credit Reporting Act. You still have to use each site's own free opt-out for those listings.
What is the difference between the Texas and California privacy laws?
Texas covers more companies because it has no revenue threshold, and it requires opt-in consent before sensitive data is processed. California gives residents a dedicated regulator, a limited right to sue over breaches, a right to limit sensitive data use, and the DROP platform that deletes from every registered data broker at once.
What counts as sensitive data in Texas?
Data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexuality, or citizenship or immigration status; genetic or biometric data used to identify you; data collected from a known child; and precise geolocation data, defined as location within a 1,750-foot radius.
How do I complain if a company ignores my Texas privacy request?
First use the company's appeal process, which it must describe when it denies you. If the appeal fails, the company has to give you a way to reach the Texas Attorney General. You can also file directly through the Attorney General's consumer privacy complaint page.
Sources: Texas Business and Commerce Code Chapter 541 (sections 541.001, 541.002, 541.003, 541.051, 541.052, 541.053, 541.055, 541.101, 541.107, 541.154, 541.155, 541.156); Texas Department of Information Resources on the TDPSA; Texas Secretary of State data broker registration FAQ; WilmerHale on the September 1, 2025 data broker amendments (SB 2121 and SB 1343) and on the Allstate lawsuit; Hunton Andrews Kurth on the Allstate lawsuit and the Meta and Google settlements; Bloomberg Law on the April 2025 jurisdiction ruling; Fisher Phillips on the January 1, 2025 effective date for agent and technology opt-outs; California Attorney General CCPA consumer page; California Privacy Protection Agency on the Delete Act and DROP.