Marketing Measurement ·

Why marketers need to understand the Texas Data Privacy and Security Act

The Texas Data Privacy & Security Act changes how brands collect, use, and sell personal data. Here's what marketers need to know about it and their measurement.

Listen
0:00 / 0:00
AI-generated audio
Why marketers need to understand the Texas Data Privacy and Security Act

A locksmith who rekeyed every lock in Texas overnight would leave a lot of people scrambling to figure out which of their spare keys still worked, who was allowed to cut new copies, and what would happen if someone got caught using an old one without asking first. That's roughly what happened to businesses collecting personal data on Texas residents when the Texas Data Privacy and Security Act took effect. Companies that had been gathering, storing, and selling personal data under a fairly loose set of rules suddenly needed permission, a documented reason, and a clear paper trail for holding onto that access at all.

For marketers, the Texas Data Privacy and Security Act changes what data you can collect, how you can use it for targeted advertising—including plain old retargeting pixels most teams already run—and what happens if a regulator decides you didn't ask the right way. Understanding how the law actually works, yes, even the detailed ins and outs, matters for anyone whose job touches customer data in Texas.

Key takeaways

  • The Texas Data Privacy and Security Act (TDPSA) took effect on July 1, 2024, and applies to any business that conducts business in Texas or offers products and services consumed by Texas residents, processes or sells personal data, and doesn't qualify as a small business under Small Business Administration guidelines.
  • Texas consumers have the right to access, correct, delete, and obtain a portable copy of their personal data, along with the right to opt out of targeted advertising, the sale of personal data, and certain profiling.
  • Sensitive personal data, like health diagnoses, biometric data, citizenship or immigration status, and precise geolocation, requires opt-in consent before a business can process it at all.
  • Businesses that use targeted advertising, sell personal data, or process sensitive data have to complete data protection assessments and keep them on file.
  • Only the Texas attorney general can enforce the TDPSA, businesses get a 30-day cure period before facing penalties, and violations can carry civil penalties of up to $7,500 each.
  • The TDPSA doesn't give consumers a private right of action, which is a key difference from the older Texas Deceptive Trade Practices Act.
  • As tracking-based data collection runs into more restrictions, marketers relying on user-level data for measurement will feel more friction than those using aggregate, privacy-resilient methods.

What the Texas Data Privacy and Security Act actually covers

Texas signed the TDPSA into law in June 2023, and its main provisions became enforceable on July 1, 2024. It's a comprehensive data privacy law that gives Texas residents more control over their personal data and puts new obligations on the businesses collecting it.

Personal data covers information tied to someone in an individual or household context, and it's a broader category than a lot of businesses expect: it includes anything linked or reasonably linkable to an identified or identifiable individual, like IP addresses, shopping histories, and device identifiers. It doesn't cover data about a person acting in a commercial or employment context, like a work email address used only for business purposes, and it excludes deidentified or publicly available information.

A second date matters just as much as the effective date: starting January 1, 2025, businesses had to start recognizing universal opt-out preference signals, similar to Global Privacy Control, whenever a consumer sends one through their browser, and to reflect that mechanism in their privacy notice.

Who has to comply with the law

Texas took a different approach to determining who falls under this law than most other states.

Most comprehensive consumer data privacy laws, including California's, use revenue or data volume thresholds. If a business doesn't process a certain number of consumers' data or generate a certain amount of revenue, it's excluded. Texas didn't build the Texas Data Privacy and Security Act that way, and the data protection expectations that follow don't scale down with company size the way they do elsewhere. A business that conducts business in Texas or produces a product or service consumed by Texas residents, processes or engages in the sale of personal data, and doesn't qualify as a small business under Small Business Administration guidelines falls within scope, regardless of revenue.

That small business exemption sounds like a loophole. It isn't much of one—Small Business Administration size standards vary widely by industry—so what counts as small for a marketing agency looks nothing like what counts as small for a manufacturer. And even businesses that do qualify as small still have to get a consumer's consent before selling their sensitive data. There's no exemption for that particular requirement.

Texas also built the TDPSA to work alongside other state and federal laws rather than replace them. A business already regulated under the Health Insurance Portability and Accountability Act, for instance, doesn't need a separate TDPSA process for the health records it already protects under that law.

Here's how that plays out next to California's approach:

Texas (TDPSA)California (CCPA/CPRA)
Who's coveredDoes business in Texas or serves Texas residents, processes or sells personal data, not an SBA-defined small business$25 million-plus in revenue, or 100,000-plus consumers' data processed, or 50 percent-plus of revenue from selling data
Private right of actionNoLimited, mainly for certain data breaches
Cure period30 daysRemoved for most violations
Who enforces itTexas attorney general onlyCalifornia Privacy Protection Agency and the state attorney general

What rights the law gives Texas consumers

The rights themselves look familiar if you've followed other state privacy laws, but a few details are specific to Texas.

  • Right to know: confirm whether a business is processing your personal data and access it.
  • Right to correct: correct inaccuracies in the personal data a business holds about you.
  • Right to delete: request deletion of personal data provided by or obtained about you.
  • Right to portability: get a copy of your personal data in a readily usable format.
  • Right to opt out: opt out of targeted advertising, the sale of personal data, and profiling used for decisions with legal or similarly significant effects, like lending or housing decisions. That opt-out right for profiling only applies to decisions based solely on automated processing, not ones that include a human reviewer.

Businesses have to set up reliable methods for consumers to submit these requests, like a webform or a toll-free number, rather than burying the option somewhere hard to find. Once a request comes in, a business has 45 days to respond and can take one 45-day extension if it's reasonably necessary. If a business denies a request, Texas requires an appeal process, and the business has to respond to that appeal in the same manner and timeframe as the original request.

What counts as sensitive data

The TDPSA singles out sensitive personal data as a category that needs a consumer's opt-in consent before a business can process such data, rather than just a chance to opt out after the fact. This includes:

  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health diagnosis
  • Sexuality
  • Citizenship or immigration status
  • Genetic or biometric data used to identify someone
  • Personal data collected from a known child
  • Precise geolocation data, generally within about 1,750 feet of a specific location

Businesses that process personal data relating to a known child also have to handle it consistent with the federal Children's Online Privacy Protection Act (commonly known as COPPA) instead of a separate, Texas-specific standard. And if a business sells sensitive data or biometric data, Texas requires a specific disclosure in the privacy notice: a written statement along the lines of "we may sell your sensitive personal data" or "we may sell your biometric data," depending on which applies. That level of specificity in a privacy notice goes further than a lot of other state privacy laws ask for, so it's worth double-checking your privacy notice if biometric data plays any role in how you build audiences.

What the law requires businesses to do

Beyond honoring consumer rights, the Texas Data Privacy and Security Act lays out standing data protection obligations that apply anytime a business is processing personal data belonging to a Texas resident.

  • Limit data collection to what's reasonably necessary for the purpose it was collected for.
  • Put reasonable data security practices in place to protect personal data from unauthorized access.
  • Get prior consent before processing sensitive data or the personal data of a known child.
  • Respond to consumer requests within 45 days.
  • Avoid denying goods or services, charging a different price, or providing a different level of service to a consumer who exercises their rights, which functions as the law's prohibition on unlawful discrimination.
  • Complete a data protection assessment before starting certain higher-risk processing activities.

Together, these duties are what most of the day-to-day data protection work under the law actually looks like. The last one on that list is easy to miss, so it's worth its own explanation. Texas requires a documented data protection assessment before a business processes personal data for targeted advertising, the sale of personal data, certain profiling, the processing of sensitive data, or any other activity carrying a heightened risk of harm to consumers, sometimes described in the statute as a reasonably foreseeable risk. These reasonable assessments have to weigh the direct or indirect benefits of the personal data processing against the risks to the consumer, and Texas only applies this requirement to processing that started after January 1, 2025, so businesses aren't expected to go back and document years of past activity. The attorney general can request these assessments during an investigation, so they need to actually hold up.

The law also uses the terms controller and processor, similar to other state privacy laws. When a controller shares personal data with a processor, a contract needs to be in place first, laying out data protection obligations, security requirements, and the processor's data processing procedures. And the TDPSA carves out a narrow exception for businesses that conduct internal research to improve or develop their own products, which doesn't require separate consent for that specific purpose.

How targeted advertising and data sales fit in

This is the part of the law that touches marketing teams most directly, even when legal handles the paperwork.

Texas defines targeted advertising as displaying ads selected based on a consumer's activity over time and across websites that aren't affiliated with each other, which covers a lot of standard retargeting and programmatic buying. The law's definition of a sale of personal data is also broader than a lot of marketers expect (and it isn't limited to a business literally exchanging data for cash) since sharing, disclosing, or transferring personal data for any kind of valuable consideration to a third party counts too. Plenty of standard ad tech integrations fall under that definition even when no money changes hands directly.

Consumers can opt out of both, and once enough of them do, tools that depend on tracking individual users across sites and sessions get less reliable. That's part of a bigger shift happening across marketing measurement. As privacy regulations like the TDPSA add more friction to user-level tracking, models that measure performance without needing to follow individual consumers around the internet hold up better over time.

What happens if a business doesn't comply

Texas built in a grace period that a lot of other states are moving away from, so enforcement here looks a little different than what's happening elsewhere.

The Texas attorney general has exclusive authority to enforce the Texas Data Privacy and Security Act, and most data protection failures that trigger an investigation come from the requirements covered above. There's no private right of action, meaning individual consumers can't file their own lawsuits over a violation the way they can under some other consumer data privacy laws. Before the attorney general can issue penalties, a business gets a 30-day cure period to fix the violation once it's notified.

If a business doesn't cure the violation in time, the attorney general can seek a civil penalty of up to $7,500 per violation, on top of attorneys' fees and other costs. That lack of a private right of action is worth flagging because it's a common point of confusion: the Texas Deceptive Trade Practices Act, a separate and much older consumer protection law, does let individuals sue over deceptive trade practices directly. The TDPSA and the DTPA cover different ground, and mixing them up can lead to bad assumptions about what legal exposure actually looks like for a business.

Where Prescient comes in

None of this means marketers have to give up on data-driven decisions. It does mean the ground under user-level tracking keeps shifting, so it's worth building a measurement approach that doesn't depend on it in the first place.

Prescient's marketing mix model measures campaign performance and halo effects from aggregate, observable data—not by following individual consumers across sites and sessions—so new opt-outs, browser changes, and state privacy laws like the TDPSA don't leave gaps in your reporting the way tracking-dependent tools do. Book a demo and we'll walk you through how that works and the powerful reporting we have available for your team.

FAQs

Who is exempt from the Texas Data Privacy and Security Act?

Businesses that qualify as a small business under Small Business Administration guidelines are exempt from most TDPSA requirements, though not entirely: even small businesses have to get a consumer's consent before selling their sensitive personal data. The law also doesn't apply to certain data and entities already regulated under other federal laws, including the Health Insurance Portability and Accountability Act, the Gramm-Leach-Bliley Act, and the Fair Credit Reporting Act, so health care services, health information technology, and financial institutions covered by those laws generally continue operating under those existing standards instead of a second, overlapping one.

What counts as a violation of the TDPSA?

A violation of the Texas Data Privacy and Security Act can be as straightforward as processing sensitive data without prior consent, selling personal data without honoring a consumer's opt-out request, or failing to post the required notice when a business sells sensitive or biometric personal data. Skipping a data protection assessment for processing data that carries a heightened risk, like targeted advertising or profiling, counts too, since the law is built around protecting any identified or identifiable individual, not just people who've formally complained. Businesses get a 30-day cure period after the attorney general notifies them, so a single mistake caught early doesn't automatically turn into a penalty.

Can consumers sue a business directly under the TDPSA?

No. The TDPSA doesn't include a private right of action, so individual consumers can't bring their own lawsuits over a violation. Only the Texas attorney general has the authority to enforce the law and pursue civil penalties, injunctive relief, or attorneys' fees. This is different from the Texas Deceptive Trade Practices Act, an older consumer protection law that does let individuals sue over deceptive or unconscionable trade practices, which is likely why people sometimes mix the two up.

How is the TDPSA different from the Texas Deceptive Trade Practices Act?

The Deceptive Trade Practices Act, or DTPA, and the TDPSA are separate laws with different jobs. The DTPA generally covers false, misleading, or deceptive acts in trade or commerce and lets individual consumers sue for damages. The TDPSA specifically regulates how businesses collect, use, and sell personal data, and only the attorney general can enforce it. A business could fully comply with the TDPSA's data practices and still face a DTPA claim if it deceived customers in some unrelated way, so the two laws aren't interchangeable.

How does the TDPSA compare to California's privacy law?

The biggest difference is how each law decides who has to comply. California's CCPA and CPRA (what some other laws would call rules for a "data subject" and Texas calls a "consumer") use revenue and data volume thresholds, so a business processing under 100,000 consumers' data and earning under $25 million a year is often exempt no matter what it does with personal data. Texas skipped the thresholds entirely. If a business conducts business in Texas or serves Texas residents, processes or sells personal data, and isn't a small business by Small Business Administration standards, the Texas Data Privacy and Security Act applies, regardless of revenue. Both laws also treat certain categories, like racial or ethnic origin and health information, as sensitive enough to need extra protection, even though the applicability rules around them differ.

What happens during the TDPSA's 30-day cure period?

Once the Texas attorney general notifies a business of a suspected violation, the business has 30 days to fix the issue before facing a civil penalty. That might mean updating a privacy notice, correcting how opt-out requests get handled, or completing a data protection assessment that was missed, since these small data protection fixes are usually enough to close out a first-time violation. If the business cures the violation and sends a written statement to the attorney general confirming the fix, it can avoid the civil penalty for that specific violation. Businesses that don't cure within the window can face penalties of up to $7,500 per violation.

The Halo

Exclusive insights, every week.

Subscribe to The Halo for sharper marketing thinking.

Keep reading