Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541)
Below is what the official text of Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541) states about whom it covers, when it applies to a business and since when. Where the pages we read do not say, the row says "not stated".
The wording shown is taken from the official page named in each row. The duties of a business and the contents of a privacy notice are in the paid checklist.
Typical situations, run through the same conditions as the check
- A for-profit US business with 150,000 people in Texas and $30 million revenue: Applies, or may apply: conditions to check.
- The same business with 8,000 people in Texas: Applies, or may apply: conditions to check.
- A US business with no users in Texas: Not triggered by these answers.
Judged on 2026-10-06. Our law data was last verified on 2026-10-06; a law that took effect after that date is not in it. These situations leave other answers blank or neutral: use the check for your own.
What the official text states
| Question | What the official text states | Source |
|---|---|---|
| What it covers | Protects consumers' personal data and binds persons that do business in Texas or produce products or services consumed by Texas residents, process or sell personal data, and are not small businesses.Official wordingSec. 541.002. APPLICABILITY OF CHAPTER. (a) This chapter applies only to a person that: | capitol.texas.gov read 2026-10-06 |
| When it applies to a business | Applies only to a person that conducts business in Texas or produces a product or service consumed by Texas residents, processes or engages in the sale of personal data, and is not a small business as defined by the U.S. Small Business Administration (small businesses must still obtain consent before selling sensitive data); there is no consumer-count threshold. Conditions to check: The small-business carve-out (U.S. SBA size standards, which vary by industry and use revenue or employee counts) cannot be covered by our questions: a small business is outside most of the chapter but may not sell sensitive personal data without consumer consent (541.107). Excluded (541.002(b)): state agencies and political subdivisions, GLBA financial institutions or data, HIPAA covered entities and business associates, nonprofit organizations, institutions of higher education, electric utilities/power generation companies/retail electric providers; plus exempt data categories (541.003). Purely personal or household processing is outside the chapter (541.004). No numeric threshold: we test whether you have users there, which is only a proxy for 'conducts business in this state or produces a product or service consumed by residents'. Official wording(a) This chapter applies only to a person that: (1) conducts business in this state or produces a product or service consumed by residents of this state; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the United States Small Business Administration, except to the extent that Section 541.107 applies to a person described by this subdivision. | capitol.texas.gov read 2026-10-06 |
| In force from | 2024-07-01 H.B. 4 section 7: takes effect July 1, 2024, except Sec. 541.055(e) (universal opt-out signal provisions) which takes effect January 1, 2025. Official wording(a) Except as provided by Subsection (b) of this section, this Act takes effect July 1, 2024. | capitol.texas.gov read 2026-10-06 |
| Privacy notice | Included in the paid checklist. See the checklist | — |
| Consent and opt-out | Included in the paid checklist. See the checklist | — |
| Rights of individuals | Included in the paid checklist. See the checklist | — |
| Data protection officer | Not stated on the official pages we read. the text read does not say whether a data protection officer or privacy officer must be appointed | — |
| Breach notification | Not stated on the official pages we read. separate breach-notification statute not read | — |
| What the privacy notice must contain | Included in the paid checklist. See the checklist | — |
What we do not cover
These areas are outside this site, so nothing on this page says anything about them:
- Privacy laws for particular sectors (for example health care, banking and credit, education)
- Rules specific to children's online privacy
- Cookie and electronic-communications rules (including consent for cookies and marketing messages)
- Employee, job applicant and contractor data
- Rules on sending personal data to other countries
- US state data-breach notification laws (a separate set of state laws)
- US state privacy laws that are not yet in force, and state laws on particular topics (for example biometric or health data)
- Privacy laws of countries that are not listed here
- Planned changes to the laws listed here