Managed IT Support Structured Cabling Installation Security Systems Installation

The Texas Data Privacy and Security Act (TDPSA): What DFW Businesses Must Do to Comply in 2026

The Texas Data Privacy and Security Act (TDPSA): What DFW Businesses Must Do to Comply in 2026

Let’s be honest about why this law matters to you

If you run a business in Dallas-Fort Worth, you’ve probably heard “data privacy law” and mentally filed it under “something for big tech companies to worry about.” That’s the mistake a lot of local business owners are making right now, and it’s an expensive one.

The Texas Data Privacy and Security Act doesn’t care how big your company is in the way you’d expect. It’s not triggered by revenue thresholds the way some other states’ laws are. It’s triggered by whether you do business in Texas and touch consumer data — full stop. A dental office in Plano, an HVAC company in Fort Worth, a boutique retailer in Uptown Dallas, a third-party logistics warehouse in Grand Prairie — all of these could be on the hook.

We work with DFW businesses on their IT and security day-to-day, and this law comes up constantly right now — usually from an owner who just heard about it from their attorney, their insurance broker, or a scary LinkedIn post, and wants a plain answer to “does this apply to me, and what do I actually need to do.” That’s exactly what this article is.

We’ll walk through what the law actually says, who it applies to (with real DFW business examples, not abstract legal categories), what data counts as “sensitive,” what rights your customers now have, the actual step-by-step compliance checklist, what happens if you ignore it, and answers to the questions we get asked most.


What is the Texas Data Privacy and Security Act, exactly?

The TDPSA is Texas’s answer to the wave of state privacy laws that started with California back in 2018. Texas signed its version into law in June 2023, and it became enforceable on July 1, 2024. A second piece, the requirement to recognize browser-level opt-out signals like Global Privacy Control — kicked in on January 1, 2025.

In plain terms: it’s a law that gives Texas consumers control over their personal data, and puts specific obligations on the businesses that collect, use, or sell that data. It’s modeled closely on Virginia’s privacy law, which means if you’ve heard anything about California’s CCPA, some of the concepts will feel familiar, but Texas’s version has its own quirks, and a few of them genuinely surprise business owners.

One important detail: only the Texas Attorney General can enforce this law. There’s no private right of action, meaning an individual customer can’t personally sue your business over a TDPSA violation. But the AG’s office can and in 2024, Attorney General Ken Paxton publicly announced a dedicated enforcement initiative around exactly this law. This isn’t a law sitting quietly on the books.


Does the TDPSA actually apply to your DFW business?

Here’s the three-part test the law uses. You’re covered if your business:

  1. Conducts business in Texas, or offers a product/service that Texas residents use
  2. Processes or sells personal data
  3. Is not classified as a “small business” under U.S. Small Business Administration size standards

That third point trips people up. The SBA’s definition of “small business” isn’t a single number — it varies by industry, and it’s usually measured in employee count or average annual receipts, not just “I’m a small shop so I must be exempt.” A 40-person medical practice and a 40-person marketing agency can fall on different sides of that line depending on their industry code.

And here’s the part that surprises almost everyone: even if your business qualifies as an SBA small business, you’re still not fully off the hook. If you sell sensitive personal data — even as a small business — you still need the consumer’s consent first. There’s no full free pass just because you’re small.

A few real DFW scenarios

Let’s make this concrete, because “conducts business in Texas and processes personal data” is vague enough to apply to almost anyone.

  • A small professional office (say, a 12-person accounting or law firm in Frisco): collects client names, contact info, and financial details. If it’s not SBA-small by its industry standard, or if it sells any of that sensitive data, it’s covered.
  • A medical or dental office in Dallas: collects health information, insurance details, sometimes biometric data (imaging, fingerprints for records access). Health data handled under HIPAA has its own carve-out — but only for the parts actually governed by HIPAA. Marketing lists, appointment reminders, and website analytics data often aren’t HIPAA-covered and fall under TDPSA instead.
  • A retail store in a DFW shopping center: loyalty programs, email marketing lists, in-store Wi-Fi tracking, point-of-sale data. Classic TDPSA territory — especially if any of that customer data gets shared with ad platforms or data brokers.
  • A warehouse or 3PL operation in Grand Prairie or Arlington: might feel exempt because “we don’t deal with consumers directly.” But if the warehouse runs a customer-facing portal, handles returns data, or processes data on behalf of a retail client, it can still be a “processor” under the Act — which comes with its own obligations.
  • A corporate office with a few hundred employees in Las Colinas or Downtown Dallas: larger companies are almost never SBA-small, so the exemption question usually isn’t even in play — the real work is building the actual compliance program (covered in detail below).

Quick-reference table: does TDPSA likely apply to you?

Business typeCollects personal/sensitive data?Likely SBA small business?TDPSA exposure
Solo/small professional office (under ~10–15 staff)Yes (client contact + financial info)Often, but not alwaysModerate — check SBA size standard for your exact industry code
Medical or dental practiceYes (health + biometric + marketing data)SometimesModerate-high — HIPAA covers clinical data, but marketing/website data usually isn’t HIPAA-protected
Retail store with loyalty/email programsYes (customer + purchase behavior data)Depends on revenue/headcountModerate-high, especially if data is shared with ad platforms
Warehouse / 3PL / logisticsSometimes (portals, returns, client data processing)VariesModerate — often overlooked as a “processor” under the Act
Corporate office (100+ employees)YesRarelyHigh — full compliance program almost always required

(This table is a directional guide, not legal advice — the SBA size standard genuinely varies by NAICS industry code, so confirm your specific threshold before assuming you’re exempt.)


What counts as “personal data” vs. “sensitive data” under the TDPSA?

This distinction matters because sensitive data comes with stricter rules — you generally need consent before processing it at all, and there are specific notice requirements if you ever sell it.

Personal data, broadly, is any information that’s linked or reasonably linkable to an identifiable person. That includes obvious things like name, email, and phone number, but also less obvious things like device identifiers or behavioral data tied back to a person. It does not include information that’s been properly de-identified, or information that’s already public.

Sensitive data is a narrower category that includes:

  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health conditions/diagnoses
  • Sexuality
  • Citizenship or immigration status
  • Genetic or biometric data used to identify someone
  • Precise geolocation data
  • Any personal data belonging to a child under 13

Biometric data gets its own definition — think fingerprints, facial geometry, voiceprints used to identify someone. It’s worth noting the law specifically excludes plain photos, videos, or audio recordings from that definition (those aren’t automatically “biometric” just because a person appears in them), and it excludes health-related biometric data that’s already governed by HIPAA.

Comparison table: personal vs. sensitive vs. biometric data

CategoryExamplesConsent required before processing?Common DFW business context
Personal dataName, email, phone, purchase history, device IDNot automatically, but must be disclosed in your privacy noticeAlmost every business collects this
Sensitive dataHealth condition, religion, immigration status, precise location, a child’s dataYes — opt-in consent requiredMedical offices, HR-adjacent data, mobile apps using location
Biometric dataFingerprints, facial scans, voiceprints (used to ID someone)Yes, and additional notice required if soldAccess-control systems, some POS/loyalty tech, HR time-clock systems

If your business uses fingerprint or facial-recognition time clocks, keycard-and-biometric access control at an office or warehouse, or any point-of-sale system that captures identity-linked behavioral data, this is the section to read twice.


What rights do your customers now have?

Under the TDPSA, any Texas consumer whose data you process can ask you to:

  • Confirm whether you’re processing their data, and get a copy of it
  • Correct inaccurate information you hold about them
  • Delete data they provided, or data you obtained about them
  • Port their data — get a usable copy they can take to another provider
  • Opt out of having their data used for targeted advertising, sold, or used in certain kinds of automated profiling (especially profiling tied to decisions about lending, housing, insurance, healthcare, education, employment, or criminal justice)

They also have the right to not be punished for exercising any of the above — you can’t charge a customer more, deny them service, or degrade their experience just because they asked you to delete their data.

For a small DFW retail shop, this might show up as an occasional customer email asking “please remove me from your list.” For a medical office or corporate office managing thousands of records, this needs an actual documented process — which is exactly what we’ll cover next.


What your business actually has to do to comply

This is the section most articles skip past with vague advice like “consult your attorney.” That’s fair advice for the legal side, but there’s a concrete operational checklist underneath it, and most DFW businesses can knock most of it out in a few focused weeks.

Here’s the short version first, then we’ll break each piece down.

The 7-item compliance checklist:

  1. Publish a compliant privacy notice
  2. Set up an opt-out mechanism (including Global Privacy Control recognition)
  3. Build a documented process for handling customer data requests
  4. Limit data collection to what you actually need
  5. Update contracts with any vendor who touches your customer data
  6. Run data protection assessments for higher-risk activities
  7. Put reasonable data security practices in place — and be able to show them

1. Your privacy notice needs specific disclosures

A generic “we value your privacy” page copied from a template five years ago won’t cut it anymore. Your privacy notice needs to spell out what categories of data you collect, why, who you share it with, and how a customer can exercise their rights.

If you ever sell sensitive personal data or biometric data, the law requires a specific, exact notice — not a paraphrase. It has to say, word for word: “NOTICE: We may sell your sensitive personal data” (or biometric, as applicable), posted in the same spot and same way as your regular privacy notice.

For a retail store in Dallas running a loyalty program that shares data with ad networks, this is often the single most common gap we see.

2. Consumers need a real way to opt out

This one has a technical piece most business owners don’t expect: as of January 1, 2025, businesses have to recognize Global Privacy Control (GPC) — a browser-level signal that tells your website “this visitor doesn’t want their data sold or used for targeted ads,” without them having to click anything on your site.

If your website runs on a platform like WordPress, Shopify, or a custom stack, this usually means a small configuration or plugin change — not a rebuild. But it does need someone who actually knows your site’s setup to implement and verify it, which is where a lot of small Dallas businesses get stuck: not because it’s hard, but because nobody owns it.

3. Build a documented data request process

When a customer asks to see, correct, delete, or transfer their data, you need at least two secure ways for them to submit that request, and you have to respond within 45 days (extendable by another 45 days if you tell them why, within the original window).

Requests have to be handled free of charge, up to twice a year per customer. If you deny a request, you need a documented reason and a clear appeal path.

For a small office, this might just be a monitored email inbox and a simple internal checklist. For a medical practice or corporate office fielding dozens of these a month, this usually needs a lightweight ticketing process — something your practice management software, CRM, or helpdesk tool can likely already support with the right configuration.

4. Only collect what you actually need

This is the “data minimization” principle: don’t collect information just because a form builder makes it easy to add another field. If you don’t have a real business reason to ask for someone’s date of birth, don’t ask for it. Fewer data fields means less risk, less to secure, and less to disclose.

5. Fix your vendor contracts

If a third party processes customer data on your behalf — your marketing agency, your billing platform, your IT provider, your CRM vendor — your contract with them needs to spell out how they’ll handle the data, that they’ll assist you in complying with the Act, and that they’ll delete or return the data when the relationship ends.

This is easy to overlook because it’s not customer-facing. But if a vendor mishandles your customers’ data, the compliance gap traces back to you.

6. Run assessments for higher-risk data activities

You need a documented assessment (weighing benefits against risks) for activities like targeted advertising, selling data, certain profiling, and any processing of sensitive data. This sounds heavier than it usually is in practice — for most DFW small and mid-size businesses, it’s a short, honest internal document, not a formal audit.

7. Put real security practices in place

The law requires “reasonable” data security practices — it doesn’t hand you a specific checklist of tools, which is both a blessing and a curse. In practice, “reasonable” for a DFW business usually means the basics done consistently: endpoint protection, patched systems, encrypted backups, access controls (including on physical systems like biometric door locks or time clocks), and staff who know how to spot a phishing attempt.

Most businesses we work with already run familiar tools for parts of this — Microsoft 365 or Google Workspace for email and file storage, a backup platform to protect against ransomware, a password manager for shared credentials. The compliance question isn’t usually “what do we buy,” it’s “are we actually using what we have correctly, and can we prove it if the AG ever asks.” That documentation piece is where a lot of businesses fall short — not the tools themselves.

This is exactly the kind of gap our team helps close for businesses across the Dallas-Fort Worth metro — auditing what’s already in place, tightening the parts that don’t meet a “reasonable security” standard, and documenting it so you have an answer ready if you’re ever asked.


What it actually costs to get compliant

There’s no single number here, and anyone who quotes you a flat fee without looking at your business first is guessing. Cost depends on a handful of real variables:

  • How much customer data you already collect — a solo consultant’s contact list is a different job than a retail chain’s loyalty database
  • What systems you’re already running — if you’re on modern, supported platforms, updates are usually configuration work; if you’re on outdated or homegrown systems, there’s more lift
  • Whether you need legal review — a privacy attorney reviewing your notice and vendor contracts is a separate cost from the IT/security work
  • How many vendors touch your data — each vendor contract that needs updating adds time
  • Whether you’re starting from zero or already have decent security hygiene

For a small DFW office with a handful of vendors and a standard website platform, the IT and documentation side of this is often a matter of days, not weeks. A multi-location retail operation or a corporate office with legacy systems is a bigger project. The honest first step for either one is the same: an assessment of what you currently have against what the law actually requires, so you’re paying for the actual gaps — not a generic package.

If you want a clear picture of where your business stands, that’s a conversation worth having before you spend a dollar on tools or consultants. Reach out to our Dallas-Fort Worth team for a straightforward compliance and security assessment — no guesswork, no upsell, just an honest look at what you actually need.


What happens if you don’t comply

Only the Texas Attorney General can enforce the TDPSA — there’s no private right of action, meaning an individual customer can’t personally sue your business over a violation. That said, the AG’s office has been vocal about actively enforcing this law, and customer complaints are what typically trigger a look.

If a violation is found, you get a 30-day cure period — a chance to fix it before any penalty. Unlike some other states, Texas’s cure period doesn’t expire after a set number of years; it stays available. But curing isn’t just “we fixed it” — you have to submit a written statement to the AG confirming the violation was fixed, that affected consumers were notified (if you had their contact info), and that you’ve updated internal policies so it doesn’t happen again.

If you don’t cure it, or you violate the terms of a cure statement you already gave, the penalty is up to $7,500 per violation. That’s per violation, not per case — which is exactly how a small oversight on a handful of records can turn into a real number quickly.


Does this apply to employee data too?

No — and this is one of the more business-friendly parts of the TDPSA compared to states like California. Data collected in the course of someone applying for a job, being employed, or acting as a contractor or agent for your business is excluded, as long as it’s used within that employment or contractor context.

So your HR files, payroll data, and internal employee records aren’t governed by this law. Your customer data is what matters here — which is also why a warehouse or corporate office with mostly B2B relationships and few direct consumers may have a lighter compliance lift than a retail store with a large customer list.


A simple DFW action plan

If you’re not sure where to start, here’s the order that makes sense for most local businesses:

  1. Figure out if you’re covered — check your SBA size standard for your specific industry, and be honest about whether you sell any sensitive data even if you think you’re exempt.
  2. Inventory your data — what you collect, where it lives, who else touches it.
  3. Fix your privacy notice and opt-out setup — this is usually the fastest win.
  4. Build your request-handling process — even a simple documented one beats none.
  5. Review vendor contracts — flag anyone processing customer data on your behalf.
  6. Get your security practices audited and documented — this is where DFW businesses lean on a local IT and security partner rather than trying to piece it together internally, since it touches backups, access control, and monitoring all at once.
  7. Put a review on your calendar — this law and its enforcement approach are still evolving; treat this as a living checklist, not a one-time project.

FAQs

When did the TDPSA take effect?

The main law took effect July 1, 2024. The requirement to recognize browser-based opt-out signals like Global Privacy Control took effect January 1, 2025.

Does the TDPSA apply to small businesses?

It depends on the SBA’s size standard for your specific industry — not just how “small” your business feels. And even businesses that qualify as SBA-small still need consent before selling sensitive personal data.

Can a customer sue my business under the TDPSA?

No. Only the Texas Attorney General can enforce the law — there’s no private right of action.

What’s the penalty for violating the TDPSA?

Up to $7,500 per violation, but only after a 30-day cure period where you have the chance to fix the issue first.

Does the TDPSA cover my employees’ data?

No. Data collected in an employment or contractor context is excluded from the law. It applies to consumer data, not workforce data.

How is “sale of data” defined under the TDPSA?

Sharing, disclosing, or transferring personal data to a third party for money or anything else of value. It doesn’t include sharing data to fulfill a service the customer actually asked for, or sharing as part of a business merger or acquisition.

Do I need special notices if I sell sensitive or biometric data?

Yes. The law requires specific, exact wording — “NOTICE: We may sell your sensitive personal data” (or biometric) — posted in the same location and format as your privacy notice.


Bottom line for DFW business owners

The TDPSA isn’t a law you can assume doesn’t apply to you just because you’re not a tech company. If you collect customer data in Texas — and almost every business does, in some form — it’s worth a genuine 20-minute check against the criteria above rather than a guess.

The businesses that get ahead of this treat it the same way they’d treat any other operational risk: assess it, fix the clear gaps, document what you’ve done, and revisit it periodically. That’s a manageable project. Ignoring it and hoping you’re too small to notice is the version that actually gets expensive.

Not sure where your business stands? Talk to our Dallas-Fort Worth team about a no-pressure compliance and security review — we’ll tell you plainly what you need and what you don’t.

Leave a comment

Google Verified Google Reviews

Verified Reviews from Real IT Support Clients

See what our satisfied customers are saying about their experience with Ighty Support.

Excellent
★★★★★
Kristopher Yglesias
11 months ago
★★★★★

Josiah and Tony did a great job to set up our new office. They took their time and did really good work. Communication was easy and the project was run efficiently. Even saved a bit of money compared to the other bids.

Read more
Theresa Schnitzler
11 months ago
★★★★★

Ighty IT Support is the Best Ever!! They are very helpful and fixed my Computer issues asap! I Highly recommend them for IT services.

Read more
Andrew R. Wetzel
11 months ago
★★★★★

Did a great job and worked quickly. Joshua and Gilberto figured out how to fix our wiring problem with ease, which is something we couldn’t do on our own. Would definitely recommend to anyone looking for cabling/networking services.

Read more
Riley Bates
4 months ago
★★★★★

We had ongoing security concerns and occasional virus alerts on our network. Jimmy helped resolve the issues and put proper safeguards in place. Everything has been stable since, and the support has been consistent and professional.

Read more
Langston Abbott
4 months ago
★★★★★

During an email migration, Joy stepped in and recommended the right approach to get everything done smoothly. The process was handled professionally, and we didn’t experience any downtime.

Read more
Dominic Robinson
4 months ago
★★★★★

Fast response and dependable IT support. Issues are handled without delays.

Read more
100% satisfaction guaranteed
or money back.