Tech Insights

Texas’s Data Privacy Law (TDPSA): What It Actually Means for Houston Small Businesses

Texas's Data Privacy Law (TDPSA): What It Actually Means for Houston Small Businesses

“California has a privacy law. We’re in Texas — that stuff doesn’t apply to us.”

We hear some version of that from a Houston business owner almost every month. It made sense for a while. For years, the big privacy laws lived in other states, and most of them came with comfortable thresholds — you had to be huge, or processing a mountain of consumer records, before anyone cared. Then Texas passed its own law, and the comfortable threshold quietly disappeared.

The Texas Data Privacy and Security Act — the TDPSA — took effect July 1, 2024. If you collect personal information from Texas residents and you haven’t looked at it, this post is for you. We’re going to explain what it actually means in plain English. We are not attorneys, and nothing here is legal advice. What we can tell you is what we see inside real Houston businesses, where the gaps usually are, and which parts of this are a technical problem you can actually fix.

Why Texas’s Law Surprised Everyone

Most state privacy laws have a built-in escape hatch. They typically only apply once a business clears a high bar — tens of millions in revenue, or processing the personal data of a hundred thousand-plus consumers. The vast majority of small businesses fall comfortably under those numbers and stop reading.

Texas did something different. The TDPSA generally applies to a person or business that:

  • conducts business in Texas, or produces products or services consumed by Texas residents, and
  • processes or engages in the sale of personal data.

Notice what’s missing: there’s no big revenue number and no big data-volume number doing the gatekeeping. That’s what caught people off guard. Instead of a size threshold, the main relief valve in the Texas law is a carve-out for businesses that qualify as a “small business” as defined by the U.S. Small Business Administration (the SBA).

That sounds like a clean exemption, and for many small companies it provides real relief. But two things matter. First, “small business under the SBA definition” is a specific legal question — the SBA sizes businesses by industry, using employee counts or revenue figures that vary widely by sector. Whether your company qualifies is a question for your attorney, not something to assume because you feel small. Second, even if you do qualify, the carve-out isn’t a total free pass.

The catch hidden inside the small-business carve-out

Even a business that meets the SBA small-business definition is still restricted from selling sensitive personal data without consent. “Sensitive data” generally covers categories like data revealing race or ethnicity, religious beliefs, health conditions, sexual orientation, citizenship or immigration status, genetic or biometric data, precise geolocation, and personal data collected from a known child.

So the mental model many owners walk away with — “I’m small, so I’m exempt, the end” — is incomplete. Confirm with your attorney how the carve-out applies to you, and don’t treat “small” as a reason to ignore the law entirely.

Who Should Be Paying Attention

Generally, if your business collects personal data from Texas residents — customers, prospects, website visitors, patients, clients — and you are not clearly within the small-business carve-out, the TDPSA is something you need to understand. That covers a lot more Houston companies than people expect: medical and dental practices, professional services firms, e-commerce sellers, contractors with online lead forms, anyone running marketing pixels and ad retargeting.

And here’s the honest part: the single most important early question — “Does my business even qualify as a small business under the SBA definition?” — is a legal question. Get that answered by your attorney before you decide how much of the law applies to you. What we can help you do is the other half: actually know what data you hold, where it lives, and whether it’s secured.

The Core Obligations, In Plain Terms

For businesses that do fall under the full law, the TDPSA generally requires a handful of things. Here’s the plain-English version — with the reminder that the exact wording of your documents is your attorney’s department.

  1. A clear privacy notice. A reasonably accessible, plain notice that explains what categories of personal data you collect, why, whether you share or sell it, and how consumers can exercise their rights.
  2. Honoring consumer rights. Texas residents can generally request to access their data, correct it, delete it, get a portable copy, and opt out of targeted advertising, the sale of their data, and certain profiling. You need a real way to receive and respond to those requests.
  3. Consent before sensitive data. You generally must obtain consent before processing sensitive personal data — and, as noted above, even small-business carve-out companies can’t sell sensitive data without consent.
  4. Data processing agreements with vendors. When another company processes personal data on your behalf — your CRM, email platform, billing system, cloud host — there generally needs to be a contract governing that processing.
  5. Reasonable data security practices. You’re expected to maintain reasonable administrative, technical, and physical safeguards to protect the personal data you hold.

That last one — reasonable security — is where compliance stops being a paperwork exercise and becomes an IT reality. A privacy notice that promises you protect customer data means nothing if the data is sitting in an unsecured shared drive that half the office can open.

The Gap We Actually See in Small Businesses

On paper, a lot of Houston businesses look fine. In reality, here’s the pattern we run into over and over.

  • The privacy notice doesn’t match what the business actually does. Someone pasted a generic template onto the website years ago. It doesn’t mention the ad pixels they’re running, the data they share with partners, or the rights consumers now have. A notice that misdescribes your real practices can be worse than no notice at all.
  • There’s no process to handle a consumer rights request. If a customer emailed today and said “delete all my personal data,” nobody would know where it all lives, who’s allowed to act on it, or how to verify the request. The clock would be ticking and the team would be guessing.
  • There are no data processing agreements with vendors. Customer data flows into a dozen cloud tools, and not one of those relationships is papered correctly. The business is responsible for data it can’t even fully account for.
  • Nobody knows what data they hold or where it lives. This is the root of all of it. You can’t write an honest privacy notice, answer a deletion request, or secure data you haven’t mapped.

That fourth point is the foundation. A proper data inventory — knowing what personal data you collect, where it’s stored, who can touch it, and which vendors it flows to — is the work that makes everything else possible. It’s also exactly the kind of work most owners have never done, because until now nothing forced the question.

Enforcement: Who Comes Knocking

The TDPSA is enforced by the Texas Attorney General — there’s generally no private lawsuit right baked into the law for consumers. Before the AG can pursue penalties, the law provides a notice-and-cure period (commonly described as 30 days), during which a business that’s notified of a violation gets a window to fix it and confirm in writing that it has.

If a violation isn’t cured, the AG can seek civil penalties per violation, plus the cost of dealing with the problem. We’re describing this qualitatively on purpose — the specifics of penalty amounts, cure timing, and how it would play out in your situation are questions for your attorney. The practical takeaway: a notice-and-cure window only helps you if you can actually cure the problem inside it. If you don’t know where your data lives, 30 days is not a lot of time to find out.

What To Actually Do

You don’t have to solve all of this at once. Start with the parts that are genuinely yours to control.

1. Know what data you collect and where it lives

Build a real data inventory. What personal data comes in, through which forms and tools, where it’s stored, who has access, and which third parties receive it. This is the backbone of making compliance real instead of theoretical, and it’s the part we do day in and day out.

2. Tighten your security

“Reasonable safeguards” means real controls: access restricted to who needs it, multifactor authentication, encryption where appropriate, monitoring, and a tested backup and recovery plan. This is core network security and ongoing managed IT work — the technical muscle behind any privacy promise you make.

3. Paper the vendor relationships

Identify every vendor that processes personal data on your behalf and make sure those relationships are governed by proper agreements. We can help you map which vendors touch your data; the contract language itself belongs with your attorney.

4. Confirm what applies to you — with a professional

Whether you qualify for the small-business carve-out, what your privacy notice needs to say, and how the law maps to your specific business are legal calls. Talk to your attorney. Then talk to us about the technical side — the data inventory, the security controls, the monitoring, and the documentation that prove your words on paper are true in reality.

The Bottom Line

The TDPSA closed the loophole most small businesses were quietly relying on. Even if the small-business carve-out covers you, you still can’t sell sensitive data without consent — and the only way to know where you stand is to actually understand what data you hold and how it’s protected. Compliant on paper isn’t the same as safe in reality. The law cares about the second one.

Here’s where Aspendora fits. We’re not a law firm and we’re not auditors — the legal text and the wording of your privacy notice are for your attorney. What we do is the technical and documentation side that makes compliance real: mapping what personal data you hold, locking it down, monitoring it, and proving it’s actually protected. If you’d like a place to start, book a free 15-minute discovery call at /discoverycall/ and we’ll talk through where your data lives and where the gaps are. To understand more about how we approach this, visit /compliance/. To be clear about cost: the 15-minute discovery call is the only free thing — the actual data inventory, security, and ongoing work are professional engagements at our published rates. That’s how it should be, because real protection isn’t a free download.

Aspendora Technologies provides cybersecurity, managed IT, and expert on-premise & open-source solutions to Houston-area small businesses since 2010.

Need IT Help?

Talk to a real Houston-based IT pro. 15 minutes, no pressure.

Schedule a Free Consultation