Consumer Data Privacy

Texas Consumer Data Privacy Law: Thresholds, Consumer Rights & Deadlines

What Texas’s consumer data privacy law requires, maintained by Stauss PLLC. Last reviewed August 2026.

What You Need to Know

The bill is based on the Virginia law, with some notable variations. The most significant variation is the applicability standard. The bill applies to persons that (1) conduct business in Texas or produce products or services consumed by Texas residents, (2) process or engage in the sale of personal data, and (3) are not small businesses as defined by the United States Small Business Administration. Notably, if a person satisfies the first two requirements but is a small business under the third, it must still obtain consumer consent for the sale of sensitive personal data. Controllers that sell sensitive personal data or biometric data must make additional disclosures on their websites. The bill does not contain additional children's protections or the right to revoke consent.

Official law text
Who the law applies to
ThresholdRequirement
Annual gross revenueN/A
Consumers whose data is processedN/A
Revenue from sale of personal dataN/A
Other conditions
  • Process or engage in the sale of personal data and not be a small business as defined by the U.S. Small Business Administration
Consumer rights under Texas's law15
RightProvided?
KnowYes
AccessYes
Obtain list of third parties to which personal data was disclosedNo
Data portability
noteRight applies only to data provided by the consumer to the controller.
Partial
DeleteYes
Correct inaccuraciesYes
Not be discriminated against for exercising rightsYes
Opt-out of saleYes
Opt-out of targeted advertising/sharingYes
Opt-out of certain types of profilingYes
Opt-out of ADMTNo
Recognize opt-out signals
noteControllers must recognize UOOMs for state residents only if they are required to do so to comply with another state’s law.
Yes
Revoke consentNo
Not process data in discriminatory mannerNo
AppealYes

Tracking Texas’s privacy law? We write about it as the law changes.

Categories treated as sensitive data8
  • Racial or ethnic origin
  • Religious beliefs
  • Mental or physical health diagnosis
  • Sexuality
  • Citizenship or immigration status
  • Genetic or biometric data for purposes of uniquely identifying an individual
  • Personal data of known child
  • Precise geolocation
    noteConnecticut, Maryland, Oregon, and Virginia ban the sale of precise geolocation data.
How sensitive data must be treated4
  • Obtain Consent to Process
  • Must Obtain Consent to Sell Sensitive Data
    noteSmall businesses must obtain consumer consent to sell sensitive data.
  • Must Provide Specific Disclosure
    noteIn Texas, if a controller engages in the sale of sensitive data, the controller shall post the following notice: “NOTICE: We may sell your sensitive personal data.” If a controller engages in the sale of biometric data, the controller shall post the following notice: “NOTICE: We may sell your biometric personal data.”
  • Conduct Data Protection or Risk Assessment
Requirements for minors' data1
  • Process personal data of children under 13 in accordance with COPPA or parental/legal guardian consent
Activities that trigger a risk or impact assessment5
  • Targeted advertising (“sharing”)
  • Sale of personal data
  • Processing of sensitive data
  • Processing personal data for purposes of profiling where it presents reasonably foreseeable risk of unfair or deceptive treatment of, or unlawful disparate impact on, consumers; financial, physical, or reputational injury to consumers; physical or other intrusion upon the solitude or seclusion, or the private affairs or concerns, of consumers, where such intrusion would be offensive to a reasonable person; other subject injury to consumers
  • Any processing activities involving personal data that present a heightened risk of harm to consumers
Other notable provisions9
  • Definition of “Sale” Includes “Other Valuable Consideration”
  • Opt-out Request Can Be Verified
  • Data Processing Agreements
  • Privacy Policy
    noteTexas requires controllers that sell sensitive data to state in their privacy policy “We may sell your sensitive personal data.” Controllers that sell biometric data must state in their privacy policy “We may sell your biometric personal data.”
  • Implement Reasonable Data Security Measures
  • Duty to Avoid Secondary Use
  • Data Minimization
  • Attorney General Enforcement
  • Right to Cure
    note30 day right to cure that does not sunset.
Enforcement actions1

1 enforcement action logged against businesses under Texas’s consumer data privacy law.

Pending — Insurance Company and Subsidiary — Jun 18, 2024 — Texas Attorney General

Full details →

Key dates1
DateWhat happens
July 1, 2024Texas's consumer data privacy law takes effect

Questions about Texas’s privacy law?

Stauss PLLC advises companies on state privacy, AI, and data broker compliance.

Contact Stauss PLLC

Follow Texas’s privacy law

Our analysis, by email, as the law moves.

This page is provided for general informational purposes only, is not legal advice, and does not create an attorney-client relationship. State laws change frequently; coverage reflects this tool’s most recent update. Contact Stauss PLLC to confirm how these requirements apply to your organization.