Understanding the Texas Data Privacy and Security Act: A New Era for Privacy in the Lone Star State

Understanding the Texas Data Privacy and Security Act: A New Era for Privacy in the Lone Star State
Photo by Adam Thomas / Unsplash

The digital landscape is continuously evolving, and with it, the need for robust data privacy laws. In response to this growing necessity, Texas has recently joined the ranks of states with comprehensive data privacy laws. The Texas Data Privacy and Security Act (TDPSA), signed into law by Governor Greg Abbott, is set to reshape the way businesses handle personal data in the Lone Star State.

Who Does the TDPSA Apply To?

The TDPSA applies to any entity that (1) conducts business in Texas or produces a product or service consumed by residents of Texas; (2) processes or engages in the sale of personal data; and (3) is not a small business as defined by the US Small Business Administration. The law defines a small business as one with fewer than 500 employees. The TDPSA is set to go into effect on July 1, 2024.

Consumer Rights Under the TDPSA

The TDPSA grants consumers several rights, similar to those found in other comprehensive data privacy laws. These include:

  1. The right to confirm whether a controller is processing the consumer’s personal data and to access that data.
  2. The right to correct inaccuracies in their personal data.
  3. The right to delete their personal data.
  4. The right to obtain a copy of their data in a digital format.
  5. The right to opt out of processing for purposes of targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.

Controller Obligations

Controllers, as defined by the TDPSA, have several obligations. They must limit the collection of personal data to what is adequate, relevant, and reasonably necessary in relation to the purpose for which that personal data is processed. They must also establish, implement, and maintain reasonable administrative, technical, and physical data security practices. Controllers are required to perform data protection assessments in certain circumstances and must publish a privacy notice that meets specified requirements.

Unique Provisions of the TDPSA

The TDPSA has several unique provisions that set it apart from other data privacy laws. These include a requirement to post prescribed notices regarding the sale of sensitive personal data and biometric personal data. There is also a thirty-day cure period that requires more from the alleged violator than a statement that the alleged violation has been cured. Additionally, the TDPSA prohibits the sale of personal data by small businesses without the prior consent of the consumers.

Preparing for the TDPSA

With the TDPSA set to go into effect in 2024, businesses should begin assessing whether the law applies to them and understanding the personal data they collect. This includes how the data is used, shared, disclosed, and sold. With this information in hand, businesses can start taking steps to comply with the TDPSA.

The enactment of the TDPSA marks a significant step in Texas's journey towards robust data privacy. As the law takes effect, businesses operating in Texas will need to adapt to these new regulations, ensuring they are in compliance and protecting the personal data of their consumers.

Read more

Global Information Security Compliance and AI Regulations: Q2 2025 Updates - A Comprehensive Analysis

Global Information Security Compliance and AI Regulations: Q2 2025 Updates - A Comprehensive Analysis

The second quarter of 2025 has marked a pivotal period in the evolution of global information security compliance and artificial intelligence regulations. Organizations worldwide are navigating an increasingly complex landscape of regulatory requirements, with significant developments across multiple jurisdictions that will reshape how businesses approach cybersecurity, data protection, and AI

By Compliance Hub
Global Data Guardians: Navigating the Fragmented Future of Data Security and Compliance

Global Data Guardians: Navigating the Fragmented Future of Data Security and Compliance

In today's interconnected digital world, multinational corporations (MCPs) face a formidable challenge: ensuring robust data security and seamless regulatory adherence across a deeply fragmented global landscape. The era of escalating cyber threats, particularly a substantial increase in ransomware incidents, demands proactive and meticulous attention to diverse international data

lock-1 By Compliance Hub
Cybersecurity Baseline Self-Assessment: A Comprehensive Framework Approach

Cybersecurity Baseline Self-Assessment: A Comprehensive Framework Approach

Overview A cybersecurity baseline self-assessment is a structured evaluation tool that helps organizations understand their current security posture and identify areas for improvement. This assessment methodology provides actionable recommendations aligned with industry-standard frameworks to enhance an organization's cybersecurity maturity. Baseline Cyber | Cybersecurity Compliance Assessment ToolEvaluate your organization’s

By Compliance Hub
Generate Policy Global Compliance Map Policy Quest Secure Checklists Cyber Templates