Does the Texas Privacy Law Apply to My Small Business?

Texas is the most misunderstood state privacy law in the country for small businesses. Here's the truth: the Texas Data Privacy and Security Act exempts SBA-defined small businesses — with one exception you need to know about.

Updated October 2026 · 9-minute read

The short answer: if your business qualifies as a "small business" under U.S. Small Business Administration size standards, you're exempt from most of the Texas Data Privacy and Security Act. But "most" isn't "all" — and Texas is unusual enough that the details matter.

Texas confuses people more than any other state privacy law, and it's not hard to see why. The Texas Data Privacy and Security Act (TDPSA) — in effect since July 1, 2024 — is the rare comprehensive privacy law with no revenue threshold and no consumer-count threshold. In most states, the question is "am I big enough to be covered?" In Texas, the question is "am I small enough to be exempt?"

That one flipped question is where nearly all the bad advice comes from. Vendors selling compliance software love the no-threshold version of the story ("every business selling to Texans is covered!"). The actual statute tells a more interesting story. Let's walk through it.

What the TDPSA actually covers

The law applies to businesses that conduct business in Texas or provide products or services consumed by Texas residents, and that process or sell personal data. Note the word "consumed" — most states say "targeted." Legal analysts at firms like Usercentrics have noted this wording seems designed to catch out-of-state sellers doing business in Texas.

Covered businesses have to do the familiar things: tell consumers what data they collect, honor opt-outs of sales and targeted advertising, respond to access/deletion/correction requests, and — since January 1, 2025 — recognize universal opt-out signals like Global Privacy Control. The Texas Attorney General enforces the law exclusively (no private lawsuits), with a 30-day cure period and civil penalties of up to $7,500 per violation.

Enforcement is real: the Texas AG filed its first TDPSA enforcement action in January 2025. This isn't a paper law.

The small-business exemption — the part everyone gets wrong

Here's the sentence that matters: the TDPSA does not apply to a business that qualifies as a small business under U.S. Small Business Administration size standards.

What does "SBA small business" mean in practice? The SBA sets size standards by industry, but the headline numbers most businesses check are:

If you're a 12-person marketing agency, a 40-employee manufacturer, or a solo Shopify seller, you are almost certainly an SBA small business — and therefore exempt from most of the TDPSA.

The exception that still catches small businesses: even an exempt small business must obtain a consumer's opt-in consent before selling that person's sensitive data — things like health information, precise geolocation, racial or ethnic origin, or children's data. If your business model involves selling or sharing sensitive data (including for targeted advertising), the exemption doesn't fully protect you. This is the one piece worth a conversation with a privacy attorney.

So: does it apply to your Texas business?

If you're a small Texas business selling locally…

You're almost certainly exempt. A restaurant, a local retailer, a services firm under 500 employees — the TDPSA's small-business exemption covers you for the core obligations. The one thing to check: are you selling or sharing customers' sensitive data (health, precise location, etc.)? If yes, get advice on the consent requirement.

If you're a small business elsewhere selling to Texans…

Same exemption logic applies — the SBA standard doesn't care where you're headquartered. But remember the "consumed by Texas residents" language is broader than other states' targeting tests, so out-of-state sellers should take the exemption question seriously rather than assuming distance protects them.

If you're not an SBA small business…

Then Texas treats you like any other covered business: privacy notices, opt-outs (including GPC since January 2025), 45-day rights-request responses, data protection for what you hold, and AG enforcement with $7,500-per-violation exposure after a 30-day cure period.

"Texas exempts you — but which states don't?"

This is the question the Texas exemption should prompt. Texas is generous to small businesses. Most other states aren't — they just use volume thresholds instead:

So the business that's comfortably exempt in Texas can be squarely covered in California or Colorado on consumer counts alone. That's the patchwork: the exemption that saves you in one state doesn't travel. Our applicability hub walks through the three-question test for every state.

Watch: Texas's first enforcement action, explained

Video: Husch privacy attorneys walk through Texas's first TDPSA enforcement action (via Byte Back Law). Useful context on how the AG actually uses the law. We haven't watched it end-to-end; verify anything you act on.

Key dates in the TDPSA timeline

If you are covered: what Texas actually requires

For the businesses above the SBA small-business line, the TDPSA's obligations track the standard state-privacy playbook:

Enforcement is AG-exclusive (no private lawsuits), with a 30-day cure period and penalties up to $7,500 per violation after that. The January 2025 enforcement action shows the AG's office is watching — but also that it started with a significant case, not a 10-person shop.

Texas vs. the standard model, side by side

Texas (TDPSA)Standard model (VA, CO, CT…)
Volume thresholdNone100,000 consumers (or 25,000 + 50% revenue from data sales)
Small-business carve-outYes — SBA-defined small businesses exempt (with the sensitive-data exception)No general carve-out; thresholds do the work
Trigger language"Conducts business in" or products/services "consumed by" residents"Conducts business in" or "targets" residents
Universal opt-out (GPC)Required since Jan 1, 2025Required in 12 states and counting
EnforcementAG only, 30-day cure, up to $7,500/violationAG only in most states; cure periods vary

The takeaway: Texas looks scary (no thresholds!) until you read the exemption, and looks generous (small-business exempt!) until you hit the sensitive-data exception. Both halves matter.

Frequently asked questions

How do I know if I'm an "SBA small business"?

The SBA publishes size standards by NAICS industry code — generally fewer than 500 employees, with revenue caps that vary widely by industry (roughly single-digit millions to low tens of millions). Look up your NAICS code on the SBA's size-standards table. If you're clearly under both the employee and revenue lines for your industry, you're in. If you're near a line, that's a question for your attorney, not a blog post.

I sell to Texans but I'm based elsewhere. Does the exemption still apply?

Yes — the SBA standard doesn't care where you're headquartered. But note Texas's "consumed by residents" language is broader than other states' "targeting" tests, so out-of-state sellers should take the exemption analysis seriously rather than assuming distance alone protects them.

What counts as "sensitive data" under the TDPSA?

The usual sensitive categories: health and genetic data, precise geolocation, racial or ethnic origin, religious beliefs, union membership, children's data, and government identifiers like Social Security numbers. Remember: even exempt small businesses need opt-in consent before selling these.

Does Texas require a cookie banner?

No — and neither does any US state privacy law. The US model is opt-out (the "Do Not Sell or Share" link plus GPC), not EU-style opt-in consent banners. If someone's selling you an EU-style banner as a Texas requirement, they're selling you the wrong product.

I'm a Texas business under 500 employees. Am I done thinking about privacy law?

For Texas, mostly yes — the SBA exemption covers you except on selling sensitive data. But your customers in other states don't care about the Texas exemption. Run the per-state threshold math for everywhere you have real customer counts, starting with California.

Does the TDPSA apply to nonprofits?

Nonprofits are generally outside the TDPSA's scope, consistent with most states' entity-level exemptions. But data practices still matter for donor trust — and nonprofit-adjacent commercial activity can blur the line. When in doubt, check with counsel.

What should I do before January 1, 2025's GPC deadline… it's already passed?

Right — universal opt-out recognition has been live since January 2025. If you're a covered business and you haven't implemented GPC honoring yet, you're behind. It's one of the simpler technical items (most consent platforms support it), so close this gap first.

Want the full system?

The $49 Starter Pack includes the Texas exemption worksheet, the 24-state threshold matrix, and the 2027 readiness system.

See the Starter Pack

Start free

The 20-question compliance checklist tells you where you stand in about ten minutes.

Get the free checklist

Important: this is not legal advice

This article is general educational information about the Texas Data Privacy and Security Act, not legal advice. Whether you qualify as an SBA small business depends on your industry's specific size standards, and the sensitive-data exception has real teeth — verify your situation against the statute and consult a licensed privacy attorney in Texas before making compliance decisions.