Privacy
Texas Data Privacy and Security Act (TDPSA)
The TDPSA applies to a person that conducts business in Texas or produces a product or service consumed by Texas residents, that processes or sells personal data, and that is not a small business as defined by the U.S. Small Business Administration. There is no consumer-count or revenue threshold. A small business that is otherwise exempt still may not sell sensitive personal data without the consumer's prior consent (§ 541.107).
What the website needs
- A controller must provide a reasonably accessible and clear privacy notice listing the categories of personal data processed, including any sensitive data, the purposes, how consumers can exercise their rights and appeal, the categories of data shared with third parties and the categories of those third parties, and the request methods the controller offers (§ 541.102(a)).
- A controller that sells sensitive personal data must include the notice 'NOTICE: We may sell your sensitive personal data.' and one that sells biometric data must include 'NOTICE: We may sell your biometric personal data.', each posted in the same place and manner as the privacy notice (§ 541.102(b)-(c)).
- A controller that sells personal data or uses it for targeted advertising must clearly and conspicuously disclose that processing and how a consumer can opt out (§ 541.103).
- A controller must offer two or more secure and reliable methods for rights requests and, if it maintains a website, a mechanism on the website for submitting requests; it may not require a consumer to create a new account (§ 541.055(a)-(c)).


