TDPSA compliance checklist 10 steps
A 10-step action checklist for TDPSA compliance efforts: scope, data mapping, notices, GPC, sensitive data consent, DSRs, and data protection assessments.
A 10-step action checklist for TDPSA compliance efforts: scope, data mapping, notices, GPC, sensitive data consent, DSRs, and data protection assessments.
The Texas Data Privacy and Security Act has been in effect since July 1, 2024. If your business processes personal data from Texas residents and is not an SBA-defined small business, you have obligations under this law right now.
This checklist covers the 10 areas your privacy program should address. For a detailed explanation of what the TDPSA requires, who it applies to, and how it compares to other state privacy laws, see Clym's Texas Data Privacy and Security Act business guide.
Work through each step with your team or legal counsel. Not every item will apply to every business, but reviewing each one is worth the time.
Before working through the checklist, confirm whether the TDPSA applies to your business. Answer yes to all three questions to be in scope:
Question | Answer |
|---|---|
Do you conduct business in Texas or produce products/services consumed by Texas residents? | Yes / No |
Do you process or sell personal data? | Yes / No |
Are you NOT classified as an SBA-defined small business? | Yes / No |
If you answered no to any of these, most TDPSA obligations do not apply to your business. However, one obligation applies to SBA small businesses regardless of exempt status: you cannot sell sensitive personal data without obtaining explicit consent from the consumer first.
Entity-level exemptions can also take a business out of scope entirely. Texas state agencies, nonprofits, and institutions of higher education are exempt from the TDPSA, as are entities already governed by HIPAA, GLBA, or FERPA for the data those frameworks cover. Employment records and publicly available information are excluded as well. These entities may still have obligations under the framework that already applies to them.
Document why the TDPSA does or does not apply to your business, so you have a record to revisit as things change:
You need a data map before you can build your privacy notice, consent setup, or data protection assessments. For each data type you collect, document:
What to document | Examples |
|---|---|
What categories of personal data you collect | Names, emails, IP addresses, location data, financial data, etc. |
Where you collect it from | Web forms, cookies, analytics tools, third-party sources |
Why you collect it (purpose) | Marketing, analytics, product delivery, fraud prevention |
Who you share it with | Ad platforms, analytics providers, business partners |
How long you retain it | Retention schedule by data type |
Is any of it sensitive? | Check against the TDPSA sensitive data list in Step 6 |
Pay particular attention to precise geolocation data (within 1,750 feet) and financial data, including account and credit card numbers. Both are sensitive categories under the TDPSA but are not treated as sensitive under the Colorado Privacy Act. If you collect either from Texas visitors, opt-in consent applies.
Review your existing privacy notice against the TDPSA’s required disclosures:
Required disclosures in your privacy notice:
Additional notices required in specific circumstances:
Your privacy and cookie notice should be easy to find, plain language, and dated whenever your data practices change, even for minor edits.
If your business sells personal data, runs targeted advertising, or profiles consumers, give Texas visitors a clear way to opt out:
Your opt-out mechanism must:
A dedicated opt-out link in your website footer, combined with a consent management experience that presents Texas visitors with the correct options, is the most common implementation approach.
Since January 1, 2025, you must honor Global Privacy Control (GPC) and other recognized universal opt-out signals from Texas visitors:
If your current setup doesn’t detect and act on GPC signals, treat this as a high-priority fix.
Get opt-in consent before processing sensitive personal data. This applies even to SBA small businesses otherwise exempt from the TDPSA when they sell sensitive data.
The following data categories are sensitive under the TDPSA:
Sensitive data category | Requirement |
|---|---|
Racial or ethnic origin | Requires opt-in consent |
Religious beliefs | Requires opt-in consent |
Mental or physical health condition or diagnosis | Requires opt-in consent |
Sex life or sexual orientation | Requires opt-in consent |
Citizenship or immigration status | Requires opt-in consent |
Genetic data that could uniquely identify an individual | Requires opt-in consent |
Biometric data processed for identification purposes | Requires opt-in consent |
Personal data from a known child under 13 | Requires parental/guardian consent |
Precise geolocation within 1,750 feet | Requires opt-in consent (TDPSA-specific) |
Financial data including account and credit card numbers | Requires opt-in consent (TDPSA-specific) |
Note that precise geolocation and financial data are sensitive categories under the TDPSA but are not listed as sensitive under the Colorado Privacy Act or the CCPA. If you already have consent flows for other state laws, review whether they cover these two categories for Texas visitors.
Build a structured process for handling access, correction, deletion, portability, and opt-out requests from Texas residents:
Area | Requirement |
|---|---|
Intake | At least one method for submitting requests (web form, email, toll-free number) |
Identity verification | Verify identity before responding; if you cannot verify, explain to the consumer and offer a path to rectify |
Response timeline | Respond within 45 days; extendable by 45 more with notice to the consumer |
Denial and appeal | If you deny a request, explain why; provide an appeal mechanism that must be responded to within 60 days |
Record retention | Keep records of all requests and responses for at least 2 years after the last consumer interaction |
If your business receives many requests, a data subject request management workflow helps track intake, verification, deadlines, and appeals without relying on manual spreadsheets.
Complete a data protection assessment before any higher-risk processing. This is a formal legal requirement, not an optional best practice.
Assessments are required before:
What each assessment should document:
Store assessments somewhere your team can produce quickly if the Texas Attorney General requests them during an investigation. Update them when the processing activity changes materially.
If you share personal data with third-party processors (analytics providers, marketing platforms, cloud services), confirm each contract requires:
Update existing agreements missing these provisions, and require them in every new vendor contract before data sharing begins.
Implement administrative, technical, and physical security practices appropriate to the volume and sensitivity of the personal data you process. The TDPSA doesn’t prescribe specific technical standards, only that measures be reasonable given the risk.
Administrative measures:
Technical measures:
Physical measures:
Review these measures regularly, and update them whenever your data collection, processing, or storage changes significantly.
The TDPSA does not have an expiration date for its cure period, but enforcement is active and the Texas AG can begin formal proceedings once 30 days have passed without a corrected violation. Here are a few practices that can help your business stay current:
For a side-by-side comparison of the TDPSA and other active US state privacy laws, including thresholds, cure periods, and enforcement, see Clym's US state privacy law comparison guide.
Clym helps bring key privacy workflows into one platform so your team spends less time managing compliance manually. For the TDPSA specifically, Clym can help you:
Present the right opt-out experience to Texas visitors. Clym's geofencing and localization features detect visitor location and serve the appropriate consent or opt-out experience automatically, without requiring a separate configuration per state.
Recognize and act on GPC signals. Clym's consent management platform detects browser-based universal opt-out signals and applies opt-out preferences for Texas visitors as required since January 1, 2025.
Handle data subject requests in a structured workflow. Receive, verify, track, and respond to access, correction, deletion, portability, and opt-out requests within the 45-day TDPSA response window, with an appeal mechanism and records retention.
Keep privacy notices accurate and up to date. Create and manage privacy and cookie notices that reflect your current data practices and can be updated as your obligations evolve.
Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the TDPSA's requirements.
Working through this checklist means reviewing 10 distinct areas of your privacy program: scope, data mapping, privacy notices, opt-out mechanisms, GPC signal recognition, sensitive data consent, consumer rights handling, data protection assessments, processor contracts, and security practices.
Not every step will require action. If you already have privacy infrastructure for California or GDPR, a significant portion of this list may already be addressed. The areas most likely to need attention for Texas specifically are the GPC signal requirement (effective January 1, 2025), the sensitive data categories that are unique to the TDPSA (precise geolocation and financial data), and data protection assessments if you run targeted advertising or sell personal data.
For a full explanation of the law itself, including who it applies to, consumer rights, enforcement, and how the TDPSA compares to other state laws, see the TDPSA business guide.