Clym Logo

TDPSA compliance checklist: 10 steps for your business

Published
AS
AuthorAdam Safar
10 min read

TDPSA compliance checklist 10 steps

A 10-step action checklist for TDPSA compliance efforts: scope, data mapping, notices, GPC, sensitive data consent, DSRs, and data protection assessments.

Summarize full article with:

The Texas Data Privacy and Security Act has been in effect since July 1, 2024. If your business processes personal data from Texas residents and is not an SBA-defined small business, you have obligations under this law right now.

This checklist covers the 10 areas your privacy program should address. For a detailed explanation of what the TDPSA requires, who it applies to, and how it compares to other state privacy laws, see Clym's Texas Data Privacy and Security Act business guide.

Work through each step with your team or legal counsel. Not every item will apply to every business, but reviewing each one is worth the time.

Key takeaways
  • Confirm scope first. The TDPSA applies differently depending on whether your business qualifies as an SBA small business. Even exempt businesses have some obligations.
  • GPC signals must be honored since January 1, 2025. Businesses must recognize browser-based opt-out signals from Texas visitors automatically.
  • Sensitive data requires opt-in consent, not opt-out. This includes financial data and precise geolocation, which are sensitive categories under the TDPSA but not under some other state laws.
  • Data protection assessments are a formal requirement before running targeted advertising, selling personal data, or processing sensitive data.
  • DSR records must be kept for at least two years after the last consumer interaction.
  • The cure period is 30 days and is currently still active, giving businesses time to correct violations before the Texas AG pursues penalties.

Quick applicability check

Before working through the checklist, confirm whether the TDPSA applies to your business. Answer yes to all three questions to be in scope:

Question

Answer

Do you conduct business in Texas or produce products/services consumed by Texas residents?

Yes / No

Do you process or sell personal data?

Yes / No

Are you NOT classified as an SBA-defined small business?

Yes / No

If you answered no to any of these, most TDPSA obligations do not apply to your business. However, one obligation applies to SBA small businesses regardless of exempt status: you cannot sell sensitive personal data without obtaining explicit consent from the consumer first.

Entity-level exemptions can also take a business out of scope entirely. Texas state agencies, nonprofits, and institutions of higher education are exempt from the TDPSA, as are entities already governed by HIPAA, GLBA, or FERPA for the data those frameworks cover. Employment records and publicly available information are excluded as well. These entities may still have obligations under the framework that already applies to them.

Step 1: Confirm scope and document your basis

Document why the TDPSA does or does not apply to your business, so you have a record to revisit as things change:

  • Record the date you determined you are subject to the TDPSA, and which threshold applies (you process Texas residents’ personal data and are not an SBA small business)
  • Confirm whether a sector-level exemption applies: state agencies, nonprofits, higher education, or data governed by HIPAA, GLBA, or FERPA
  • If you believe you qualify as an SBA small business, confirm your classification using the SBA size standards table for your industry
  • If you are an SBA small business, document that you do not sell sensitive personal data, or get explicit consent before doing so

Step 2: Map your personal data

You need a data map before you can build your privacy notice, consent setup, or data protection assessments. For each data type you collect, document:

What to document

Examples

What categories of personal data you collect

Names, emails, IP addresses, location data, financial data, etc.

Where you collect it from

Web forms, cookies, analytics tools, third-party sources

Why you collect it (purpose)

Marketing, analytics, product delivery, fraud prevention

Who you share it with

Ad platforms, analytics providers, business partners

How long you retain it

Retention schedule by data type

Is any of it sensitive?

Check against the TDPSA sensitive data list in Step 6

Pay particular attention to precise geolocation data (within 1,750 feet) and financial data, including account and credit card numbers. Both are sensitive categories under the TDPSA but are not treated as sensitive under the Colorado Privacy Act. If you collect either from Texas visitors, opt-in consent applies.

Step 3: Update your privacy notice

Review your existing privacy notice against the TDPSA’s required disclosures:

Required disclosures in your privacy notice:

  • Categories of personal data you process
  • The purpose for which each category is processed
  • Categories of personal data you share with third parties, if any
  • Categories of third parties you share data with, if any
  • How Texas residents can exercise their rights (access, correction, deletion, portability, opt-out)
  • How residents can appeal a decision if their request is denied
  • Contact information for submitting rights requests

Additional notices required in specific circumstances:

  • "NOTICE: We may sell your sensitive personal data." Required if you sell sensitive personal data, displayed at the same location as your privacy notice
  • "NOTICE: We may sell your biometric personal data." Required if you sell biometric personal data specifically

Your privacy and cookie notice should be easy to find, plain language, and dated whenever your data practices change, even for minor edits.

Step 4: Set up opt-out mechanisms for data sales and targeted advertising

If your business sells personal data, runs targeted advertising, or profiles consumers, give Texas visitors a clear way to opt out:

Your opt-out mechanism must:

  • Must be clearly visible and accessible to Texas visitors
  • Must be available before any opt-out-eligible processing occurs
  • Should not require visitors to create an account or navigate multiple pages to opt out
  • Must not discriminate against consumers who exercise the right (no reduced quality of service or higher prices)

A dedicated opt-out link in your website footer, combined with a consent management experience that presents Texas visitors with the correct options, is the most common implementation approach.

Step 5: Honor GPC and universal opt-out signals

Since January 1, 2025, you must honor Global Privacy Control (GPC) and other recognized universal opt-out signals from Texas visitors:

  • When a Texas visitor's browser sends a GPC signal to your website, treat it as a formal opt-out request for data sales and targeted advertising
  • The visitor should not need to take any additional steps or fill out a form
  • Your consent management setup must detect these signals and suppress the relevant processing before it occurs

If your current setup doesn’t detect and act on GPC signals, treat this as a high-priority fix.

Step 6: Get opt-in consent before processing sensitive data

Get opt-in consent before processing sensitive personal data. This applies even to SBA small businesses otherwise exempt from the TDPSA when they sell sensitive data.

The following data categories are sensitive under the TDPSA:

Sensitive data category

Requirement

Racial or ethnic origin

Requires opt-in consent

Religious beliefs

Requires opt-in consent

Mental or physical health condition or diagnosis

Requires opt-in consent

Sex life or sexual orientation

Requires opt-in consent

Citizenship or immigration status

Requires opt-in consent

Genetic data that could uniquely identify an individual

Requires opt-in consent

Biometric data processed for identification purposes

Requires opt-in consent

Personal data from a known child under 13

Requires parental/guardian consent

Precise geolocation within 1,750 feet

Requires opt-in consent (TDPSA-specific)

Financial data including account and credit card numbers

Requires opt-in consent (TDPSA-specific)

Note that precise geolocation and financial data are sensitive categories under the TDPSA but are not listed as sensitive under the Colorado Privacy Act or the CCPA. If you already have consent flows for other state laws, review whether they cover these two categories for Texas visitors.

Step 7: Build a data subject rights process

Build a structured process for handling access, correction, deletion, portability, and opt-out requests from Texas residents:

Area

Requirement

Intake

At least one method for submitting requests (web form, email, toll-free number)

Identity verification

Verify identity before responding; if you cannot verify, explain to the consumer and offer a path to rectify

Response timeline

Respond within 45 days; extendable by 45 more with notice to the consumer

Denial and appeal

If you deny a request, explain why; provide an appeal mechanism that must be responded to within 60 days

Record retention

Keep records of all requests and responses for at least 2 years after the last consumer interaction

If your business receives many requests, a data subject request management workflow helps track intake, verification, deadlines, and appeals without relying on manual spreadsheets.

Step 8: Complete data protection assessments for high-risk activities

Complete a data protection assessment before any higher-risk processing. This is a formal legal requirement, not an optional best practice.

Assessments are required before:

  • Using personal data for targeted advertising
  • Selling personal data
  • Processing sensitive personal data
  • Profiling individuals for decisions with significant legal or similar effects

What each assessment should document:

  • The specific purpose of the processing activity
  • The categories of personal data involved
  • The potential risks the activity creates for consumers
  • The safeguards in place to reduce those risks
  • Why the business benefits outweigh the consumer risks

Store assessments somewhere your team can produce quickly if the Texas Attorney General requests them during an investigation. Update them when the processing activity changes materially.

Step 9: Review contracts with data processors

If you share personal data with third-party processors (analytics providers, marketing platforms, cloud services), confirm each contract requires:

  • Instructions for the processing, including its nature and purpose
  • Types of personal data involved and the duration of processing
  • Rights and obligations of both the controller and processor
  • A duty of confidentiality for the personal data
  • Requirement to delete or return all personal data at the end of the service, unless retention is required by law
  • Requirement to cooperate with reasonable compliance assessments by the controller
  • Requirement that any subprocessors are bound by the same obligations

Update existing agreements missing these provisions, and require them in every new vendor contract before data sharing begins.

Step 10: Implement and maintain appropriate data security measures

Implement administrative, technical, and physical security practices appropriate to the volume and sensitivity of the personal data you process. The TDPSA doesn’t prescribe specific technical standards, only that measures be reasonable given the risk.

Administrative measures:

  • Privacy and security policies and procedures
  • Employee training on data handling and privacy obligations
  • Designated responsibility for privacy and data security

Technical measures:

  • Encryption of personal data in transit and at rest, particularly for sensitive categories
  • Access controls based on least privilege
  • Regular security assessments and vulnerability management
  • Incident detection and response procedures

Physical measures:

  • Physical access controls for systems holding personal data
  • Secure disposal of physical media containing personal data

Review these measures regularly, and update them whenever your data collection, processing, or storage changes significantly.

Common TDPSA checklist mistakes

  • Assuming a revenue or consumer-count threshold applies, when the TDPSA uses the SBA small-business test instead
  • Configuring a consent management platform before January 1, 2025, and never revisiting it to confirm GPC signals are actually detected and honored
  • Treating precise geolocation and financial data as non-sensitive because they aren’t sensitive categories under Colorado or the CCPA
  • Assuming an SBA small-business exemption covers sensitive data sales too. It doesn’t, explicit consent is still required
  • Never testing opt-out and data subject request links live, so a broken mechanism goes unnoticed

How to stay on top of TDPSA changes

The TDPSA does not have an expiration date for its cure period, but enforcement is active and the Texas AG can begin formal proceedings once 30 days have passed without a corrected violation. Here are a few practices that can help your business stay current:

  • Review your privacy notice and data practices at least once a year and whenever your processing activities change materially
  • Monitor Texas AG guidance and any formal enforcement actions, which can signal where scrutiny is concentrated
  • Update your data map when you add new vendors, tools, or data collection methods
  • Revisit your data protection assessments when processing purposes or methods change
  • If you operate across multiple states, check how the TDPSA interacts with the other state laws that apply to your business

For a side-by-side comparison of the TDPSA and other active US state privacy laws, including thresholds, cure periods, and enforcement, see Clym's US state privacy law comparison guide.

How Clym can support your TDPSA privacy program

Clym helps bring key privacy workflows into one platform so your team spends less time managing compliance manually. For the TDPSA specifically, Clym can help you:

Present the right opt-out experience to Texas visitors. Clym's geofencing and localization features detect visitor location and serve the appropriate consent or opt-out experience automatically, without requiring a separate configuration per state.

Recognize and act on GPC signals. Clym's consent management platform detects browser-based universal opt-out signals and applies opt-out preferences for Texas visitors as required since January 1, 2025.

Handle data subject requests in a structured workflow. Receive, verify, track, and respond to access, correction, deletion, portability, and opt-out requests within the 45-day TDPSA response window, with an appeal mechanism and records retention.

Keep privacy notices accurate and up to date. Create and manage privacy and cookie notices that reflect your current data practices and can be updated as your obligations evolve.

Clym does not guarantee compliance. Your obligations depend on your specific data practices, legal advice, and internal processes. The platform provides tools to support your privacy operations and help you work toward the TDPSA's requirements.

Conclusion

Working through this checklist means reviewing 10 distinct areas of your privacy program: scope, data mapping, privacy notices, opt-out mechanisms, GPC signal recognition, sensitive data consent, consumer rights handling, data protection assessments, processor contracts, and security practices.

Not every step will require action. If you already have privacy infrastructure for California or GDPR, a significant portion of this list may already be addressed. The areas most likely to need attention for Texas specifically are the GPC signal requirement (effective January 1, 2025), the sensitive data categories that are unique to the TDPSA (precise geolocation and financial data), and data protection assessments if you run targeted advertising or sell personal data.

For a full explanation of the law itself, including who it applies to, consumer rights, enforcement, and how the TDPSA compares to other state laws, see the TDPSA business guide.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam