Texas Data Privacy and Security Act – Office of the Attorney General
- Document
- 1 July 2024
- Event
- 1 July 2024
- Retrieved
- 16 September 2026
The workload
Most US state privacy laws start a founder's compliance workload with a consumer-count or revenue test; Texas's does not. Verified: the statute's own text, preserved in a 2024 archived capture of Business and Commerce Code Chapter 541, Section 541.002 because the live statute page renders through client-side scripting that automated retrieval cannot read directly, applies to any person that conducts business in Texas or produces a product or service consumed by its residents, processes or sells personal data, and is not a small business as defined by the United States Small Business Administration. The workload is therefore an SBA size-standard lookup, not a consumer count: a founder has to find the SBA's own threshold for the specific industry code, since the standard is not one number.
What the documents show
Verified: the Texas Attorney General's own overview of the Act, effective 1 July 2024 as the page itself states, confirms small businesses under the SBA standard are generally exempt from the Act, except that a small business selling a consumer's sensitive data must first obtain the consumer's consent. That single exception means an SBA-qualifying small business still cannot treat the Act as fully inapplicable if its product sells sensitive categories of data, such as precise geolocation or a child's personal data. The statute's own text confirms this carve-out does not reach the sensitive-data-sale consent requirement, matching the Attorney General's summary to the codified law.
The operating cost
Verified: the Attorney General's overview states a company that violates the Act after its cure period, or breaches a written statement submitted to the Attorney General, is liable for a civil penalty of up to $7,500 per violation, with no private right of action for individual consumers — enforcement runs exclusively through the Attorney General's office.
The stop condition
Verified: the same overview states the Attorney General must issue a written notice of violation and allow a company 30 days in which to cure before any enforcement action or penalty can be filed, and that cure right does not expire the way Connecticut's does — it is stated as a standing precondition to enforcement, not a program with its own end date.
- Does the SBA size standard for this specific industry code actually exempt the business, rather than assuming small revenue automatically qualifies?
- Does any product sell sensitive personal data, which removes the small-business exemption's protection regardless of size?
- If a notice of violation arrives, has the 30-day cure window and its required written statement of remediation been used before the $7,500-per-violation penalty becomes possible?
Texas built its privacy law around a federal size standard instead of a consumer count, which means the relevant question for a solo founder is an SBA lookup, not a headcount of Texas customers.
Sources & reading trail
States the Act's 1 July 2024 effective date, the SBA small-business exemption and its sensitive-data-sale exception, the $7,500 civil penalty, and the 30-day cure period.
Source published: Not established · Retrieved: 16 September 2026
Codified statute text confirming applicability turns on the SBA small-business standard rather than a consumer count, added by Acts 2023, 88th Leg., H.B. 4.
Source published: Not established · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.