Texas Data Privacy Act (TDPSA) Compliance: Answer Data Subject Requests on the 45-Day Clock
The Texas Data Privacy and Security Act gives Texas residents the right to see, correct, delete, and port the personal data you hold, and to opt out of its sale. A verified request starts a 45-day clock, and the data is usually scattered across your CRM, warehouse, billing, and support tools. Obtainer finds where a person's data lives across those systems, compiles one reviewable manifest, drafts the response, and tracks the deadline.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
The Texas Data Privacy and Security Act (TDPSA) took effect on July 1, 2024, and it is unusual among US state privacy laws for having no revenue or consumer-count threshold. It applies to any entity that conducts business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and is not a small business under the federal Small Business Administration definition (generally fewer than 500 employees). Small businesses are largely exempt, but must still get consent before selling a consumer's sensitive data. Texas consumers can request access to, correction of, deletion of, and a portable copy of their personal data, and can opt out of the sale of their data, targeted advertising, and certain profiling. You generally must respond within 45 days, extendable once by another 45 days with notice. Since January 1, 2025, controllers must also honor universal opt-out signals such as Global Privacy Control. The Texas Attorney General has exclusive enforcement authority, with civil penalties of up to $7,500 per violation and a 30-day cure period; there is no private right of action. Obtainer handles the operational side of a TDPSA request: it intakes the request, discovers where the person's data lives across your systems, compiles a source-system manifest, drafts a deadline-safe response, and tracks the 45-day clock. Nothing is disclosed automatically; a human reviews, redacts, and approves. Obtainer helps you comply. It is not legal advice, so whether the TDPSA applies to your business and how you handle exemptions stay with your team. Self-serve from $49/mo.
Why it fits
Texas businesses, plus out-of-state SaaS, ecommerce, and B2B firms serving Texas residents, that want the discovery, drafting, and 45-day deadline tracking for a TDPSA data subject request handled in one place without an enterprise governance suite.
No revenue or headcount threshold
Texas is the outlier: there is no minimum revenue or consumer count that triggers the TDPSA. If you conduct business in Texas or serve Texas residents and process personal data, you are likely in scope unless you qualify as an SBA small business. That makes it easy for a mid-market company with no compliance team to be covered without realizing it.
45 days to respond, five rights to honor
Texas residents can ask to access, correct, delete, or port their data, and to opt out of sale, targeted advertising, and profiling. You have 45 days from a verified request, extendable once by 45 days. Obtainer starts the countdown when the request arrives, finds the data across your stack, and drafts the reply so the deadline stays workable.
Discovery across your stack, priced for you
One consumer's data sits in your production database, warehouse, Stripe, help desk, and email. Obtainer surfaces where it lives and compiles one manifest instead of leaving an engineer to hunt it down, and it honors universal opt-out signals in the intake. Self-serve from $49/mo, with no five-figure floor before you can answer your first request.
More use cases
Related features
Questions
Common questions about this
Who must comply with the Texas Data Privacy and Security Act?
Any entity that conducts business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and is not a small business under the SBA definition (generally fewer than 500 employees). Texas is unique for having no revenue or consumer-count threshold, so many mid-market companies are in scope. Small businesses are largely exempt but still need consent to sell sensitive data.
When did the Texas Data Privacy Act take effect?
The TDPSA took effect on July 1, 2024. A related provision requiring controllers to honor universal opt-out signals, such as Global Privacy Control, took effect on January 1, 2025. The Texas Responsible AI Governance Act, effective January 1, 2026, later added AI-specific obligations for personal data used in automated systems.
What are the penalties for violating the TDPSA?
The Texas Attorney General has exclusive authority to enforce the TDPSA and can seek civil penalties of up to $7,500 per violation, plus injunctive relief, attorney fees, and costs. Businesses get a 30-day cure period after receiving notice of an alleged violation. There is no private right of action, so consumers cannot sue directly under the law.
What rights do Texas consumers have under the TDPSA?
Texas residents can confirm whether you process their personal data and access it, correct inaccuracies, delete it, and obtain a portable copy. They can also opt out of the sale of their personal data, targeted advertising, and certain profiling. You generally must respond within 45 days, extendable once by another 45 days if you notify the consumer of the delay.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.