home / guides / Texas Data Privacy Law and AI: What Small Businesses Need to Know

Guide

Texas Data Privacy Law and AI: What Small Businesses Need to Know

What the Texas Data Privacy and Security Act requires, who's exempt, and where AI tools fit into your obligations.

Updated 2026-09-27 · 8 min read · yforest AI Labs

Key takeaways

  • The Texas Data Privacy and Security Act (TDPSA) took effect July 1, 2024, and gives Texas residents rights over their personal data — access, correction, deletion, and opt-out of targeted advertising and data sales.
  • Businesses that meet the federal Small Business Administration's small-business definition are generally exempt from most TDPSA obligations — but even exempt businesses must still get consent before selling sensitive personal data.
  • The Texas Attorney General has exclusive enforcement authority, with civil penalties up to $7,500 per violation — there's no separate right for consumers to sue directly.
  • AI tools that process customer data don't get a TDPSA exemption just because AI is involved — if your business is covered, the same rules apply to data flowing through an AI tool as any other system.
  • This guide is general information, not legal advice. Confirm your business's specific coverage and obligations with an attorney familiar with Texas privacy law.

If you run a small business in Texas and haven't looked closely at the Texas Data Privacy and Security Act, you're not alone — and depending on your size, you may be exempt from most of it. But "may be exempt" and "definitely exempt" are different things, and the parts that apply even to exempt businesses are exactly the parts that intersect with how your team uses AI tools on customer data.

What the Texas Data Privacy and Security Act actually does

The TDPSA took effect on July 1, 2024, and it gives Texas residents a set of rights over the personal data companies hold about them: the right to know what data a company has, the right to correct it, the right to delete it, and the right to opt out of targeted advertising and the sale of their data. Companies covered by the law also have to provide a clear privacy notice, use "reasonable data security practices," and limit data collection to what's genuinely needed for the purposes they've disclosed.

Consumers can't sue a company directly under the TDPSA — enforcement sits exclusively with the Texas Attorney General, who can pursue civil penalties of up to $7,500 per violation.

The small business exemption — and its limits

Here's the detail most small-business owners actually need: businesses that meet the U.S. Small Business Administration's definition of a small business are generally exempt from most of the TDPSA's requirements. That covers a real share of the businesses this guide is written for.

But the exemption isn't unconditional. Even a business that qualifies as small under the SBA definition must still get consumer consent before selling sensitive personal data. "Sensitive" in Texas privacy law generally covers things like health information, biometric or genetic data, precise geolocation, and data revealing racial or ethnic origin, religious belief, or citizenship status. If your business touches any of those categories and monetizes them in any way, the exemption doesn't fully cover you.

Don't self-certify from memory

The SBA's small-business size standards vary by industry and are based on revenue or employee count thresholds that differ across sectors. Whether your specific business qualifies is a factual question worth confirming with your accountant or attorney rather than assuming from your general sense of "we're small."

Where AI tools fit into your TDPSA obligations

The TDPSA doesn't have a carve-out for data that happens to pass through an AI tool. If your business is a covered entity under the law, personal data of Texas residents is regulated the same way whether it sits in a spreadsheet, a CRM, or a prompt typed into a chatbot. A few practical implications follow from that:

  • If a customer asks what data you hold on them, and some of that data lives in AI-tool logs or AI-generated summaries stored in your systems, that data is potentially in scope for their access request.
  • If an AI vendor uses customer data to train its own models without your customers' knowledge, and that counts as a "sale" or transfer of personal data under the Act's definitions, that's a compliance question worth raising directly with the vendor — not assuming away.
  • "Reasonable data security practices" applies to however you store AI outputs that contain customer data, the same as it applies to any other system holding that data.

This is one more reason the vendor's own data-use terms matter — see our guide on what happens to data typed into ChatGPT and similar tools for how consumer and business plans differ on this point.

Practical steps for a Texas small business using AI

StepWhat to do
1. Confirm your size statusCheck your revenue and employee count against the SBA's size standards for your industry, with your accountant if needed
2. Identify sensitive data categoriesList whether your business collects health, biometric, geolocation, or similar sensitive data — the exemption doesn't fully cover these even for small businesses
3. Check AI vendor data-use termsConfirm whether your AI vendor's terms could count as a data "sale" or transfer under the Act's definitions
4. Write a plain privacy noticeEven if not strictly required by size, a short notice builds customer trust and covers you if your size status changes
5. Revisit annuallyRevenue growth or a new data category can move a business out of the small-business exemption over time
Texas privacy self-check — copy and use
Answer these before assuming you're exempt from the TDPSA: 1. Does our revenue and employee count fall under the SBA small-business threshold for our industry? [YES/NO/UNSURE — confirm with accountant] 2. Do we collect health, biometric, geolocation, or similar sensitive data about Texas customers? [YES/NO] 3. If yes to #2 — do we have documented consumer consent before any sale of that data? [YES/NO] 4. Does any AI vendor we use have terms that could count as selling or transferring customer data? [YES/NO/UNSURE — check vendor terms] 5. Do we have a written privacy notice, even a short one? [YES/NO]

How this fits with other data rules you might already follow

Texas isn't the only state with a comprehensive privacy law anymore, and if your business serves customers outside Texas, a similar law in another state may apply to those customers even while the TDPSA covers your Texas ones. The practical takeaway is the same either way: a data classification and vendor-vetting approach built once, at a reasonably high standard, tends to satisfy several state frameworks at once rather than needing a separate process per state.

If your business is also subject to HIPAA, GLBA, or another federal data rule, the TDPSA generally layers on top of those rather than replacing them — meeting one doesn't automatically satisfy the other. See our guides on HIPAA and AI for medical and dental offices and AI in financial and insurance offices if either applies to you, and our broader guide to protecting customer PII for a data classification approach that works across all of these frameworks at once.

What a Texas resident can actually ask your business for

For businesses that are covered by the TDPSA (not exempt as a small business, or exempt but still handling sensitive data sales), it helps to know what a consumer request actually looks like in practice. Under the Act, a Texas resident can ask a covered business to confirm what personal data it holds about them, correct inaccurate data, delete their data, and stop selling their data or using it for targeted advertising. Covered businesses are required to offer at least two secure, reliable ways for a resident to submit that kind of request, and must respond within 45 days, with one 45-day extension available if needed.

If your business is exempt as a small business but voluntarily wants to build customer trust, offering a simple way to ask "what do you have on me" — even informally, by email — costs little and heads off a more adversarial version of the same question later.

Why this needs a standing owner, not a one-time review

Texas privacy law, like most state privacy frameworks, tends to be amended and interpreted further over time — new sensitive-data categories can be added, thresholds can shift, and enforcement priorities from the Attorney General's office can change what actually gets scrutinized. Treating this as a "read once and file away" document is how businesses end up out of step with a law that looked settled a year earlier. Assign one person — often whoever already owns your privacy notice or your AI vendor list — to check for updates at least once a year, alongside the broader review described in our AI governance for small business guide.

Common mistakes

  • Assuming "small business" is a self-evident label. The SBA's size standards are specific and vary by industry — check the actual threshold, not a gut feeling.
  • Treating the exemption as total. The consent requirement for selling sensitive data applies even to exempt small businesses.
  • Ignoring AI vendor terms. If an AI tool's data-use terms function like a data sale under the Act, your exemption status doesn't necessarily cover that specific practice.
  • Never revisiting size status. A growing business can cross the small-business threshold without anyone noticing until an audit or complaint raises it.

◆ Small Business AI Kickstart

Get AI ready today.
Before it's too late.

yforest AI Labs comes to your company, trains your team, and ships your first tools.

FAQ

When did the Texas Data Privacy and Security Act take effect?

July 1, 2024.

Are small businesses exempt from the TDPSA?

Businesses that meet the U.S. Small Business Administration's small-business definition are generally exempt from most TDPSA requirements, but must still get consent before selling sensitive personal data.

Can Texas consumers sue a business directly under the TDPSA?

No. The Texas Attorney General has exclusive enforcement authority, with civil penalties of up to $7,500 per violation — there's no private right of action for consumers.

Does using an AI tool change our TDPSA obligations?

The law doesn't have a carve-out for data processed through AI — if your business is covered, the same rules apply to personal data in an AI tool as anywhere else in your systems.

Is this guide legal advice?

No. This is general information, not legal advice. Confirm your business's specific size status and obligations with an attorney familiar with Texas privacy law.

Sources

  1. Texas Attorney General — Texas Data Privacy and Security Act

This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.