Does the Texas privacy law apply to your business? Probably not, with one exception.
Texas keyed its exemption to the SBA definition of a small business, which puts most local firms outside the law. The hole is what you may do with sensitive data.
John "Holliday" Mahlow
Founder, Cursive Media
An email arrives saying your website is not compliant with Texas privacy law, that penalties are significant, and that a compliance package is available for a monthly fee.
Before you buy anything, it is worth knowing where the line actually sits. Nothing here is legal advice, and if you genuinely have exposure it belongs with a lawyer rather than with an agency.
What the law is
The Texas Data Privacy and Security Act took effect on 1 July 2024, with one section following on 1 January 2025. It sits in Chapter 541 of the Business and Commerce Code and gives Texans rights over personal data that businesses hold about them.
The exemption most local businesses fall into
Here is where Texas did something unusual. Most state privacy laws set thresholds based on how many records you process or how much revenue you make. Texas exempts small businesses instead, using the Small Business Administration's definition of what counts as one.
Which means the question is not how many customer records you hold. It is whether your business is small by the SBA's reckoning, and that definition varies by industry rather than being one number, so the answer depends on what you do rather than on your database.
For a plumbing company with nine staff, this is not a close call.
Other exemptions exist too, covering state agencies, nonprofits, educational institutions and organisations already regulated under Gramm-Leach-Bliley or HIPAA, which sweeps in a fair number of businesses that assumed they were caught.
The hole in the exemption
Being exempt is not the same as being unregulated, and this is the part the scare emails get closest to right.
An otherwise-exempt small business still needs consent before selling sensitive personal data.
Sensitive data is defined broadly. It covers race, ethnicity, religion and sexuality. It covers health conditions, immigration status and genetic data. It also covers precise location data, and any data about children under thirteen.
Precise location is the one worth pausing on, because a local business collecting addresses and job sites is holding more of that than it usually realises, and because selling data is a broader idea than most owners assume when they agree to share a customer list with a partner.
What the law gives Texans, if you are covered
If your business is not exempt, Texans get a set of rights over the data you hold. They can ask whether you process it. They can obtain a copy in a readily usable format, have errors corrected, and have it deleted.
They can also opt out of targeted advertising, of data sales, and of certain profiling.
And they can submit any of those requests without creating an account with you, which quietly rules out the common trick of putting a login in front of the process.
What none of this means
It does not mean a small business needs nothing on its website. Advertising platforms and analytics tools impose their own requirements through their terms, other states have their own laws that can reach a business with customers there, and this post is about the Texas statute alone.
It also does not mean the compliance email is a scam. It means the pitch is usually built on the assumption that the law applies to you, and in Texas that assumption is the thing to check first rather than last.
If a compliance email has landed and you want a straight read on whether it describes your situation, book a strategy call. If the answer turns out to be that you have genuine exposure, the next call is to a lawyer rather than to us, and we will tell you that plainly.
John "Holliday" Mahlow
Founder, Cursive Media
