iQ Cookie  State Law Series

State 20 of 25 · Texas

Cookie & Privacy Law in Texas

Published August 2026
Law in effect
No consumer-count threshold

Educational purposes only — not legal advice. This guide is intended to help you understand Texas’s data privacy law as it relates to cookie consent and website compliance. Laws change, and your specific situation may vary. Always consult a qualified legal professional before making compliance decisions. iQ Cookie is a technology tool, not a law firm.

LAW
TDPSA
Tex. Bus. & Com. Code Ch. 541
SIGNED
Jun 18, 2023
Effective Jul 1, 2024
CURE PERIOD
30 days
Perpetual, does not sunset
STATE RANK
#9
To enact a law

The short version

Texas’s TDPSA took effect July 1, 2024, and like Nebraska, it skips the usual consumer-count math entirely: there is no minimum threshold, and coverage instead turns on whether you qualify as a small business under federal SBA standards. Texas is also home to the two largest privacy enforcement settlements in the country to date — both brought before the TDPSA itself even took effect, under separate biometric and deceptive-practices statutes, but a clear signal of how aggressively the state pursues privacy violations.

Texas does not have a separate cookie law. Cookie compliance flows from the TDPSA itself — its opt-out and sensitive-data rules apply directly to cookies and tracking technology.

Texas Legislature — Official Text
Texas Data Privacy and Security Act — Tex. Bus. & Com. Code § 541

Who does it apply to?

The TDPSA covers any business that conducts business in Texas, or produces products or services consumed by Texas residents, and processes or sells personal data — with no consumer-count or revenue floor to clear.

THE REAL TEST

Are you a "small business" under U.S. Small Business Administration standards? Thresholds vary by industry (NAICS code) — for example, roughly $41.5 million in average annual receipts or 500–1,500 employees for tech and software.

SMALL BUSINESS EXCEPTION

Small businesses still cannot sell sensitive data without opt-in consent. That one rule reaches every business regardless of size.

HIPAA-covered entities and data, GLBA financial institutions and data, FERPA-compliant entities, and certain employment and B2B contexts are exempt.

Consumer rights

Texas residents whose data is covered by the TDPSA can:

Access
Confirm processing and receive a copy of their data
Correct
Fix inaccurate personal data
Delete
Request removal of personal data
Portability
Receive data in a usable, portable format
Opt out
Sale, targeted advertising, and significant profiling
Appeal
Challenge a denied request through an internal process

Businesses must respond within 45 days, extendable once by 45 more. There is no private right of action — only the Attorney General can enforce.

What makes Texas different

No threshold — a first-of-its-kind approach when TDPSA passed. Coverage turns on federal small-business status rather than a consumer count, meaning some businesses far smaller than the 25,000-to-100,000-consumer bar used elsewhere are still fully in scope.

A specific disclosure sentence is required for sensitive/biometric data sales. If you sell sensitive or biometric personal data, Texas law requires a specific notice: "NOTICE: We may sell your sensitive personal data" or "NOTICE: We may sell your biometric personal data" — displayed prominently, not buried in a general policy.

The cure period is perpetual and procedural. The 30-day cure opportunity never sunsets, but curing requires more than a fix — you must provide the AG written evidence you remedied the violation, notified affected consumers, and updated internal policies.

A companion AI law layers on new obligations. The Texas Responsible AI Governance Act (TRAIGA, HB 149) took effect January 1, 2026, requiring AI developers to provide risk documentation and deployers to conduct impact assessments for high-risk systems — with its own 60-day AG cure period and provisions that touch TDPSA processor obligations.

The largest privacy settlements in the country happened here. Texas secured a $1.4 billion settlement from Meta over biometric data practices and a $1.375 billion settlement from Google over location tracking — both under separate Texas statutes, but a clear signal of the state’s enforcement posture on data privacy generally.

Sensitive data & children

Processing sensitive data requires opt-in consent before any collection begins. Sensitive data includes:

Racial / ethnic origin
Religious beliefs
Health diagnosis
Sexual orientation
Citizenship / immigration status
Biometric identification data
Known children’s data (under 13)

Data from known children under 13 is classified as sensitive data and must be processed in compliance with COPPA. Sale of known children’s data is prohibited outright, and targeted advertising directed at minors requires opt-in consent.

What this means for your cookies

Cookie / data typeRequirementWhat to do
Sensitive / biometric data cookiesOpt-in requiredGate these behind affirmative consent; add the required sale-notice sentence if applicable.
Sale / targeted advertising cookiesOpt-out requiredProvide a clear opt-out mechanism.
GPC / universal opt-out signalsRequired since Jan 1, 2025Confirm your consent tool honors GPC automatically.
Known-children sale cookiesProhibitedBlock sale-related cookies outright for known children under 13.
Targeted ad cookies — known childrenOpt-in requiredNo targeted-ad cookies without consent for known minors.

Enforcement

$7,500
Max penalty per uncured violation
30 days
Perpetual cure period, does not sunset
AG only
No private right of action

The Texas Attorney General has exclusive enforcement authority. Curing a violation requires written proof of remediation, consumer notification, and policy updates — not just fixing the underlying issue. Texas has also shown, through record-setting settlements under separate statutes, that it will pursue privacy violations aggressively when it chooses to.

Your action checklist

1

Check your small-business status first, not your consumer count. If you don’t qualify as a federal small business (thresholds vary by NAICS code) and you process or sell any personal data, you are likely in scope.

2

Add the required sale-notice language if you sell sensitive or biometric data. The specific disclosure sentence is a statutory requirement, not just good practice.

3

Confirm GPC recognition is live. Required since January 1, 2025.

4

Block sale-related cookies for known children under 13. This is a prohibition, not just an opt-in gate.

5

Check whether TRAIGA applies to any AI systems you run. High-risk AI deployments now carry separate risk-documentation and impact-assessment obligations as of January 1, 2026.

6

Document your cure process end to end. If notified of a violation, be ready to show remediation, consumer notice, and policy updates in writing.

7

Review vendor contracts. Any processor handling Texas resident data must be covered by a written agreement specifying processing instructions and confidentiality obligations.

Not sure where your site stands with Texas?

iQ Cookie scans your site for compliance gaps and deploys a lightweight US-built consent banner.

iQ Cookie State Law Series  ·  Guide 20 of 25  ·  Next: Utah →