Consent Resolve
Compliance & Privacy Blog

The Texas TDPSA and What It Means for Your Website

You don't need to read the Texas privacy statute cover to cover. You need a short list of what to change on your website this week — and a setup that handles most of it for you.

By Andy Mentges, Chief Executive Officer at Consent Resolve 7 min readReviewed by Stefan Dimitrov, Head of Engineering

You don’t need the statute — you need a checklist

If you run a contracting business in Texas, here’s the good news up front: you do not have to read the Texas Data Privacy & Security Act cover to cover. What you need is a short, plain list of what to change on your website, and a way to check it off before the week is out.

The TDPSA took effect in 2024, and it is exactly what it sounds like — a comprehensive consumer data-privacy law for Texas, enforced by an Attorney General who has made privacy a signature issue. The mistake owners make is treating it like a legal research project. It isn’t. It’s a handful of concrete site changes, most of which a consent-first setup handles for you.

Why the “we’re too small” assumption is the real risk

The instinct is to wave it off: you’re a five-truck shop, not a tech giant, so surely the privacy law isn’t about you. A lot of state laws do draw that line — they only bite once you’re processing data on hundreds of thousands of people. The TDPSA does not draw it the same way. It has no small-business size threshold. It turns on whether you handle Texans’ personal data — and a website that captures visitor information does exactly that.

That matters because Texas has shown it will enforce. None of these figures is a forecast for your shop; they’re proof the state means what it wrote. In January 2025, Texas filed the first-ever enforcement suit under a comprehensive state data-privacy law, over driving data collected and sold without consent. And it had already obtained a $1.4 billion settlement with Meta over biometric data captured without permission, plus a $1.375 billion settlement with Google over tracking Texans without consent — the largest privacy settlements a single state has ever won. The common thread in all of it is the word the TDPSA is built around: consent. That’s the reason it’s worth being on the right side of the line, not the wrong one.

What should I change on my website this week?

Strip away the legal language and the TDPSA asks your site for four practical things. Here is the week-one checklist, in order.

Monday — post a findable privacy notice. Say what personal data you collect and why, in a notice a visitor can actually reach from your site. Not buried, not missing. If you can’t find a link to it on your own homepage, neither can a regulator who comes looking.

Tuesday — turn on a clear consent banner. Identification should only happen for visitors who say yes. A clear consent banner handles both the transparency and the affirmative-yes parts of the law in one move.

Wednesday — make the opt-out honest and easy. Give people a real way to opt out of targeted advertising and the sale of their data. “Easy” is the operative word: a path that’s technically present but practically hidden is the kind of thing enforcement notices.

Thursday — start keeping the receipt. A timestamped consent log on a 7-year audit trail means that when anyone asks who agreed and when, the answer is one lookup instead of a scramble. Proof should exist before it’s requested.

Notice what none of these ask. None of them tell you to stop marketing or stop knowing who’s on your site. They ask you to be upfront, honor a no, and get a yes before the sensitive stuff. Those are manners, not walls — and they happen to be the same manners that make homeowners trust you.

Here’s the part that makes the checklist short. With a consent-first approach, the law’s requirements aren’t bolted on after the fact — they’re built into how a lead gets captured in the first place.

The banner handles transparency and the yes. The timestamped log handles proof. And because follow-up is email-grade only — you never get a phone number to cold-dial — you also stay clear of the call-and-text rules that ride alongside privacy law. The lead drops into the funnel you already run, whether that’s Jobber, Housecall Pro, ServiceTitan, or HubSpot. Three of the four checklist items are done the moment you switch it on; the privacy notice is the one bit of homework left to you.

Compare that with the alternative. A purchased list or a shared-platform lead arrives with someone else’s consent assumptions, or none at all. If a Texan exercises a TDPSA right and asks where their data came from, “we bought it from a vendor” is not an answer you want to give the Attorney General’s office.

The bar that covers Texas and then some

If you build to one standard, build to the highest one. Consent Resolve was engineered to a stricter bar than any U.S. state law — the GDPR standard, whose maximum fine reaches €20 million or 4% of global revenue. Clear that bar and the TDPSA’s day-to-day requirements come along for the ride. Every figure here is sourced on our stats page.

The short version for Texas pros

The TDPSA isn’t a statute to memorize — it’s a four-item checklist: disclose what you collect, get consent, honor opt-outs, and keep proof. Run a consent-first website and most of it is already done, while you keep capturing the homeowners you’re paying to bring to your site. See why consent-first protects your shop, and weigh it against what your current lead channels actually cost, in fees and in exposure. This article is general information, not legal advice — for how the TDPSA applies to your specific business, talk to a Texas attorney.

FAQ

Frequently asked questions

Four practical things: publish a privacy notice visitors can find, run a clear consent banner so identification only happens for people who agree, give an easy opt-out of targeted ads and data sale, and keep a timestamped record of who consented. None of it asks you to stop marketing. This is general information, not legal advice.
Get Started — $7 Email Us