Skip to main content
Privacy Law & Rights
9 min read

Texas Data Privacy Rights and Data Brokers (TDPSA Guide, 2026)

A statute-bounded Texas TDPSA guide to covered scope, consumer rights, authentication, response windows, exemptions, and broker requests.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
Texas Data Privacy Rights and Data Brokers (TDPSA Guide, 2026)
Texas Data Privacy Rights and Data Brokers (TDPSA Guide, 2026)
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

Texas's Data Privacy and Security Act (TDPSA), Business and Commerce Code Chapter 541, took effect July 1, 2024. It gives qualifying Texas consumers rights over certain personal-data processing, but coverage depends on the controller, the small-business rule, exemptions, request type, and authentication. A broker having a Texas resident's profile does not by itself prove that the broker or every record is covered.

This is a source guide, not legal advice. Read the current statute and the Texas Attorney General's TDPSA information before relying on a legal request.

Key takeaways

  • TDPSA scope is conditional. The small-business rule, exemptions, definitions, and the business's role must be checked before citing Chapter 541.
  • Covered, authenticated consumer requests generally have a 45-day response period, with a possible additional 45 days when the statute's conditions and notice rules are met. That is a response window, not a guaranteed deletion result.
  • Texas provides access, correction, deletion, portability, and defined opt-out rights, but exceptions and authentication can change what a controller must do.
  • Sensitive-data processing generally requires consent under the statute, but the exact category and exemption matter. Do not treat every inferred attribute as automatically covered sensitive data.
  • The official Texas materials reviewed here do not identify a single data-broker deletion mechanism equivalent to California's separate DROP program. A Texas resident should normally use each provider's current route unless another applicable process exists.

Who and what the TDPSA covers

Chapter 541 generally applies to a person conducting business in Texas or producing a product or service consumed by Texas residents, who processes or sells personal data and is not a small business under the federal Small Business Administration definition, subject to the statute's exemptions. Unlike some state privacy laws, Section 541.002 does not use a general 100,000-consumer or 25%-of-revenue threshold. Section 541.107 separately addresses a small business that sells sensitive data.

That scope rule is only part of the analysis. The statute excludes or treats differently categories such as certain state agencies, financial institutions and GLBA-covered data, HIPAA-covered entities and business associates, nonprofit organizations, higher-education institutions, and specified electric utilities. The exact processing activity and data category still matter.

Request Drafting

Exercise your statutory data deletion rights

Review source-aware privacy-rights request drafts directly in your browser. Send or submit each request yourself after checking the provider route and applicable law.

Start Free Statutory Opt-Out Free for selected workflows · No opt-out profile stored · No card needed

The statute also excludes “publicly available information” from its definition of personal data in the relevant context. A public record can still be displayed or reused in ways that raise other legal or privacy questions, but a Texas request should not assume that every public-record field is subject to the same right.

Rights a covered Texas consumer may exercise

Section 541.051 lists consumer rights that can include:

Right described in this guideScope or condition stated in the guide
Confirm processingWhether a controller is processing personal data
AccessPersonal data the controller is processing
CorrectInaccuracies, taking account of the data and processing purpose
DeletePersonal data provided by or obtained about the consumer
Portable copyPersonal data the consumer previously provided, where the statutory conditions apply
Opt outProcessing for targeted advertising, the sale of personal data, or profiling that produces a legal or similarly significant effect

These are not unconditional commands to delete every record. A controller may apply statutory exceptions, may need to authenticate the requester, and may be unable to associate a request with data held in a form the law does not require it to reidentify. A request should identify the exact provider, profile, and action requested.

Response time, authentication, and appeals

For a covered request, Chapter 541 generally gives a controller no later than 45 days after receipt to respond. The statute permits one additional 45-day period when reasonably necessary because of the complexity or number of requests, with the required notice. Confirm the current text of Section 541.052 before treating a date as applicable to your request.

The controller may use reasonable methods to authenticate that the requester is the consumer entitled to exercise the right. It may ask for additional information reasonably necessary to authenticate the consumer and request. Provide the minimum information needed, and do not send a full Social Security number, identity document, or unrelated personal data when a less sensitive match will work.

If a controller refuses or only partly grants a request, use the appeal process described in its privacy notice. Preserve the original submission, confirmation, verification exchange, response, and appeal result. A complaint to the Texas Attorney General can report a concern, but it is not a guarantee of an investigation, a specific enforcement action, or a deletion outcome.

Sensitive data and opt-in consent

Chapter 541 defines sensitive data to include personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, or citizenship or immigration status; genetic or biometric data processed to uniquely identify an individual; data collected from a known child; and precise geolocation data.

The statute generally prohibits processing a consumer's sensitive data without consent, subject to the statute's text and exceptions. “Inferred,” “predicted,” or “marketed” attributes should not automatically be labeled sensitive data under Texas law. Identify the field, how it was obtained, the processing purpose, and the controller's notice before choosing a legal basis.

How to submit a Texas request to a broker

1. Identify the exact record

Search your name, address, phone number, email, and likely aliases. Save the profile URL and the fields shown. Confirm the provider's legal entity and current privacy notice. A brand family may contain several controllers or products.

2. Start with the provider's current privacy route

Use the opt-out, access, correction, deletion, or privacy-request form listed by the provider. Read the verification instructions and choose the request type that matches the record. Do not claim that a catalog listing proves Texas coverage or that a generic opt-out reaches every affiliate.

If the facts appear to fit Chapter 541, a request can identify the law without pretending that it overrides an exception:

Pursuant to the Texas Data Privacy and Security Act, Texas Business and Commerce Code Chapter 541, I request review of the personal data associated with this profile and deletion of data within the scope of the law. Please identify the verification required, any applicable exception, the response route, and the scope of any action taken.

3. Track the response

Record the submission date, verification steps, confirmation number, response deadline, extension notice, decision, and appeal route. A provider's acknowledgement proves that it received a request; it does not prove that every copy, affiliate record, or downstream listing was removed.

4. Escalate carefully

If a covered controller does not respond within the applicable period, or if its response does not explain the denial, preserve the evidence and use the provider's appeal process. You can review the Texas AG's current consumer-privacy complaint route. Consider qualified legal advice when the request involves employment, credit reporting, health data, a public record, a business dispute, or a safety risk.

OfflistMe can create browser-local, user-reviewed drafts for supported provider workflows. You submit each request yourself. Catalog inclusion is not proof of Texas registration, TDPSA coverage, a current provider route, or acceptance. Provider verification, exemptions, and results remain separate.

Texas versus California: do not merge the systems

California's CCPA/CPRA and Delete Act have different definitions, applicability rules, regulators, and mechanisms. The California Privacy Protection Agency explains DROP, a California-specific deletion mechanism for registered data brokers and non-exempt personal information under its rules. A Texas resident should not assume that California's portal, deadlines, or eligibility rules apply to a Texas request.

Likewise, do not turn a comparison table into a legal strength ranking. Texas and California differ in applicability rules, exemptions, profiling rules, sensitive-data treatment, universal opt-out signals, enforcement, and private-right-of-action rules. Check the statute that applies to the person, provider, data, and purpose.

Practical privacy steps beyond TDPSA

Even when a provider is outside TDPSA scope, you can still:

  • use the provider's ordinary opt-out or correction route;
  • remove unnecessary address and phone information from your own website and public profiles;
  • review credit-reporting, FCRA, employment, health, and financial channels under their separate rules;
  • use browser privacy signals where the provider and applicable law recognize them; and
  • recheck important listings based on your risk and provider evidence, without assuming a fixed quarterly or annual schedule.

These measures address different layers. A broker opt-out does not delete a government record, erase a credit file, remove a breach copy, or guarantee that a provider will not receive a new matching record.

Frequently asked questions

Does TDPSA apply to a broker located outside Texas?

Possibly, but location is not the only test. Review the statute's business connection, small-business rule, controller role, processing, exemptions, and the consumer's status before concluding that Chapter 541 applies.

Can I sue a broker under TDPSA?

The Texas Attorney General's current overview describes state enforcement. Do not assume that Chapter 541 gives an individual a private right of action; consult the statute and qualified counsel about other possible claims or laws.

Is 45 days a guaranteed deletion deadline?

No. For a covered and authenticated request, it is generally a response period subject to the statute's extension and exception rules. The response may grant, partially grant, deny, or request more authentication; it does not promise complete deletion.

Can a broker charge me to submit a TDPSA request?

Review the provider's current notice and the statute. A paid service assisting with preparation is different from a controller charging for a statutory request, and fee rules can depend on the request and applicable law.

Does Texas have one portal that deletes every broker profile?

This guide does not identify a Texas equivalent to California's DROP mechanism. Use the current provider routes and verify any claimed registry or centralized portal against an official Texas source.

Related guides

Sources and limits

Provider coverage, controller classification, authentication, exemptions, request acceptance, response, deletion, downstream copies, and enforcement outcomes remain fact-specific. This guide does not replace legal advice.

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription