RoutineMetric

Texas Data Privacy & Security Act (TDPSA) Calculator

Determine your regulatory status and calculate compliance readiness under Texas Business and Commerce Code Chapter 541.

Step 1: Scope & Texas Nexus Checks

Conducts Business in TexasDoes your organization have a commercial presence in Texas?
Produces Products for TexansAre your services or products consumed by Texas residents?
Processes Personal DataDo you collect, store, structure, or use consumer personal data?
Sells Personal DataDo you exchange personal data for monetary or valuable consideration?

Step 2: SBA Small Business Size Determination

About SBA Size Standards

Determining whether an organization is classified as an SBA Small Business concern is NAICS-specific. If your company operates across multiple NAICS codes, the primary NAICS sector generating the plurality of revenue governs.

Step 3: Statutory Entity Exemptions

Select any entity-level statutory exemptions that apply to your organization under TDPSA Sec. 541.002:

GLBA Covered EntityFinancial institution subject to GLBA
HIPAA Covered EntityCovered entity or business associate
Non-Profit OrganizationQualified 501(c)(3) tax-exempt entities
Institution of Higher EdState/private college or university
State Agency / GovernmentPolitical subdivisions and state agencies
Electric Utility / PowerElectric cooperative or utility

Step 4: Sensitive & Biometric Data Processing

Under TDPSA Sec. 541.107, SBA small businesses are NOT fully exempt from the act if they sell sensitive or biometric personal data. Check below:

Sell Sensitive Personal DataRacial, health, religious, citizenship status, precise geolocation, etc.
Sell Biometric Personal DataFingerprints, voiceprints, iris, or facial geometry data.

Step 5: TDPSA Compliance Readiness Checklist

Assess your legal and operational compliance posture across the six primary obligations of the TDPSA:

1. Privacy Notice (Sec. 541.102)Maintain a clear, accessible privacy policy stating categories processed/shared/sold, purposes, consumer rights pathways, and details on appealing request denials.
2. Consumer Rights Intake & Processing (Sec. 541.051 - .055)Provide functional mechanisms for Texas consumers to request Access, Correction, Deletion, Portability, and Opt-out of targeted ads, sales, and profiling.
3. Data Processing Agreements (Sec. 541.104)Execute structured contracts with all third-party processors that bind them to specific processing instructions, confidentiality, subprocessor checks, and security audits.
4. Data Protection Assessments (Sec. 541.105)Perform and document comprehensive risk assessments for targeted advertising, sales of personal data, profiling with foreseeable risk of harm, or processing sensitive data.
5. Response Timelines & Appeal Protocols (Sec. 541.053)Ensure systems can resolve consumer rights requests within 45 days (with a single 45-day extension) and support a formal appeal process within 60 days of denial.
6. Security Measures & TOMs (Sec. 541.101)Implement adequate physical, administrative, and technical data security safeguards matching the volume, nature, and risks associated with consumer data.

Regulatory Status

SBA Exempt

Qualifies as an SBA Small Business and does not sell sensitive or biometric personal data.

SBA Status Details

Selected NAICS:Software Publishers (513210)
SBA Standard Metric:employees
SBA Limit Threshold:1,500 employees
Your Size Metric:120 employees
SBA Classification:Small Business Concern

Compliance Readiness Score

0%
Gap identified. Toggle on completed readiness elements as you implement them.
Advertisement
Bottom Banner Ad (728x90)
Contemporaneous Memo Generator

CONTEMPORANEOUS COMPLIANCE MEMORANDUM: TDPSA STATUS ASSESSMENTS

TO: Legal Counsel / Compliance Record
FROM: RoutineMetric Assessment Tool
DATE: August 14, 2026
SUBJECT: Texas Ch. 541 Threshold Review

1. Scope and Applicability Findings

This document serves as a contemporaneous business record of the threshold compliance evaluation under the Texas Data Privacy and Security Act (TDPSA), codified at Texas Business and Commerce Code Chapter 541.

SBA SMALL BUSINESS EXEMPTION ATTACHED: The organization is categorized as an SBA Small Business Concern under 13 CFR Part 121 in its primary NAICS sector (Software Publishers).

Consequently, under Sec. 541.002, the organization is exempt from the broader consumer rights mandates, mandatory processor contracts (DPAs), and documented Data Protection Impact Assessments (DPIAs), EXCEPT for sensitive and biometric personal data sales.

2. SBA Size Calculations

Under Section 541.002, the TDPSA imports the federal Small Business Administration (SBA) definitions of a "small business concern" under 13 CFR Part 121.

• INDUSTRY SECTOR: Software Publishers (NAICS 513210)
• METRIC TYPE: Total Employee Headcount
• SBA LIMIT VALUE: 1,500 employees
• COMPANY SIZE VALUE: 120 employees
• CLASSIFICATION RESULT: SBA SMALL BUSINESS CONCERN (PASS)

3. Sensitive and Biometric Data Sales (Sec. 541.107)

The organization does not engage in the sale of sensitive or biometric personal data. Therefore, the special consent and notice duties under Section 541.107 do not apply at this time.

4. Compliance Readiness and Gap Analysis

Evaluation of the six operational compliance pillars (Overall Score: 0%):

Privacy Notice: Non-Compliant (Drafting required)
Consumer Rights: Non-Compliant (Needs intake form)
Processor Agreements: Non-Compliant (Contracts missing clauses)
Impact Assessments: Non-Compliant (DPIAs not documented)
Appeals Mechanism: Non-Compliant (Appeal flow missing)
Security Safeguards: Non-Compliant (Security audit recommended)

5. Signature & Record Keeping

This document is a formal record of contemporary statutory assessment. Maintain this PDF/printed copy within corporate compliance registries as evidence of good-faith regulatory threshold audits.

Reviewed By (Print Name)
Date
Advertisement