Texas answered the privacy question later than California but more broadly than most states: the Texas Data Privacy and Security Act applies to almost any business doing business in the state and processing personal data, without the revenue or record-count thresholds other states use as a filter. This page explains what the TDPSA actually covers, where purely B2B contact data sits outside it, and why lead.box applies the same EU-grade baseline to Texas traffic regardless of what state law strictly requires.
At a glance
- Framework
- Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code Ch. 541, effective 1 July 2024
- Supervision
- Texas Attorney General exclusively, with a 30-day cure period before enforcement
- Usual legal basis
- Legitimate business purpose; company-level identification falls outside the TDPSA's consumer-in-an-individual-context definition
- Processing location
- ISO-certified EU data centres
The Texas Data Privacy and Security Act
Regulation at a glance
- FrameworkTexas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code Ch. 541, effective 1 July 2024
- SupervisionTexas Attorney General exclusively, with a 30-day cure period before enforcement
- Usual legal basisLegitimate business purpose; company-level identification falls outside the TDPSA's consumer-in-an-individual-context definition
- Processing locationISO-certified EU data centres
The Texas Data Privacy and Security Act, codified at Texas Business & Commerce Code Chapter 541, took effect on 1 July 2024 and gives Texas residents rights over their personal data broadly similar to other comprehensive state privacy laws: access, correction, deletion, portability and the right to opt out of sale, targeted advertising and certain profiling. What sets the TDPSA apart is scope: unlike Virginia, Colorado, Connecticut or most other states, it carries no revenue threshold and no minimum count of consumer records processed. Instead it applies to any entity that conducts business in Texas, processes or sells personal data, and does not qualify as a small business under the U.S. Small Business Administration's size standards.
That design choice is deliberate and unusually broad: a modest regional company with no California-style revenue can still fall inside the TDPSA simply by processing Texas residents' personal data commercially, unless the SBA small-business exemption applies to it. Enforcement sits exclusively with the Texas Attorney General — there is no private right of action, and no separate state privacy agency the way California has the CPPA. Before bringing an enforcement action, the Attorney General must give a controller 30 days to cure the alleged violation, a cure period written into the statute itself rather than left to prosecutorial discretion.
From 1 January 2025, the TDPSA also requires controllers that process sensitive data or biometric identifiers to include a clear notice of that processing, disclosed before or at the point of collection, and it requires large data controllers and processors to recognise a universal opt-out mechanism when a consumer sends one through their browser or device. Neither obligation is triggered by company-level visitor identification, since it does not process biometric identifiers and does not collect sensitive categories of data about a named individual, but both are relevant background for any Texas privacy notice a customer maintains.
Why purely B2B data sits outside the TDPSA
The TDPSA defines a 'consumer' as a Texas resident acting only in an individual or household context, and it expressly excludes a person acting in a commercial or employment context — someone communicating with a company as an employee, contractor or business representative rather than as a private individual. That single line moves an entire category of data outside the statute's reach: a business card exchanged at a trade show, a work email used to request a demo, or a visit from a company's IT department researching a vendor is not 'consumer' data under Texas law in the way it would be treated in California.
This is the opposite of the California position. Under CCPA/CPRA, the temporary B2B and employee exemptions expired on 1 January 2023, so business contact and employment-related personal information is now squarely inside the statute's coverage and its shared enforcement between the California Privacy Protection Agency and the Attorney General. The TDPSA never had that exemption to lose — it built the exclusion directly into the definition of 'consumer' from the start, so a Texas-only sales operation faces a materially narrower personal-data compliance surface than an equivalent operation selling into California.
Layer a third distinction on top of both positions: lead.box does not resolve a named employee at all. It identifies the organisation behind a website visit from network-level signals — the visiting company, not the person browsing on its behalf — so the question of whether Texas or California law treats B2B contact data as 'consumer' data is a separate legal question from whether company-level identification touches personal data in the first place. The two questions deserve separate answers, and neither is a compliance guarantee; this page is not legal advice, and Texas customers should have their own counsel confirm how these definitions apply to their specific data flows.
Start free
Install the snippet and see the first named companies on your own traffic.
The federal picture
This state page sits inside the wider United States market page, which covers the federal layer, cross-border transfers and the documentation a US buyer usually asks for.
United States overview →What you actually see
Named companies in your dashboard, with industry, size and the pages they read.
How Texas sales and procurement teams put this to work
Texas procurement culture leans practical rather than adversarial: energy, manufacturing, logistics and public-sector-adjacent buyers in Houston, Dallas-Fort Worth and Austin tend to ask a vendor review committee for a straightforward data flow diagram and a signed processing agreement before signing off, rather than demanding a certification that does not exist for this category of tool. A clear written answer to 'what does this collect, and does it touch personal data under the TDPSA' moves faster through that review than a marketing claim of blanket compliance.
Oil-and-gas services companies, industrial equipment manufacturers and Texas-based SaaS vendors selling into enterprise accounts share a common pattern: long, quiet research cycles by a multi-person buying committee, often from a corporate network or VPN, followed by a single inbound inquiry from whichever stakeholder was assigned to make first contact. Seeing the company name during that research window lets a Texas sales rep reach out before a competitor already has a call on the calendar, without needing to identify which individual on the buying committee was reading which page.
How lead.box works here
GDPR-compliant visitor identification: the 5 rules
1. Company level only
Identification resolves the organisation behind a visit through network and IP-to-company matching. Individual people are never identified, and a visit that cannot be matched to a company stays anonymous.
2. Legal basis: legitimate interest, Art. 6(1)(f) GDPR
Company-level identification is commonly based on legitimate interest under Art. 6(1)(f) GDPR, documented with a balancing test. Consent is not required where no personal identifiers are processed; the final assessment stays with you as the controller.
3. No personal identifiers
No names, personal e-mail addresses, device fingerprints or cross-site profiles are created. Raw network addresses are not available in the interface, exports or API — only the resolved company is stored.
4. EU data processing
Personal and visitor data concerning the EU is processed in ISO-certified data centres in the European Union. EU visitor data is not moved outside the EU for this purpose.
5. Transparency and opt-out
Disclose the identification in your privacy policy — a copy-ready paragraph is on this page. Every visitor can object at any time through the public opt-out page.
lead.box applies all five rules by design.
Questions from this market
Generally, no. The TDPSA defines a 'consumer' as a Texas resident acting only in an individual or household context, and it expressly excludes anyone acting in a commercial or employment capacity — for example, an employee requesting a demo on a company's behalf or a procurement contact exchanging business details. That exclusion means routine B2B contact data, such as a work email submitted through a lead form or a company representative's name tied to a business inquiry, typically sits outside the statute's consumer rights provisions, even though the same company might separately be a covered controller for other data it holds. Whether a specific dataset qualifies still depends on how it was collected and used, and the line between commercial and individual context is not always obvious in mixed data sets. This is not legal advice; a Texas business should have counsel review its actual data flows against the statutory definition before relying on the exclusion.
No, and this is what makes the TDPSA unusual compared with Virginia, Colorado, Connecticut and most comparable state laws. Those statutes typically exempt smaller businesses through a revenue floor or a minimum count of consumer records processed annually. The TDPSA instead applies to any entity that conducts business in Texas, processes or sells personal data, and does not meet the U.S. Small Business Administration's definition of a small business — a standard that varies by industry and is based on factors like employee count or annual receipts, not a single dollar figure written into the privacy statute itself. That means a company that would be exempt under Virginia's or Colorado's revenue thresholds could still be a covered controller in Texas, so applicability has to be checked against SBA size standards for that company's specific industry rather than assumed from experience with other states' laws.
Enforcement of the TDPSA sits exclusively with the Texas Attorney General; there is no private right of action, meaning individual consumers cannot sue a company directly for an alleged violation, and there is no separate dedicated privacy agency the way California has the CPPA. Before the Attorney General can bring an enforcement action, the statute requires that the controller or processor be given written notice and a 30-day period to cure the alleged violation, giving a business a defined window to correct a practice before facing penalties. That cure period is written directly into the statute rather than left to prosecutorial discretion, which is a meaningfully different enforcement posture than states without a mandatory cure provision. None of this changes whether a given data practice is compliant in the first place, only how an alleged violation would be addressed procedurally.
The difference is structural, not incidental. Under CCPA/CPRA, the temporary exemptions that once excluded B2B and employee personal information expired on 1 January 2023, so business contact and employment-related data are now fully within scope of California's consumer rights and are enforced jointly by the California Privacy Protection Agency and the Attorney General. The TDPSA never carried an equivalent exemption to expire — its definition of 'consumer' excludes commercial and employment-context activity from the outset, so the exclusion is permanent and built into the statute's core definitions rather than a lapsed transitional carve-out. A company selling only into Texas therefore faces a narrower personal-data compliance question for its B2B contact records than an equivalent company selling into California, though both should still document their data flows carefully rather than rely on a general impression of either state's law.
lead.box resolves the organisation behind a website visit from network-level and firmographic signals — the visiting company's name, industry and size band — rather than identifying a named person, setting a persistent device identifier, or building a profile of an individual's browsing across unrelated sites. Because the TDPSA's 'consumer' definition centres on an identified or reasonably identifiable individual acting in an individual or household context, company-level identification is designed to sit outside that category by not resolving a person at all, which is a separate and arguably more fundamental distinction than the commercial-context exclusion discussed elsewhere on this page. Confirming that against your own privacy notice and your own specific implementation remains your responsibility as the controller; this is general information, not a legal opinion on your deployment.
From 1 January 2025, TDPSA amendments require controllers processing sensitive data categories or biometric identifiers to give consumers clear notice of that processing, generally disclosed before or at the point of collection, alongside the statute's broader universal opt-out mechanism recognition requirement for larger controllers and processors. Company-level visitor identification does not process biometric identifiers such as fingerprints or facial geometry, and it does not process the TDPSA's defined sensitive categories tied to an identified individual, so these specific notice obligations are not triggered by that activity on their own. They remain relevant background, though, for any Texas site that separately collects sensitive data through other tools, forms or account features, and a site's overall privacy notice should reflect the full set of data collected across all its tools, not just this one.
Starting 1 January 2025, larger Texas controllers and processors must recognise an opt-out preference signal a consumer sends through their browser or device — comparable to the Global Privacy Control signal recognised under California law — and treat it as a valid request to opt out of the sale of personal data or targeted advertising, where those activities apply. Because lead.box does not sell personal information or use visitor data for targeted advertising, and because company-level identification does not depend on advertising identifiers or cross-site tracking that a universal opt-out signal is designed to stop, this requirement generally does not change how the product operates. It is still worth documenting in your own privacy notice how your site as a whole responds to such signals, particularly if other tools on the same site do rely on advertising-related data sharing.
Texas buyers in energy services, industrial manufacturing and logistics tend to run vendor review through a practical lens rather than a compliance checklist: a data flow description, a signed data processing agreement, confirmation of where data is stored, and a straight answer on whether personal data or advertising identifiers are involved. Procurement teams accustomed to long sales cycles and multi-stakeholder sign-off, common in energy and industrial sectors, generally move faster when a vendor volunteers this documentation upfront rather than waiting to be asked. lead.box provides a written processing agreement, discloses that processing happens in ISO-certified EU data centres, and explains plainly that it identifies the visiting company rather than a named individual — the same documentation a European buyer would expect, adapted for the Texas review process, and not a substitute for the buyer's own legal review.
See which Texas companies are already on your site
Install a first-party snippet, watch the first Texas accounts appear, and hand procurement the same documentation a European buyer would expect.