General Educational Information — For Educational Purposes Only, Not Professional Advice.
Smart Business Blueprint is not a law firm or accounting firm and does not provide tax, legal, or accounting services.
Laws change frequently and may differ based on individual circumstances.
Get Updates on New Texas Business Guides
Texas now has a comprehensive consumer privacy law, the Texas Data Privacy and Security Act (TDPSA), which took effect July 1, 2024. However, Texas website operators may also have obligations under federal laws, Texas data-security laws, and industry-specific requirements. This guide walks through what a well-drafted privacy policy and terms of use should cover, along with the federal and Texas-specific rules that shape those documents.
Quick Answer
- Texas has a comprehensive privacy statute — the Texas Data Privacy and Security Act (TDPSA) — alongside several federal and Texas-specific laws that shape website obligations.
- COPPA applies to websites directed at children under 13 and imposes strict consent requirements.
- The Texas Identity Theft Enforcement and Protection Act governs how sensitive personal information must be safeguarded.
- Industry-specific laws like HIPAA and GLBA add further requirements for healthcare and financial services websites.
- E-commerce sites face additional obligations covering payment security, sale terms, and return policies.
Key Takeaways
- Most Texas business websites should consider having both a terms of use and a privacy policy, depending on the website's activities, data practices, and applicable laws.
- The TDPSA generally requires covered businesses to provide a clear privacy notice and honor certain consumer rights over their data, subject to exemptions.
- A privacy policy should clearly disclose what data is collected, how it's used, and how users can exercise their rights.
- COPPA compliance is mandatory for any site directed at children under 13, or with actual knowledge it is collecting data from children under 13.
- ADA accessibility considerations increasingly apply to commercial websites, not just physical locations.
- PCI DSS standards apply to any business that processes online payment card transactions.
- Healthcare and financial services websites face additional obligations under HIPAA and GLBA respectively.
- Terms of use should clearly disclose shipping, returns, and sale terms for e-commerce businesses.
- International customers may trigger additional compliance considerations beyond U.S. and Texas law.
- Privacy and terms documents should be reviewed periodically as the business's data practices evolve.
1. Terms of Use vs. Privacy Policy: What's the Difference?
A terms of use (or terms of service) agreement governs the legal relationship between a website and its users — rules for use, intellectual property, liability limitations, and dispute resolution. A privacy policy specifically discloses what personal data is collected and how it's handled. Most business websites benefit from having both, and they serve distinct legal purposes.
2. The Texas and Federal Legal Framework
Texas website operators sit at the intersection of a state comprehensive privacy law, several federal laws, and sector-specific requirements. The Texas Data Privacy and Security Act governs data practices generally, while federal laws like the Children's Online Privacy Protection Act (COPPA), accessibility considerations under the Americans with Disabilities Act (ADA), and sector-specific laws like HIPAA and the Gramm-Leach-Bliley Act (GLBA) add further obligations depending on the business.
3. The Texas Data Privacy and Security Act
The Texas Data Privacy and Security Act (TDPSA), codified at Texas Business and Commerce Code Chapter 541, is Texas's comprehensive consumer data privacy law and took effect July 1, 2024. It generally applies to businesses that conduct business in Texas or serve Texas residents, process or sell personal data, and don't qualify for the small-business or other statutory exemptions.
For website operators, the TDPSA's most direct impact is the requirement to provide consumers with a reasonably accessible and clear privacy notice describing what personal data is collected, how it's processed, and how consumers can exercise rights such as access, correction, deletion, and opt-out of certain processing.
4. COPPA: Sites Directed at Children
Any website that is directed at children under 13, or that has actual knowledge it is collecting personal information from children under 13, must comply with COPPA — including obtaining verifiable parental consent before collecting personal information and providing clear notice of data practices to parents.
5. ADA Accessibility Requirements
Website accessibility under the Americans with Disabilities Act has become an increasingly active area of litigation. While the ADA doesn't set specific technical web standards for private businesses, many businesses align their sites with the Web Content Accessibility Guidelines (WCAG) as a practical benchmark for compliance and to reduce litigation risk.
6. Privacy Policy Essentials
A well-drafted privacy policy should be written in plain language and clearly address:
- What information is collected (personal data, cookies, analytics)
- How information is used and shared with third parties
- Data retention practices and timelines
- User rights regarding their information
- Security measures implemented to protect data
- Contact information for privacy-related inquiries
7. What Information Is Being Collected
Privacy policies should specifically distinguish between different categories of data collection — information users actively provide (names, emails, payment details), information collected automatically (IP addresses, device data, cookies), and information obtained from third-party sources (analytics providers, ad networks).
8. How Information Is Used and Shared
Users should understand not just what's collected, but why — marketing communications, service delivery, analytics, or sharing with service providers and business partners. Vague or overly broad "we may use your information for any purpose" language undermines the transparency a privacy policy is meant to provide, and may itself raise TDPSA compliance concerns for covered businesses.
9. Data Retention and User Rights
The policy should describe how long data is retained and what rights users have regarding their own information — such as requesting deletion, correction, or a copy of data held about them. For businesses covered by the TDPSA, these rights are a statutory requirement rather than just a best practice.
10. Texas Identity Theft Enforcement and Protection Act
The Texas Identity Theft Enforcement and Protection Act, part of the Texas Business and Commerce Code, requires businesses that own or license computerized data containing sensitive personal information to implement and maintain reasonable procedures to protect that information from unauthorized disclosure.
11. Industry-Specific Regulations
| Industry | Applicable Law | Key Obligation |
|---|---|---|
| Healthcare | HIPAA | Protects patient health information |
| Financial Services | GLBA | Requires safeguarding of nonpublic financial information |
| E-commerce (payments) | PCI DSS | Sets security standards for handling card data |
| Sites for children | COPPA | Requires parental consent for data collection |
| General consumer data | TDPSA | Requires privacy notices and honors consumer data rights |
12. E-Commerce Compliance Requirements
Businesses selling goods or services online face additional compliance layers beyond a standard privacy policy, including:
- PCI DSS standards for any business handling payment card transactions
- Clear disclosure of terms of sale, including pricing, taxes, and order acceptance
- Shipping and return policies that are clearly stated before checkout
- Order confirmation and dispute-resolution procedures
13. International Customer Considerations
Businesses serving customers outside the United States may trigger additional obligations, such as the EU's General Data Protection Regulation (GDPR) for European customers. Even a Texas-based business with no physical presence abroad can become subject to foreign privacy laws depending on who it actually sells to online.
14. Terms of Use Essentials
Beyond privacy, a strong terms of use agreement typically addresses intellectual property rights, acceptable use restrictions, disclaimers of warranties, limitation of liability, and the process for resolving disputes (including any arbitration clause and governing law provision).
15. Common Mistakes
Mistake
Using a Generic, Copy-Pasted Privacy Policy
A policy copied from another website often doesn't accurately reflect the business's actual data practices, which can itself create liability for misrepresentation.
Mistake
Assuming the TDPSA Doesn't Apply
Businesses sometimes assume Texas has no comprehensive privacy law and skip evaluating TDPSA applicability entirely, overlooking notice and consumer-rights obligations that may apply.
Mistake
Ignoring COPPA Applicability
Businesses sometimes assume COPPA doesn't apply simply because their site isn't "for kids," without evaluating whether any content or user base could trigger it.
Mistake
Never Updating the Policy as Practices Change
Adding new analytics tools, ad networks, or data-sharing partnerships without updating the privacy policy creates a mismatch between disclosed and actual practices.
Mistake
No Accessibility Review of the Website
Skipping a basic accessibility audit increases exposure to ADA-related demand letters and litigation.
Mistake
Missing E-Commerce Disclosures
Failing to clearly disclose shipping timelines, return policies, and total costs before checkout is a common source of consumer complaints and disputes.
Mistake
Overlooking Industry-Specific Obligations
Healthcare and financial services businesses sometimes treat a general privacy policy as sufficient without layering in HIPAA or GLBA-specific requirements.
Mistake
No Clear Contact Method for Privacy Questions
Omitting a designated contact for privacy inquiries makes it harder for users to exercise rights and can be viewed unfavorably in a dispute.
16. Compliance Checklist
- Determine whether the business is a covered entity or exempt under the TDPSA.
- Privacy policy accurately reflects actual data collection and use practices.
- COPPA applicability has been evaluated for the site's audience and content.
- Website has undergone a basic accessibility review.
- Terms of use covers IP rights, liability limitations, and dispute resolution.
- Sensitive personal information is safeguarded per Texas requirements.
- Industry-specific obligations (HIPAA, GLBA, PCI DSS) are addressed if applicable.
- E-commerce sites clearly disclose pricing, shipping, and return terms.
- International compliance needs have been assessed if serving customers abroad.
- Privacy policy and terms of use are reviewed at least annually.
17. Primary Government Sources
Texas Business and Commerce Code, Chapter 541 — Texas Data Privacy and Security Act (Texas Constitution and Statutes)
Texas Attorney General — Texas Data Privacy and Security Act
Federal Trade Commission — Children's Online Privacy Protection Rule (COPPA)
18. Frequently Asked Questions
Does Texas require every website to have a privacy policy?
There's no single Texas statute mandating a privacy policy for every website, but the Texas Data Privacy and Security Act, federal laws, industry-specific rules, and general consumer protection principles make having one a practical necessity for most businesses.
What is the Texas Data Privacy and Security Act, and does it apply to my website?
The TDPSA is Texas's comprehensive consumer data privacy law, effective July 1, 2024. It applies to covered businesses that process Texas residents' personal data and don't qualify for the small-business or other statutory exemptions, and generally requires a clear privacy notice describing the business's data practices.
What is COPPA and when does it apply?
COPPA is a federal law that applies to websites directed at children under 13, or that have actual knowledge they are collecting personal information from children under 13, and requires verifiable parental consent before collecting that information.
Do I need to comply with the ADA for my website?
ADA accessibility considerations increasingly extend to commercial websites, particularly those offering goods or services to the public, and this is an active area of litigation. Many businesses use WCAG guidelines as a practical accessibility benchmark, though the ADA itself does not set specific technical web standards for private businesses.
What is the Texas Identity Theft Enforcement and Protection Act?
It's a Texas statute requiring businesses that own or license computerized data containing sensitive personal information to implement reasonable procedures to protect that data from unauthorized disclosure.
Does Texas have a law like California's CCPA?
Yes. The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, is Texas's comprehensive consumer privacy law. Texas businesses also navigate a combination of federal law, sector-specific statutes, and general consumer protection and data security requirements alongside it.
Do healthcare websites have additional requirements?
Yes. Healthcare businesses handling patient health information are subject to HIPAA, which imposes specific requirements for safeguarding and disclosing protected health information, and are generally exempt from the TDPSA for HIPAA-regulated data.
What is PCI DSS and who needs to comply?
PCI DSS is a set of security standards for handling payment card data, not a government statute. Any business that processes, stores, or transmits credit or debit card information online generally needs to comply with applicable PCI DSS standards.
Do I need a different privacy policy for international customers?
Not necessarily a separate policy, but businesses serving customers in jurisdictions with their own privacy laws, such as the EU's GDPR, may need to incorporate additional disclosures or rights into their existing policy.
How often should I update my terms of use and privacy policy?
At minimum, these documents should be reviewed annually and updated any time the business meaningfully changes how it collects, uses, or shares data, or adds new website features.
Can I be sued for an inaccurate privacy policy even without a data breach?
Potentially. A privacy policy that misrepresents actual data practices can create liability under general consumer protection principles or the TDPSA, separate from any liability tied to a security breach.