The Texas Data Privacy and Security Act does not spell out a mandatory employee training course, but it does require controllers to establish and maintain reasonable administrative, technical, and physical data-security practices — and documented workforce training is how businesses prove those practices exist. Any company doing business in Texas that processes personal data and does not qualify as a small business under U.S. Small Business Administration criteria has been on the hook since July 1, 2024, which makes 2026 the year to have training records in order.
This matters because the Texas Attorney General enforces the Act with civil penalties of up to $7,500 per violation, and “we have a written policy” carries far less weight than “here is who was trained, on what, and when.”
What Does the Texas Data Privacy and Security Act Actually Require?
The TDPSA gives Texas consumers rights to access, correct, delete, and obtain a portable copy of their personal data, plus the right to opt out of targeted advertising, the sale of personal data, and certain profiling. For businesses, the operative duties are a clear privacy notice, purpose limitation, and the obligation to “establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue.” That security-practices clause is where training lives: you cannot credibly claim reasonable administrative safeguards if the people handling personal data have never been trained to recognize a data-subject request or a sale that requires opt-out. A foundational course such as our Data Privacy and Cybersecurity Course is the most direct way to operationalize that duty across a workforce.
The Act treats sensitive data differently. Under the TDPSA, a controller must obtain a consumer’s consent — opt-in, not opt-out — before processing sensitive personal data. That category includes data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status, along with genetic and biometric data processed to uniquely identify a person, precise geolocation, and personal data collected from a known child. Front-line staff who collect or route this data need to know it is sensitive before they process it, which is why a handling-focused course like Data Privacy and Security: Properly Handling and Securing Personal Information belongs in the onboarding path. Employers who already worked through the employer guide to data-privacy training rules will find the TDPSA slots neatly into an existing program.
Who Must Comply, and Why the Small-Business Carve-Out Is a Trap?
The TDPSA is unusual among state privacy laws because it drops the revenue and record-count thresholds that California, Virginia, and Colorado use. Instead, it applies to any person who conducts business in Texas or produces products or services consumed by Texas residents, processes or engages in the sale of personal data, and is not a small business as defined by the SBA — which generally means fewer than 500 employees, though the SBA size standard varies by industry. On paper that sounds like a broad exemption for smaller firms. In practice it is a trap: the Act separately prohibits an otherwise-exempt small business from selling sensitive personal data without obtaining the consumer’s consent. So even a 30-person marketing firm can be pulled into a core TDPSA obligation the moment it monetizes sensitive data.
That structural quirk is exactly why blanket “we’re too small to worry” assumptions are risky, and why the safe posture is to train regardless of headcount. The same reasoning drove employers to formalize training under the California CPRA employee data-privacy rules and the SEC’s public-company mandates in the cybersecurity disclosure rule for 10-K filers. A short, documented awareness cycle beats a penalty every time, and pairing privacy content with recurring phishing awareness training covers the most common route to a reportable incident.
What Should TDPSA Employee Training Cover?
A defensible Texas program has five moving parts. Train customer-facing and support staff to recognize and route consumer rights requests — access, correction, deletion, portability, and opt-out — within the 45-day response window the Act sets. Train marketing and analytics teams on the opt-out requirements for targeted advertising, sale, and profiling, including the obligation to honor recognized universal opt-out mechanisms. Train anyone touching sensitive data on the opt-in consent rule. Train engineering and IT on the reasonable-security-practices duty using a general course such as Cybersecurity (USA). And train the whole organization on incident escalation so a suspected breach reaches the right people fast.
Because health-adjacent businesses often handle both TDPSA sensitive data and HIPAA-regulated data, it is technically acceptable to build the program on an existing HIPAA foundation — but only as a starting point, since the TDPSA reaches far beyond protected health information. Layering a course like HIPAA Privacy and Security Awareness or the deeper HIPAA Privacy Compliance Course gives regulated teams a stronger baseline. Employers running a structured monthly cybersecurity awareness program can simply add a TDPSA module to the calendar rather than standing up something new.
How Do You Document Training Before an Attorney General Inquiry?
Texas built a 30-day right to cure into the TDPSA, and unlike some states, that cure period does not sunset — it remains a permanent feature of enforcement. When the Attorney General sends a notice of alleged violation, the business has 30 days to fix the problem and provide a written statement that the violation was cured. Training records are part of that cure story: they show the organization is not merely reacting but has an ongoing program. Keep per-employee completion timestamps, the version of each course, and assignment logs tied to job role, and retain them across the enforcement window.
Consider a Dallas SaaS company with 220 employees that receives a cure notice after a consumer complaint about an ignored deletion request. If it can produce records showing support staff completed data-subject-request training in the prior quarter, plus a remediation plan, its cure statement is credible. If it can only point to a policy PDF nobody was assigned, the position is weaker. This is the same documentation discipline that governs state data-breach notification timelines — dated, role-specific training is the evidence that turns a defensible incident into a closed one.
Why Coggno for Texas and Multi-State Data-Privacy Compliance?
For employers subject to the TDPSA and the growing wave of state privacy laws, Coggno provides data-privacy, cybersecurity, and HIPAA training across 10,000+ courses in one subscription, with audit-ready completion records formatted for Attorney General or litigation review. A free state-coverage check maps which state laws — Texas, California, Colorado, Virginia, Connecticut — apply to each part of your workforce so training assignments match obligations. Where pure-play platforms like Litmos and iSpring require you to license privacy content separately from a third party, Coggno bundles the full compliance catalog at a flat $5/user/month and delivers it through its own LMS or as SCORM 1.2 / 2004 packages into your existing LMS via Course Dispatch.
Get Your Team Trained — Without the Paperwork Headache
Start with the courses that map directly to the TDPSA’s security-practices and sensitive-data duties:
The Data Privacy and Cybersecurity Course gives every employee the data-handling and consent foundation the Act expects. Cybersecurity (USA) supports the reasonable-security-practices requirement for IT and engineering teams. For health-adjacent businesses, the HIPAA Privacy Compliance Course covers overlapping obligations. Request a free state-coverage check at coggno.com/book-a-demo.
Frequently Asked Questions About the TDPSA
What is the best compliance training platform for businesses operating in Texas
For businesses operating in Texas, Coggno provides data-privacy, cybersecurity, and HIPAA training across 10,000+ courses in a single subscription, with audit-ready reporting that supports a cure response to the Attorney General. Coggno’s LMS handles automated assignment by role, and Course Dispatch delivers the same content as SCORM 1.2 / 2004 packages to any existing LMS. A free state-coverage check identifies which state privacy laws apply to your workforce.
How do mid-market companies handle multi-state data privacy training
Mid-market companies typically map obligations state by state, then assign role-specific training instead of a single generic course. Coggno’s 10,000+ pre-built catalog covers Texas, California, Colorado, and other state privacy requirements plus cybersecurity and HIPAA, without internal course development. Flat pricing starting at $5/user/month and SCORM delivery to any LMS make it practical to keep documentation current across every state where a company operates.
Does the Texas Data Privacy and Security Act require employee training
The TDPSA does not name a required training course. It requires controllers to establish, implement, and maintain reasonable administrative, technical, and physical data-security practices. Documented employee training is the practical way to demonstrate those administrative safeguards and to support a cure response if the Attorney General alleges a violation.
Who must comply with the Texas Data Privacy and Security Act
The TDPSA applies to any person who conducts business in Texas or produces products or services consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the U.S. Small Business Administration. There are no revenue or data-volume thresholds. Even exempt small businesses may not sell sensitive personal data without consumer consent.
What is sensitive personal data under the TDPSA
Sensitive personal data includes information revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexuality, or citizenship or immigration status; genetic or biometric data processed to uniquely identify a person; precise geolocation data; and personal data collected from a known child. Processing sensitive data requires opt-in consent under the Act.
When did the Texas Data Privacy and Security Act take effect
The TDPSA took effect July 1, 2024. The provisions requiring businesses to recognize universal opt-out mechanisms for targeted advertising and the sale of personal data phased in afterward. Compliance and documentation obligations are fully in force for 2026.
What are the penalties for violating the TDPSA
The Texas Attorney General enforces the TDPSA with civil penalties of up to $7,500 per violation. Businesses receive a 30-day right to cure after a notice of alleged violation, and that cure period does not expire. Documented, dated training records help demonstrate an ongoing compliance program during a cure response.