Guide

GA4 Compliance Under the Texas Data Privacy and Security Act

Texas's TDPSA applies to more businesses than most state privacy laws because it drops the usual revenue and volume thresholds. Here's what that means for your GA4 setup.

Published August 28, 2026·Last updated August 28, 2026

The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, is worth a dedicated look for one reason that catches a lot of businesses off guard: unlike most other state privacy laws, it doesn’t set a minimum number of consumers or a revenue floor tied to that volume. If your business just isn’t a small business under the (fairly generous) SBA definition, and you do business in Texas or target Texas residents, the TDPSA likely applies, full stop.

Who the TDPSA applies to

The TDPSA applies to any entity that:

  • Conducts business in Texas or produces products/services consumed by Texas residents, and
  • Processes or engages in the sale of personal data, and
  • Is not classified as a “small business” under U.S. Small Business Administration size standards.

There’s no “100,000 consumers” or “$25 million revenue” threshold the way there is in most other state laws. This is a meaningfully broader net, a mid-size company that’s well under California’s or Colorado’s volume thresholds can still be squarely in scope for Texas if it isn’t SBA-small.

What that means for GA4 specifically

Because the applicability test doesn’t hinge on data volume, more businesses running standard GA4 setups with Google Signals or Ads Linking enabled are in scope than they’d assume from checking CCPA or CDPA thresholds alone. The substantive requirements track the now-familiar pattern:

  • Opt-out rights for sale, targeted advertising, and profiling, essentially the same three categories as Virginia’s CDPA and Colorado’s CPA.
  • Mandatory recognition of universal opt-out mechanisms (i.e., GPC) as of January 1, 2025, this puts Texas alongside Colorado as a state where GPC recognition isn’t optional for in-scope businesses. See our GPC and GA4 guide for the implementation details.
  • Sensitive data protections, requiring opt-in consent (not just an opt-out right) before processing categories like precise geolocation, which is relevant if your GA4 setup has geolocation reporting enabled; see our piece on sensitive data and GA4.
  • Enforcement exclusively by the Texas Attorney General, with a 30-day cure period, no private right of action, similar to Virginia’s model.
Our recommendation

Enzuzo

Because the TDPSA's applicability doesn't hinge on hitting a consumer-volume threshold, businesses that assumed they were 'too small' for state privacy law often aren't, for Texas specifically. Enzuzo's guided setup helps confirm what your GA4 configuration needs without requiring a dedicated compliance team.

Try Enzuzo

The SBA small-business exemption isn’t automatic

Don’t assume you’re exempt just because you feel like a small business. The SBA’s size standards vary by industry (based on either revenue or employee count, depending on NAICS code) and are more specific than a general impression of company size. Check your actual NAICS-code threshold rather than assuming.

How Texas compares to the states you may already be handling

If you’ve already configured GA4 for California’s CCPA/CPRA or Colorado’s CPA, most of the technical work (opt-out mechanism, GPC recognition, sensitive data handling) transfers directly to Texas. The main thing to re-check is applicability itself, since the TDPSA can apply even when the volume-based laws don’t. See our state-by-state comparison for the full picture.

This guide is educational and not legal advice. Whether the TDPSA applies to your business, including the SBA small-business exemption, depends on facts a privacy attorney should review.