21 questions across all major obligations of the Texas Data Privacy and Security Act — effective July 1, 2024, actively enforced by the Texas AG. Find your gaps before they cost you $7,500 per violation.
Step 1 of 2 — Select your industry
Which sector best describes your organization?
The quiz covers universal TDPSA obligations. Your industry selection tailors the results page, gap roadmap PDF, and remediation CTAs to your specific enforcement exposure and regulatory stack.
Where should we send your TDPSA readiness roadmap?
We'll email a formatted PDF with your obligation-by-obligation scores, AG enforcement exposure by gap, and a prioritized 30/60/90 remediation roadmap — plus copy john@corerecon.com so you can schedule a free consultation before the Texas AG comes calling.
TDPSA became enforceable for all covered controllers and processors. No grace period — obligations attached on day one of applicability.
Universal Opt-Out — Jan 1, 2025
Controllers must honor GPC signals and other universal opt-out mechanisms for targeted advertising and data sales. Many Texas SaaS companies have not yet implemented GPC recognition.
Cure Period — Discretionary After June 2025
Through May 31, 2025 controllers received a mandatory 30-day cure notice. After June 1, 2025, the Texas AG may file suit without offering a cure. Documented programs are your best defense.
Civil Penalties Up to $7,500/Violation
The AG can seek injunctive relief and civil penalties. Each uncured violation is a separate penalty event — a failure to honor 500 consumer requests could be 500 separate violations.
Score Guide
179–210 Ready
126–178 Mostly Ready
63–125 Material Gaps
<63 Not Compliant
📅 Key TDPSA Dates
July 1, 2024
TDPSA took effect. Controller and processor obligations immediate for covered entities.
January 1, 2025
Universal opt-out mechanism recognition required (GPC signals, similar browser controls).
June 1, 2025+
AG may pursue civil penalties without mandatory cure notice. Active enforcement posture.