If you run a manufacturing operation in Central Texas, the short answer is that the Texas Data Privacy and Security Act, known as the TDPSA, probably does not apply to your business directly in 2026, because the law exempts companies that qualify as a small business under the U.S. Small Business Administration size standard for their industry.
That exemption only covers your own duties as a data controller. It does nothing to remove two risks that hit manufacturers every day: the sensitive data you must still protect with consent, and the vendors and software partners who touch your data whether you are exempt or not.
Quick Answer:Â Most Central Texas manufacturers with fewer than 500 employees are exempt from most TDPSA controller duties, but they still must get consent before selling sensitive personal data, and they remain exposed whenever a vendor holding their data gets breached.
Key Takeaways
- The TDPSA exemption is based on SBA small business size standards tied to your NAICS code, not your revenue or how much data you hold.
- Being exempt from TDPSA controller duties does not remove your duty to get consent before selling sensitive personal data such as health or biometric information.
- The Texas Responsible AI Governance Act, effective January 1, 2026, added AI specific processor duties to the TDPSA, and those duties can reach an otherwise exempt business through its vendor contracts.
- Third party vendors were involved in 48 percent of all data breaches worldwide in 2026, the highest share ever recorded, according to Verizon's Data Breach Investigations Report.
- An exempt manufacturer can still be responsible for notifying customers and employees if a vendor holding their data suffers a breach.
What's at Stake
A shop floor exemption from the TDPSA does not exempt you from the fallout when a vendor mishandles the data you handed them.
Owners hear "small business exemption" and stop reading, and that is the mistake. The Texas Attorney General enforces the TDPSA exclusively, with no private right of action, but the penalties are still real: up to $7,500 per violation after a 30 day cure period expires without a fix.
Since 2024, the AG's Data Privacy and Security Initiative has investigated more than 200 companies and produced the two largest single state privacy settlements in U.S. history. Manufacturers rarely think of themselves as a privacy enforcement target, and most are not, but the vendors, ERP platforms, staffing agencies, and OEM portals a plant depends on are squarely in scope.
When one of them is breached, the notification burden and the customer conversation often land on you, not on the vendor whose system actually failed. If your shop also does defense or government work, TDPSA exposure sits on top of CMMC and NIST 800-171 obligations you already carry, not instead of them.
Why Central Texas Businesses Face This Challenge
Central Texas manufacturing has grown fast, and the software stack underneath it has grown faster than most owners have tracked.
A plant in Georgetown or Round Rock today runs an ERP system, a quality management platform, a payroll processor, a supplier portal, and often two or three point solutions nobody remembers approving. Each one is a vendor with a copy of your data. The 48 percent third party breach share in this year's Verizon report is not an abstract statistic for a business like that, it is a description of exactly how exposure spreads through a typical Central Texas supply chain.
The TDPSA's small business exemption was written with this in mind only in the sense that it recognizes smaller operations cannot run a full privacy program. It was not written to suggest the risk goes away. Add the TRAIGA amendments taking effect this year, which layer AI specific processor obligations on top of the existing law, and a manufacturer using an AI powered scheduling tool or a vendor with embedded AI features has a genuinely new compliance question that did not exist two years ago.
How CTTS Helps Central Texas Manufacturers Manage Vendor and Data Privacy Risk
The goal is a system between your business and the vendors you depend on, not a plant manager turned privacy lawyer.
CTTS has served Central Texas businesses since 2002, and our Complete Care Coverage plan builds vendor and data risk management into the same flat rate agreement that covers your helpdesk, monitoring, and patching. That means a living inventory of which vendors and SaaS tools actually touch your sensitive data, contract language reviews so breach notification and subprocessor terms are spelled out before you sign, and monitoring that flags when an employee connects a new AI tool or app to company data without anyone approving it.
Clients reach a live person in three rings, and our team carries a 96 percent client satisfaction score across 159 surveys, so this is not theoretical support that shows up only when a vendor already failed. For manufacturers with federal or defense contracts, CTTS is also a Cisco U.S. Federal Authorized Partner, which matters when vendor vetting and data handling standards have to satisfy a contracting officer, not just your own comfort level.
TDPSA Compliance Best Practices for Manufacturers
What Counts as Sensitive Personal Data Under the TDPSA?
Sensitive personal data includes health information, biometric or genetic data, precise geolocation, citizenship or immigration status, and data revealing racial or ethnic origin, religious belief, or sexual orientation.
If your manufacturing business collects any of this, through wellness programs, biometric time clocks, or background checks, you need consent before selling it regardless of whether the SBA exemption applies to you.
Do I Need to Register or File Anything With the State of Texas?
No. Unlike some other state privacy laws, the TDPSA does not require a registration, filing, or fee to the state. The exemption and the underlying obligations both apply automatically based on your size and the data you handle, which is exactly why so many owners never notice the law until a vendor incident forces the question.
How Do I Know If My Vendor Contracts Meet TDPSA Standards?
Pull your top ten vendor contracts by data access, not by dollar amount, and check for three things: a defined data handling scope, a breach notification timeline, and subprocessor disclosure language. Most standard SaaS agreements written before 2024 have none of the three.
Three Steps to Check Your TDPSA Exposure This Quarter
- Confirm your SBA small business size status for your specific NAICS code, since the threshold varies by industry and is not a flat employee count across the board.
- Build or update an inventory of every vendor and software tool that touches sensitive personal data, including AI features bundled into tools you already use.
- Update vendor contracts to include breach notification timelines and subprocessor disclosure, starting with the vendors that hold the most sensitive data.
Take the Next Step
Guessing at your TDPSA exposure costs more than checking it. CTTS offers a free Executive IT Risk Assessment for Central Texas manufacturers and other businesses with 10 to 250 employees, covering your vendor exposure, data handling practices, and where an exempt business still carries real risk.
Schedule a free strategy session with CTTS and get a clear answer instead of a guess.
Have Questions? We've Got Answers
Does the TDPSA apply to nonprofits or government contractors?
Registered nonprofits are exempt from the TDPSA regardless of size, and most government entities fall outside the law's definition of a covered business. Government contractors are a different story, since the contract itself, not the TDPSA, usually sets the actual data handling requirements, and those often exceed anything the state law would require anyway.
What happens if my exempt business still has a vendor data breach?
Texas's separate breach notification law still applies to you even when the TDPSA does not, so you generally must notify affected Texas residents without unreasonable delay. The SBA exemption protects you from TDPSA controller duties, not from the state's breach notification statute or from the reputational cost of telling customers their data was exposed.
Is the TDPSA the same as HIPAA or CMMC?
No, and treating them as interchangeable is a common and costly mistake. The TDPSA is a general consumer privacy law, HIPAA governs protected health information specifically, and CMMC governs controlled unclassified information for Department of Defense contractors. A manufacturer can be exempt from the TDPSA and still be fully on the hook for HIPAA or CMMC obligations depending on what it handles and who it contracts with.
Contact CTTS today for IT support and managed services in Austin, TX. Let us handle your IT so you can focus on growing your business. Visit CTTSonline.com or call us at (512) 388-5559 to get started!
