The Texas Data Privacy and Security Act (TDPSA) brings several new consumer rights to the forefront and one of the most important is the Data Subject Access Request (DSAR).
This page covers one piece of the picture. For the full scope of the TDPSA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the TDPSA and cookies.
If your company processes personal data from Texas residents, you need to understand how DSARs work and what your responsibilities are.
A DSAR is a formal request from a consumer asking a business to disclose the personal data it has collected about them.
Under the TDPSA, consumers have the right to know what personal information is collected, how it’s used, with whom it’s shared, and why.
Businesses are required to respond to DSARs within a reasonable timeframe typically within 45 days.
When a Data Subject Access Request (DSAR) is submitted, businesses are legally required to provide a clear and comprehensive summary of the personal data they have collected about the individual.
This includes not only basic identifiers like names and contact details but also any sensitive data categories processed, such as health, financial, or biometric data.
Organizations must outline the purpose of the data processing, where the data was sourced from, and whether it has been shared with third parties. If data has been disclosed, the organization must also identify the recipients or categories of recipients.
All this information must be delivered in a concise, transparent, intelligible, and easily accessible formatusually free of charge and within a legally defined timeframe.
Beyond the data itself, organizations must explain the individual's rights under applicable data protection laws, such as the right to rectify inaccurate information, request deletion, or object to certain types of data processing.
Companies must also provide information about how long personal data will be retained and the logic involved in any automated decision-making or profiling that affects the individual.
If the data was transferred internationally, especially outside of jurisdictions with strong data protection laws, the response must include the safeguards in place—like Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs)—to protect the data during cross-border transfers.
To ensure compliance, many businesses rely on privacy management tools or external partners that help automate the DSAR response process.
These tools can pull together information from multiple systems, standardize the formatting, and track deadlines, reducing the risk of non-compliance penalties. It's crucial for organizations to have an internal protocol in place to verify the identity of the requester, especially when dealing with sensitive personal data.
Failing to fulfill a DSAR accurately or on time can lead to reputational damage and fines under laws like the GDPR, CCPA, or the TDPSA. For help in setting up a compliant DSAR process, book a meeting with a data privacy expert from AdOpt.
Submitting a Data Subject Access Request (DSAR) should be a simple and accessible process for users. Most privacy laws, including the GDPR, CCPA, and TDPSA, require businesses to provide at least one easy-to-use method for submitting these requests.
Common channels include web forms, email addresses, privacy portals, or even physical mail. Some companies also integrate DSAR options within cookie banners or consent preference centers.
Whatever the method, it must be clearly visible and not require users to jump through unnecessary hoops.
Transparency is key users should know exactly where to go and what to do when they want to exercise their privacy rights.
Once a user initiates a DSAR, the business must verify the identity of the requester to protect against fraud or unauthorized access to personal data.
This verification process might involve confirming account details, sending a confirmation email, or requesting additional information especially for sensitive data categories.
However, the business must strike a balance: while protecting data, it should not make the verification process intentionally difficult or discourage users from completing their request.
Under most laws, once identity is verified, the organization must respond to the DSAR within a specified timeframe usually 30 to 45 days, depending on the jurisdiction.
To streamline the process and avoid delays, many businesses use automated DSAR workflows or third-party solutions that centralize requests, track deadlines, and ensure consistent responses.
These tools often include templates for standard communication and dashboards to manage compliance risks. In addition to responding within the legal timeframe, businesses must also keep detailed records of each request and how it was resolved.
This documentation is crucial in case of regulatory audits or disputes. If you’re unsure whether your DSAR submission process meets compliance requirements, speak with an expert at AdOpt to get guidance tailored to your region and business model.
DSAR and Other Consumer Rights
A Data Subject Access Request (DSAR) is a powerful tool under the Texas Data Privacy and Security Act (TDPSA), but it’s just one of several rights available to consumers.
The TDPSA is designed to give Texans greater control over their personal data, and understanding these rights helps both individuals and businesses stay compliant. Alongside the right to access data through a DSAR, Texas residents can also correct inaccurate information, delete personal data, and opt out of specific uses like targeted advertising and data sales.
These rights reflect a growing trend among U.S. states toward broader, more user-centric data privacy laws.
The right to correct data means consumers can request a business to fix or update any incorrect personal information it holds. This is crucial for maintaining data accuracy, especially in sectors like finance, healthcare, or education.
The TDPSA requires businesses to respond to such correction requests within a set timeframe and to clearly communicate any actions taken.
Similarly, the right to deletion allows users to request the removal of their data from a company’s systems.
While some exceptions apply such as for legal obligations or security purposes businesses must honor these requests when possible and explain any denials clearly.
One of the most critical rights under the TDPSA is the ability to opt out of the sale of personal data and targeted advertising. This means consumers can say “no” to companies sharing their data with third parties for profit or using it to display behavior-based ads.
To stay compliant, businesses should implement clear and accessible opt-out mechanisms usually via cookie banners or privacy preference centers. If you want to ensure your site offers users the tools they need to opt out and manage consent, learn more about consent management with AdOpt.
These rights work together with DSARs to form a comprehensive, user-first approach to data privacy.
Handling a Data Subject Access Request (DSAR) properly is a key requirement of the** Texas Data Privacy** and Security Act (TDPSA).
Once a request is submitted, businesses are responsible for verifying the identity of the requester to avoid unauthorized data disclosure. This step is especially important when dealing with sensitive personal data.
Verification methods can vary, but common options include two-step authentication or confirming details the company already has.
If a request comes through a web form or email, businesses should be sure those channels are secure and trustworthy.
After verifying identity, the business must respond to the DSAR within 45 days. An additional 45-day extension is allowed if the request is particularly complex or if there’s a high volume of requests but the consumer must be notified about the extension within the initial time frame.
The response should include all relevant data, often in a portable and machine-readable format like CSV or JSON. This ensures the consumer can understand and potentially transfer their data to another service.
If you’re unsure how to structure your DSAR response, our guide on how to build a privacy-first UX can help.
Providing a convenient submission method is also part of compliance.
The TDPSA encourages businesses to offer easy-to-access web forms or a dedicated privacy email address. Clear instructions should be included in your privacy policy, along with links to your cookie preferences or consent banner, if relevant.
Failure to fulfill a DSAR on time or correctly can lead to investigations or fines from the Texas Attorney General. To avoid enforcement actions, businesses should regularly test their DSAR process and ensure every team involved from legal to IT understands their role.
Tools like AdOpt can help simplify this process with built-in DSAR support and consent recordkeeping.
Managing DSARs efficiently goes beyond just avoiding legal penalties it’s a powerful way to build consumer trust.
By demonstrating that your business takes privacy seriously and handles requests transparently, you foster stronger relationships with customers. One of the most effective ways to streamline DSAR management is through automation.
By leveraging tools like AdOpt, you can automatically collect, organize, and respond to requests, saving your team time while ensuring compliance with the Texas Data Privacy and Security Act (TDPSA).
Another essential step is maintaining a centralized data inventory. Having a clear understanding of where all customer data resides within your organization makes it easier to respond to DSARs accurately and promptly.
It also helps you avoid unnecessary delays or mistakes that could lead to legal repercussions.
To do this, establish a data governance strategy that categorizes and tracks consumer data from collection to deletion. Integrating this process with your privacy management software ensures that all data is organized and easily accessible when needed.
Finally, training internal teams is critical for effective DSAR management. All employees, especially those in customer service, IT, and legal, should be familiar with the procedures for handling these requests.
Regular workshops and ongoing education will ensure that your team is well-prepared to respond quickly and accurately to DSARs, ensuring continuous TDPSA compliance.
The smoother your DSAR process is, the more confident your customers will be in the security of their personal data.
Is there an ideal and _foolproof_ Privacy Policy? This is one of the most difficult questions to answer nowadays. Especially considering all the jurisprudence already established in Europe with the GDPR, the extensive history of cases, and the numerous tips we see in the market. Not to mention the judicial decisions that are already emerging in Brazil with the LGPD.
Ignoring Terms of Use and their significance within a website, particularly now with LGPD, is a common mistake that both consumers and website owners frequently commit.
Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Iowa ICDPA explained: the longest response deadline of all US state privacy laws (90 days), 90-day cure period, opt-out for sensitive data, limited deletion scope, no right to correct, and how it compares to UCPA, VCDPA, and OCPA.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Discover what the New Hampshire Privacy Act (NHDPA) means for your business. Learn about compliance steps, consumer rights, penalties, and how to simplify it all with AdOpt, a Google-certified CMP.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
AdOpt CMP: Google-certified consent platform with prior blocking, granular choices, encrypted logs, and GTM/Consent Mode
Learn what your TIPA Privacy Policy must include to comply with the Tennessee Information Protection Act from consumer rights and targeted advertising disclosures to the NIST affirmative defense, appeal mechanisms, and how to keep your notice aligned with your operational program.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
What the Virginia VCDPA requires from your Privacy Policy: the 5 mandatory content categories, sensitive data obligations, targeted advertising disclosure, and the appeal process explained.
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
How to handle DSARs under the Colorado CPA: 5 consumer rights, portability limited to twice per year, Universal Opt-Out Mechanism, 24-month record retention, and District Attorney enforcement.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
How to handle DSARs under the Connecticut CTDPA: 5 consumer rights, opt-outs without mandatory authentication, 60-day appeal deadline, 15-day consent revocation, and AG-only enforcement.
What the Oregon OCPA requires from your Privacy Policy: actively monitored contact channel, detailed third-party descriptions, derived data in scope, GPC from January 2026, and the elimination of the cure period.
Oregon OCPA DSAR guide: the L.O.C.K.E.D. rights, opt-out without authentication, derived data in deletion scope, 15-day revocation deadline, GPC from January 2026, and the elimination of the cure period.
What the Utah UCPA requires from your Privacy Policy: five mandatory elements, opt-out model for sensitive data, no retention periods required, no active contact channel mandate, and the guaranteed 30-day cure period.
What the Iowa ICDPA requires from your Privacy Policy: five mandatory elements, 90-day response deadline, 60-day appeal process, opt-out for sensitive data, no retention periods required, and the 90-day cure period.
14 May 2025
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications