Privacy Policy for a Website: What Texas Actually Requires
Cal HewittPublished 11 min read
- contracts
- what goes on a site

Every other site has one, so yours probably should, and a generator will produce a plausible one in four minutes. That is where most small-business privacy policies come from, and it is why so many of them describe practices the site does not have: data sold to partners it has never heard of, cookies it does not set, rights it has no way to honour. A policy is a public statement about your business, and a pasted one that is untrue is worse than none. The way to a true one is short and starts somewhere other than the template. It starts with a list of what the site actually collects, then a plain reading of which rules reach a business of your shape in Texas, and only then the writing. This is general information, not legal advice, and where a question needs a lawyer the piece says so.
Key Takeaways
Inventory before policy.
Every form field, tag, embed and vendor, mapped to what it collects, why, where it goes and how long it stays.
The Texas act's test turns on the size of the business.
It reaches a person doing business in Texas, processing personal data, who is not a small business as the SBA defines it.
The small-business exemption has one exception
no selling sensitive personal data without prior consent, exempt or not.
Platform and other-state rules reach sites the act does not.
Google Analytics requires disclosure from every user. California's rule applies to sites collecting Californians' data. COPPA applies where children are involved.
A template is a worksheet.
It becomes a policy only when every line has been checked against what the site does.
The Inventory Comes Before the Policy
A privacy policy describes data flows, so the first job is to know what they are, and a small site usually has more than the owner expects. Walk the site as a visitor and note every place information is captured or sent: the contact form and each of its fields, a booking or appointment tool, a newsletter sign-up, a chat widget, a review widget, file uploads, account creation, a checkout. Then look behind the page: the analytics tag, any advertising or social pixel, an embedded map or video, the CAPTCHA, the hosting logs, the CRM the form feeds, the payment processor, the email platform, any AI feature.
For each one, record five things: what category of data it touches, why it is collected, where it is stored, who receives it, and how long it is kept before deletion. That table is the policy in draft. Every sentence you eventually publish should be traceable to a row in it, and a generator's sentence with no row behind it is a sentence to delete.

The Texas Test Turns on the Size of the Business
The Texas Data Privacy and Security Act, Chapter 541 of the Business and Commerce Code, took effect on 1 July 2024. Its applicability test has three parts: a person who conducts business in Texas or produces a product or service consumed by Texas residents, who processes or engages in the sale of personal data, and who is not a small business as defined by the US Small Business Administration. There is no consumer-count or revenue threshold in that list. A business either fits the SBA's small-business definition for its industry or it does not, and the Attorney General's overview says plainly that small businesses are generally exempt from the act's duties.
Whether your business is a small business under the SBA's size standards for your industry is a factual question with a checkable answer, and it is the question a lawyer will ask first. The act's duties, the notice contents, the request clocks and the penalties in the sections below all hang on it. So do the Attorney General's enforcement powers, which are exclusive: after written notice and a 30-day cure period, a civil penalty of up to $7,500 per violation, an injunction, and the Attorney General's fees. There is no private right of action under the act, which means nobody sues you under it except the state.
The Small-Business Exemption Has One Exception
The exemption that covers most local firms carries one duty that survives it. Under the act, a small business may not sell a consumer's sensitive personal data without the consumer's prior consent, exempt or not. Sensitive data means the categories the statute names, including racial or ethnic origin, religious beliefs, health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify a person, precise geolocation, and personal data collected from a known child.
For a brochure site with a contact form, the practical question is whether anything on the site collects those categories and whether any vendor arrangement amounts to a sale. A medical practice's intake form, a form that asks for a location pin, or an advertising pixel that passes health-related page visits to a platform each deserves a closer look than a plumber's "how can we help" box. If the answer to either question might be yes, the exemption stops being a reason to relax and the conversation moves to a lawyer.
When the Act Applies, the Notice Has a Fixed Content List
For a business the act does reach, the privacy notice is a document with required contents rather than a style choice. Sections 541.102 and 541.103 require a reasonably accessible and clear notice that states the categories of personal data processed, the purpose of the processing, how a consumer may exercise their rights and appeal a decision, the categories of personal data shared with third parties, and the categories of those third parties. Where the business sells personal data or uses it for targeted advertising, it must say so clearly and conspicuously and give a way to opt out.
The rights and their clocks are equally fixed. A controller must respond to an authenticated consumer request without undue delay and within 45 days, extendable once by a further 45 days where reasonably necessary and the consumer is told within the first period. An appeal must be decided in writing within 60 days. Section 541.054 makes any contract term that waives or limits those rights void. And a controller using a processor, which for a small site means the host, the form tool, the CRM and the email platform, needs a contract carrying the elements in Section 541.104: instructions, purpose, data type, duration, both parties' obligations, confidentiality for anyone handling the data, deletion or return at the end, compliance information on request, cooperation with assessments, and written obligations flowing down to subcontractors.
The clocks the Texas act sets for a business it reaches
- 1
**Consumer request received**: respond without undue delay and within 45 days
- 2
**Extension where reasonably necessary**: one further 45 days, with the consumer told inside the first period
- 3
**Appeal of a decision**: written response within 60 days
- 4
**Attorney General notice of a violation**: 30 days to cure before enforcement
- 5
**After cure fails**: civil penalty of up to $7,500 per violation, injunction, fees
A policy that promises access or deletion to a business that cannot find the records is a policy that fails on the first request. The inventory is what makes the promise keepable.
Google Analytics, California and Children Reach Sites the Act Does Not
Three rules apply whether or not Texas's act does, and a site can be caught by all three while being fully exempt from the statute.
Google's Analytics disclosure policy requires anyone using Google Analytics to disclose that they use it and how it collects and processes data. That is a condition of the service, and a site running the tag with no policy is out of step with Google's own terms regardless of Texas. Google's safeguarding page describes what the tag actually handles, first-party cookies, device and browser data, IP addresses and on-site activity, and prohibits sending personally identifiable information into Analytics at all, which is a configuration point for a form-heavy site.
California's Online Privacy Protection Act, as the state's Attorney General describes it, requires a commercial website collecting personally identifiable information from California consumers to post a conspicuous policy stating the categories collected, the kinds of third parties it may be shared with, and an effective date. A Texas business with a national audience and a contact form is a Texas business collecting Californians' data.
The FTC's COPPA compliance plan applies to a site directed at children under 13, or a general site with actual knowledge that it is collecting from one, and it requires a compliant policy and verifiable parental consent before that collection. A tutoring business, a youth sports club or a children's clothing shop is closer to that line than it may feel.
A cookie banner sits apart from all of this. It is an interface, and the Texas provisions describe notice, rights and opt-out rather than a banner. Where a banner is used, it should reflect what the tags actually do, which the inventory already told you.
The Audit Runs From Inventory to a Working Link
The workflow is an operational sequence rather than a legal opinion, and it ends with a page that matches the site.
- Inventory every collection point, front and back of the page.
- Map each one to category, purpose, storage, recipient and retention.
- Classify the business: Texas applicability and the SBA question, whether Californians are collected from, whether children are involved, whether HIPAA or GLBA applies to the sector.
- Compare what the site does with what the applicable rules and platform terms require, and remove collection that has no purpose.
- Draft from the inventory in plain words: an effective date, the real categories and purposes, a contact route that reaches a person, and nothing the business cannot perform.
- Configure the site to match: a permanent footer link, a tested request route, tags adjusted, unnecessary fields removed.
- Record the review, and recheck whenever a form, plugin, tag, vendor, campaign or law changes.
The only clocks in the subject are the request and appeal periods above, which start when a request arrives and only for a business the act reaches. For most local firms the audit is an afternoon of inventory and a morning of writing, followed by a habit.
The Worksheet Is Yours, the Applicability Question Is a Lawyer's
An owner can safely do the whole of the inventory: list every form and field, export the installed plugins and tags, check each dashboard for connected services, name the inbox that will receive privacy requests, delete a field that has no purpose, confirm the footer link works, and date the changes. A template or a generator is a fine worksheet at that stage, on one condition: every line in it is checked against what the site actually does before it is published, and every line that does not match is cut.
The published product prices, read in September 2026, are a scale rather than a recommendation. Termly's pricing page lists a free tier with one basic policy, a Starter plan at $10 per website per month billed annually or $14 monthly, and a Pro+ plan at $15 annually or $20 monthly, with policy edits, cookie scans and updates spread across the tiers. Rocket Lawyer's pricing page lists memberships at $149, $249 and $349 a year and quotes no figure for a Texas attorney reviewing a website policy. A Texas lawyer's review or drafting is priced per engagement, and it rises with a checkout, account data, advertising pixels and remarketing, children's, health or financial data, several processors, and audiences outside the state.
The stopping line is clear. Whether the act applies to your business, whether anything you collect is sensitive, whether a child-directed question arises, whether you engage in targeted advertising or a sale, a breach, an out-of-state or international audience, or a vendor contract that makes you responsible for a processor: each is a question for counsel. So are the assessments the act requires of a covered business for targeted advertising, sale, risky profiling and sensitive data, which are documents rather than checkboxes. And separately from the policy, the Attorney General's breach-reporting page requires a business suffering a breach affecting 250 or more Texans to report it to the office within 30 days of discovery and to notify the people affected.

A Policy Stays True Through a Review Habit
The policy drifts the moment the site changes, and sites change constantly: a new form field for a campaign, a pixel added for an ad, a booking tool, a chat widget, an AI feature, a new email vendor. Prevention is a change-control habit with one data map and one policy owner. Before any of those goes live, the owner asks what it collects and where it sends it, updates the map, and checks whether the public policy still describes the site. Periodically, a scan of the tags that fire and the fields the forms ask for, compared line by line against the policy and the vendor list.
It is working when the policy, the tag scan, the form fields, the platform settings and the vendor list all agree, the footer link and the request route both work, no unapproved third-party tag fires, and, for a business the act reaches, a request could be answered inside 45 days from records you can actually find.
Locally, the Greater Arlington Chamber's business resources list the Tarrant County Small Business Development Center, SCORE Fort Worth and a free legal-services resource through SMU, and Tarrant SBDC says its advising is free to eligible clients. Those are places to take the inventory and the applicability question before paying for an hour of anyone's time, and none of them replaces a Texas privacy lawyer when the answer turns out to be yes.
Which of these makes the policy untrue?
1. You run a two-person plumbing business with a contact form, Google Analytics and an embedded map. Which sentence should come out of the generated policy?
Pick an answer to begin.
Frequently Asked Questions About privacy policy for website
Do I need a privacy policy for my website in Texas?
If the Texas act reaches your business, yes, with fixed contents. If it does not, Google Analytics' terms, California's rule for sites collecting Californians' data, and COPPA where children are involved can each require one anyway. Start with what the site collects and the SBA size question.
Does the Texas Data Privacy and Security Act apply to a small business?
The act generally exempts a business that is small under the SBA's definition for its industry, with one exception: no selling sensitive personal data without prior consent. Whether you fit the definition is a factual question worth answering precisely.
Can I use a privacy policy template?
As a worksheet. Every line has to be checked against the inventory before publication, and every line that describes something the site does not do has to go. A template published unread is a public statement you have not verified.
What should a privacy policy for a small business website say?
What the site collects, by category, why, who receives it, how long it is kept, how to contact a real person about it, and an effective date. Where the Texas act applies, the statute's full content list, the rights, the appeal route and any opt-out for targeted advertising or sale.
Is a cookie banner enough?
A banner is an interface. The Texas provisions describe notice, rights and opt-out, and Google Analytics requires a disclosure of its own. A banner that does not match what the tags do adds a second untrue statement rather than fixing the first.
We do not sell data. Do we still need one?
Probably. Analytics alone triggers Google's disclosure requirement, a national audience brings California's rule into view, and a contact form collects personal information whether or not anything is sold.
The words in the statute and the settings
Tap a term to see what it means.
**Controller**: the business that decides why and how personal data is processed, and the party the Texas act's duties fall on.
Moving Forward
The generated policy was never the problem. Publishing it unread was, because a privacy policy is a promise about how the business behaves and a promise nobody checked is a promise nobody can keep. The inventory takes an afternoon, the applicability question has a checkable answer, and the writing that follows is short because it only says what is true.
Keep the map current, review it before anything new goes live, and the policy stays a description of the site rather than a description of somebody else's.
If the inventory is the part that feels impossible because nobody knows what tags the site is running, Arlington Website Designer builds that map for businesses in Arlington, TX as part of looking after a site, tag by tag and form by form. Send the site address and the list of tools you know about through the contact page, and you will get back the collection points the site actually has, including the ones nobody remembers adding.