← Texas Business Law Glossary

Texas Business Law · Glossary

Consent (Texas Data Privacy and Security Act)

A clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous agreement to process personal data. The TDPSA requires it before any sensitive data is processed, before processing outside disclosed purposes, and before a small business sells sensitive data. Accepting a general terms of use document does not count. Neither does anything obtained through a dark pattern.

Consent under the TDPSA is a high bar by design. Tex. Bus. & Com. Code § 541.001 defines it as a clear affirmative act signifying a consumer's freely given, specific, informed and unambiguous agreement to process personal data relating to the consumer. Four adjectives, each doing work. Freely given rules out coercion. Specific rules out blanket permissions. Informed rules out burying the disclosure. Unambiguous rules out inference from conduct.

What does not count

The definition excludes acceptance of a general or broad terms of use document, or a similar document that contains descriptions of personal data processing alongside unrelated information. It excludes hovering over, muting, pausing or closing a given piece of content. And it excludes agreement obtained through a dark pattern, meaning an interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making or choice.

That third exclusion is where consent programs fail. A pre-checked box is not consent. A modal where the accept button is styled prominently and the decline path sits three clicks deep invites the argument. So does a cookie banner offering only "Accept" and "Manage preferences" with no visible way to refuse. The test is not whether a user could theoretically say no. It is whether the design steered them.

Where the statute demands it

Four places matter. Under § 541.101(b)(1) a controller may not process personal data for a purpose that is neither reasonably necessary to nor compatible with the purpose disclosed to the consumer unless the consumer consents. Under § 541.101(b)(4) a controller may not process sensitive data without consent, and where the consumer is a known child must comply with the federal Children's Online Privacy Protection Act instead. Under § 541.107 a business exempt from the rest of the chapter because it is an SBA small business still may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer. And an authorized-agent opt-out signal under § 541.055(e) must be sent with the consumer's consent.

The small business point surprises people. The carve-out in § 541.002(a)(3) is not a complete pass, and § 541.107(b) makes a violator subject to the same penalty under § 541.155 that a covered controller faces.

Proving it two years later

The statute says nothing about documenting consent, which puts the burden where it always lands. Keep the interface, not just the outcome. A log entry showing that a specific consumer clicked a specific button is worth little if you cannot reproduce the screen that consumer saw, the text above the button, and the alternatives offered at that moment. Version your consent flows. Timestamp them. Store the rendered copy alongside the log.

Withdrawal deserves a plan too. Chapter 541 builds the consumer-facing exits through the opt-out rights in § 541.051(b)(5) and the request methods in § 541.055, so a consent architecture that can record a yes but cannot process a later no is only half built. Remember what the cure provision actually gives you: § 541.154 allows 30 days to fix an identified violation, and reconstructing consent evidence after the attorney general's notice arrives is not a fix.

See also
Sensitive Data (Texas Data Privacy and Security Act)·Controller (Texas Data Privacy and Security Act)·Universal Opt-Out Mechanism (Texas)·Sale of Personal Data (Texas Data Privacy and Security Act)
Last updated: August 15, 2026