Bill

Bill > SB2610


TX SB2610

TX SB2610
Relating to a limitation on civil liability of business entities in connection with a breach of system security.


summary

Introduced
03/13/2025
In Committee
05/16/2025
Crossed Over
04/30/2025
Passed
06/20/2025
Dead
Signed/Enacted/Adopted
06/20/2025

Introduced Session

89th Legislature Regular Session

Bill Summary

AN ACT relating to a limitation on civil liability of business entities in connection with a breach of system security.

AI Summary

This bill establishes a cybersecurity safe harbor for small businesses in Texas with fewer than 250 employees that own or license computerized data containing sensitive personal information. The bill provides that if a business implements and maintains a comprehensive cybersecurity program that meets specific requirements, it cannot be liable for exemplary (punitive) damages in the event of a system security breach. The cybersecurity program must include administrative, technical, and physical safeguards that protect personal identifying information, conform to recognized industry cybersecurity frameworks (such as NIST, ISO, or Payment Card Industry standards), and be scaled according to the business's size. For businesses with fewer than 20 employees, the requirements are simplified and focus on password policies and employee training, while larger businesses must meet more comprehensive standards. Importantly, the bill explicitly states that it does not create a private cause of action or change existing legal duties. The provisions will apply to causes of action that accrue on or after September 1, 2025, providing small businesses with a clear incentive to develop robust cybersecurity protocols to limit potential legal liability.

Committee Categories

Business and Industry, Government Affairs

Sponsors (3)

Last Action

Effective on 9/1/25 (on 06/20/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...