Bill
Bill > SB2610
TX SB2610
TX SB2610Relating to a limitation on civil liability of business entities in connection with a breach of system security.
summary
Introduced
03/13/2025
03/13/2025
In Committee
05/16/2025
05/16/2025
Crossed Over
04/30/2025
04/30/2025
Passed
06/20/2025
06/20/2025
Dead
Signed/Enacted/Adopted
06/20/2025
06/20/2025
Introduced Session
89th Legislature Regular Session
Bill Summary
AN ACT relating to a limitation on civil liability of business entities in connection with a breach of system security.
AI Summary
This bill establishes a cybersecurity safe harbor for small businesses in Texas with fewer than 250 employees that own or license computerized data containing sensitive personal information. The bill provides that if a business implements and maintains a comprehensive cybersecurity program that meets specific requirements, it cannot be liable for exemplary (punitive) damages in the event of a system security breach. The cybersecurity program must include administrative, technical, and physical safeguards that protect personal identifying information, conform to recognized industry cybersecurity frameworks (such as NIST, ISO, or Payment Card Industry standards), and be scaled according to the business's size. For businesses with fewer than 20 employees, the requirements are simplified and focus on password policies and employee training, while larger businesses must meet more comprehensive standards. Importantly, the bill explicitly states that it does not create a private cause of action or change existing legal duties. The provisions will apply to causes of action that accrue on or after September 1, 2025, providing small businesses with a clear incentive to develop robust cybersecurity protocols to limit potential legal liability.
Committee Categories
Business and Industry, Government Affairs
Sponsors (3)
Last Action
Effective on 9/1/25 (on 06/20/2025)
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
Loading...