Florida 2025 1st Special Session

Florida House Bill HB1183

Caption

Cybersecurity Incident Liability:

Summary

HB 1183 creates a new section of Florida law limiting liability for certain public and private entities after a cybersecurity incident if they can show substantial compliance with recognized cybersecurity standards. The bill defines covered entities broadly to include commercial entities, and it also covers third-party agents that store, maintain, or process personal information on behalf of those entities. For counties, municipalities, and other political subdivisions, the bill provides immunity from liability in connection with a cybersecurity incident if they have policies that substantially comply with cybersecurity standards, disaster recovery planning, and multi-factor authentication. For covered entities and third-party agents, the bill creates a presumption against liability in class actions arising from a cybersecurity incident when the entity has a cybersecurity program that substantially complies with Florida’s data breach law and either follows recognized cybersecurity frameworks or complies with certain other state or federal security regimes, such as HIPAA, GLBA, FISMA, HITECH, or CJIS. The bill also allows compliance to be shown through documentation or an assessment, requires entities to update their programs within one year of revised standards or laws, and states that the measure does not create a private cause of action.

Impact

The bill would add s. 768.401, F.S., creating a liability shield and evidentiary protections for local governments, businesses, and vendors handling personal information when they have implemented qualifying cybersecurity programs. It would affect tort and class-action litigation by making compliance with specified cybersecurity frameworks relevant to immunity or a presumption against liability, while also barring plaintiffs from using the mere availability of the shield as evidence of negligence or fault. The bill applies to putative class actions filed before, on, or after the effective date, and it places the burden on defendants to prove substantial compliance.

Sentiment

The available record shows no committee transcript or recorded votes, so there is no detailed public debate captured here. Based on the bill’s structure, the measure appears designed to be favorable to counties, municipalities, businesses, and cybersecurity-compliant vendors by reducing litigation exposure after a breach. Its failure in the State Affairs Committee suggests it did not advance, but the provided materials do not show whether that was due to policy concerns, timing, or other committee objections.

Contention

The main policy tension is between encouraging cybersecurity best practices and limiting remedies for people harmed by data breaches. Supporters would likely view the bill as rewarding entities that invest in recognized security controls and disaster recovery planning, while opponents may argue that it could make it harder for consumers and class-action plaintiffs to recover damages after a breach. Another likely point of contention is the breadth of the liability shield, including its application to public entities, its use in class actions, and the rule that evidence of potential eligibility for the shield cannot be used to show negligence or fault.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.