Texas 2025 - 89th Regular

Texas Senate Bill SB 2610

Filed
3/13/25  
Out of Senate Committee
4/28/25  
Voted on by Senate
4/30/25  
Out of House Committee
5/21/25  
Voted on by House
5/28/25  
Governor Action
6/20/25  

Caption

Relating to a limitation on civil liability of business entities in connection with a breach of system security.

Summary

SB 2610 creates a new Chapter 542 in the Texas Business & Commerce Code establishing a cybersecurity-program safe harbor for certain small and mid-sized business entities. The bill applies only to Texas businesses with fewer than 250 employees that own or license computerized data containing sensitive personal information. If such a business is sued over a breach of system security, the bill bars recovery of exemplary damages if the business can show it had implemented and maintained a qualifying cybersecurity program at the time of the breach. To qualify, the cybersecurity program must include administrative, technical, and physical safeguards and be aligned with an industry-recognized framework. The bill scales the requirements by company size: businesses with fewer than 20 employees may use simplified measures such as password policies and employee cybersecurity training; businesses with 20 to 99 employees must meet moderate controls, including the Center for Internet Security Controls Implementation Group 1; and businesses with 100 to 249 employees must comply with a recognized framework such as NIST, ISO/IEC 27000-series, HITRUST, FedRAMP, or similar standards. The bill also allows compliance through existing federal regimes like HIPAA, GLBA, FISMA, HITECH, or PCI DSS when applicable.

Impact

The bill does not create a new private cause of action or alter existing common-law or statutory duties, but it does change the remedies available in certain data-breach lawsuits by limiting exemplary damages for covered businesses that meet the cybersecurity-program requirements. It effectively encourages smaller Texas businesses handling sensitive personal information to adopt formal cybersecurity controls and align with recognized security standards in order to reduce litigation exposure after a breach. The new law applies only to causes of action accruing on or after September 1, 2025.

Sentiment

The bill appears to have broad legislative support overall, passing the Senate unanimously and the House by a substantial margin. The vote totals suggest general agreement with the bill’s goal of encouraging cybersecurity preparedness while offering liability protection to businesses that take preventive measures. The absence of committee transcript material limits insight into detailed debate, but the strong final votes indicate a favorable overall sentiment.

Contention

The main point of contention is the balance between protecting consumers harmed by data breaches and shielding businesses from punitive exposure. Supporters likely view the bill as a practical incentive for small and medium-sized businesses to adopt cybersecurity frameworks without imposing the full burden of large-enterprise compliance. Critics may be concerned that limiting exemplary damages could reduce deterrence or compensation in breach cases, especially for individuals whose sensitive personal information is exposed. The bill addresses this by limiting the safe harbor to businesses that can demonstrate compliance with specified cybersecurity standards, rather than granting blanket immunity.

Companion Bills

No companion bills found.

Previously Filed As

TX HB644

Relating to the civil liability of certain businesses in connection with allowing concealed handguns on the business premises.

TX SB2620

Relating to the civil liability of certain businesses in connection with allowing concealed handguns on the business premises.

TX SB82

Relating to civil liability of a business in connection with prohibiting concealed handguns on the business premises.

TX H93

Relative to protecting sensitive information from security breaches

TX SB2471

Cyber breach; limit liability for certain entities.

TX HB1007

Relating to the security of election systems.

TX SB78

Relating to the security of election systems.

TX HB1718

Modifies provisions relating to limitations on awards for certain liability claims against public entities

TX HB381

An Act To Amend Title 6 Of The Delaware Code Relating To Computer Security Breaches.

TX HB1098

Provides with respect to a limitation of liability for aerospace entities

Similar Bills

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

CA AB979

California Cybersecurity Integration Center: artificial intelligence.

NJ A1550

Requires adoption and implementation of cybersecurity standards by casinos and sportsbooks; establishes safe gaming certification program.

NM SB254

Cybersecurity Act & Office Changes

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A1549

Establishes Gaming Cybersecurity Intelligence and Response Council.

TX HB150

Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.