Relating to a limitation on civil liability of business entities in connection with a breach of system security.
Summary
SB 2610 creates a new Chapter 542 in the Texas Business & Commerce Code establishing a cybersecurity-program safe harbor for certain small and mid-sized business entities. The bill applies only to Texas businesses with fewer than 250 employees that own or license computerized data containing sensitive personal information. If such a business is sued over a breach of system security, the bill bars recovery of exemplary damages if the business can show it had implemented and maintained a qualifying cybersecurity program at the time of the breach.
To qualify, the cybersecurity program must include administrative, technical, and physical safeguards and be aligned with an industry-recognized framework. The bill scales the requirements by company size: businesses with fewer than 20 employees may use simplified measures such as password policies and employee cybersecurity training; businesses with 20 to 99 employees must meet moderate controls, including the Center for Internet Security Controls Implementation Group 1; and businesses with 100 to 249 employees must comply with a recognized framework such as NIST, ISO/IEC 27000-series, HITRUST, FedRAMP, or similar standards. The bill also allows compliance through existing federal regimes like HIPAA, GLBA, FISMA, HITECH, or PCI DSS when applicable.
Impact
The bill does not create a new private cause of action or alter existing common-law or statutory duties, but it does change the remedies available in certain data-breach lawsuits by limiting exemplary damages for covered businesses that meet the cybersecurity-program requirements. It effectively encourages smaller Texas businesses handling sensitive personal information to adopt formal cybersecurity controls and align with recognized security standards in order to reduce litigation exposure after a breach. The new law applies only to causes of action accruing on or after September 1, 2025.
Sentiment
The bill appears to have broad legislative support overall, passing the Senate unanimously and the House by a substantial margin. The vote totals suggest general agreement with the bill’s goal of encouraging cybersecurity preparedness while offering liability protection to businesses that take preventive measures. The absence of committee transcript material limits insight into detailed debate, but the strong final votes indicate a favorable overall sentiment.
Contention
The main point of contention is the balance between protecting consumers harmed by data breaches and shielding businesses from punitive exposure. Supporters likely view the bill as a practical incentive for small and medium-sized businesses to adopt cybersecurity frameworks without imposing the full burden of large-enterprise compliance. Critics may be concerned that limiting exemplary damages could reduce deterrence or compensation in breach cases, especially for individuals whose sensitive personal information is exposed. The bill addresses this by limiting the safe harbor to businesses that can demonstrate compliance with specified cybersecurity standards, rather than granting blanket immunity.
Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.
Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.