Tennessee 2025-2026 Regular Session

Tennessee House Bill HB1033

Introduced
2/5/25  

Caption

AN ACT to amend Tennessee Code Annotated, Title 20; Title 29 and Title 47, Chapter 18, relative to data security.

Summary

HB1033 creates a new Tennessee data security law that defines covered entities broadly to include businesses that handle personal information, personal health information, or restricted information. It defines what counts as a data breach, what information is protected, and what qualifies as encryption and other sensitive data categories. The bill is aimed at encouraging stronger cybersecurity practices by tying legal protections to the adoption and maintenance of a written cybersecurity program. Under the bill, a covered entity that wants to claim an affirmative defense in a tort action must maintain a cybersecurity program with administrative, technical, operational, and physical safeguards, annual risk assessments, employee training, and a designated security officer. The program must reasonably conform to an industry-recognized cybersecurity framework, such as NIST standards, HIPAA security rules, GLBA, FISMA, HITECH, PCI standards, or another applicable state or federal regulation. If a business meets these requirements, it may use compliance as a defense to claims alleging that inadequate security caused a breach of protected data. The bill also requires timely mitigation and notification if the entity had actual notice of a threat, and it does not create a private right of action. The bill’s impact on state law is to add a new part to Tennessee’s consumer protection chapter in Title 47 and to affect how data-breach-related tort claims are litigated in Tennessee courts. It does not impose a new standalone damages remedy; instead, it creates a compliance-based affirmative defense for businesses that follow recognized cybersecurity frameworks. The measure is set to take effect July 1, 2025. Because there are no committee transcripts or recorded votes provided, the available context does not show direct debate or formal opposition. Based on the bill text alone, the overall policy direction appears favorable toward cybersecurity compliance and business certainty, while also protecting consumers by encouraging stronger safeguards for sensitive data. The main tension inherent in the bill is between reducing liability exposure for businesses that adopt recognized security practices and preserving remedies for individuals harmed by data breaches.

Impact

HB1033 would add a new data-security framework to Tennessee law by creating statutory definitions for covered entities, personal information, personal health information, restricted information, and data breaches, and by establishing a compliance-based affirmative defense in tort actions. It would affect businesses that store, process, or transmit sensitive data and would influence how courts evaluate negligence or related claims arising from a breach. The bill also expressly states that it does not create a private right of action or class action.

Sentiment

No committee discussion or vote history was provided, so there is no recorded legislative sentiment to summarize. From the bill text, the measure appears to be framed as a pro-cybersecurity, pro-compliance bill that is likely intended to be acceptable to both business and consumer protection interests. Its structure suggests support for standardized security practices rather than punitive liability alone.

Contention

The principal point of contention is likely the affirmative defense for covered entities: supporters may view it as a way to reward businesses that follow recognized cybersecurity standards, while critics may argue it could make it harder for breach victims to recover in court. Another possible issue is the breadth of the covered-entity definition and the reliance on external frameworks such as NIST, HIPAA, GLBA, and PCI standards, which may raise concerns about compliance costs and the complexity of proving conformity. The bill’s explicit statement that it creates no private right of action may also be seen as limiting remedies for affected individuals.

Companion Bills

TN SB1421

Crossfiled AN ACT to amend Tennessee Code Annotated, Title 20; Title 29 and Title 47, Chapter 18, relative to data security.

Previously Filed As

TN SB1421

AN ACT to amend Tennessee Code Annotated, Title 20; Title 29 and Title 47, Chapter 18, relative to data security.

TN HB1242

AN ACT to amend Tennessee Code Annotated, Title 47, Chapter 18 and Title 56, relative to 340B entities.

TN SB1414

AN ACT to amend Tennessee Code Annotated, Title 47, Chapter 18 and Title 56, relative to 340B entities.

TN SB0230

AN ACT to amend Tennessee Code Annotated, Title 9, Chapter 8; Title 16; Title 18; Title 20; Title 21; Title 27; Title 28; Title 29; Title 45 and Title 47, relative to credit data.

TN HB0223

AN ACT to amend Tennessee Code Annotated, Title 9, Chapter 8; Title 16; Title 18; Title 20; Title 21; Title 27; Title 28; Title 29; Title 45 and Title 47, relative to credit data.

TN SB0402

AN ACT to amend Tennessee Code Annotated, Title 9, Chapter 8; Title 16; Title 18; Title 20; Title 21; Title 27; Title 28; Title 29; Title 45; Title 47; Title 63 and Title 68, relative to credit data.

TN HB0539

AN ACT to amend Tennessee Code Annotated, Title 9, Chapter 8; Title 16; Title 18; Title 20; Title 21; Title 27; Title 28; Title 29; Title 45; Title 47; Title 63 and Title 68, relative to credit data.

TN HB0053

AN ACT to amend Tennessee Code Annotated, Title 47, Chapter 18 and Title 58, Chapter 3, relative to veterans.

TN SB0183

AN ACT to amend Tennessee Code Annotated, Title 47, Chapter 18 and Title 58, Chapter 3, relative to veterans.

TN HB1885

AN ACT to amend Tennessee Code Annotated, Title 4; Title 4, Chapter 49; Title 8, Chapter 6, Part 4; Title 40, Chapter 2 and Title 47, relative to illegal activity.

Similar Bills

No similar bills found.