SESSION WATCH
Died HOUSE · SESSION 2026

No. CS/HB 635

Cybersecurity Standards and Liability
Send via email
SPONSOR
Information Technology Budget & Policy Subcommittee; Giallombardo; Blanco
FILED BY
Mike Giallombardo — District 79, Republican [search donations]
Omar Blanco — District 115, Republican [search donations]
EFFECTIVE
upon becoming a law
DIED IN
State Affairs Committee

Filed under Legal.

PROVIDED SUMMARY

Cybersecurity Standards and Liability; Prohibits local governments from imposing certain cybersecurity standards or processes on vendors; defines "vendor"; prohibits local governments from adopting or enforcing certain cybersecurity standards or processes; provides that local government, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to implement revised frameworks, standards, laws, or regulations.

Full bill text →

Plain English Summary

AI-GENERATED
Shields governments and businesses from liability after data breaches.

Local governments become immune from lawsuits over a cybersecurity incident if they have adopted policies matching recognized cybersecurity standards, a disaster recovery plan, and multi-factor authentication.

Businesses and their vendors get a presumption against liability in class action lawsuits over a data breach if their cybersecurity program meets the same kind of standards, or complies with laws like HIPAA or Gramm-Leach-Bliley.

The presumption applies even to class actions already filed before this law takes effect, and a defendant's failure to seek this protection cannot be used in court as evidence that it was negligent.

Separately, local governments can no longer impose cybersecurity requirements on their information-technology vendors that go beyond the state's own standard, for contracts signed or amended after July 1, 2026.

KEY PROVISIONS
§ 1 Local governments immune from cybersecurity incident lawsuits majors. 768.401(2)

AIA local government cannot be held liable for a cybersecurity incident if it has adopted policies matching recognized cybersecurity standards, a disaster recovery plan, and multi-factor authentication, no matter what caused the incident.

“A local government is not liable in connection with a cybersecurity incident if the local government has implemented” bill text, line 88 →
§ 2 Presumption against liability for businesses in data-breach class actions majors. 768.401(3)

AIA covered entity or third-party agent that maintains personal information gets a presumption against liability in a class action over a cybersecurity incident if its cybersecurity program meets specified standards or complies with sector-specific federal laws like HIPAA.

“has a presumption against liability in a class action resulting from a cybersecurity incident” bill text, line 95 →
§ 3 Protection reaches class actions already pending in court majors. 768.401(9)

AIThe liability shield and presumption against liability apply to any class action lawsuit over a cybersecurity incident that was already filed before this law takes effect, not just to future incidents.

“This section applies to any putative class action filed before, on, or after the effective date of this act.” bill text, line 152 →
§ 4 Local governments barred from imposing stricter cybersecurity rules on vendors majors. 282.3185(4)(a)

AIA local government cannot require an information-technology vendor to meet cybersecurity standards tougher than the state's own framework, except to satisfy state or federal law or industry-specific rules, and only for contracts made or amended on or after July 1, 2026.

“A local government may not impose cybersecurity standards or processes on a vendor that exceed the standards” bill text, line 40 →
§ 5 Failure to seek the shield cannot be used as proof of negligence moderates. 768.401(7)

AIIf a defendant did not implement a qualifying cybersecurity program and is sued anyway, the fact that it could have obtained the liability shield is not admissible as evidence of negligence and cannot be used under any other liability theory.

“is not admissible as evidence of negligence, does not constitute negligence per se” bill text, line 19 →
§ 6 Defendant bears the burden of proving compliance moderates. 768.401(8)

AIWhen a local government, covered entity, or third-party agent invokes the liability shield or presumption, it, not the plaintiff, carries the burden of proving it substantially complied with the cybersecurity standards.

“the defendant has the burden of proof to establish substantial compliance with this section” bill text, line 150 →
§ 7 Annual update required to keep the liability protection moderates. 768.401(5)

AIA covered entity or third-party agent must update its cybersecurity program to match new versions of the relevant frameworks or laws within one year of their publication date, or it loses the liability protection.

“must update its cybersecurity program to incorporate any revisions of relevant frameworks or standards” bill text, line 131 →
§ 8 No new private right to sue created technicals. 768.401(6)

AIThis section itself creates no new right to sue. It only supplies a defense or a presumption that can be raised in a case brought under some other law.

“This section does not establish a private cause of action.” bill text, line 137 →
TIMELINE
3/13/2026
Died in State Affairs Committee
2/3/2026
Now in State Affairs Committee
2/3/2026
Reported out of Civil Justice & Claims Subcommittee
2/3/2026
Favorable by Civil Justice & Claims Subcommittee
1/30/2026
Added to Civil Justice & Claims Subcommittee agenda
1/22/2026
1st Reading (Committee Substitute 1)
1/22/2026
Now in Civil Justice & Claims Subcommittee
1/22/2026
Referred to State Affairs Committee
1/22/2026
Referred to Civil Justice & Claims Subcommittee
1/21/2026
CS Filed
1/21/2026
Laid on Table under Rule 7.18(a)
1/21/2026
Reported out of Information Technology Budget & Policy Subcommittee
1/20/2026
Favorable with CS by Information Technology Budget & Policy Subcommittee
1/15/2026
Added to Information Technology Budget & Policy Subcommittee agenda
1/13/2026
1st Reading (Original Filed Version)
12/12/2025
Now in Information Technology Budget & Policy Subcommittee
12/12/2025
Referred to State Affairs Committee
12/12/2025
Referred to Civil Justice & Claims Subcommittee
12/12/2025
Referred to Information Technology Budget & Policy Subcommittee
12/3/2025
Filed
14 EARLIER →
STATUTES IT CHANGES
s. 282.3185
+109 / −0
s. 768.401
+709 / −0
STAFF ANALYSES