No. CS/SB 692
Filed under Legal.
Cybersecurity Standards and Liability; Prohibiting local governments from imposing certain cybersecurity standards or processes on vendors; providing that a local government, a covered entity, or a third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident under certain circumstances; requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability, etc.
Plain English Summary
AI-GENERATEDLocal governments become immune from lawsuits over a cybersecurity incident if they have adopted policies matching recognized cybersecurity standards, a disaster recovery plan, and multi-factor authentication.
Businesses and their vendors get a presumption against liability in class action lawsuits over a data breach if their cybersecurity program meets the same kind of standards, or complies with laws like HIPAA or Gramm-Leach-Bliley.
The presumption applies even to class actions already filed before this law takes effect, and a defendant's failure to seek this protection cannot be used in court as evidence that it was negligent.
Separately, local governments can no longer impose cybersecurity requirements on their information-technology vendors that go beyond the state's own standard, for contracts signed or amended after July 1, 2026.
AIA local government cannot be held liable for a cybersecurity incident if it has adopted policies matching recognized cybersecurity standards, a disaster recovery plan, and multi-factor authentication, no matter what caused the incident.
AIA covered entity or third-party agent that maintains personal information gets a presumption against liability in a class action over a cybersecurity incident if its cybersecurity program meets specified standards or complies with sector-specific federal laws like HIPAA.
AIThe liability shield and presumption against liability apply to any class action lawsuit over a cybersecurity incident that was already filed before this law takes effect, not just to future incidents.
AIA local government cannot require an information-technology vendor to meet cybersecurity standards tougher than the state's own framework, except to satisfy state or federal law or industry-specific rules, and only for contracts made or amended on or after July 1, 2026.
AIIf a defendant did not implement a qualifying cybersecurity program and is sued anyway, the fact that it could have obtained the liability shield is not admissible as evidence of negligence and cannot be used under any other liability theory.
AIWhen a local government, covered entity, or third-party agent invokes the liability shield or presumption, it, not the plaintiff, carries the burden of proving it substantially complied with the cybersecurity standards.
AIA covered entity or third-party agent must update its cybersecurity program to match new versions of the relevant frameworks or laws within one year of their publication date, or it loses the liability protection.
AIThis section itself creates no new right to sue. It only supplies a defense or a presumption that can be raised in a case brought under some other law.