SESSION WATCH
Died SENATE · SESSION 2026

No. CS/SB 692

Cybersecurity Standards and Liability
Send via email
SPONSOR
Governmental Oversight and Accountability; Leek
FILED BY
Thomas J. Leek — District 7, Republican [search donations]
EFFECTIVE
Upon becoming a law
DIED IN
Appropriations

Filed under Legal.

PROVIDED SUMMARY

Cybersecurity Standards and Liability; Prohibiting local governments from imposing certain cybersecurity standards or processes on vendors; providing that a local government, a covered entity, or a third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident under certain circumstances; requiring covered entities and third-party agents to implement revised frameworks, standards, laws, or regulations within a specified timeframe in order to retain protection from liability, etc.

Full bill text →

Plain English Summary

AI-GENERATED
Shields governments and businesses from liability after data breaches.

Local governments become immune from lawsuits over a cybersecurity incident if they have adopted policies matching recognized cybersecurity standards, a disaster recovery plan, and multi-factor authentication.

Businesses and their vendors get a presumption against liability in class action lawsuits over a data breach if their cybersecurity program meets the same kind of standards, or complies with laws like HIPAA or Gramm-Leach-Bliley.

The presumption applies even to class actions already filed before this law takes effect, and a defendant's failure to seek this protection cannot be used in court as evidence that it was negligent.

Separately, local governments can no longer impose cybersecurity requirements on their information-technology vendors that go beyond the state's own standard, for contracts signed or amended after July 1, 2026.

KEY PROVISIONS
§ 1 Local governments immune from cybersecurity incident lawsuits majors. 768.401(2)

AIA local government cannot be held liable for a cybersecurity incident if it has adopted policies matching recognized cybersecurity standards, a disaster recovery plan, and multi-factor authentication, no matter what caused the incident.

“A local government is not liable in connection with a cybersecurity incident if the local government has implemented” bill text, line 89 →
§ 2 Presumption against liability for businesses in data-breach class actions majors. 768.401(3)

AIA covered entity or third-party agent that maintains personal information gets a presumption against liability in a class action over a cybersecurity incident if its cybersecurity program meets specified standards or complies with sector-specific federal laws like HIPAA.

“has a presumption against liability in a class action resulting from a cybersecurity incident” bill text, line 96 →
§ 3 Protection reaches class actions already pending in court majors. 768.401(9)

AIThe liability shield and presumption against liability apply to any class action lawsuit over a cybersecurity incident that was already filed before this law takes effect, not just to future incidents.

“This section applies to any putative class action filed before, on, or after the effective date of this act.” bill text, line 153 →
§ 4 Local governments barred from imposing stricter cybersecurity rules on vendors majors. 282.3185(4)(a)

AIA local government cannot require an information-technology vendor to meet cybersecurity standards tougher than the state's own framework, except to satisfy state or federal law or industry-specific rules, and only for contracts made or amended on or after July 1, 2026.

“A local government may not impose cybersecurity standards or processes on a vendor which exceed the standards” bill text, line 41 →
§ 5 Failure to seek the shield cannot be used as proof of negligence moderates. 768.401(7)

AIIf a defendant did not implement a qualifying cybersecurity program and is sued anyway, the fact that it could have obtained the liability shield is not admissible as evidence of negligence and cannot be used under any other liability theory.

“is not admissible as evidence of negligence, does not constitute negligence per se” bill text, line 20 →
§ 6 Defendant bears the burden of proving compliance moderates. 768.401(8)

AIWhen a local government, covered entity, or third-party agent invokes the liability shield or presumption, it, not the plaintiff, carries the burden of proving it substantially complied with the cybersecurity standards.

“the defendant has the burden of proof to establish substantial compliance with this section” bill text, line 151 →
§ 7 Annual update required to keep the liability protection moderates. 768.401(5)

AIA covered entity or third-party agent must update its cybersecurity program to match new versions of the relevant frameworks or laws within one year of their publication date, or it loses the liability protection.

“must update its cybersecurity program to incorporate any revisions of relevant frameworks or standards” bill text, line 132 →
§ 8 No new private right to sue created technicals. 768.401(6)

AIThis section itself creates no new right to sue. It only supplies a defense or a presumption that can be raised in a case brought under some other law.

“This section does not establish a private cause of action.” bill text, line 138 →
TIMELINE
3/13/2026
Died in Appropriations
2/11/2026
Now in Appropriations
2/10/2026
Favorable by Judiciary; YEAS 9 NAYS 2
2/5/2026
On Committee agenda-- Judiciary, 02/10/26, 12:00 pm, 110 Senate Building
1/29/2026
CS by Governmental Oversight and Accountability read 1st time
1/28/2026
Now in Judiciary
1/27/2026
Pending reference review under Rule 4.7(2) - (Committee Substitute)
1/26/2026
CS by Governmental Oversight and Accountability; YEAS 5 NAYS 4
1/21/2026
On Committee agenda-- Governmental Oversight and Accountability,...
1/13/2026
Introduced
12/16/2025
Referred to Governmental Oversight and Accountability; Judiciary;...
12/2/2025
Filed
6 EARLIER →
STATUTES IT CHANGES
s. 282.3185
+108 / −0
s. 768.401
+721 / −0
STAFF ANALYSES