Cybersecurity Event Class Action Liability Limit
Nebraska Cybersecurity Event Liability Law
Data security · Breach notification
Enacted by LB241 (2025), this law raises the liability standard for data breach class actions against private entities. A cybersecurity event is unauthorized access to, or disruption or misuse of, an information system or nonpublic information such as SSNs, driver's license numbers, financial account numbers, access codes, or biometric records.
- Where
- Nebraska
- Citation
- Neb. Rev. Stat. 87-1201
- Status
- In force
- In force since
- 2025-09-03
- Enforced by
- Courts (limits private litigation)
- People can sue
- Limited
- Penalties
- No penalties; the law bars class-action liability for a cybersecurity event unless the event was caused by the private entity's willful, wanton, or gross negligence (87-1201(2)).
- Applies to
- Private entities (corporations, religious or charitable organizations, associations, partnerships, LLCs, and other for-profit or nonprofit private businesses) facing class actions arising from a cybersecurity event (87-1201(1)(d))
Other duties
- A private entity is not liable in a class action resulting from a cybersecurity event unless the event was caused by its willful, wanton, or gross negligence.Neb. Rev. Stat. 87-1201(2)
Sources
- Official text
- Neb. Rev. Stat. 87-1201 (Nebraska Legislature)
- Revisor cross-reference table of effective dates, 2025 session (LB241: September 3, 2025)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.