Privacy Law Library

Cybersecurity Program Safe Harbor (S.B. 2610)

Texas Cybersecurity Safe Harbor

Data security · Breach notification

Gives small and mid-sized Texas businesses a defense against exemplary (punitive) damages in data breach lawsuits if, at the time of the breach, they maintained a cybersecurity program scaled to their size and conforming to a recognized framework such as NIST, CIS Controls, ISO 27000, SOC 2, or applicable HIPAA, GLBA, or PCI DSS requirements.

Where
Texas
Citation
Tex. Bus. & Com. Code ch. 542 (542.001-542.005)
Status
In force
In force since
2025-09-01
Enforced by
None (liability defense only)
People can sue
No
Penalties
No penalties; the chapter bars exemplary damages in breach suits against qualifying small businesses (542.003).
Applies to
  • Texas business entities with fewer than 250 employees that own or license computerized data including sensitive personal information (542.002)

Security duties

  • To qualify, maintain administrative, technical, and physical safeguards designed to protect personal and sensitive personal information and conforming to an industry-recognized framework.Tex. Bus. & Com. Code 542.004(a)-(b) · Only if: Voluntary: condition for the exemplary-damages safe harbor
  • Scale: under 20 employees may use simplified measures (password policies, training); 20-99 employees need CIS Controls Implementation Group 1-level measures; 100-249 must conform to a listed framework.Tex. Bus. & Com. Code 542.004(a)(4) · Only if: Voluntary: condition for the safe harbor

Other duties

  • Update the program to revised framework versions by the later of the standard's implementation date or one year after publication.Tex. Bus. & Com. Code 542.004(c) · Only if: Voluntary: condition for the safe harbor

Sources

Checked against these sources on 2026-09-24 by research agent (Claude), primary sources.

Research reference, not legal advice.