S 2464 New Jersey Senate · 2024-2025 Regular Session

Creates affirmative defense for certain breaches of security.

This bill creates an "affirmative defense" for businesses and government entities (called "covered entities") that experience security breaches involving personal or restricted information. To qualify for this defense, covered entities must maintain a written cybersecurity program with administrative, technical, and physical safeguards that reasonably conforms to industry standards like NIST or PCI DSS. The program's requirements must be scaled based on factors including the entity's size, the sensitivity of information, and available resources. The Director of Consumer Affairs can determine if a cybersecurity program meets the standard, and courts will consider this determination when evaluating breach claims. The bill does not create new legal claims for individuals affected by security breaches.
Bill status in committee 1 of 4 stages cleared
Introduction
Feb 2024
Committee Review
Floor Vote
Governor
Introduced Feb 5, 2024 Last action Feb 5, 2024
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
1
Key actions
0
Committee
0
Feb 5, 2024
Introduced
Introduced in the Senate, Referred to Senate Economic Growth Committee
upper
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Tony Bucco
Tony Bucco
RRepublican
NJ
25