Civil Procedure - As introduced, creates an affirmative defense that may be utilized by a covered entity that is the subject of a data breach, if the covered entity’s cybersecurity program meets certain criteria at the time the breach occurs. - Amends TCA Title 20; Title 29 and Title 47, Chapter 18.
HB 1033 (Tennessee) creates a legal defense for businesses that experience a data breach, provided they maintained a cybersecurity program meeting specific standards at the time of the breach. It applies to "covered entities" - businesses handling personal information, health data, or sensitive restricted information - requiring them to have written security protocols aligned with industry frameworks (like NIST). If compliant, these entities can use this defense against lawsuits alleging negligence in data security, excluding breaches from law enforcement requests or authorized employee transmissions. The bill does not change breach notification rules but offers legal protection for businesses meeting its cybersecurity criteria.
Bill status
in committee
1 of 4 stages cleared
Introduction
Feb 2025
Committee Review
Floor Vote
Governor
Introduced Feb 6, 2025
Last action Feb 11, 2025
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
4
Key actions
0
Committee
2
Feb 11, 2025
Committee
Assigned to s/c Civil Justice Subcommittee
lower
Feb 10, 2025
Committee
P2C, ref. to Judiciary Committee
lower
Feb 6, 2025
Introduced
Intro., P1C.
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Vincent Dixie
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about HB 1033
Scope: TN
Hi! I can help you understand HB 1033. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline