HB 1033 Tennessee House · 114th Regular Session (2025-2026)

Civil Procedure - As introduced, creates an affirmative defense that may be utilized by a covered entity that is the subject of a data breach, if the covered entity’s cybersecurity program meets certain criteria at the time the breach occurs. - Amends TCA Title 20; Title 29 and Title 47, Chapter 18.

HB 1033 (Tennessee) creates a legal defense for businesses that experience a data breach, provided they maintained a cybersecurity program meeting specific standards at the time of the breach. It applies to "covered entities" - businesses handling personal information, health data, or sensitive restricted information - requiring them to have written security protocols aligned with industry frameworks (like NIST). If compliant, these entities can use this defense against lawsuits alleging negligence in data security, excluding breaches from law enforcement requests or authorized employee transmissions. The bill does not change breach notification rules but offers legal protection for businesses meeting its cybersecurity criteria.
Bill status in committee 1 of 4 stages cleared
Introduction
Feb 2025
Committee Review
Floor Vote
Governor
Introduced Feb 6, 2025 Last action Feb 11, 2025
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
4
Key actions
0
Committee
2
Feb 11, 2025
Committee
Assigned to s/c Civil Justice Subcommittee
lower
Feb 10, 2025
Committee
P2C, ref. to Judiciary Committee
lower
Feb 6, 2025
Introduced
Intro., P1C.
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Vincent Dixie
Vincent Dixie
DDemocratic
TN
54