SB 1421 Tennessee Senate · 114th Regular Session (2025-2026)

Civil Procedure - As introduced, creates an affirmative defense that may be utilized by a covered entity that is the subject of a data breach, if the covered entity’s cybersecurity program meets certain criteria at the time the breach occurs. - Amends TCA Title 20; Title 29 and Title 47, Chapter 18.

SB 1421 creates an affirmative defense for businesses that experience data breaches if they maintained a written cybersecurity program meeting industry-recognized standards at the time of the breach. It applies to "covered entities" (businesses handling personal information, health data, or sensitive restricted information) and requires written security protocols based on frameworks like NIST, annual risk assessments, and employee training. Businesses using this defense must prove their program met these criteria when the breach occurred. This defense applies only to lawsuits alleging inadequate security controls, not to breaches resulting from known threats the business ignored.
Bill status in committee 1 of 4 stages cleared
Introduction
Feb 2025
Committee Review
Floor Vote
Governor
Introduced Feb 10, 2025 Last action Mar 9, 2026
Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
4
Key actions
0
Committee
2
Mar 9, 2026
Committee
Assigned to General Subcommittee of Senate Judiciary Committee
lower
Feb 12, 2025
Committee
Passed on Second Consideration, refer to Senate Judiciary Committee
upper
Feb 10, 2025
Introduced
Introduced, Passed on First Consideration
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Raumesh Akbari
Raumesh Akbari
DDemocratic
TN
29