Civil Procedure - As introduced, creates an affirmative defense that may be utilized by a covered entity that is the subject of a data breach, if the covered entity’s cybersecurity program meets certain criteria at the time the breach occurs. - Amends TCA Title 20; Title 29 and Title 47, Chapter 18.
SB 1421 creates an affirmative defense for businesses that experience data breaches if they maintained a written cybersecurity program meeting industry-recognized standards at the time of the breach. It applies to "covered entities" (businesses handling personal information, health data, or sensitive restricted information) and requires written security protocols based on frameworks like NIST, annual risk assessments, and employee training. Businesses using this defense must prove their program met these criteria when the breach occurred. This defense applies only to lawsuits alleging inadequate security controls, not to breaches resulting from known threats the business ignored.
Bill status
in committee
1 of 4 stages cleared
Introduction
Feb 2025
Committee Review
Floor Vote
Governor
Introduced Feb 10, 2025
Last action Mar 9, 2026
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
4
Key actions
0
Committee
2
Mar 9, 2026
Committee
Assigned to General Subcommittee of Senate Judiciary Committee
lower
Feb 12, 2025
Committee
Passed on Second Consideration, refer to Senate Judiciary Committee
upper
Feb 10, 2025
Introduced
Introduced, Passed on First Consideration
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Raumesh Akbari
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about SB 1421
Scope: TN
Hi! I can help you understand SB 1421. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline